Luke57 ha scritto:
Riavvia il pc, collegati e posta questi 2 logs (copiandoli e incollandoli in un post)
C:\vundofix.txt
C:\combofix.txt
ecco i log:
Vundo:
VundoFix V7.0.3
Scan started at 10.24.04 06/05/2008
Listing files found while scanning....
No infected files were found.
Combo:
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Eddy\Dati applicazioni\inst.exe
C:\WINNT\system32\config\SAM.SAV
C:\WINNT\system32\kbdit142n.dll
C:\WINNT\Web\default.htt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_fuhyvngm
-------\Service_fuhyvngm
((((((((((((((((((((((((( Files Creati Da 2008-04-06 al 2008-05-06 )))))))))))))))))))))))))))))))))))
.
2008-05-06 10:37 . 08-05-06 10:37 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_20c.dat
2008-05-03 18:24 . 08-05-03 18:24 <DIR> d---s---- C:\Documents and Settings\Eddy\UserData
2008-05-03 18:11 . 08-05-03 18:11 <DIR> d-------- C:\Programmi\Dnote Software
2008-05-02 19:27 . 08-05-02 19:27 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2008-05-02 19:26 . 08-05-02 19:26 <DIR> d-------- C:\Programmi\SUPERAntiSpyware
2008-05-02 19:26 . 08-05-02 19:26 <DIR> d-------- C:\Documents and Settings\Eddy\Dati applicazioni\SUPERAntiSpyware.com
2008-05-02 18:31 . 08-05-02 18:31 <DIR> d--h----- C:\WINNT\msdownld.tmp
2008-05-02 18:01 . 08-05-02 18:01 1,144 --a------ C:\WINNT\mozver.dat
2008-05-02 17:03 . 08-05-02 17:39 1,410 --a------ C:\WINNT\imsins.BAK
2008-05-02 16:49 . 08-05-04 13:06 367,410 ---h----- C:\WINNT\ShellIconCache
2008-05-02 12:19 . 08-05-02 12:19 <DIR> d-------- C:\VundoFix Backups
2008-05-02 12:01 . 02-05-15 15:16 462,848 --a------ C:\WINNT\system32\msaatext.dll
2008-05-02 12:01 . 02-05-15 15:16 360,448 --a------ C:\WINNT\system32\oleacc.dll
2008-05-02 12:01 . 02-05-15 15:16 360,448 --a------ C:\WINNT\system32\dllcache\oleacc.dll
2008-05-02 12:01 . 02-05-15 15:16 356,352 --a------ C:\WINNT\system32\oleaccrc.dll
2008-05-02 12:01 . 02-05-15 15:16 356,352 --a------ C:\WINNT\system32\dllcache\oleaccrc.dll
2008-04-30 19:53 . 08-04-30 19:53 <DIR> d-------- C:\FOUND.000
2008-04-30 19:27 . 08-04-30 19:27 <DIR> d-------- C:\WINNT\IE Uninstall
2008-04-30 19:17 . 08-04-30 19:17 <DIR> d-------- C:\WINNT\Application Data
2008-04-30 18:54 . 03-06-19 12:05 618,889 --a------ C:\WINNT\system32\instcat.sql
2008-04-30 18:54 . 03-06-19 12:05 4,296 --a------ C:\WINNT\system32\odbcconf.rsp
2008-04-30 18:23 . 08-04-30 18:23 <DIR> d-------- C:\Programmi\Free Window Registry Repair
2008-04-30 14:55 . 08-04-30 14:55 <DIR> d-------- C:\Documents and Settings\Eddy\Dati applicazioni\Grisoft
2008-04-30 14:55 . 07-05-30 14:10 10,872 --a------ C:\WINNT\system32\drivers\AvgAsCln.sys
2008-04-30 12:44 . 08-04-30 12:44 <DIR> d-------- C:\Programmi\Opera
2008-04-30 10:53 . 08-04-30 10:53 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-04-30 10:49 . 08-04-30 10:49 <DIR> d-------- C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2008-04-30 10:35 . 08-04-30 10:35 <DIR> d-------- C:\Programmi\File comuni\Mozilla Shared
2008-04-30 10:35 . 08-04-30 10:35 196,608 --a------ C:\WINNT\system32\libssl32.dll
2008-04-24 18:25 . 08-04-24 18:25 <DIR> d-------- C:\Programmi\TomTom HOME 2
2008-04-24 18:25 . 08-04-24 18:25 <DIR> d-------- C:\Documents and Settings\Eddy\Dati applicazioni\TomTom
2008-04-24 11:46 . 08-04-24 12:46 128 --a------ C:\WINNT\CTWave32.ini
2008-04-16 11:33 . 08-04-16 11:33 <DIR> d-------- C:\Programmi\Tom-TOOLS 7V.5
2008-04-15 20:14 . 08-04-19 11:59 852 --a------ C:\WINNT\BetPC2007.ini
2008-04-15 19:13 . 08-04-15 19:13 <DIR> d-------- C:\Programmi\HappySoft
2008-04-15 19:13 . 08-04-15 19:13 <DIR> d-------- C:\Programmi\File comuni\HappySoft
2008-04-15 19:13 . 07-12-01 17:30 406,528 --a------ C:\WINNT\system32\betpc_images.dll
2008-04-12 18:51 . 08-04-12 18:51 <DIR> d--h----- C:\LGFolder
2008-04-12 18:50 . 08-04-12 18:50 <DIR> d-------- C:\Documents and Settings\Eddy\Dati applicazioni\LG Electronics
2008-04-12 18:49 . 08-04-12 18:49 <DIR> d-------- C:\Programmi\LG PC Suite
2008-04-12 18:48 . 08-04-12 18:48 <DIR> d-------- C:\Programmi\LG Electronics
2008-04-12 18:48 . 05-06-24 18:36 39,036 --a------ C:\WINNT\system32\drivers\lgusbmodem.sys
2008-04-12 18:48 . 05-05-26 11:01 38,144 --a------ C:\WINNT\system32\drivers\lgusbdiag.sys
2008-04-12 18:48 . 05-05-26 11:01 21,344 --a------ C:\WINNT\system32\drivers\lgusbbus.sys
2008-04-09 13:15 . 08-04-09 13:15 <DIR> d-------- C:\Documents and Settings\Eddy\Dati applicazioni\dvdcss
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-30 08:35 1,015,808 ----a-w C:\WINNT\system32\libeay32.dll
2008-04-05 17:27 --------- d-----w C:\Programmi\TomTom HOME
2008-04-03 17:11 --------- d-----w C:\Programmi\PokerStars.NET
2008-04-02 17:37 --------- d-----w C:\Programmi\Tom-TOOLS (7V4)
2008-04-01 09:23 --------- d-----w C:\Documents and Settings\Eddy\Dati applicazioni\DisplayTune
2008-04-01 09:22 --------- d-----w C:\Programmi\Portrait Displays
2008-04-01 09:22 --------- d-----w C:\Programmi\File comuni\Portrait Displays
2008-04-01 09:00 --------- d-----w C:\Programmi\PowerStrip
2008-03-29 14:57 74,752 ----a-w C:\WINNT\ST6UNST.EXE
2008-03-29 14:57 122,880 ------w C:\WINNT\Setup2.exe
2008-03-29 14:44 --------- d-----w C:\Programmi\Gazza
2008-03-19 16:52 74,752 ----a-w C:\WINNT\cadkasdeinst01e.exe
2008-03-19 16:52 --------- d-----w C:\Programmi\PDF Editor 2
2008-03-14 15:23 47,360 ----a-w C:\WINNT\system32\drivers\pcouffin.sys
2008-03-14 15:23 47,360 ----a-w C:\Documents and Settings\Eddy\Dati applicazioni\pcouffin.sys
2008-03-13 15:37 --------- d-----w C:\Programmi\WinAVIVideoConverter
2008-03-11 16:18 --------- d-----w C:\Documents and Settings\Eddy\Dati applicazioni\InstallShield
2008-03-07 09:17 --------- d-----w C:\Programmi\directx
2008-01-23 22:54 271 ---h--w C:\Programmi\desktop.ini
2008-01-23 22:54 22,075 ---h--w C:\Programmi\folder.htt
2000-08-10 22:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3674680A-2FFE-406B-95EE-F1D2724F1DC3}]
00-08-11 00:00 82432 --a------ c:\winnt\system32\kbdit142n.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [08-05-02 20:17 1481968]
"Uniblue RegistryBooster 2"="C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zone Labs Client"="C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe" [05-11-15 00:51 755472]
"NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [01-07-09 11:50 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [00-08-11 00:00 20752 C:\WINNT\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Programmi\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 20:05 188176]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office\OSA9.EXE [2000-01-21 09:15:56 65588]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmi\SUPERAntiSpyware\SASSEH.DLL [06-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmi\SUPERAntiSpyware\SASWINLO.dll 07-04-19 13:41 294912 C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wqpehtgw]
kbdit142n.dll 00-08-11 00:00 82432 C:\WINNT\system32\kbdit142n.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
R1 aswSP;avast! Self Protection;C:\WINNT\system32\drivers\aswSP.sys [08-03-29 19:31 ]
R2 aswMon;avast! Standard Shield Support;C:\WINNT\system32\drivers\aswMon.sys [08-01-17 17:34 ]
R2 PStrip;PSTRIP;C:\WINNT\system32\DRIVERS\PSTRIP.SYS [07-07-15 03:37 ]
R3 S3SAVAGE4;S3SAVAGE4;C:\WINNT\system32\DRIVERS\s3savg4m.sys [00-08-10 14:03 ]
S3 DLKRTL;D-Link DFE-528TX PCI Adapter NT Driver;C:\WINNT\system32\DRIVERS\DLKRTL.SYS [01-10-10 10:37 ]
S3 S3Inc;S3Inc;C:\WINNT\system32\DRIVERS\s3sav4m.sys [99-10-25 23:35 ]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
fuhyvngm
*Newly Created Service* - IPNAT
*Newly Created Service* - RASAUTO
*Newly Created Service* - SHAREDACCESS
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-06 10:37:55
Windows 5.0.2195 Service Pack 4 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
C:\WINNT\TEMP\_avast4_\unp194323454.tmp 327680 bytes
Scansione completata con successo
Files nascosti: 1
**************************************************************************
.
Ora fine scansione: 2008-05-06 10:39:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-06 08:39:42
13 Directory 8,032,092,160 byte disponibili
17 Directory 7,978,352,640 byte disponibili
143
Cmnq, anche dopo ste scansione IE non si avvia