Combofix Log:
ComboFix 07-12-26.4 - Giorgia 2007-12-26 16.59.48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.69 [GMT 1:00]
Eseguito da: C:\Documents and Settings\Giorgia\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\Fonts\Crack.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\hosts
C:\WINDOWS\system32\auhxxwsf.dll
C:\WINDOWS\system32\batloucd.dll
C:\WINDOWS\system32\bhefqofh.dll
C:\WINDOWS\system32\bswfhdmx.exe
C:\WINDOWS\system32\byxvtus.dll
C:\WINDOWS\system32\cbxvsrp.dll
C:\WINDOWS\system32\cbxvwwu.dll
C:\WINDOWS\system32\ccsamexd.ini
C:\WINDOWS\system32\evwkddyf.dll
C:\WINDOWS\system32\fcfdwwgr.ini
C:\WINDOWS\system32\fswxxhua.ini
C:\WINDOWS\system32\gbalmoxw.ini
C:\WINDOWS\system32\hfoqfehb.ini
C:\WINDOWS\system32\iwxrnwbh.exe
C:\WINDOWS\system32\jmapwosg.exe
C:\WINDOWS\system32\jrmwitid.dll
C:\WINDOWS\system32\lmueofot.exe
C:\WINDOWS\system32\nfanaqey.dll
C:\WINDOWS\system32\opnmmmj.dll
C:\WINDOWS\system32\prnugyio.dll
C:\WINDOWS\system32\qbtkpfci.exe
C:\WINDOWS\system32\qgekoete.exe
C:\WINDOWS\system32\qjfmcsmn.dll
C:\WINDOWS\system32\qkrmxbdd.ini
C:\WINDOWS\system32\rnkoasya.dll
C:\WINDOWS\system32\rqrqnnm.dll
C:\WINDOWS\system32\service.exe
C:\WINDOWS\system32\srgootji.ini
C:\WINDOWS\system32\uninstall.exe
C:\WINDOWS\system32\uxwvw.ini
C:\WINDOWS\system32\uxwvw.ini2
C:\WINDOWS\system32\veepyowf.ini
C:\WINDOWS\system32\vpfsuqfo.exe
C:\WINDOWS\system32\vuvmvrho.exe
C:\WINDOWS\system32\wmkolaos.exe
C:\WINDOWS\system32\wvwxu.dll
C:\WINDOWS\system32\xfujicaa.dll
C:\WINDOWS\system32\yayaxvt.dll
C:\WINDOWS\Fonts\'
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Creati Da 2007-11-26 al 2007-12-26 )))))))))))))))))))))))))))))))))))
.
2007-12-22 19:22 . 2007-12-22 19:22 1,424 --a------ C:\WINDOWS\system32\host5.zip
2007-12-21 10:47 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-12-17 12:13 . 2007-12-17 12:13 <DIR> d-------- C:\Programmi\Plant Tycoon
2007-12-17 10:51 . 2007-12-17 10:51 <DIR> d-------- C:\Documents and Settings\Giorgia\Dati applicazioni\Home Sweet Home
2007-12-15 18:17 . 2007-12-15 18:17 876 --a------ C:\WINDOWS\$_hpcst$.hpc
2007-12-15 16:58 . 2007-12-15 16:58 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-12-13 12:28 . 2007-12-13 12:28 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-13 12:28 . 2007-12-13 12:28 1,409 --a------ C:\WINDOWS\QTFont.for
2007-11-26 11:36 . 2007-11-27 18:58 <DIR> d-------- C:\Documents and Settings\Giorgia\Dati applicazioni\Dcads Advanced Toolbar
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-26 15:33 --------- d---a-w C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2007-12-25 16:19 --------- d-----w C:\Programmi\eMule
2007-12-21 17:32 --------- d-----w C:\Documents and Settings\Giorgia\Dati applicazioni\SolidDocuments
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-11-26 11:00 --------- d-----w C:\Documents and Settings\Giorgia\Dati applicazioni\Adssite Advanced Toolbar
2007-11-12 17:57 --------- d-----w C:\Documents and Settings\Giorgia\Dati applicazioni\MysteryStudio
2007-11-12 17:47 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\JollyBear
2007-11-10 12:21 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Fugazo
2007-11-05 11:53 --------- d-----w C:\Documents and Settings\Giorgia\Dati applicazioni\GameHouse
2007-11-05 11:53 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\n7-89-o9-3r-4t-r9
2007-11-05 08:53 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Microsoft Help
2007-10-29 12:23 --------- d-----w C:\Documents and Settings\Giorgia\Dati applicazioni\Ohana Games
2007-10-29 11:33 --------- d-----w C:\Documents and Settings\Giorgia\Dati applicazioni\ViquaSoft
2007-10-29 10:04 --------- d-----w C:\Documents and Settings\Giorgia\Dati applicazioni\Lavasoft
2005-09-05 07:39 19,544 ----a-w C:\Documents and Settings\Giorgia\Dati applicazioni\GDIPFONTCACHEV1.DAT
2004-11-22 16:00 5,547,008 ----a-w C:\Programmi\pspf.msi
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D39A900-0F3A-4C29-A254-3E65244FDC34}]
C:\Programmi\ContextTool\ContextTool-2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7648AC4A-76F6-4d95-B2C4-F0DBD88E5DD5}]
2007-05-28 07:17 208384 --a------ C:\WINDOWS\system32\wmvploc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Programmi\MSN Messenger\MsnMsgr.exe" []
"PcSync"="C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-06-24 13:08]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 23:39]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="RunDll32 cmicnfg.cpl" []
"EPSON Stylus C62 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.exe" [2002-07-01 04:05]
"QuickTime Task"="C:\Programmi\QuickTime\qttask.exe" [2006-10-25 18:58]
"DataLayer"="C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe" [2005-06-07 10:31]
"PCSuiteTrayApplication"="C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-06-29 14:29]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00]
"iTunesHelper"="C:\Programmi\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"GrooveMonitor"="C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 23:39]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma Loader.lnk - C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2005-05-09 09:44:23]
Alice ti aiuta.lnk - C:\Programmi\Alice ti aiuta\bin\matcli.exe [2005-08-30 08:50:07]
Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
WinZip Quick Pick.lnk - C:\Programmi\WinZip\WZQKPICK.EXE [2006-12-29 16:01:45]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"
S0 ifgbsrci;ifgbsrci;C:\WINDOWS\system32\drivers\qvvrmqhq.sys []
.
Contenuto della cartella 'Scheduled Tasks'
"2007-10-29 12:48:22 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmi\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-12-26 17:12:31
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2007-12-26 17:15:18 - machine was rebooted
Fresh HiJack log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17.22.21, on 26/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Programmi\QuickTime\qttask.exe
C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe
C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\PROGRA~1\FILECO~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programmi\WinZip\WZQKPICK.EXE
C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Hijack This\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Programmi\ContextTool\ContextTool-2.dll (file missing)
O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Programmi\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: PopBlocker Class - {7648AC4A-76F6-4d95-B2C4-F0DBD88E5DD5} - C:\WINDOWS\system32\wmvploc.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C62 Series" /O6 "USB001" /M "Stylus C62"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) -
http://www.playfirst.com/play/game/wedding...sh.1.0.0.44.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{346CE3E6-CEFF-487D-8062-41622532CFC9}: NameServer = 212.216.172.62,212.216.172.162
O17 - HKLM\System\CCS\Services\Tcpip\..\{9E23121B-051B-4265-97D3-DE26F9093EA0}: NameServer = 85.37.17.6 85.38.28.89
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
--
End of file - 6046 bytes
That's all.
Bye
Thanks