ComboFix 08-01-29.3 - Filippo 2008-01-29 17.58.29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.511 [GMT 0:00]
Eseguito da: C:\Documents and Settings\Filippo\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Filippo\Dati applicazioni\addon.dat
C:\WINDOWS\system32\adsliicx.ini
C:\WINDOWS\system32\ajqytbot.ini
C:\WINDOWS\system32\axdvorpi.ini
C:\WINDOWS\system32\bgfypbee.ini
C:\WINDOWS\system32\bonoiqxk.ini
C:\WINDOWS\system32\bvjellgp.dll
C:\WINDOWS\system32\ccfuqfhd.ini
C:\WINDOWS\system32\cctloudy.ini
C:\WINDOWS\system32\dadohcdm.ini
C:\WINDOWS\system32\degdvqhw.ini
C:\WINDOWS\system32\domcdicg.ini
C:\WINDOWS\system32\dqkxwfhk.ini
C:\WINDOWS\system32\duoikeje.ini
C:\WINDOWS\system32\fjukfeql.dll
C:\WINDOWS\system32\flrxmhoe.ini
C:\WINDOWS\system32\fwoycrti.ini
C:\WINDOWS\system32\gqdgwlpc.ini
C:\WINDOWS\system32\gquqklfa.ini
C:\WINDOWS\system32\hbrysatf.ini
C:\WINDOWS\system32\hfmhkibq.dll
C:\WINDOWS\system32\igqynttb.ini
C:\WINDOWS\system32\jvynrhgn.ini
C:\WINDOWS\system32\kqiocmwx.ini
C:\WINDOWS\system32\kxhfrjho.ini
C:\WINDOWS\system32\lqwqoksw.ini
C:\WINDOWS\system32\lsvvwlhd.ini
C:\WINDOWS\system32\lvqloopr.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mhnmtbje.ini
C:\WINDOWS\system32\mivxlequ.ini
C:\WINDOWS\system32\mngidaec.ini
C:\WINDOWS\system32\mnicvysq.ini
C:\WINDOWS\system32\mugjmqbx.ini
C:\WINDOWS\system32\nsbwvoru.ini
C:\WINDOWS\system32\pdvqritj.dll
C:\WINDOWS\system32\pnbggjku.ini
C:\WINDOWS\system32\pnugkbcy.dll
C:\WINDOWS\system32\prldqguh.ini
C:\WINDOWS\system32\quxoigux.ini
C:\WINDOWS\system32\rhtlsclp.ini
C:\WINDOWS\system32\tlulhfpv.ini
C:\WINDOWS\system32\vyovmnas.ini
C:\WINDOWS\system32\walsvypd.ini
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\wkbeqcbo.ini
C:\WINDOWS\system32\wmgplnlr.dll
C:\WINDOWS\system32\wmotjrvx.ini
C:\WINDOWS\system32\wqdmvbqw.ini
C:\WINDOWS\system32\xgglvpvi.ini
C:\WINDOWS\system32\xrvsfqir.dll
C:\WINDOWS\system32\xyccpqir.dll
C:\WINDOWS\system32\yfwhfjlx.ini
C:\WINDOWS\system32\yvpgntmc.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Creati Da 2007-12-28 al 2008-01-29 )))))))))))))))))))))))))))))))))))
.
2008-01-29 17:23 . 2008-01-29 17:53 <DIR> d-------- C:\VundoFix Backups
2008-01-29 16:54 . 2008-01-29 16:54 53,312 --a------ C:\WINDOWS\system32\rdudjodl.exe
2008-01-29 16:08 . 2008-01-29 16:08 53,312 --a------ C:\WINDOWS\system32\lllrwiic.exe
2008-01-29 09:58 . 2008-01-29 09:58 53,312 --a------ C:\WINDOWS\system32\lfoocroi.exe
2008-01-28 18:42 . 2008-01-28 18:42 53,312 --a------ C:\WINDOWS\system32\dsgvripp.exe
2008-01-28 08:40 . 2008-01-28 08:40 53,312 --a------ C:\WINDOWS\system32\ylqwonhd.exe
2008-01-27 09:34 . 2008-01-27 09:34 53,312 --a------ C:\WINDOWS\system32\hctfptvt.exe
2008-01-26 12:53 . 2008-01-26 12:53 53,312 --a------ C:\WINDOWS\system32\fqmfjajt.exe
2008-01-26 09:49 . 2008-01-26 09:49 53,312 --a------ C:\WINDOWS\system32\xcuhhibi.exe
2008-01-25 18:52 . 2008-01-25 18:52 53,312 --a------ C:\WINDOWS\system32\ymkagnay.exe
2008-01-25 09:04 . 2008-01-25 09:04 53,312 --a------ C:\WINDOWS\system32\vtphmqyb.exe
2008-01-24 09:02 . 2008-01-24 09:02 53,312 --a------ C:\WINDOWS\system32\csfxvgld.exe
2008-01-23 19:49 . 2008-01-23 19:49 53,312 --a------ C:\WINDOWS\system32\uqttgbwa.exe
2008-01-23 12:52 . 2008-01-23 12:52 53,312 --a------ C:\WINDOWS\system32\dmtpilri.exe
2008-01-22 21:33 . 2008-01-22 21:33 53,312 --a------ C:\WINDOWS\system32\vltpphht.exe
2008-01-18 19:58 . 2008-01-18 19:58 1,076,330 ---hs---- C:\WINDOWS\system32\degdvqhw.tmp
2008-01-18 12:59 . 2008-01-18 12:59 <DIR> d-------- C:\Programmi\Windows Live Safety Center
2008-01-12 14:00 . 2008-01-12 14:58 <DIR> d-------- C:\QUARANTENA_VIRIT
2008-01-12 13:17 . 2008-01-27 10:08 <DIR> d-------- C:\VEXPLITE
2008-01-12 13:17 . 2008-01-23 13:19 36,480 --a------ C:\WINDOWS\system32\drivers\VIRAGTLT.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-29 17:49 --------- d-----w C:\Documents and Settings\Filippo\Dati applicazioni\vmntoolbar
2008-01-28 20:20 --------- d-----w C:\Programmi\AdunanzA
2008-01-09 20:41 --------- d-----w C:\Programmi\EA SPORTS
2007-12-23 20:00 20,816 ----a-w C:\Documents and Settings\Filippo\tezuaxea.exe
2007-12-21 20:00 48,884 ----a-w C:\Programmi\update.zip
2007-12-15 14:34 --------- d-----w C:\Programmi\Polar
2007-12-02 14:00 32,764 ----a-w C:\WINDOWS\17PHolmes2000351.exe
2007-12-01 11:10 --------- d-----w C:\Programmi\GUILD WARS
2007-11-29 13:53 --------- d-----w C:\Programmi\THQ
2007-02-09 16:43 386,630 --sha-r C:\Programmi\wunauclt.zip
2007-02-09 16:43 386,630 --sha-r C:\Programmi\wunauclt.tbe
2006-08-27 13:38 1,015,973 --sha-r C:\Programmi\serial.zip
2006-08-27 13:38 1,015,973 --sha-r C:\Programmi\serial.tde
2006-08-27 13:19 56,239 ----a-w C:\Programmi\svchosts.tbe
2006-06-23 06:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
2005-09-28 08:56 185,856 ----a-w C:\Programmi\7za.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7F82CB68-7BFE-477C-B6E8-769D30597B00}]
C:\WINDOWS\system32\ssqrq.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 13:39 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-09-13 09:12 139264]
"MsnMsgr"="C:\Programmi\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 19:53 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Programmi\Analog Devices\Core\smax4pnp.exe" [2006-05-01 10:07 843776]
"SoundMAX"="C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" [2006-04-10 07:19 729088]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-06-02 08:45 385024]
"ATICCC"="C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 15:41 45056]
"RemoteControl"="C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 18:24 32768]
"nod32kui"="C:\Programmi\Eset\nod32kui.exe" [2006-10-14 10:03 921600]
"NeroFilterCheck"="C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"Lexmark 1200 Series"="C:\Programmi\Lexmark 1200 Series\lxczbmgr.exe" [2006-03-16 07:20 57344]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"DAEMON Tools-1033"="C:\Programmi\D-Tools\daemon.exe" [2004-08-22 16:05 81920]
"I downloaded pirated Software from P2P"="Virtua Tennis 3" []
"I downloaded pirated Software from P2P "="NHL Live 2007" []
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"VIRIT LITE MONITOR"="C:\VEXPLITE\MONLITE.EXE" [2008-01-26 13:23 245760]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-19 13:39 160256]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 13:39 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"helpsvc"=2 (0x2)
"ERSvc"=2 (0x2)
R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-01-23 13:19]
R2 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2008-01-26 13:23]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{49491f1f-5b6b-11db-b658-806d6172696f}]
\Shell\AutoRun\command - D:\ASUSACPI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C5CD9787-54F4-6B5A-7054-5E50F28A8F48}]
C:\WINDOWS\crack\crack.exe s
.
Contenuto della cartella 'Scheduled Tasks'
"2007-12-02 14:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\wunauclt.exe
"2008-01-29 17:38:06 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Programmi\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-29 18:07:58
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\Programmi\Eset\pr_imon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Eset\nod32krn.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\VEXPLITE\viritsvc.exe
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\Programmi\Analog Devices\SoundMAX\Smax4.exe
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmi\Eset\nod32kui.exe
C:\Programmi\Lexmark 1200 Series\lxczbmgr.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\Lexmark 1200 Series\lxczbmon.exe
C:\Programmi\D-Tools\daemon.exe
C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\VEXPLITE\MONLITE.EXE
C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
C:\Programmi\MSN Messenger\MsnMsgr.Exe
C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\Programmi\MSN Messenger\usnsvc.exe
C:\Programmi\Eset\nod32.exe
C:\VEXPLITE\VIRITEXP.EXE
.
**************************************************************************
.
Ora fine scansione: 2008-01-29 18:10:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 18:10:28
VundoFix V6.7.7
Checking Java version...
Sun Java not detected
Scan started at 17.23.56 29/01/2008
Listing files found while scanning....
C:\WINDOWS\system32\dafymbxg.dll
C:\WINDOWS\system32\fjukfeql.dll
C:\WINDOWS\system32\fxqlsblv.dll
C:\WINDOWS\system32\gelnryjw.dll
C:\WINDOWS\system32\gqyposgj.dll
C:\windows\system32\haxynvri.dllbox
C:\WINDOWS\system32\hboqcdcl.dll
C:\WINDOWS\system32\hphewyhu.dll
C:\WINDOWS\system32\jtatqcvo.dll
C:\WINDOWS\system32\kpuncnmi.dll
C:\WINDOWS\system32\lqefkujf.ini
C:\WINDOWS\system32\nxryxaxv.dll
C:\WINDOWS\system32\obsajuwv.dll
C:\WINDOWS\system32\oenquejc.dll
C:\WINDOWS\system32\pbjobodc.dll
C:\WINDOWS\system32\qrqss.bak1
C:\WINDOWS\system32\qrqss.bak2
C:\WINDOWS\system32\qrqss.ini
C:\WINDOWS\system32\qrqss.ini2
C:\WINDOWS\system32\qrqss.tmp
C:\WINDOWS\system32\qslqfsbh.dll
C:\WINDOWS\system32\rjlwvyiy.dll
C:\WINDOWS\system32\sefvchar.dll
C:\WINDOWS\system32\ssqrq.dll
C:\WINDOWS\system32\tdamsrhx.dll
C:\WINDOWS\system32\tgfkxcap.dll
C:\WINDOWS\system32\thtsnuxp.dll
C:\WINDOWS\system32\tpwiutxa.dll
C:\WINDOWS\system32\udheinhq.dll
C:\WINDOWS\system32\uokquylv.dll
C:\WINDOWS\system32\xgucylam.dll
C:\WINDOWS\system32\xixkhble.dll
C:\WINDOWS\system32\xljfhwfy.dll
C:\WINDOWS\system32\xyccpqir.dll
C:\WINDOWS\system32\yvpgntmc.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\dafymbxg.dll
C:\WINDOWS\system32\dafymbxg.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\fjukfeql.dll
C:\WINDOWS\system32\fjukfeql.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\fxqlsblv.dll
C:\WINDOWS\system32\fxqlsblv.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\gelnryjw.dll
C:\WINDOWS\system32\gelnryjw.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\gqyposgj.dll
C:\WINDOWS\system32\gqyposgj.dll Has been deleted!
Attempting to delete C:\windows\system32\haxynvri.dllbox
C:\windows\system32\haxynvri.dllbox Has been deleted!
Attempting to delete C:\WINDOWS\system32\hboqcdcl.dll
C:\WINDOWS\system32\hboqcdcl.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\hphewyhu.dll
C:\WINDOWS\system32\hphewyhu.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\jtatqcvo.dll
C:\WINDOWS\system32\jtatqcvo.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\kpuncnmi.dll
C:\WINDOWS\system32\kpuncnmi.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\lqefkujf.ini
C:\WINDOWS\system32\lqefkujf.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\nxryxaxv.dll
C:\WINDOWS\system32\nxryxaxv.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\obsajuwv.dll
C:\WINDOWS\system32\obsajuwv.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\oenquejc.dll
C:\WINDOWS\system32\oenquejc.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\pbjobodc.dll
C:\WINDOWS\system32\pbjobodc.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\qrqss.bak1
C:\WINDOWS\system32\qrqss.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\qrqss.bak2
C:\WINDOWS\system32\qrqss.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\qrqss.ini
C:\WINDOWS\system32\qrqss.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\qrqss.ini2
C:\WINDOWS\system32\qrqss.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\qrqss.tmp
C:\WINDOWS\system32\qrqss.tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\qslqfsbh.dll
C:\WINDOWS\system32\qslqfsbh.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\rjlwvyiy.dll
C:\WINDOWS\system32\rjlwvyiy.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\sefvchar.dll
C:\WINDOWS\system32\sefvchar.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ssqrq.dll
C:\WINDOWS\system32\ssqrq.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tdamsrhx.dll
C:\WINDOWS\system32\tdamsrhx.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tgfkxcap.dll
C:\WINDOWS\system32\tgfkxcap.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\thtsnuxp.dll
C:\WINDOWS\system32\thtsnuxp.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tpwiutxa.dll
C:\WINDOWS\system32\tpwiutxa.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\udheinhq.dll
C:\WINDOWS\system32\udheinhq.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\uokquylv.dll
C:\WINDOWS\system32\uokquylv.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\xgucylam.dll
C:\WINDOWS\system32\xgucylam.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\xixkhble.dll
C:\WINDOWS\system32\xixkhble.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Aspetto notizie!!! Scusate il rita

rdo!!