ok, scan completed, i do not have recovery console installed, (when combo fix prompted for the download , it was during restart and the lan drivers hadn't loaded yet) but i have already created a restore point when i first spotted the virus though, (will attempt to install recovery console manually) thankyou…
ComboFix 10-05-16.02 - dani 17/05/2010 17.09.07.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.447.96 [GMT 2:00]
Eseguito da: e:\documents and settings\dani\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Sygate Personal Firewall *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_SSHNAS
——-\Service_SSHNAS
((((((((((((((((((((((((( Files Creati Da 2010-04-17 al 2010-05-17 )))))))))))))))))))))))))))))))))))
.
2010-05-12 06:08 . 2010-05-12 06:08 ——– d—–w- e:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Apple
2010-05-12 02:02 . 2010-05-12 02:02 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\TEMP
2010-05-12 01:44 . 2006-06-19 10:01 69632 —-a-w- e:\windows\system32\ztvcabinet.dll
2010-05-12 01:44 . 2006-05-25 12:52 162304 —-a-w- e:\windows\system32\ztvunrar36.dll
2010-05-12 01:44 . 2005-08-25 22:50 77312 —-a-w- e:\windows\system32\ztvunace26.dll
2010-05-12 01:44 . 2003-02-02 17:06 153088 —-a-w- e:\windows\system32\UNRAR3.dll
2010-05-12 01:44 . 2002-03-05 22:00 75264 —-a-w- e:\windows\system32\unacev2.dll
2010-05-12 01:44 . 2010-05-12 01:44 ——– d—–w- e:\programmi\Trojan Remover
2010-05-12 01:44 . 2010-05-12 01:44 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\Simply Super Software
2010-05-12 01:44 . 2010-05-12 01:44 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\Simply Super Software
2010-05-06 03:07 . 2010-05-06 03:25 ——– d—–w- e:\programmi\ERUNT
2010-05-06 02:18 . 2010-05-06 02:18 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\Driver Whiz
2010-05-06 01:34 . 2010-05-06 01:34 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\Media Player Classic
2010-05-04 22:45 . 2010-05-04 22:45 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\Facebook
2010-05-04 15:47 . 2010-05-04 15:47 57272 —ha-w- e:\windows\system32\mlfcache.dat
2010-04-29 13:43 . 2010-04-29 13:43 ——– d—–w- e:\programmi\Trend Micro
2010-04-25 04:13 . 2010-05-15 18:48 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\vlc
2010-04-25 01:19 . 2010-04-25 01:19 ——– d—–w- e:\programmi\Mozilla ActiveX Control v1.7.12
2010-04-25 01:17 . 2010-04-25 01:19 ——– d—–w- e:\programmi\Graboid
2010-04-18 00:56 . 2010-04-18 00:56 ——– d—–w- e:\programmi\MSECache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-15 16:43 . 2010-02-11 16:34 664 —-a-w- e:\documents and settings\dani\Impostazioni locali\Dati applicazioni\d3d9caps.dat
2010-05-12 14:44 . 2010-02-21 15:33 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-05-08 12:56 . 2010-01-11 01:17 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\avg9
2010-05-06 03:22 . 2010-02-03 13:53 ——– d—–w- e:\programmi\TrojanHunter 5.0
2010-05-06 03:21 . 2010-04-17 11:47 ——– d—–w- e:\programmi\Panda Security
2010-05-05 14:21 . 2010-01-14 02:18 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\Soulseek
2010-04-26 07:16 . 2001-08-31 15:00 96334 —-a-w- e:\windows\system32\perfc010.dat
2010-04-26 07:16 . 2001-08-31 15:00 516544 —-a-w- e:\windows\system32\perfh010.dat
2010-04-23 18:33 . 2010-01-11 02:06 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\Skype
2010-04-23 18:06 . 2010-03-10 12:51 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\skypePM
2010-04-21 07:23 . 2010-01-11 01:17 242896 —-a-w- e:\windows\system32\drivers\avgtdix.sys
2010-04-12 23:13 . 2010-01-17 23:04 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\Intelliremote
2010-04-10 01:30 . 2010-04-10 01:30 ——– d—–w- e:\programmi\File comuni\Java
2010-04-10 01:29 . 2010-01-14 01:20 ——– d—–w- e:\programmi\Java
2010-03-18 15:58 . 2010-01-27 16:56 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\dvdcss
2010-03-13 11:30 . 2010-03-13 11:30 12464 —-a-w- e:\windows\system32\avgrsstx.dll
2010-03-13 11:30 . 2010-01-11 01:17 29512 —-a-w- e:\windows\system32\drivers\avgmfx86.sys
2010-03-13 11:28 . 2010-01-11 01:17 216200 —-a-w- e:\windows\system32\drivers\avgldx86.sys
2010-03-10 12:51 . 2010-03-10 12:51 56 —ha-w- e:\windows\system32\ezsidmv.dat
2010-03-10 06:15 . 2004-08-19 13:39 420352 —-a-w- e:\windows\system32\vbscript.dll
2010-03-09 02:28 . 2010-01-14 01:21 411368 —-a-w- e:\windows\system32\deploytk.dll
2010-02-25 06:16 . 2004-08-19 13:39 916480 —-a-w- e:\windows\system32\wininet.dll
2010-02-24 13:11 . 2004-08-03 21:15 455680 —-a-w- e:\windows\system32\drivers\mrxsmb.sys
2010-02-21 16:21 . 2010-01-10 23:09 76184 —-a-w- e:\documents and settings\dani\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-02-21 15:00 . 2010-02-21 15:00 691696 —-a-w- e:\windows\system32\drivers\sptd.sys
2010-02-16 19:05 . 2004-08-19 13:34 2149888 —-a-w- e:\windows\system32\ntoskrnl.exe
2010-02-16 19:05 . 2004-08-19 15:34 2028032 —-a-w- e:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="e:\programmi\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="e:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"PHIME2002ASync"="e:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="e:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"acerWireless"="e:\programmi\acer\Wireless\Utility\WlanUtil.exe" [2005-01-10 462848]
"SoundMan"="SOUNDMAN.EXE" [2010-01-10 67584]
"SynTPLpr"="e:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2010-01-10 98304]
"SynTPEnh"="e:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2010-01-10 536576]
"AGRSMMSG"="AGRSMMSG.exe" [2010-01-10 88363]
"LtMoh"="e:\programmi\ltmoh\Ltmoh.exe" [2010-01-10 184320]
"QuickTime Task"="e:\programmi\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="e:\programmi\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"SmcService"="e:\progra~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
"SunJavaUpdateSched"="e:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="e:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="e:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"GrooveMonitor"="e:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TrojanScanner"="e:\programmi\Trojan Remover\Trjscan.exe" [2010-02-27 1165192]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 11:30 12464 —-a-w- e:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-07-18 16:55 451872 —-a-w- e:\programmi\File comuni\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883856 —-a-w- e:\programmi\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 —-a-w- e:\programmi\File comuni\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
2009-12-23 19:18 2642168 —-a-w- e:\programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"NBService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Irmon"=2 (0x2)
"idsvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"e:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"e:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"e:\\Programmi\\iTunes\\iTunes.exe"=
"e:\\Programmi\\AVG\\AVG9\\avgemc.exe"=
"e:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"e:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"e:\\Programmi\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"e:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"e:\\Programmi\\Skype\\Phone\\Skype.exe"=
R0 sptd;sptd;e:\windows\system32\drivers\sptd.sys [21/02/2010 17.00.22 691696]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;e:\windows\system32\drivers\avgldx86.sys [11/01/2010 3.17.11 216200]
R1 AvgTdiX;AVG Free Network Redirector;e:\windows\system32\drivers\avgtdix.sys [11/01/2010 3.17.24 242896]
R2 avg9emc;AVG Free E-mail Scanner;e:\programmi\AVG\AVG9\avgemc.exe [13/03/2010 13.28.09 916760]
R2 avg9wd;AVG Free WatchDog;e:\programmi\AVG\AVG9\avgwdsvc.exe [13/03/2010 13.30.16 308064]
S3 IPN2220;acer IPN2220 Wireless LAN Card Driver;e:\windows\system32\drivers\i2220ntx.sys [10/01/2010 18.32.00 160896]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-07-18 16:53 451872 —-a-w- e:\programmi\File comuni\LightScribe\LSRunOnce.exe
.
Contenuto della cartella 'Scheduled Tasks'
2010-05-12 e:\windows\Tasks\AppleSoftwareUpdate.job
- e:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-05-17 e:\windows\Tasks\OGALogon.job
- e:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
2010-05-17 e:\windows\Tasks\WGASetup.job
- e:\windows\system32\KB905474\wgasetup.exe [2010-01-12 21:18]
.
.
——- Scansione supplementare ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - e:\documents and settings\dani\Dati applicazioni\Mozilla\Firefox\Profiles\zs4vq599.default\
FF - plugin: e:\documents and settings\dani\Dati applicazioni\Facebook\npfbplugin_1_0_3.dll
FF - plugin: e:\programmi\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: e:\programmi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: e:\programmi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - e:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
e:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
e:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
e:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
e:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-17 17:25
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti …
scansione entrate autostart nascoste …
Scansione files nascosti …
Scansione completata con successo
Files nascosti: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spcm.sys >>UNKNOWN [0x8438F938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7591f28
\Driver\ACPI -> ACPI.sys @ 0xf73f9cb8
\Driver\atapi -> atapi.sys @ 0xf7370b40
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e710a
ParseProcedure -> ntoskrnl.exe @ 0x80578f7a
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e710a
ParseProcedure -> ntoskrnl.exe @ 0x80578f7a
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
——————— CHIAVI DI REGISTRO BLOCCATE ———————
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\*+áÅ-]
"DisplayName"=""
"DeviceDesc"=""
"ProviderName"=""
"MFG"="????????\02"
"ReinstallString"="??"
"DeviceInstanceIds"=multi:"s\\dani\\documenti\\download\\smbus_ati_5.10.1000.2_xpx86\\smbus_ati_5.10.1000.2_xpx86\\smbus\\smbusati.inf\00"
.
——————— Dlls caricate dai processi in esecuzione ———————
- - - - - - - > 'explorer.exe'(3300)
e:\windows\system32\WININET.dll
e:\windows\system32\SSSensor.dll
e:\windows\system32\webcheck.dll
.
———————— Altri processi in esecuzione ————————
.
e:\programmi\Sygate\SPF\smc.exe
e:\programmi\AVG\AVG9\avgchsvx.exe
e:\programmi\AVG\AVG9\avgrsx.exe
e:\programmi\AVG\AVG9\avgcsrvx.exe
e:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
e:\programmi\Bonjour\mDNSResponder.exe
e:\programmi\Java\jre6\bin\jqs.exe
e:\windows\system32\wdfmgr.exe
e:\programmi\AVG\AVG9\avgnsx.exe
e:\programmi\AVG\AVG9\avgcsrvx.exe
e:\windows\system32\wscntfy.exe
e:\windows\system32\wbem\wmiapsrv.exe
e:\windows\SOUNDMAN.EXE
e:\windows\AGRSMMSG.exe
e:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2010-05-17 17:38:07 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-05-17 15:37
Pre-Run: 37.725.560.832 byte disponibili
Post-Run: 38.263.533.568 byte disponibili
- - End Of File - - F5C0247BF537B66EFE659B810D54A8EA