Tomk,
thanks for your help…
here is the log file for Combofix:
ComboFix 08-10-25.01 - Emilio 2008-10-27 1.24.03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.3095 [GMT 1:00]
Eseguito da: C:\Documents and Settings\Emilio\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Creati Da 2008-09-27 al 2008-10-27 )))))))))))))))))))))))))))))))))))
.
2008-10-27 00:09 . 2008-10-27 00:09 d——– C:\Programmi\Malwarebytes' Anti-Malware
2008-10-27 00:09 . 2008-10-27 00:09 d——– C:\Documents and Settings\Emilio\Dati applicazioni\Malwarebytes
2008-10-27 00:09 . 2008-10-27 00:09 d——– C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
2008-10-27 00:09 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-27 00:09 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-26 21:47 . 2008-10-26 21:47 d——– C:\Programmi\Trend Micro
2008-10-24 19:45 . 2008-10-25 22:18 373 –a—— C:\WINDOWS\system32\%LocalXml%
2008-10-24 19:08 . 2008-10-24 19:08 16,244 –a—— C:\WINDOWS\system32\rrt_is.wav
2008-10-24 19:08 . 2008-10-24 19:08 7,302 –a—— C:\WINDOWS\system32\rrt_vf.wav
2008-10-24 19:08 . 2008-10-24 19:08 7,148 –a—— C:\WINDOWS\system32\rrt_tv.wav
2008-10-24 19:08 . 2008-10-24 19:08 6,282 –a—— C:\WINDOWS\system32\rrt_tn.wav
2008-10-24 18:35 . 2008-10-24 19:23 d-a—— C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-10-24 14:32 . 2008-10-24 14:33 d——– C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-10-24 11:29 . 2008-10-24 11:37 96,976 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-10-24 11:29 . 2008-10-24 11:37 87,855 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-10-24 11:28 . 2008-10-24 11:28 d——– C:\Programmi\Kaspersky Lab
2008-10-24 11:28 . 2008-10-27 01:25 9,465,376 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-24 11:28 . 2008-10-27 01:25 450,592 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-24 11:28 . 2008-10-27 01:25 76,076 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-24 11:28 . 2008-10-27 01:25 3,668 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-24 10:48 . 2008-10-24 10:48 d——– C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2008-10-24 09:32 . 2008-10-24 09:32 d——– C:\Documents and Settings\All Users\Dati applicazioni\LogiShrd
2008-10-24 09:29 . 2008-10-24 09:29 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2008-10-24 09:28 . 2008-10-24 09:28 d——– C:\Programmi\File comuni\Logishrd
2008-10-24 09:28 . 2008-10-24 09:28 d——– C:\Documents and Settings\Emilio\Dati applicazioni\InstallShield
2008-10-24 09:28 . 2008-05-02 01:38 301,656 –a—— C:\WINDOWS\system32\BtCoreIf.dll
2008-10-24 09:27 . 2008-10-15 17:36 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-23 21:00 . 2008-10-23 21:00 92 –a—— C:\WINDOWS\wininit.ini
2008-10-23 14:32 . 2008-10-23 14:32 d——– C:\Temp
2008-10-23 09:48 . 2008-10-23 09:48 d——– C:\Program Files
2008-10-23 09:35 . 2008-10-23 09:35 d——– C:\xampplite
2008-10-16 17:02 . 2008-10-16 17:02 306,432 –a—— C:\WINDOWS\system32\TuneUpDefragService.exe
2008-10-16 17:02 . 2007-12-20 09:41 29,440 –a—— C:\WINDOWS\system32\uxtuneup.dll
2008-10-15 08:56 . 2008-08-14 14:22 2,192,896 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 08:56 . 2008-08-14 14:22 2,148,864 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 08:56 . 2008-08-14 14:22 2,069,760 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 08:56 . 2008-08-14 14:22 2,027,520 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 08:56 . 2008-09-15 16:24 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 08:56 . 2008-09-08 11:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-10 11:29 . 2008-10-19 00:19 d——– C:\Programmi\FileZilla FTP Client
2008-10-10 11:29 . 2008-10-23 09:04 d——– C:\Documents and Settings\Emilio\Dati applicazioni\FileZilla
2008-10-09 09:36 . 2008-10-27 01:25 d——– C:\Programmi\Microsoft Silverlight
2008-10-08 22:35 . 2008-10-08 22:35 d——– C:\Documents and Settings\Emilio\Dati applicazioni\Digsby
2008-10-08 22:34 . 2008-10-16 14:05 d——– C:\Programmi\Digsby
2008-10-07 00:12 . 2008-10-07 00:13 d——– C:\Programmi\Notepad++
2008-10-07 00:12 . 2008-10-07 00:13 d——– C:\Documents and Settings\Emilio\Dati applicazioni\Notepad++
2008-10-06 12:44 . 2008-10-06 13:09 d——– C:\wamp
2008-10-02 00:54 . 2008-10-02 00:54 d——– C:\Programmi\PDFCreator
2008-10-02 00:54 . 2004-03-09 00:00 662,288 –a—— C:\WINDOWS\system32\MSCOMCT2.OCX
2008-10-02 00:54 . 1998-08-05 07:45 150,528 –a—— C:\WINDOWS\system32\MSCMCIT.DLL
2008-10-02 00:54 . 1998-06-24 00:00 137,000 –a—— C:\WINDOWS\system32\MSMAPI32.OCX
2008-10-02 00:54 . 1998-08-05 07:45 122,128 –a—— C:\WINDOWS\system32\VB6IT.DLL
2008-10-02 00:54 . 2001-10-28 16:42 116,224 –a—— C:\WINDOWS\system32\pdfcmnnt.dll
2008-10-02 00:54 . 1998-08-05 07:45 63,488 –a—— C:\WINDOWS\system32\MSCC2IT.DLL
2008-10-02 00:54 . 1998-07-06 00:00 23,552 –a—— C:\WINDOWS\system32\MSMPIDE.DLL
2008-09-30 22:41 . 2008-10-24 14:41 d——– C:\Programmi\Spybot - Search & Destroy
2008-09-30 22:41 . 2008-10-24 14:41 d——– C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-09-30 11:43 . 2008-04-13 19:40 43,904 –a—— C:\WINDOWS\system32\drivers\sbp2port.sys
2008-09-30 11:43 . 2008-04-13 19:40 43,904 –a–c— C:\WINDOWS\system32\dllcache\sbp2port.sys
2008-09-30 08:06 . 2008-09-30 08:06 164 –a—— C:\install.dat
2008-09-29 22:08 . 2008-09-30 22:59 d——– C:\Documents and Settings\Emilio\Dati applicazioni\Antispyware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 23:24 ——— d—–w C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-10-24 18:27 ——— d—–w C:\Programmi\File comuni\Wise Installation Wizard
2008-10-24 08:28 ——— d–h–w C:\Programmi\InstallShield Installation Information
2008-10-24 08:28 ——— d—–w C:\Programmi\File comuni\Logitech
2008-10-22 12:34 ——— d—–w C:\Documents and Settings\Emilio\Dati applicazioni\uTorrent
2008-10-22 12:05 ——— d—–w C:\Programmi\PowerISO
2008-10-16 16:03 ——— d—–w C:\Programmi\TuneUp Utilities 2008
2008-09-25 22:02 ——— d—–w C:\Programmi\MagicISO
2008-09-24 09:43 ——— d—–w C:\Programmi\eMule AdunanzA
2008-09-24 08:10 ——— d—–w C:\Programmi\Foxit Software
2008-09-24 08:02 ——— d—–w C:\Programmi\File comuni\Control Panels
2008-09-24 08:01 ——— d—–w C:\Programmi\File comuni\Adobe
2008-09-24 07:54 ——— d—–w C:\Documents and Settings\All Users\Dati applicazioni\ALM
2008-09-24 07:35 ——— d—–w C:\Programmi\QuickTime
2008-09-24 07:20 ——— d—–w C:\Programmi\Bonjour
2008-09-24 07:08 ——— d—–w C:\Programmi\File comuni\Macrovision Shared
2008-09-23 22:34 ——— d—–w C:\Programmi\uTorrent
2008-09-23 16:14 ——— d—–w C:\Programmi\Microsoft.NET
2008-09-23 16:03 ——— d—–w C:\Programmi\7-Zip
2008-09-23 08:56 ——— d—–w C:\Documents and Settings\Emilio\Dati applicazioni\vlc
2008-09-23 08:54 ——— d—–w C:\Programmi\VideoLAN
2008-09-22 19:51 ——— d—–w C:\Programmi\WinASO
2008-09-22 19:45 ——— d—–w C:\Documents and Settings\Emilio\Dati applicazioni\TuneUp Software
2008-09-22 19:45 ——— d—–w C:\Documents and Settings\All Users\Dati applicazioni\TuneUp Software
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Programmi\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"StartCCC"="C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"DT HPW"="C:\Programmi\Portrait Displays\HP My Display\DTHtml.exe" [2007-01-16 280576]
"ISUSScheduler"="C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"Acrobat Assistant 8.0"="C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
ASUS WiFi-AP Solo.lnk - C:\Programmi\ASUS WiFi-AP Solo\RtWLan.exe [2007-11-22 995328]
Logitech SetPoint.lnk - C:\Programmi\Logitech\SetPoint\SetPoint.exe [2007-11-23 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\Programmi\File comuni\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmi\\uTorrent\\uTorrent.exe"=
"C:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\Italian\\setup.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 24592]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-09-05 176128]
R3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2006-06-23 13532]
S3 AVPsys;AVPsys;C:\WINDOWS\system32\drivers\cdaudio.sys [2001-08-17 18688]
S3 bsusbser;PHD USB Device for Legacy Serial Communication;C:\WINDOWS\system32\DRIVERS\bsusbser.sys [2006-12-20 94848]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-10-16 306432]
S3 wampapache;wampapache;c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe [2008-01-18 24635]
S3 wampmysqld;wampmysqld;c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe wampmysqld [ ]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenuto della cartella 'Scheduled Tasks'
2008-10-24 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Programmi\TuneUp Utilities 2008\OneClick.exe [2008-01-08 12:31]
2008-10-26 C:\WINDOWS\Tasks\User_Feed_Synchronization-{DA3D4D72-6111-4933-912D-2F56E24CB66F}.job
- C:\WINDOWS\system32\msfeedssync.exe [2007-08-13 18:36]
.
.
——- Supplementare di scansione ——-
.
FireFox -: Profile - C:\Documents and Settings\Emilio\Dati applicazioni\Mozilla\Firefox\Profiles\zu8n8cfk.default\
FF -: plugin - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\browser\nppdf32.dll
FF -: plugin - C:\Programmi\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - C:\Programmi\Microsoft Silverlight\2.0.31005.0\npctrl.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-27 01:27:03
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti …
scansione entrate autostart nascoste …
Scansione files nascosti …
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="C:/FoxServ/mysql/bin/mysqld-nt.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="C:/FoxServ/mysql/bin/mysqld-nt.exe"
.
———————— Altri processi in esecuzione ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\File comuni\Portrait Displays\Shared\DTSRVC.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Programmi\File comuni\Portrait Displays\Shared\HookManager.exe
C:\ComboFix\catchme.tmp
C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Programmi\File comuni\Logishrd\KHAL2\KHALMNPR.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Ora fine scansione: 2008-10-27 1:32:14 - macchina è stato riavviato
ComboFix-quarantined-files.txt 2008-10-27 00:32:12
Pre-Run: 296.418.336.768 byte disponibili
Post-Run: 297,510,592,512 byte disponibili
WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
;
;Warning: Boot.ini is used on Windows XP and earlier operating systems.
;Warning: Use BCDEDIT.exe to modify Windows Vista boot options.
;
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /NOEXECUTE=OPTIN /FASTDETECT /USEPMTIMER
215 — E O F — 2008-10-24 08:39:45
FYI the dtp didn't give any problem while running Combofix.
all those steps made me think to a quick question (will also be good for me to learn something…. if the answer is too long feel free not to answer):
- even though i have Kaspersky Internet Security 2009 with all its firewall/antivirus features i am not completely safe from Malware, Trojan, virus etc…. this is because, even though i have a firewall activated to block all "suspect" activities, a virus (or trojan or malware) might be hidden behind a fully trusted app (such as a windows, Office, flash etc!!!). am i correct?
Thanks,
Emil