Ciao a tutti. Anche io ho avuto il problema degli URL bloccati, e leggendo il post sono riuscito a risolvere con Combofix. Tuttavia noto ancora una lentezza della connessione, e ogni tanto vedo che il mio PC si connette a degli indirizzi che no conosco. Vorrei quindi pubblicare di seguito il mio ComboFix.txt dell'ultima esecuzione per controllare se, oltre la dll che bloccava gli indirizzi, non si entrato anche qualche backdoor che non sono riuscito ad inviduare. Se qualcuno più esperto di me potesse darci un'occhiata, gliene sarei grato.
Grazie dell'aiuto:
ComboFix 09-10-01.05 - Riccardo 04/10/2009 22.34.24.4.2 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.39.1033.18.3070.2074 [GMT 1:00]
Eseguito da: c:\users\Riccardo\Desktop\abc.exe
Opzioni usate :: /killall
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 0 bytes in 1 streams. ((((((((((((((((((((((((( Files Creati Da 2009-09-04 al 2009-10-04 )))))))))))))))))))))))))))))))))))
.
2009-10-04 21:38 . 2009-10-04 21:38 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-10-04 21:38 . 2009-10-04 21:38 -------- d-----w- c:\users\GestPay\AppData\Local\temp
2009-10-04 21:38 . 2009-10-04 21:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-04 19:02 . 2009-10-04 19:04 -------- d-----w- c:\windows\system32\ca-ES
2009-10-04 19:02 . 2009-10-04 19:04 -------- d-----w- c:\windows\system32\eu-ES
2009-10-04 19:02 . 2009-10-04 19:04 -------- d-----w- c:\windows\system32\vi-VN
2009-10-04 13:46 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-10-04 13:46 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-10-04 13:45 . 2009-10-04 13:45 -------- d-----w- c:\program files\iPod
2009-10-04 13:45 . 2009-10-04 13:46 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-04 13:45 . 2009-10-04 13:46 -------- d-----w- c:\program files\iTunes
2009-10-04 00:59 . 2009-10-04 00:59 -------- d-----w- c:\windows\system32\EventProviders
2009-10-04 00:57 . 2009-04-11 06:28 747008 ----a-w- c:\windows\system32\WsmSvc.dll
2009-10-04 00:02 . 2009-10-04 21:43 -------- d-----w- c:\users\Riccardo\AppData\Local\temp
2009-10-03 00:48 . 2009-10-01 09:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-30 15:39 . 2009-09-30 15:39 -------- d-----w- c:\program files\Microsoft
2009-09-22 15:25 . 2009-09-22 15:25 -------- d-----w- c:\program files\gs
2009-09-22 15:19 . 2009-09-22 15:19 -------- d-----w- c:\programdata\PlotSoft
2009-09-22 15:19 . 2009-09-22 15:19 -------- d-----w- c:\program files\PlotSoft
2009-09-22 13:57 . 2009-10-02 12:34 -------- d-----w- c:\users\Riccardo\AppData\Roaming\Nitro PDF
2009-09-22 13:57 . 2009-09-15 09:16 17728 ----a-w- c:\windows\system32\nitrolocalui.dll
2009-09-22 13:57 . 2009-09-15 09:15 26432 ----a-w- c:\windows\system32\nitrolocalmon.dll
2009-09-22 13:57 . 2009-09-22 13:57 -------- d-----w- c:\programdata\Nitro PDF
2009-09-22 13:57 . 2009-09-22 13:57 -------- d-----w- c:\program files\Nitro PDF
2009-09-22 13:57 . 2009-09-22 13:57 -------- d-----w- c:\program files\Common Files\Nitro PDF
2009-09-22 13:56 . 2009-09-22 13:56 -------- d-----w- c:\users\Riccardo\AppData\Roaming\Downloaded Installations
2009-09-16 13:53 . 2009-09-16 13:53 -------- d-----w- c:\program files\QuickTime
2009-09-15 09:17 . 2009-09-15 09:17 61760 ----a-w- c:\windows\system32\ASTSRV.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-04 21:42 . 2008-10-21 08:44 32156 ----a-w- c:\programdata\nvModes.dat
2009-10-04 21:38 . 2008-10-21 07:47 12 ----a-w- c:\windows\bthservsdp.dat
2009-10-04 19:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-10-04 19:05 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-04 19:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-10-04 19:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-10-04 19:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-10-04 19:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-10-04 19:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-10-04 15:42 . 2009-03-16 22:24 -------- d-----w- c:\program files\JDownloader
2009-10-04 13:48 . 2009-05-01 11:05 -------- d-----w- c:\users\Riccardo\AppData\Roaming\Apple Computer
2009-10-04 13:45 . 2009-05-01 11:03 -------- d-----w- c:\program files\Common Files\Apple
2009-10-03 23:35 . 2009-10-03 23:35 4096 ----a-w- c:\windows\system32\06CE5.tmp
2009-10-03 23:10 . 2009-10-03 23:10 4096 ----a-w- c:\windows\system32\07232.tmp
2009-10-03 22:26 . 2009-10-03 22:26 4096 ----a-w- c:\windows\system32\06D14.tmp
2009-10-03 13:10 . 2009-10-03 13:10 4096 ----a-w- c:\windows\system32\099CE.tmp
2009-10-03 12:22 . 2009-10-03 12:22 4096 ----a-w- c:\windows\system32\07196.tmp
2009-10-03 11:37 . 2009-10-03 11:37 4096 ----a-w- c:\windows\system32\09462.tmp
2009-10-03 02:53 . 2009-01-17 21:30 -------- d-----w- c:\programdata\pdf995
2009-10-03 01:24 . 2008-11-19 23:13 -------- d-----w- c:\users\Riccardo\AppData\Roaming\FileZilla
2009-10-02 14:36 . 2008-11-27 18:26 -------- d-----w- c:\users\Riccardo\AppData\Roaming\Skype
2009-10-02 14:07 . 2008-11-27 18:27 -------- d-----w- c:\users\Riccardo\AppData\Roaming\skypePM
2009-09-27 18:09 . 2008-11-19 23:13 -------- d-----w- c:\program files\FileZilla FTP Client
2009-09-22 13:18 . 2009-01-17 21:30 51716 ----a-w- c:\windows\system32\pdf995mon.dll
2009-09-22 13:18 . 2009-01-17 21:30 249856 ----a-w- c:\windows\system32\pdfmona.dll
2009-09-18 14:04 . 2008-10-21 10:17 -------- d-----w- c:\program files\ClipX
2009-09-10 01:17 . 2008-10-21 08:28 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-02 18:13 . 2008-12-01 07:54 -------- d-----w- c:\programdata\Installations
2009-09-02 18:11 . 2008-12-01 07:55 -------- d-----w- c:\program files\Nokia
2009-09-02 18:10 . 2008-12-01 08:21 -------- d-----w- c:\program files\Common Files\Nokia
2009-08-30 10:00 . 2009-08-30 10:00 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-08-29 22:46 . 2009-02-18 17:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-29 22:01 . 2008-10-20 22:46 -------- d-----w- c:\programdata\NVIDIA
2009-08-29 21:13 . 2009-07-05 23:18 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-29 21:12 . 2009-07-05 23:18 -------- d-----w- c:\program files\AGEIA Technologies
2009-08-29 00:27 . 2009-09-02 20:00 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-02 20:00 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 13:54 . 2009-05-14 11:25 -------- d-----w- c:\program files\Common Files\TortoiseOverlays
2009-08-28 13:54 . 2009-02-28 12:39 -------- d-----w- c:\program files\TortoiseSVN
2009-08-21 12:17 . 2008-10-20 22:41 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-08-19 12:35 . 2009-08-19 12:35 9787488 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2009-08-19 12:35 . 2009-08-19 12:35 678432 ----a-w- c:\windows\system32\nvcuvid.dll
2009-08-19 12:35 . 2009-08-19 12:35 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-08-19 12:35 . 2009-08-19 12:35 4224 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2009-08-19 12:35 . 2009-08-19 12:35 3197952 ----a-w- c:\windows\system32\nvwgf2um.dll
2009-08-19 12:35 . 2009-08-19 12:35 1740800 ----a-w- c:\windows\system32\nvcuda.dll
2009-08-19 12:35 . 2009-08-19 12:35 155648 ----a-w- c:\windows\system32\nvcod163.dll
2009-08-19 12:35 . 2009-08-19 12:35 155648 ----a-w- c:\windows\system32\nvcod.dll
2009-08-19 12:35 . 2009-08-19 12:35 1317408 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-08-19 12:35 . 2008-09-15 23:58 991744 ----a-w- c:\windows\system32\nvapi.dll
2009-08-19 12:35 . 2008-09-15 23:58 7660544 ----a-w- c:\windows\system32\nvd3dum.dll
2009-08-19 12:35 . 2008-09-15 23:58 10420224 ----a-w- c:\windows\system32\nvoglv32.dll
2009-08-17 22:25 . 2008-12-01 07:58 -------- d-----w- c:\users\Riccardo\AppData\Roaming\Nokia
2009-08-17 14:08 . 2008-10-22 08:18 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-17 14:08 . 2008-10-22 08:18 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-17 14:08 . 2008-10-22 08:18 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-16 15:47 . 2008-10-20 21:51 -------- d-----w- c:\programdata\Microsoft Help
2009-08-15 01:41 . 2009-08-15 01:14 -------- d-----w- c:\program files\boost
2009-08-14 16:27 . 2009-09-09 20:41 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-09 20:41 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-09 20:41 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-09 20:41 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-09 20:41 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-09 20:41 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-09 20:41 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-09 20:41 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-09 20:41 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-09 20:41 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-09 20:41 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-12 22:08 . 2009-06-02 18:20 -------- d-----w- c:\program files\Safari
2009-08-07 18:51 . 2009-08-07 18:51 15308424 ----a-w- c:\windows\system32\xlive.dll
2009-08-07 18:51 . 2009-08-07 18:51 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2009-08-03 14:07 . 2009-08-03 14:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 14:07 . 2009-08-03 14:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 14:07 . 2009-08-03 14:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-07-26 15:44 . 2009-07-26 15:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-21 21:52 . 2009-07-30 19:48 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-30 19:48 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-30 19:48 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-30 19:48 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 03:58 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-15 12:40 . 2009-08-12 03:58 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 03:58 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 03:58 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 03:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-15 09:14 . 2009-07-15 09:14 229224 ----a-w- c:\windows\system32\drivers\VMM.sys
2009-07-11 19:01 . 2009-09-09 20:41 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-07-11 19:01 . 2009-09-09 20:41 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-07-11 19:01 . 2009-09-09 20:41 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-07-11 19:01 . 2009-09-09 20:41 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-07-11 17:03 . 2009-09-09 20:41 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2006-05-03 09:06 . 2009-05-09 22:13 163328 --sh--r- c:\windows\System32\flvDX.dll
2007-02-21 10:47 . 2009-05-09 22:13 31232 --sh--r- c:\windows\System32\msfDX.dll
2008-03-16 12:30 . 2009-05-09 22:13 216064 --sh--r- c:\windows\System32\nbDX.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 17:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"EVEREST AutoStart"="c:\program files\Lavalys\EVEREST Ultimate Edition\everest_start.exe" [2009-05-24 334928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-17 2007832]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-19 13793824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-07-06 4669440]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-06-15 1826816]
c:\users\Riccardo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LCDHype Version 0.6.lnk - c:\program files\LCDHype\lcdhype.exe [2009-6-11 1531392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^Riccardo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CCTray.lnk]
path=c:\users\Riccardo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CCTray.lnk
backup=c:\windows\pss\CCTray.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001
"VistaSp2"=hex(b):87,db,44,49,26,45,ca,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2F19C3BB-935C-4842-B324-727CFE41CB50}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{3A53433D-C1E6-47DF-AF64-03FB9E7AB3F9}c:\\program files\\microsoft virtual pc\\virtual pc.exe"= UDP:c:\program files\microsoft virtual pc\virtual pc.exe:Virtual PC 2007 SP1
"UDP Query User{D9CE08C0-39C2-4989-8C46-E2997E95F859}c:\\program files\\microsoft virtual pc\\virtual pc.exe"= TCP:c:\program files\microsoft virtual pc\virtual pc.exe:Virtual PC 2007 SP1
"{D70F5686-DB55-4D3E-ABFA-1F3499FD8B37}"= c:\program files\Common Files\Microsoft Shared\XNA\XnaTrans\v3.0\XnaTransX.exe:XNA Game Studio 3.0 Transport
"{9F97D69B-F512-4B8C-92FF-5F969B1A76CA}"= c:\program files\Microsoft XNA\XNA Game Studio\v3.0\Bin\XnaLiveProxy.exe:XNA Framework Games for Windows - LIVE
"{589461BD-9B6D-417D-B648-7D45F29FD3AB}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{DFE6FACA-2E6B-4CC6-A688-EE079E2DDD40}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A5376931-8F24-4A74-9E5F-853CE6161172}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A929DA00-4C73-4C69-AC23-6EA1BB352064}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{7C42E9F9-E2DA-4722-8DA6-220D79FC78BA}"= UDP:d:\giochi\StreetFighterIV\StreetFighterIV.exe:STREET FIGHTER IV
"{6D9B8B6D-8DA7-48BC-ADFF-EBD52D2EE066}"= TCP:d:\giochi\StreetFighterIV\StreetFighterIV.exe:STREET FIGHTER IV
"{F6D5AA4C-58EB-43A2-97C0-C8992B0352D8}"= UDP:d:\giochi\Steam\steamapps\common\left 4 dead\left4dead.exe:Left 4 Dead
"{920812F2-2A21-43B9-9F2C-A1F70C4B4A4B}"= TCP:d:\giochi\Steam\steamapps\common\left 4 dead\left4dead.exe:Left 4 Dead
"{A58D9196-5B71-42A9-A6E3-80BCA041EB34}"= UDP:5615:qzvztaz
"{A58C12DD-3691-4083-B8E0-73221D8667D9}"= UDP:5615:qzvztaz
"{6BC632A7-8A3F-4C31-AE52-1623B04D98E3}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{E8226B34-8384-40A8-ADE7-4FC7713F0F0E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [22/10/2008 9.18.26 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [22/10/2008 9.18.24 297752]
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\Nitro PDF\Professional\NitroPDFDriverService.exe [15/09/2009 10.20.30 188736]
R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [11/06/2009 15.20.54 26736]
S3 MsDtsServer;SQL Server Integration Services;c:\program files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe [25/11/2008 0.26.34 203616]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\System32\drivers\nmwcdnsu.sys [19/03/2009 14.48.18 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\System32\drivers\nmwcdnsuc.sys [19/03/2009 14.48.12 8320]
S3 PRODIGY;PRODIGY;c:\windows\System32\drivers\prodigy.sys [07/06/2009 14.44.33 32377]
--- Altri Servizi/Drivers In Memoria ---
*NewlyCreated* - EVERESTDRIVER
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1769182520-1221554094-1942206469-1000Core.job
- c:\users\Riccardo\AppData\Local\Google\Update\GoogleUpdate.exe [2008-10-21 14:15]
2009-10-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1769182520-1221554094-1942206469-1000UA.job
- c:\users\Riccardo\AppData\Local\Google\Update\GoogleUpdate.exe [2008-10-21 14:15]
.
.
------- Scansione supplementare -------
.
uStart Page =
hxxp://www.google.com/uInternet Settings,ProxyOverride = *.local
IE: &Scarica con FlashGet - c:\program files\FlashGet\jc_link.htm
IE: &Scarica tutto con FlashGet - c:\program files\FlashGet\jc_all.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
FF - ProfilePath - c:\users\Riccardo\AppData\Roaming\Mozilla\Firefox\Profiles\iwiweab0.default\
FF - prefs.js: browser.startup.homepage -
http://www.google.itFF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Riccardo\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-04 22:43
Windows 6.0.6002 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
c:\windows\TEMP\TMP0000002FD4179AF31A9D2455 524288 bytes
Scansione completata con successo
Files nascosti: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msftesql]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe\" -s:MSSQL.2 -f:MSSQLSERVER"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'Explorer.exe'(3836)
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\program files\LCDHype\data\screensaver.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng-us.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\program files\Microsoft Virtual PC\VPCShExH.DLL
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\nvvsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\System32\ASTSRV.EXE
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\program files\Lavalys\EVEREST Ultimate Edition\everest.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2009-10-04 22.47.34 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-10-04 21:47
ComboFix2.txt 2009-10-04 21:26
Pre-Run: 48.665.886.720 bytes free
Post-Run: 48.436.174.848 bytes free
334 --- E O F --- 2009-10-04 18:56