okay, ho effettuato la scansione completa con Combofix ed allego il report generato. Che mi dite, sono a posto? Devo fare altre attività di controllo/pulizia? Attendo ulteriori istruzioni, anche per sapere come disinstallare Combofix. Grazie
ComboFix 10-07-23.02 - maurizio 28/07/2010 18:16:54.4.4 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.39.1040.18.3326.2540 [GMT 2:00]
Eseguito da: c:\users\maurizio\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
---- Esecuzione precedente -------
.
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((( Files Creati Da 2010-06-28 al 2010-07-28 )))))))))))))))))))))))))))))))))))
.
2010-07-28 16:22 . 2010-07-28 16:24 -------- d-----w- c:\users\maurizio\AppData\Local\temp
2010-07-28 16:22 . 2010-07-28 16:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-09 15:56 . 2010-07-09 15:57 -------- d-----w- c:\program files\PokerStars.IT
2010-07-05 18:42 . 2010-07-05 18:42 -------- d-----w- c:\users\maurizio\AppData\Roaming\Malwarebytes
2010-07-05 15:26 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-05 15:25 . 2010-07-05 15:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-05 15:25 . 2010-07-05 15:25 -------- d-----w- c:\programdata\Malwarebytes
2010-07-05 15:25 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-04 14:58 . 2010-07-04 14:58 388096 ----a-r- c:\users\maurizio\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-28 20:36 . 2010-06-28 20:36 -------- d-----w- c:\windows\system32\Wat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-28 16:23 . 2009-12-05 10:30 -------- d-----w- c:\programdata\NVIDIA
2010-07-28 16:23 . 2009-12-28 21:46 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-07-24 07:11 . 2010-04-25 14:03 -------- d-----w- c:\program files\Process xp
2010-07-11 17:34 . 2010-04-25 09:42 -------- d-----w- c:\programdata\Zoom Player
2010-06-28 13:49 . 2009-12-01 15:27 104968 ----a-w- c:\users\maurizio\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-26 14:11 . 2010-06-13 13:37 -------- d-----w- c:\users\maurizio\AppData\Roaming\Skype
2010-06-26 14:01 . 2010-06-13 13:41 -------- d-----w- c:\users\maurizio\AppData\Roaming\skypePM
2010-06-13 13:41 . 2010-06-13 13:41 56 ---ha-w- c:\programdata\ezsidmv.dat
2010-06-13 13:37 . 2010-06-13 13:36 -------- d-----r- c:\program files\Skype
2010-06-13 13:36 . 2010-06-13 13:36 -------- d-----w- c:\program files\Common Files\Skype
2010-06-13 13:36 . 2010-06-13 13:36 -------- d-----w- c:\programdata\Skype
2010-06-11 12:24 . 2009-07-14 08:21 689234 ----a-w- c:\windows\system32\perfh010.dat
2010-06-11 12:24 . 2009-07-14 08:21 124420 ----a-w- c:\windows\system32\perfc010.dat
2010-06-11 12:24 . 2010-06-11 12:23 -------- d-----w- c:\users\maurizio\AppData\Roaming\U3
2010-06-11 12:23 . 2010-06-11 12:23 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-06-11 12:01 . 2010-06-11 12:01 -------- d-----w- c:\program files\Thrustmaster
2010-06-11 12:01 . 2009-12-25 11:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-11 12:00 . 2010-06-11 12:00 -------- d-----w- c:\users\maurizio\AppData\Roaming\InstallShield
2010-06-06 06:49 . 2010-05-11 07:50 -------- d-----w- c:\users\maurizio\AppData\Roaming\WindSolutions
2010-06-06 06:49 . 2010-05-11 07:50 -------- d-----w- c:\programdata\WindSolutions
2010-06-03 15:03 . 2010-05-12 16:16 -------- d-----w- c:\users\maurizio\AppData\Roaming\Canon
2010-05-30 07:21 . 2010-05-30 07:21 -------- d-----w- c:\users\maurizio\AppData\Roaming\ScummVM
2010-05-27 07:24 . 2010-06-10 18:32 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49 . 2010-06-10 18:32 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 12:14 . 2009-12-01 14:02 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-21 05:18 . 2010-06-10 18:32 977920 ----a-w- c:\windows\system32\wininet.dll
2010-05-09 09:14 . 2010-06-24 06:43 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-05-09 09:14 . 2010-06-24 06:43 417792 ----a-w- c:\windows\system32\msdri.dll
2010-05-01 14:49 . 2010-06-10 18:32 2326528 ----a-w- c:\windows\system32\win32k.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GDFirewallTray"="c:\program files\G Data\InternetSecurity\Firewall\GDFirewallTray.exe" [2009-10-21 1124424]
"G DATA AntiVirus Trayapplication"="c:\program files\G Data\InternetSecurity\AVKTray\AVKTray.exe" [2010-01-06 951880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
R2 gupdate;Servizio di Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-05-02 136176]
R3 GrabsterSeries.X86;GRABSTER SERIES, Service X86;c:\windows\system32\DRIVERS\GrabsterSeries.X86.SYS [2007-11-28 310016]
R3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS [2006-12-05 507136]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-28 1343400]
S0 GDBehave;GDBehave;c:\windows\system32\drivers\GDBehave.sys [2010-02-14 28616]
S1 gdwfpcd;G DATA WFP CD;c:\windows\system32\DRIVERS\gdwfpcd32.sys [2010-02-14 40904]
S1 GRD;G Data Rootkit Detector Driver;c:\windows\system32\drivers\GRD.sys [2009-12-01 29992]
S2 AVKProxy;G Data AntiVirus Proxy;c:\program files\Common Files\G DATA\AVKProxy\AVKProxy.exe [2009-12-15 1054792]
S2 AVKService;G Data Scheduler;c:\program files\G Data\InternetSecurity\AVK\AVKService.exe [2009-09-07 397896]
S2 AVKWCtl;G Data Guardiano del file system;c:\program files\G Data\InternetSecurity\AVK\AVKWCtl.exe [2009-11-25 1251488]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-04-03 240232]
S3 GDFwSvc;G Data Personal Firewall;c:\program files\G Data\InternetSecurity\Firewall\GDFwSvc.exe [2009-11-25 1547104]
S3 GDMnIcpt;GDMnIcpt;c:\windows\system32\drivers\MiniIcpt.sys [2010-02-14 55624]
S3 GDPkIcpt;GDPkIcpt;c:\windows\system32\drivers\PktIcpt.sys [2010-02-14 47560]
S3 GDScan;G Data Scanner;c:\program files\Common Files\G DATA\GDScan\GDScan.exe [2009-11-26 302152]
S3 HookCentre;HookCentre;c:\windows\system32\drivers\HookCentre.sys [2009-12-01 35272]
.
.
------- Scansione supplementare -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{C4046502-6524-4d87-896C-878F57D1FF07} - c:\program files\PokerStars.IT\PokerStarsUpdate.exe
TCP: {EC8A2FEE-5C13-4BBB-956F-8D9543AA2F95} = 192.168.2.1
FF - ProfilePath - c:\users\maurizio\AppData\Roaming\Mozilla\Firefox\Profiles\r10cqkqs.default\
FF - prefs.js: browser.startup.homepage -
www.libero.itFF - component: c:\program files\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}\components\AvkWebFilterFF.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_USERS\S-1-5-21-2020141486-3086581876-3591650722-1001\Software\SecuROM\License information*]
"datasecu"=hex:d6,5b,79,24,18,b6,b6,3a,5b,73,5c,3a,da,08,fa,e6,d4,cd,8a,10,9f,
c7,47,2d,45,73,2e,49,80,6e,03,b2,e2,66,99,76,03,47,ea,f0,39,71,4c,46,40,f5,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'Explorer.exe'(5428)
c:\program files\G Data\InternetSecurity\Shredder\Reisswlf.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Ora fine scansione: 2010-07-28 18:27:09 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-07-28 16:27
Pre-Run: 42.659.471.360 byte disponibili
Post-Run: 42.655.801.344 byte disponibili
- - End Of File - - 57D76333C7B32DA05D412A3841316232