il mio pc e' lento ho usato norman malware cleaner,malwarebites,ccleaner.drweb,ho eliminato un virus e un trojan poi ho usato combofix ComboFix 12-02-19.02 - utente 20/02/2012 12.08.57.8.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1023.616 [GMT 1:00]
Eseguito da: c:\documents and settings\utente\Documenti\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Creati Da 2012-01-20 al 2012-02-20 )))))))))))))))))))))))))))))))))))
.
.
2012-02-19 18:46 . 2012-02-19 18:46 -------- d-----w- c:\documents and settings\utente\DoctorWeb
2012-02-18 11:17 . 2012-02-18 11:17 -------- d-----w- c:\windows\system32\wbem\Repository
2012-02-15 11:27 . 2012-01-11 19:06 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-02-15 11:27 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-03 21:28 . 2012-02-03 21:28 -------- d-----w- c:\documents and settings\utente\Dati applicazioni\TuneUp Software
2012-02-03 21:27 . 2012-02-03 21:40 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\TuneUp Software
2012-02-03 21:26 . 2012-02-03 21:26 -------- d-sh--w- c:\documents and settings\All Users\Dati applicazioni\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-02-01 09:53 . 2012-02-01 09:53 -------- d-----w- c:\documents and settings\utente\Dati applicazioni\ProgSense
2012-02-01 09:53 . 2012-02-09 21:10 -------- d-----w- c:\documents and settings\utente\Dati applicazioni\Orbit
2012-01-30 05:48 . 2012-01-31 12:44 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-25 19:34 . 2012-01-25 19:34 -------- d-----w- c:\programmi\MALWAREBYTES ANTI-MALWARE
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-31 17:03 . 2009-08-09 15:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-01-31 17:03 . 2009-07-21 06:52 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-01-12 17:20 . 2008-04-14 12:00 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-20 11:03 . 2011-12-20 11:03 388096 ----a-r- c:\documents and settings\utente\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-18 13:43 . 2007-08-13 16:54 11082240 ----a-w- c:\windows\system32\ieframe(2).dll
2011-12-17 19:43 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:43 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2011-12-17 19:43 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2011-12-10 14:24 . 2009-04-23 09:43 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-04 10:57 . 2011-06-27 11:51 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 21:57 . 2008-04-14 12:00 293888 ----a-w- c:\windows\system32\winsrv.dll
2012-01-08 10:40 . 2011-03-22 21:35 121816 ----a-w- c:\programmi\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-05-30 20:29 . FC9E0012557DD863EFA4C4B13B16D030 . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\atapi.sys
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-02-23 5537792]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^HP Digital Imaging Monitor.lnk]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^NCProTray.lnk]
path=c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\NCProTray.lnk
backup=c:\windows\pss\NCProTray.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-14 19:17 49152 ----a-w- c:\programmi\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2007-08-22 14:31 80896 ----a-w- c:\programmi\HP\Digital Imaging\bin\HpqSRmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KB2492386]
2008-04-14 12:00 125952 ----a-w- c:\windows\system32\apphelp.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-01-13 13:53 460872 ----a-w- c:\programmi\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2005-02-23 20:26 5537792 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedLord]
2011-06-02 07:05 2693120 ----a-w- c:\programmi\SpeedLord\SpeedLord.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 10:59 254696 ----a-w- c:\programmi\File comuni\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USBestCR]
2011-06-15 11:29 4218880 ----a-w- c:\programmi\USBESTDI\iconcs4635875.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Mozilla Firefox\\firefox.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\ProgDVB\\ProgDvbNet.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19665:TCP"= 19665:TCP:BitComet 19665 TCP
"19665:UDP"= 19665:UDP:BitComet 19665 UDP
"16851:TCP"= 16851:TCP:BitComet 16851 TCP
"16851:UDP"= 16851:UDP:BitComet 16851 UDP
"5985:TCP"= 5985:TCP:*:Disabled:Gestione remota Windows
.
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [10/06/2009 12.34.50 47360]
S2 AfaService;Afa Card Reader Service;c:\windows\system32\afasrv32.exe [11/06/2011 17.22.50 65536]
S3 MHIKEY10;MHIKEY10;c:\windows\system32\drivers\MHIKEY10.sys [15/06/2011 12.29.35 51072]
S3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [22/10/2009 15.15.00 55208]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14/04/2008 13.00.00 14336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WINRM REG_MULTI_SZ WINRM
.
.
------- Scansione supplementare -------
.
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D4559FAC-0CDD-4EF3-8E73-A1AF3D0DCF54}: DhcpNameServer = 192.168.1.1
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\utente\Dati applicazioni\Mozilla\Firefox\Profiles\c50i6igm.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.libero.it/
FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/webResults.html?src=ffb&q=
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
MSConfigStartUp-nwiz - nwiz.exe
MSConfigStartUp-SUPERAntiSpyware - c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-20 12:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scansione processi nascosti ...
.
scansione entrate autostart nascoste ...
.
Scansione files nascosti ...
.
Scansione completata con successo
Files nascosti: 0
.
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"0140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'explorer.exe'(3448)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2012-02-20 12:21:11
ComboFix-quarantined-files.txt 2012-02-20 11:21
.
Pre-Run: 43.589.083.136 byte disponibili
Post-Run: 43.833.458.688 byte disponibili
.
- - End Of File - - E7C6A49913BEFD8D43165F801AEF5F1D
il pc e' a posto o sono ancora infetto?????grazie a chi mi aiutera'