Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

pc lentissimo all'avvio posto Hijack.... Opzioni
andemaldom
Inviato: Friday, April 15, 2011 10:02:18 AM
Rank: Member

Iscritto dal : 4/15/2011
Posts: 17
è un po' di tempo che si avvia lentamente ho trovato un sacco di file missing 023 service....... ho provato a fixrli ma non si cancellano qualcuno mi aiuta per capire che problema ho sul pc ??? grazie
File log.............



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:32:59, on 14/04/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: mipony-plugin Toolbar - {90d46c30-9f25-4104-aea9-35c3f84477ff} - C:\Program Files (x86)\mipony-plugin\tbmipo.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: mipony-plugin Toolbar - {90d46c30-9f25-4104-aea9-35c3f84477ff} - C:\Program Files (x86)\mipony-plugin\tbmipo.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O3 - Toolbar: mipony-plugin Toolbar - {90d46c30-9f25-4104-aea9-35c3f84477ff} - C:\Program Files (x86)\mipony-plugin\tbmipo.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [VideoWebCamera] "C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe" -a
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Scarica con Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 5451 bytes


Sponsor
Inviato: Friday, April 15, 2011 10:02:18 AM

 
cbbusto
Inviato: Friday, April 15, 2011 12:04:49 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Ciao, vedo che sei nuovo, benvenuto nel forum.
Hai troppi programmi installati per questo il pc è lento, fai una pulizia con Ccleaner compreso il registro, poi
vai in strumenti/avvio e disattiva i programmi che usi poco.
Poi chiudi tutti i programmi e disconnesso avvia HJT in mod provvisoria e fixa queste voci:

R3 - URLSearchHook: mipony-plugin Toolbar - {90d46c30-9f25-4104-aea9-35c3f84477ff} - C:\Program Files (x86)\mipony-plugin\tbmipo.dll

O2 - BHO: mipony-plugin Toolbar - {90d46c30-9f25-4104-aea9-35c3f84477ff} - C:\Program Files (x86)\mipony-plugin\tbmipo.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O3 - Toolbar: mipony-plugin Toolbar - {90d46c30-9f25-4104-aea9-35c3f84477ff} - C:\Program Files (x86)\mipony-plugin\tbmipo.dll

O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)


Gli altri lasciali stare.
Poi non vedo un antivirus, oppure è disattivato, ti consiglio di usare QUESTO assieme al firewall di Seven.
Installa QUESTO programma, aggiornalo e poi fai una scansione COMPLETA non veloce, elimina tutto quello che trova, posta il log.
Rifai una nuova scansione con HJT e posta il nuovo log.
Fai anche una deframmentazione del disco, usa QUESTO programma.
Ci risentiamo
r16
Inviato: Friday, April 15, 2011 6:59:40 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Stiamo scherzando cbbusto ?
Non ti è sorto il dubbio, che quel S.O è a 64 bit?

@andemaldom :
Non eliminare nessuna delle voci 023. (sono legittime)

Segui il consiglio di fare la scansione con Malwarebytes.
andemaldom
Inviato: Friday, April 15, 2011 8:49:52 PM
Rank: Member

Iscritto dal : 4/15/2011
Posts: 17
si è 64 bit confermo....
andemaldom
Inviato: Friday, April 15, 2011 8:56:00 PM
Rank: Member

Iscritto dal : 4/15/2011
Posts: 17
fatto malware o virus trovati posto il log

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Versione database: 6369

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

15/04/2011 21:00:58
mbam-log-2011-04-15 (21-00-58).txt

Tipo di scansione: Scansione veloce
Elementi esaminati: 163606
Tempo trascorso: 2 minuti, 10 secondi

Processi infetti in memoria: 0
Moduli di memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Voci infette nei dati di registro: 0
Cartelle infette: 0
File infetti: 0

Processi infetti in memoria:
(Non sono stati rilevati elementi nocivi)

Moduli di memoria infetti:
(Non sono stati rilevati elementi nocivi)

Chiavi di registro infette:
(Non sono stati rilevati elementi nocivi)

Valori di registro infetti:
(Non sono stati rilevati elementi nocivi)

Voci infette nei dati di registro:
(Non sono stati rilevati elementi nocivi)

Cartelle infette:
(Non sono stati rilevati elementi nocivi)

File infetti:
(Non sono stati rilevati elementi nocivi)
andemaldom
Inviato: Friday, April 15, 2011 9:29:14 PM
Rank: Member

Iscritto dal : 4/15/2011
Posts: 17
questo è il log della scansione approfondita

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Versione database: 6369

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

15/04/2011 21:34:08
mbam-log-2011-04-15 (21-34-08).txt

Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi esaminati: 309089
Tempo trascorso: 31 minuti, 14 secondi

Processi infetti in memoria: 0
Moduli di memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Voci infette nei dati di registro: 0
Cartelle infette: 0
File infetti: 0

Processi infetti in memoria:
(Non sono stati rilevati elementi nocivi)

Moduli di memoria infetti:
(Non sono stati rilevati elementi nocivi)

Chiavi di registro infette:
(Non sono stati rilevati elementi nocivi)

Valori di registro infetti:
(Non sono stati rilevati elementi nocivi)

Voci infette nei dati di registro:
(Non sono stati rilevati elementi nocivi)

Cartelle infette:
(Non sono stati rilevati elementi nocivi)

File infetti:
(Non sono stati rilevati elementi nocivi)
r16
Inviato: Friday, April 15, 2011 9:38:56 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Elimina queste voci di HijackThis:
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe"

Dai una pulita (registro compreso)con CCleaner: http://www.aiutamici.com/software?ID=11223

Scarica Combofix (usa Internet Explorer)

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Salvalo sul desktop. (è obligatorio)

Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.

Doppio click su combofix.exe (se usi Vista: tasto destro su Combofix.exe e clicca su: "Esegui come Amministratore" )

E' probabile che ti siano inviati messaggi dall'antivirus,(o dallo stesso Combofix) tu ignorali.

Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt.
Postalo qui.
cbbusto
Inviato: Friday, April 15, 2011 10:12:16 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
r16 ha scritto:
Stiamo scherzando cbbusto ?
Non ti è sorto il dubbio, che quel S.O è a 64 bit?

@andemaldom :
Non eliminare nessuna delle voci 023. (sono legittime)

Segui il consiglio di fare la scansione con Malwarebytes.


Ciao r16, vorrei spiegarti il motivo per cui ho segnalato quelle voci.
Non ho detto che riguardano infezioni, però non essendo file di sistema si possono eliminare senza danni, infatti provengono tutte da software installati e alle volte possono causare danni o rallentamenti.
Analizziamole una ad una:
nvvsvc.exe è utilizzato da 'NVIDIA Driver Helper Service,
spoolsv.exe è un processo registrato come vulnerabilità segreta che può essere installata per scopi
illeciti permettendo l'accesso al pc da posizioni remote e potrebbe rubare le parole d'accesso, le attività bancarie di Internet ed i dati personali.
UI0Detect.exe appartiene a Microsoft® Windows® Operating System si poteva anche lasciare ma non è un file di sistema.
vds.exe riguarda Virtual Disk Service.

Non so se sei d'accordo o meno.
colpodifrusta
Inviato: Friday, April 15, 2011 10:33:49 PM

Rank: AiutAmico

Iscritto dal : 11/4/2010
Posts: 682
r16 ha scritto:
Stiamo scherzando cbbusto ?
Non ti è sorto il dubbio, che quel S.O è a 64 bit?

Infatti le voci 023 con la @ (file missing) anche volendo non si cancellano.
r16
Inviato: Friday, April 15, 2011 10:37:24 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Commenta:
Non so se sei d'accordo o meno.

No, non sono per niente d'accordo.
I "Servizi attivi" legittimi, non vanno mai eliminati.
Al massimo, vanno disattivati.
La ragione è semplice: molti servizi, sono collegati ad altri file di sistema, che eliminandoli potrebbero creare malfunzionamenti ad alcuni programmi.

Esempio:
spoolsv.exe
Questo, fa funzionare i Fax e le stampanti.
Commenta:
Il processo spoolsv.exe è il componente del sistema operativo che gestisce i processi di stampa sul computer locale

Se hai il sospetto che sia un troyan, lo disattivi, perchè se lo elimini, e ti sei sbagliato, i fax e le stampanti, non funzioneranno più.
cbbusto
Inviato: Saturday, April 16, 2011 12:21:19 AM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
r16 ha scritto:
Commenta:
Non so se sei d'accordo o meno.

No, non sono per niente d'accordo.
I "Servizi attivi" legittimi, non vanno mai eliminati.
Al massimo, vanno disattivati.
La ragione è semplice: molti servizi, sono collegati ad altri file di sistema, che eliminandoli potrebbero creare malfunzionamenti ad alcuni programmi.

Esempio:
spoolsv.exe
Questo, fa funzionare i Fax e le stampanti.
Commenta:
Il processo spoolsv.exe è il componente del sistema operativo che gestisce i processi di stampa sul computer locale

Se hai il sospetto che sia un troyan, lo disattivi, perchè se lo elimini, e ti sei sbagliato, i fax e le stampanti, non funzioneranno più.


OK - ho capito. Speak to the hand
andemaldom
Inviato: Saturday, April 16, 2011 8:38:40 PM
Rank: Member

Iscritto dal : 4/15/2011
Posts: 17
posto il report combofix

ComboFix 11-04-15.06 - Maury 16/04/2011 20:35:30.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.39.1040.18.4091.2918 [GMT 2:00]
Eseguito da: c:\users\Maury\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\listcmd.bin
.
.
((((((((((((((((((((((((( Files Creati Da 2011-03-16 al 2011-04-16 )))))))))))))))))))))))))))))))))))
.
.
2011-04-16 18:39 . 2011-04-16 18:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-16 15:35 . 2011-03-14 20:17 8424784 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1AC20684-EE5A-4545-8629-62689EBFEAB0}\mpengine.dll
2011-04-15 18:58 . 2010-12-20 16:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-15 18:58 . 2011-04-15 18:58 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-04-14 20:03 . 2011-04-14 20:24 -------- d-----w- c:\program files (x86)\Unlocker
2011-04-14 11:48 . 2010-09-06 09:26 189520 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys
2011-04-14 09:27 . 2011-04-14 09:27 -------- d-----w- c:\users\Maury\AppData\Roaming\Malwarebytes
2011-04-14 09:26 . 2011-04-14 09:26 -------- d-----w- c:\programdata\Malwarebytes
2011-04-14 09:26 . 2010-12-20 16:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-13 22:29 . 2011-04-13 22:29 -------- d-----w- c:\users\Maury\AppData\Local\{8ED0AB98-376A-4C4E-B526-5D8A38F7BE78}
2011-04-13 20:23 . 2011-02-05 17:06 605552 ----a-w- c:\windows\system32\winload.exe
2011-04-13 20:23 . 2011-02-05 17:06 566208 ----a-w- c:\windows\system32\winresume.efi
2011-04-13 20:23 . 2011-02-05 17:10 642944 ----a-w- c:\windows\system32\winload.efi
2011-04-13 20:23 . 2011-02-05 17:10 20352 ----a-w- c:\windows\system32\kdusb.dll
2011-04-13 20:23 . 2011-02-05 17:10 19328 ----a-w- c:\windows\system32\kd1394.dll
2011-04-13 20:23 . 2011-02-05 17:10 17792 ----a-w- c:\windows\system32\kdcom.dll
2011-04-13 20:23 . 2011-02-05 17:06 518672 ----a-w- c:\windows\system32\winresume.exe
2011-04-13 20:23 . 2011-02-12 11:34 267776 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-13 20:23 . 2011-02-23 04:56 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-13 20:23 . 2011-02-23 04:55 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-13 20:23 . 2011-02-23 04:55 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-13 20:23 . 2011-02-23 04:55 90624 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-12 15:10 . 2011-04-12 15:10 388096 ----a-r- c:\users\Maury\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-12 15:10 . 2011-04-12 15:10 -------- d-----w- c:\program files (x86)\Trend Micro
2011-04-09 14:23 . 2011-04-09 14:23 -------- d-----w- c:\users\Maury\AppData\Roaming\GlarySoft
2011-04-09 14:20 . 2011-04-09 17:06 -------- d-----w- c:\program files (x86)\Glary Utilities
2011-04-09 14:15 . 2011-04-09 14:15 -------- d-----w- c:\users\Maury\AppData\Roaming\Reviversoft
2011-04-09 14:15 . 2011-03-16 11:28 18240 ----a-w- c:\windows\system32\roboot64.exe
2011-04-09 11:10 . 2011-01-17 11:09 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2011-04-09 11:10 . 2011-01-17 05:47 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2011-04-09 09:46 . 2011-04-14 18:26 80248 ----a-w- c:\windows\SysWow64\drivers\viragtlt.sys
2011-04-09 09:29 . 2011-04-09 09:29 -------- d-----w- c:\users\Maury\AppData\Local\PackageAware
2011-04-08 19:16 . 2011-04-08 19:16 -------- d-----w- c:\users\Maury\AppData\Local\Windows Live Writer
2011-04-08 19:16 . 2011-04-08 19:16 -------- d-----w- c:\users\Maury\AppData\Roaming\Windows Live Writer
2011-04-07 19:24 . 2011-04-07 19:24 -------- d-----w- c:\windows\SysWow64\wbem\en-US
2011-04-07 19:24 . 2011-04-07 19:24 -------- d-----w- c:\windows\system32\wbem\en-US
2011-04-07 18:40 . 2011-04-07 18:40 -------- d-----w- c:\windows\system32\SPReview
2011-04-07 18:37 . 2011-04-07 18:37 -------- d-----w- c:\windows\system32\EventProviders
2011-04-07 18:36 . 2010-11-05 01:57 48976 ----a-w- c:\windows\system32\netfxperf.dll
2011-04-07 18:36 . 2010-11-05 01:57 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-04-07 18:36 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-04-07 18:36 . 2010-11-20 13:33 5563776 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-07 18:36 . 2010-11-20 13:27 12288 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-04-07 18:36 . 2010-11-20 13:27 14967808 ----a-w- c:\program files\DVD Maker\OmdBase.dll
2011-04-07 18:36 . 2010-11-20 13:27 3715584 ----a-w- c:\windows\system32\mstscax.dll
2011-04-07 18:36 . 2010-11-20 13:26 1838080 ----a-w- c:\windows\system32\d3d10warp.dll
2011-04-07 18:36 . 2010-11-20 11:07 59392 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2011-04-07 18:36 . 2010-11-20 12:19 3215872 ----a-w- c:\windows\SysWow64\mstscax.dll
2011-04-07 18:34 . 2010-11-20 13:27 1096704 ----a-w- c:\program files\Windows Photo Viewer\PhotoAcq.dll
2011-04-07 18:33 . 2010-11-20 13:27 132608 ----a-w- c:\windows\system32\wmpshell.dll
2011-04-07 18:32 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-04-07 18:32 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-04-07 18:31 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-04-07 18:31 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-04-07 18:31 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-04-07 18:31 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll
2011-04-07 18:31 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe
2011-04-07 18:30 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll
2011-04-07 18:30 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
2011-04-05 08:27 . 2011-01-25 21:59 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9243FD2C-7E7A-4F3F-9BBA-82210FC611BC}\gapaengine.dll
2011-03-29 19:40 . 2010-04-12 15:29 411368 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-03-29 19:40 . 2010-04-12 15:29 411368 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-03-26 07:28 . 2011-01-25 21:59 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-07 18:47 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-04-07 18:47 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-04-07 18:35 . 2011-04-07 18:35 4 --sha-w- c:\windows\Fonts\ARIAL.TCX
2011-03-14 20:17 . 2010-10-06 16:45 8424784 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-19 12:05 . 2011-03-09 19:17 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 12:04 . 2011-03-09 19:17 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 12:04 . 2011-03-09 19:17 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 06:30 . 2011-03-09 19:17 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-02-19 06:30 . 2011-03-09 19:17 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{90d46c30-9f25-4104-aea9-35c3f84477ff}"= "c:\program files (x86)\mipony-plugin\tbmipo.dll" [2010-02-22 2353176]
.
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
2010-02-22 11:05 2353176 ----a-w- c:\program files (x86)\mipony-plugin\tbmipo.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{90d46c30-9f25-4104-aea9-35c3f84477ff}"= "c:\program files (x86)\mipony-plugin\tbmipo.dll" [2010-02-22 2353176]
.
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"VideoWebCamera"="c:\program files (x86)\VideoWebCamera\VideoWebCamera.exe" [2009-08-11 1507410]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 VBoxDRV;PortableVBoxDRV;f:\virtualbox\Portable-VirtualBox\app64\drivers\VBoxDrv\VBoxDrv.sys [x]
R2 VBoxUSBMon;PortableVBoxUSBMon;f:\virtualbox\Portable-VirtualBox\app64\drivers\USB\filter\VBoxUSBMon.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 16776]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 9096]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S3 k57nd60a;Gigabit Ethernet Broadcom NetXtreme - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 netw5v64;Driver scheda Intel(R) Wireless WiFi Link serie 5000 per Windows Vista a 64 bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
.
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-04-16 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-04-09 15:24]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-10-05 1684264]
"Corel Photo Downloader"="c:\program files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" [2007-08-16 531272]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Scansione supplementare -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.it/
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&sporta in Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: Scarica con Mipony - file://c:\program files (x86)\MiPony\Browser\IEContext.htm
FF - ProfilePath - c:\users\Maury\AppData\Roaming\Mozilla\Firefox\Profiles\twwqr4r2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2465030&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - mipony-plugin Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2465030&SearchSource=13
FF - prefs.js: network.proxy.ftp - wsecmr.atm.root.local
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - wsecmr.atm.root.local
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - wsecmr.atm.root.local
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - wsecmr.atm.root.local
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - wsecmr.atm.root.local
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: mipony-plugin Toolbar: {90d46c30-9f25-4104-aea9-35c3f84477ff} - %profile%\extensions\{90d46c30-9f25-4104-aea9-35c3f84477ff}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{90D46C30-9F25-4104-AEA9-35C3F84477FF} - (no file)
.
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2011-04-16 20:41:34
ComboFix-quarantined-files.txt 2011-04-16 18:41
.
Pre-Run: 41.976.340.480 byte disponibili
Post-Run: 42.282.573.824 byte disponibili
.
- - End Of File - - C9DE4B87AE2E73DBC8F518F2E5C32B5E



grazie


andemaldom
Inviato: Saturday, April 16, 2011 8:54:54 PM
Rank: Member

Iscritto dal : 4/15/2011
Posts: 17
scusate .......... questo è fatto conme amministratore

ComboFix 11-04-15.06 - Maury 16/04/2011 20:50:38.2.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.39.1040.18.4091.2933 [GMT 2:00]
Eseguito da: c:\users\Maury\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Creati Da 2011-03-16 al 2011-04-16 )))))))))))))))))))))))))))))))))))
.
.
2011-04-16 18:53 . 2011-04-16 18:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-16 18:42 . 2011-03-14 20:17 8424784 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5DE6CE1-FA96-4FED-B50E-BF10B535AE5E}\mpengine.dll
2011-04-15 18:58 . 2010-12-20 16:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-15 18:58 . 2011-04-15 18:58 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-04-14 20:03 . 2011-04-14 20:24 -------- d-----w- c:\program files (x86)\Unlocker
2011-04-14 11:48 . 2010-09-06 09:26 189520 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys
2011-04-14 09:27 . 2011-04-14 09:27 -------- d-----w- c:\users\Maury\AppData\Roaming\Malwarebytes
2011-04-14 09:26 . 2011-04-14 09:26 -------- d-----w- c:\programdata\Malwarebytes
2011-04-14 09:26 . 2010-12-20 16:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-13 22:29 . 2011-04-13 22:29 -------- d-----w- c:\users\Maury\AppData\Local\{8ED0AB98-376A-4C4E-B526-5D8A38F7BE78}
2011-04-13 20:23 . 2011-02-05 17:06 605552 ----a-w- c:\windows\system32\winload.exe
2011-04-13 20:23 . 2011-02-05 17:06 566208 ----a-w- c:\windows\system32\winresume.efi
2011-04-13 20:23 . 2011-02-05 17:10 642944 ----a-w- c:\windows\system32\winload.efi
2011-04-13 20:23 . 2011-02-05 17:10 20352 ----a-w- c:\windows\system32\kdusb.dll
2011-04-13 20:23 . 2011-02-05 17:10 19328 ----a-w- c:\windows\system32\kd1394.dll
2011-04-13 20:23 . 2011-02-05 17:10 17792 ----a-w- c:\windows\system32\kdcom.dll
2011-04-13 20:23 . 2011-02-05 17:06 518672 ----a-w- c:\windows\system32\winresume.exe
2011-04-13 20:23 . 2011-02-12 11:34 267776 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-13 20:23 . 2011-02-23 04:56 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-13 20:23 . 2011-02-23 04:55 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-13 20:23 . 2011-02-23 04:55 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-13 20:23 . 2011-02-23 04:55 90624 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-12 15:10 . 2011-04-12 15:10 388096 ----a-r- c:\users\Maury\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-12 15:10 . 2011-04-12 15:10 -------- d-----w- c:\program files (x86)\Trend Micro
2011-04-09 14:23 . 2011-04-09 14:23 -------- d-----w- c:\users\Maury\AppData\Roaming\GlarySoft
2011-04-09 14:20 . 2011-04-09 17:06 -------- d-----w- c:\program files (x86)\Glary Utilities
2011-04-09 14:15 . 2011-04-09 14:15 -------- d-----w- c:\users\Maury\AppData\Roaming\Reviversoft
2011-04-09 14:15 . 2011-03-16 11:28 18240 ----a-w- c:\windows\system32\roboot64.exe
2011-04-09 11:10 . 2011-01-17 11:09 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2011-04-09 11:10 . 2011-01-17 05:47 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2011-04-09 09:46 . 2011-04-14 18:26 80248 ----a-w- c:\windows\SysWow64\drivers\viragtlt.sys
2011-04-09 09:29 . 2011-04-09 09:29 -------- d-----w- c:\users\Maury\AppData\Local\PackageAware
2011-04-08 19:16 . 2011-04-08 19:16 -------- d-----w- c:\users\Maury\AppData\Local\Windows Live Writer
2011-04-08 19:16 . 2011-04-08 19:16 -------- d-----w- c:\users\Maury\AppData\Roaming\Windows Live Writer
2011-04-07 19:24 . 2011-04-07 19:24 -------- d-----w- c:\windows\SysWow64\wbem\en-US
2011-04-07 19:24 . 2011-04-07 19:24 -------- d-----w- c:\windows\system32\wbem\en-US
2011-04-07 18:40 . 2011-04-07 18:40 -------- d-----w- c:\windows\system32\SPReview
2011-04-07 18:37 . 2011-04-07 18:37 -------- d-----w- c:\windows\system32\EventProviders
2011-04-07 18:36 . 2010-11-05 01:57 48976 ----a-w- c:\windows\system32\netfxperf.dll
2011-04-07 18:36 . 2010-11-05 01:57 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-04-07 18:36 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-04-07 18:36 . 2010-11-20 13:33 5563776 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-07 18:36 . 2010-11-20 13:27 12288 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2011-04-07 18:36 . 2010-11-20 13:27 14967808 ----a-w- c:\program files\DVD Maker\OmdBase.dll
2011-04-07 18:36 . 2010-11-20 13:27 3715584 ----a-w- c:\windows\system32\mstscax.dll
2011-04-07 18:36 . 2010-11-20 13:26 1838080 ----a-w- c:\windows\system32\d3d10warp.dll
2011-04-07 18:36 . 2010-11-20 11:07 59392 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2011-04-07 18:36 . 2010-11-20 12:19 3215872 ----a-w- c:\windows\SysWow64\mstscax.dll
2011-04-07 18:34 . 2010-11-20 13:27 1096704 ----a-w- c:\program files\Windows Photo Viewer\PhotoAcq.dll
2011-04-07 18:33 . 2010-11-20 13:27 132608 ----a-w- c:\windows\system32\wmpshell.dll
2011-04-07 18:32 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-04-07 18:32 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-04-07 18:31 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-04-07 18:31 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-04-07 18:31 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-04-07 18:31 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll
2011-04-07 18:31 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe
2011-04-07 18:30 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll
2011-04-07 18:30 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
2011-04-05 08:27 . 2011-01-25 21:59 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9243FD2C-7E7A-4F3F-9BBA-82210FC611BC}\gapaengine.dll
2011-03-29 19:40 . 2010-04-12 15:29 411368 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-03-29 19:40 . 2010-04-12 15:29 411368 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-03-26 07:28 . 2011-01-25 21:59 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-07 18:47 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-04-07 18:47 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-04-07 18:35 . 2011-04-07 18:35 4 --sha-w- c:\windows\Fonts\ARIAL.TCX
2011-03-14 20:17 . 2010-10-06 16:45 8424784 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-19 12:05 . 2011-03-09 19:17 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 12:04 . 2011-03-09 19:17 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 12:04 . 2011-03-09 19:17 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 06:30 . 2011-03-09 19:17 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-02-19 06:30 . 2011-03-09 19:17 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{90d46c30-9f25-4104-aea9-35c3f84477ff}"= "c:\program files (x86)\mipony-plugin\tbmipo.dll" [2010-02-22 2353176]
.
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
2010-02-22 11:05 2353176 ----a-w- c:\program files (x86)\mipony-plugin\tbmipo.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{90d46c30-9f25-4104-aea9-35c3f84477ff}"= "c:\program files (x86)\mipony-plugin\tbmipo.dll" [2010-02-22 2353176]
.
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"VideoWebCamera"="c:\program files (x86)\VideoWebCamera\VideoWebCamera.exe" [2009-08-11 1507410]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 VBoxDRV;PortableVBoxDRV;f:\virtualbox\Portable-VirtualBox\app64\drivers\VBoxDrv\VBoxDrv.sys [x]
R2 VBoxUSBMon;PortableVBoxUSBMon;f:\virtualbox\Portable-VirtualBox\app64\drivers\USB\filter\VBoxUSBMon.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 16776]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 9096]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S3 k57nd60a;Gigabit Ethernet Broadcom NetXtreme - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 netw5v64;Driver scheda Intel(R) Wireless WiFi Link serie 5000 per Windows Vista a 64 bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
.
.
Contenuto della cartella 'Scheduled Tasks'
.
2011-04-16 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-04-09 15:24]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-10-05 1684264]
"Corel Photo Downloader"="c:\program files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" [2007-08-16 531272]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
.
------- Scansione supplementare -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.it/
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&sporta in Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: Scarica con Mipony - file://c:\program files (x86)\MiPony\Browser\IEContext.htm
FF - ProfilePath - c:\users\Maury\AppData\Roaming\Mozilla\Firefox\Profiles\twwqr4r2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2465030&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - mipony-plugin Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2465030&SearchSource=13
FF - prefs.js: network.proxy.ftp - wsecmr.atm.root.local
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - wsecmr.atm.root.local
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - wsecmr.atm.root.local
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - wsecmr.atm.root.local
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - wsecmr.atm.root.local
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: mipony-plugin Toolbar: {90d46c30-9f25-4104-aea9-35c3f84477ff} - %profile%\extensions\{90d46c30-9f25-4104-aea9-35c3f84477ff}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{90D46C30-9F25-4104-AEA9-35C3F84477FF} - (no file)
.
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2011-04-16 20:55:26
ComboFix-quarantined-files.txt 2011-04-16 18:55
ComboFix2.txt 2011-04-16 18:41
.
Pre-Run: 42.189.234.176 byte disponibili
Post-Run: 41.908.875.264 byte disponibili
.
- - End Of File - - 103A28653B10670D8EEA5AAE896CD9AB
r16
Inviato: Sunday, April 17, 2011 3:36:48 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Non hai scaricato Combofix, sul Desktop, come avevo indicato, ma nella cartella "Downloads".

Scarica MBRCheck, e e salvalo sul desktop.
http://ad13.geekstogo.com/MBRCheck.exe
Chiudi tutti i programmi.
Doppio click su MBRCheck, che hai scaricato sul desktop, ed eseguilo.
Attendi la fine della scansione.
Finita la scansione (dura pochissimo) ti appare nella finestra questa scritta:
Found non-standard or infected MBR.
Oppure:
Windows xp MBR code detected.
Dimmi quale della 2 ti compare.

@Alfonso:
In questo momento, le pagine del forum, si aprono con estrema lentezza.
O c'è una manutenzione in corso, oppure ci sono problemi.
andemaldom
Inviato: Sunday, April 17, 2011 7:40:50 PM
Rank: Member

Iscritto dal : 4/15/2011
Posts: 17
il 2°
Windows xp MBR code detected.

scaricato su desktop eseguito come amministratore

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Professional
Windows Information: Service Pack 1 (build 7601), 64-bit
Base Board Manufacturer: Packard Bell
BIOS Manufacturer: Phoenix Technologies LTD
System Manufacturer: Packard Bell
System Product Name: EASYNOTE TJ65
Logical Drives Mask: 0x0000000c

Kernel Drivers (total 185):
0x02C4F000 \SystemRoot\system32\ntoskrnl.exe
0x02C06000 \SystemRoot\system32\hal.dll
0x00BAC000 \SystemRoot\system32\kdcom.dll
0x00C4D000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00C9C000 \SystemRoot\system32\PSHED.dll
0x00CB0000 \SystemRoot\system32\CLFS.SYS
0x00D0E000 \SystemRoot\system32\CI.dll
0x00EB0000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F54000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00F63000 \SystemRoot\system32\drivers\ACPI.sys
0x00FBA000 \SystemRoot\system32\drivers\WMILIB.SYS
0x00FC3000 \SystemRoot\system32\drivers\msisadrv.sys
0x00FCD000 \SystemRoot\system32\drivers\pci.sys
0x00E00000 \SystemRoot\system32\drivers\vdrvroot.sys
0x00E0D000 \SystemRoot\System32\drivers\partmgr.sys
0x00E22000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00E2B000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00E37000 \SystemRoot\system32\drivers\volmgr.sys
0x00E4C000 \SystemRoot\System32\drivers\volmgrx.sys
0x00DCE000 \SystemRoot\System32\drivers\mountmgr.sys
0x00C00000 \SystemRoot\system32\drivers\vmbus.sys
0x00DE8000 \SystemRoot\system32\drivers\winhv.sys
0x00C3C000 \SystemRoot\system32\drivers\atapi.sys
0x01083000 \SystemRoot\system32\drivers\ataport.SYS
0x010AD000 \SystemRoot\system32\drivers\msahci.sys
0x010B8000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x010C8000 \SystemRoot\system32\drivers\amdxata.sys
0x010D3000 \SystemRoot\system32\drivers\fltmgr.sys
0x0111F000 \SystemRoot\system32\drivers\fileinfo.sys
0x01226000 \SystemRoot\System32\Drivers\Ntfs.sys
0x01133000 \SystemRoot\System32\Drivers\msrpc.sys
0x013C9000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01000000 \SystemRoot\System32\Drivers\cng.sys
0x013E4000 \SystemRoot\System32\drivers\pcw.sys
0x013F5000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x014E4000 \SystemRoot\system32\drivers\ndis.sys
0x01400000 \SystemRoot\system32\drivers\NETIO.SYS
0x01460000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x0160F000 \SystemRoot\System32\drivers\tcpip.sys
0x01813000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0185D000 \SystemRoot\system32\drivers\vmstorfl.sys
0x0186D000 \SystemRoot\system32\drivers\volsnap.sys
0x018B9000 \SystemRoot\System32\Drivers\spldr.sys
0x018C1000 \SystemRoot\System32\drivers\rdyboost.sys
0x018FB000 \SystemRoot\System32\Drivers\mup.sys
0x0190D000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01916000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01950000 \SystemRoot\system32\DRIVERS\disk.sys
0x01966000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x0148B000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0x01600000 \SystemRoot\System32\Drivers\Null.SYS
0x019F8000 \SystemRoot\System32\Drivers\Beep.SYS
0x014BC000 \SystemRoot\System32\drivers\vga.sys
0x015D7000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x014CA000 \SystemRoot\System32\drivers\watchdog.sys
0x014DA000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x01200000 \SystemRoot\system32\drivers\rdpencdd.sys
0x01209000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01212000 \SystemRoot\System32\Drivers\Msfs.SYS
0x01072000 \SystemRoot\System32\Drivers\Npfs.SYS
0x01191000 \SystemRoot\system32\DRIVERS\tdx.sys
0x011B3000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x03AF3000 \SystemRoot\system32\drivers\afd.sys
0x03B7C000 \SystemRoot\System32\DRIVERS\netbt.sys
0x03BC1000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x03BCA000 \SystemRoot\system32\DRIVERS\pacer.sys
0x03BF0000 \SystemRoot\system32\DRIVERS\netbios.sys
0x03A00000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x03A1B000 \SystemRoot\system32\drivers\termdd.sys
0x03A2F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x03A80000 \SystemRoot\system32\drivers\nsiproxy.sys
0x03A8C000 \SystemRoot\system32\drivers\mssmbios.sys
0x03A97000 \SystemRoot\System32\drivers\discache.sys
0x03CED000 \SystemRoot\system32\drivers\csc.sys
0x03D70000 \SystemRoot\System32\Drivers\dfsc.sys
0x03D8E000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x03D9F000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x0F03E000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x0FCD0000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x0FCD2000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x03C00000 \SystemRoot\System32\drivers\dxgmms1.sys
0x0FDC6000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x03C46000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x0FDD3000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x0F000000 \SystemRoot\system32\drivers\HDAudBus.sys
0x03C9C000 \SystemRoot\system32\DRIVERS\k57nd60a.sys
0x03E32000 \SystemRoot\system32\DRIVERS\netw5v64.sys
0x0436D000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x04372000 \SystemRoot\system32\drivers\i8042prt.sys
0x04390000 \SystemRoot\system32\drivers\kbdclass.sys
0x0439F000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x043E5000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x043E7000 \SystemRoot\system32\drivers\mouclass.sys
0x043F6000 \SystemRoot\system32\drivers\wmiacpi.sys
0x03E00000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x03E16000 \SystemRoot\system32\drivers\CompositeBus.sys
0x0F024000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x03DC5000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x03E26000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x03AA6000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x0FDE4000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x011C0000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x03AD5000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x03DE9000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x0F03A000 \SystemRoot\system32\drivers\swenum.sys
0x048A0000 \SystemRoot\system32\drivers\ks.sys
0x048E3000 \SystemRoot\system32\drivers\umbus.sys
0x048F5000 \SystemRoot\system32\drivers\usbhub.sys
0x0494F000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x04964000 \SystemRoot\system32\drivers\HdAudio.sys
0x049C0000 \SystemRoot\system32\drivers\portcls.sys
0x04800000 \SystemRoot\system32\drivers\drmk.sys
0x04822000 \SystemRoot\system32\drivers\ksthunk.sys
0x04828000 \SystemRoot\system32\drivers\nvhda64v.sys
0x0484B000 \SystemRoot\System32\Drivers\crashdmp.sys
0x04859000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x04865000 \SystemRoot\System32\Drivers\dump_msahci.sys
0x04870000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x00000000 \SystemRoot\System32\win32k.sys
0x04883000 \SystemRoot\System32\drivers\Dxapi.sys
0x01996000 \SystemRoot\system32\drivers\usbccgp.sys
0x01E4C000 \SystemRoot\System32\Drivers\usbvideo.sys
0x01E7A000 \SystemRoot\system32\DRIVERS\monitor.sys
0x005F0000 \SystemRoot\System32\TSDDD.dll
0x006F0000 \SystemRoot\System32\cdd.dll
0x01E88000 \SystemRoot\system32\drivers\luafv.sys
0x01EAB000 \SystemRoot\system32\drivers\WudfPf.sys
0x01ECC000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x01EE1000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x01F34000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x01F47000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x046A1000 \SystemRoot\system32\drivers\HTTP.sys
0x0476A000 \SystemRoot\system32\DRIVERS\bowser.sys
0x04788000 \SystemRoot\System32\drivers\mpsdrv.sys
0x047A0000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x04600000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x0464D000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x062CB000 \SystemRoot\system32\drivers\peauth.sys
0x06371000 \SystemRoot\System32\Drivers\secdrv.SYS
0x0637C000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x063AD000 \SystemRoot\System32\drivers\tcpipreg.sys
0x063BF000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x063DC000 \SystemRoot\system32\DRIVERS\MpNWMon.sys
0x06200000 \SystemRoot\System32\DRIVERS\srv2.sys
0x01F5F000 \SystemRoot\System32\DRIVERS\srv.sys
0x0626A000 \SystemRoot\system32\DRIVERS\NisDrvWFP.sys
0x77310000 \Windows\System32\ntdll.dll
0x47F70000 \Windows\System32\smss.exe
0xFF630000 \Windows\System32\apisetschema.dll
0xFF660000 \Windows\System32\autochk.exe
0xFF580000 \Windows\System32\clbcatq.dll
0xFF4A0000 \Windows\System32\oleaut32.dll
0x771F0000 \Windows\System32\kernel32.dll
0xFF450000 \Windows\System32\ws2_32.dll
0xFF3F0000 \Windows\System32\Wldap32.dll
0xFF350000 \Windows\System32\comdlg32.dll
0x774E0000 \Windows\System32\normaliz.dll
0xFF2B0000 \Windows\System32\msvcrt.dll
0xFF1E0000 \Windows\System32\usp10.dll
0xFF1D0000 \Windows\System32\lpk.dll
0x770F0000 \Windows\System32\user32.dll
0xFE440000 \Windows\System32\shell32.dll
0x774D0000 \Windows\System32\psapi.dll
0xFE3C0000 \Windows\System32\difxapi.dll
0xFE290000 \Windows\System32\rpcrt4.dll
0x76EE0000 \Windows\System32\iertutil.dll
0xFE270000 \Windows\System32\imagehlp.dll
0xFE260000 \Windows\System32\nsi.dll
0xFE230000 \Windows\System32\imm32.dll
0x76D90000 \Windows\System32\urlmon.dll
0xFE120000 \Windows\System32\msctf.dll
0xFE0A0000 \Windows\System32\shlwapi.dll
0xFDE90000 \Windows\System32\ole32.dll
0xFDCB0000 \Windows\System32\setupapi.dll
0xFDBD0000 \Windows\System32\advapi32.dll
0x76C30000 \Windows\System32\wininet.dll
0xFDBB0000 \Windows\System32\sechost.dll
0xFDB40000 \Windows\System32\gdi32.dll
0xFDB00000 \Windows\System32\wintrust.dll
0xFDA60000 \Windows\System32\comctl32.dll
0xFD9F0000 \Windows\System32\KernelBase.dll
0xFD880000 \Windows\System32\crypt32.dll
0xFD860000 \Windows\System32\devobj.dll
0xFD820000 \Windows\System32\cfgmgr32.dll
0xFD810000 \Windows\System32\msasn1.dll

Processes (total 43):
0 System Idle Process
4 System
264 C:\Windows\System32\smss.exe
356 csrss.exe
408 C:\Windows\System32\wininit.exe
420 csrss.exe
460 C:\Windows\System32\services.exe
476 C:\Windows\System32\lsass.exe
488 C:\Windows\System32\lsm.exe
584 C:\Windows\System32\winlogon.exe
624 C:\Windows\System32\svchost.exe
684 C:\Windows\System32\nvvsvc.exe
724 C:\Windows\System32\svchost.exe
772 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
872 C:\Windows\System32\svchost.exe
904 C:\Windows\System32\svchost.exe
932 C:\Windows\System32\svchost.exe
404 C:\Windows\System32\svchost.exe
1152 C:\Windows\System32\svchost.exe
1336 C:\Windows\System32\nvvsvc.exe
1372 C:\Windows\System32\spoolsv.exe
1400 C:\Windows\System32\svchost.exe
600 C:\Windows\System32\dwm.exe
552 C:\Windows\explorer.exe
1276 C:\Windows\System32\taskhost.exe
1784 C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
2060 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2068 C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
2080 C:\Program Files\Microsoft Security Client\msseces.exe
2088 C:\Program Files\Windows Sidebar\sidebar.exe
2472 C:\Windows\System32\svchost.exe
2700 C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
2780 C:\Windows\System32\svchost.exe
2904 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
2408 C:\Windows\System32\SearchIndexer.exe
2740

questo è il log




r16
Inviato: Sunday, April 17, 2011 10:04:58 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ok.
In pratica non sono state rilevate infezioni.

Commenta:
è un po' di tempo che si avvia lentamente

Quanto lentamente?
Quanto ci mette, ad arrivare al Desktop?
andemaldom
Inviato: Sunday, April 17, 2011 10:21:31 PM
Rank: Member

Iscritto dal : 4/15/2011
Posts: 17
un paio di settimane,,,,, ci mette circa 5 minuti la pw di windows è rapida ci mettetanto ad arrivare al desktop, se interrompo il primo avvio riavviandolo si avvia più rapidamente.....

spero di essermi spiegato
r16
Inviato: Sunday, April 17, 2011 10:44:33 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Prova a disistallare Microsoft Security Essentials .
Vedi se migliora.
Attenzione, non navigare senza antivirus.
andemaldom
Inviato: Tuesday, April 19, 2011 11:00:23 PM
Rank: Member

Iscritto dal : 4/15/2011
Posts: 17
sembro aver risolto disistallando explorer 9 ma è in versione beta??????

comunque grazie per l'aiuto.....
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.