Ciao, inizio con il rispondere alla domanda: perchè il S.O. non è aggiornato. Forse sarà una mia fobia ,ma non faccio molti aggiornamenti perchè temo che questi possano appesantirmi il sistema.
Il mio pc non è di ultmissima generazione, ed inoltre da alcun mesi soffre maledettamente di lentezza. Le ho già tentate tutte ma con scarsi risultati per cui diciamo che mi sono quasi rassegnato a tenermelo così, almeno fino alla prossima formattazione. Perchè mi sa che la formattazione sia ormai l'unico rimedio che mi è rimasto a parte quello di cambiare il pc.
Riguardo alla scansone con Malwarebytes ne ho fatta una ieri ,ma non ha riscontrato nulla. Comunque ti posto ugualmente il log, e casomai se servisse sono pronto a rifarla.
La scansone con Combofix è appena terminata e anche di quella ti posto il log.
Ad ogni modo grazie mllle. Ciao.
Scansione con MalwarebytesMalwarebytes' Anti-Malware 1.41
Versione del database: 2881
Windows 5.1.2600 Service Pack 2, v.2135
01/10/2009 15.23.11
mbam-log-2009-10-01 (15-23-11).txt
Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 159351
Tempo trascorso: 1 hour(s), 12 minute(s), 3 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)
Chiavi di registro infette:
(Nessun elemento malevolo rilevato)
Valori di registro infetti:
(Nessun elemento malevolo rilevato)
Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)
Cartelle infette:
(Nessun elemento malevolo rilevato)
File infetti:
(Nessun elemento malevolo rilevato)
Scansione con CombofxComboFix 09-10-01.01 - Administrator 02/10/2009 19.41.13.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1033.18.767.554 [GMT 7:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {00000002-0002-0000-5424-1C7708000A00}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
/wow section - STAGE 8
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
/wow section - STAGE 9
The process cannot access the file because it is being used by another process.
/wow section - STAGE 10
/wow section - STAGE 17
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
/wow section - STAGE 23
The process cannot access the file because it is being used by another process.
/wow section - STAGE 24
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
/wow section - STAGE 32A
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The system cannot find the file LockedB.
/wow section - STAGE 33
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
/wow section - STAGE 34
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\libfn.dll
.
((((((((((((((((((((((((( Files Creati Da 2009-09-02 al 2009-10-02 )))))))))))))))))))))))))))))))))))
.
2009-10-02 10:46 . 2009-10-02 12:40 -------- d-----w- c:\windows\system32\CatRoot2
2009-10-02 05:22 . 2009-10-02 06:36 -------- d-----w- c:\program files\WhoCrashed
2009-09-18 14:17 . 2002-01-05 00:48 974848 ------w- c:\windows\system32\mfc70.dll
2009-09-18 14:17 . 2002-01-05 00:10 61440 ------w- c:\windows\system32\mfc70ita.dll
2009-09-18 14:17 . 2002-01-04 23:37 344064 ------w- c:\windows\system32\msvcr70.dll
2009-09-18 12:18 . 2004-05-18 13:52 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-09-04 03:50 . 2009-09-04 03:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\FTPGetter
2009-09-04 03:50 . 2009-09-04 03:51 -------- d-----w- c:\documents and settings\All Users\Application Data\FTPGetter
2009-09-04 03:50 . 2009-09-04 03:50 -------- d-----w- c:\program files\FTPGetter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-02 11:27 . 2009-01-16 05:38 -------- d-----w- c:\program files\eMule
2009-10-01 05:40 . 2008-10-02 09:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-29 04:44 . 2008-10-04 11:20 40416 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-26 20:18 . 2008-10-03 16:42 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype
2009-09-26 15:18 . 2008-10-03 16:44 -------- d-----w- c:\documents and settings\Administrator\Application Data\skypePM
2009-09-22 08:41 . 2009-05-27 12:14 -------- d-----w- c:\documents and settings\Administrator\Application Data\dvdcss
2009-09-18 14:17 . 2009-01-03 16:12 -------- d-----w- c:\program files\Common Files\Macromedia
2009-09-18 14:16 . 2008-10-02 08:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-10 07:54 . 2008-10-02 09:16 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 07:53 . 2008-10-02 09:16 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-06 11:26 . 2009-01-01 05:52 -------- d-----w- c:\program files\Macromedia
2009-08-19 05:48 . 2009-05-31 06:27 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-28 10:28 . 2009-07-28 10:28 4608 ----a-w- c:\windows\system32\w95inf32.dll
2009-07-28 10:28 . 2009-07-28 10:28 2272 ----a-w- c:\windows\system32\w95inf16.dll
2009-07-19 15:50 . 2004-04-23 10:57 12464 ----a-w- c:\windows\system32\drivers\secdrv.sys
2009-07-19 15:50 . 2009-07-19 15:50 564 ----a-w- c:\windows\eReg.dat
2009-01-26 11:12 . 2009-01-26 11:11 24 --sh--w- c:\windows\S3648A81E.tmp
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2009-06-27 190024]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-05-18 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"UseDesktopIniCache"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-15 04:19 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^PartMetBackup.lnk]
backup=c:\windows\pss\PartMetBackup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^IDW Logging Tool.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"DisplayTrayIcon"=c:\windows\system32\TrayIcon.exe
"flockbox"=c:\program files\My Lockbox\flockbox.exe /a
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\LinkCreator.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Strategy First\\War Times\\wartimes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [05/01/2009 18.12.53 17264]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [03/09/2008 14.07.14 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [03/09/2008 14.07.12 55024]
R2 FTPGetterLauncher;FTPGetter Launcher;c:\program files\FTPGetter\ftpgsrv.exe [04/09/2009 10.50.46 53760]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [03/09/2008 14.07.16 7408]
.
Contenuto della cartella 'Scheduled Tasks'
2009-10-02 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-12-07 02:38]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.msn.it/
uInternet Connection Wizard,ShellNext = hxxp://www.tot.co.th/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\b37eqjo7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\b37eqjo7.default\extensions\{bc4be15d-6a34-4356-9e97-79e43da32b1d}\components\FFAlert.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-02 19:49
Windows 5.1.2600 Service Pack 2, v.2135 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(692)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'lsass.exe'(760)
c:\windows\system32\dssenh.dll
.
Ora fine scansione: 2009-10-02 19.52.32
ComboFix-quarantined-files.txt 2009-10-02 12:51
ComboFix2.txt 2009-05-29 05:19
Pre-Run: 15.192.928.256 bytes free
Post-Run: 15.167.205.376 bytes free
176