Valutazione 4.87/ 5 (100.00%) 5838 voti

Condividi:        

File log ComboFix su Packardbell

Risolvi qui i tuoi problemi legati a Windows '95, '98, ME, NT, 2000, XP, 2003, Vista...

Moderatori: -> EleKtrA <-, antoo69

File log ComboFix su Packardbell

Postdi paolis » 28/11/12 10:21

Ho un packardbell 8,00 giga di ram, windows 7 home premium sp1, Intel(R) Core (TM) i7 cpu 860 @2.80 ghz
il computer è lentissimo, erano stati installati tanti programmi sicuramente con virus. allego file log di combofix

ComboFix 12-11-27.01 - user 28/11/2012 9:49.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.39.1040.18.8183.6546 [GMT 1:00]
Eseguito da: c:\users\user\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Creato nuovo punto di ripristino
.
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\URTTemp
c:\windows\SysWow64\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Files Creati Da 2012-10-28 al 2012-11-28 )))))))))))))))))))))))))))))))))))
.
.
2012-11-28 08:52 . 2012-11-28 08:52 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-11-28 08:52 . 2012-11-28 08:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-28 08:52 . 2012-11-28 08:52 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{940EE433-8E9B-4126-9820-04AD9F79EA52}\offreg.dll
2012-11-26 11:20 . 2012-11-26 11:20 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-11-26 10:57 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{940EE433-8E9B-4126-9820-04AD9F79EA52}\mpengine.dll
2012-11-21 15:01 . 2012-11-21 15:04 -------- d-----w- c:\users\user\AppData\Local\Microsoft Games
2012-11-21 14:52 . 2009-12-09 15:06 34632 ----a-w- c:\windows\system32\TURegOpt.exe
2012-11-21 14:52 . 2009-12-09 14:59 25928 ----a-w- c:\windows\system32\authuitu.dll
2012-11-21 14:52 . 2009-12-09 14:59 21320 ----a-w- c:\windows\SysWow64\authuitu.dll
2012-11-21 14:52 . 2009-12-09 14:59 36168 ----a-w- c:\windows\system32\uxtuneup.dll
2012-11-21 14:52 . 2009-12-09 14:59 30024 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2012-11-21 14:52 . 2012-11-21 14:52 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2010
2012-11-21 14:52 . 2012-11-21 14:52 -------- d-sh--w- c:\programdata\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2012-11-21 11:19 . 2012-08-24 18:05 340992 ----a-w- c:\windows\system32\schannel.dll
2012-11-21 11:19 . 2012-08-24 16:57 247808 ----a-w- c:\windows\SysWow64\schannel.dll
2012-11-21 11:19 . 2012-08-24 18:13 154480 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-11-21 11:19 . 2012-08-24 18:09 458712 ----a-w- c:\windows\system32\drivers\cng.sys
2012-11-21 11:19 . 2012-08-24 18:04 307200 ----a-w- c:\windows\system32\ncrypt.dll
2012-11-21 11:19 . 2012-08-24 18:03 1448448 ----a-w- c:\windows\system32\lsasrv.dll
2012-11-21 11:19 . 2012-08-24 16:57 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2012-11-21 11:19 . 2012-08-24 16:57 220160 ----a-w- c:\windows\SysWow64\ncrypt.dll
2012-11-21 11:19 . 2012-08-24 16:53 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2012-11-21 11:10 . 2012-11-21 11:10 -------- d-----w- c:\users\user\AppData\Local\ElevatedDiagnostics
2012-11-21 11:07 . 2011-04-01 07:21 41984 ----a-w- c:\windows\system32\Spool\prtprocs\x64\KOAZ8A_P.DLL
2012-11-21 11:06 . 2011-03-10 07:14 15360 ----a-w- c:\windows\system32\KOAZ8A_L.DLL
2012-11-21 10:51 . 2011-03-10 15:14 15360 ----a-w- c:\windows\system32\KOAZ8J_L.DLL
2012-11-17 17:39 . 2012-11-17 17:39 -------- d-----w- c:\program files (x86)\Microsoft CAPICOM 2.1.0.2
2012-11-17 16:05 . 2012-11-17 16:06 -------- d-----w- c:\users\user\AppData\Roaming\GlarySoft
2012-11-17 16:05 . 2012-11-17 16:06 -------- d-----w- c:\program files (x86)\Glary Utilities
2012-11-15 11:54 . 2012-07-26 08:00 2560 ----a-w- c:\windows\system32\drivers\it-IT\wdf01000.sys.mui
2012-11-15 11:54 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-15 11:54 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-15 11:54 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2012-11-15 11:54 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-15 11:49 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-11-15 11:49 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-15 11:49 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-15 11:49 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-15 11:49 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2012-11-15 11:49 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2012-11-15 11:49 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-15 11:41 . 2012-11-15 11:41 -------- d--h--w- c:\programdata\Common Files
2012-11-15 11:40 . 2012-11-21 14:52 -------- d-----w- c:\users\user\AppData\Roaming\TuneUp Software
2012-11-15 11:39 . 2012-11-21 14:52 -------- d-----w- c:\programdata\TuneUp Software
2012-11-15 11:39 . 2012-11-15 11:39 -------- d-sh--w- c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-11-15 11:10 . 2012-11-15 11:10 -------- d-----w- c:\users\user\AppData\Local\Google
2012-11-15 11:10 . 2012-11-15 11:10 -------- d-----w- c:\program files (x86)\Google
2012-11-15 11:09 . 2012-11-15 11:10 -------- d-----w- c:\users\user\AppData\Local\Deployment
2012-11-15 11:09 . 2012-11-15 11:09 -------- d-----w- c:\users\user\AppData\Local\Apps
2012-11-14 19:39 . 2012-11-21 11:22 -------- d-----w- c:\program files (x86)\Microsoft Works
2012-11-14 19:37 . 2012-11-14 19:37 -------- d-----w- c:\program files\Microsoft Office
2012-11-14 19:37 . 2012-11-14 19:37 -------- d-----w- C:\IDE
2012-11-14 19:37 . 2012-11-14 19:37 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2012-11-14 19:37 . 2012-11-14 19:37 -------- d-----w- c:\users\user\AppData\Local\Microsoft Help
2012-11-14 19:37 . 2012-11-26 11:21 -------- d-----w- c:\programdata\Microsoft Help
2012-11-14 19:36 . 2012-11-14 19:36 -------- d-----r- C:\MSOCache
2012-11-14 19:34 . 2012-11-14 19:34 -------- d-----w- c:\users\user\Dati applicazioni
2012-11-05 10:25 . 2012-11-05 10:25 -------- d-----w- c:\users\user\AppData\Roaming\Unitelm
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-15 11:50 . 2012-10-09 14:06 66395536 ----a-w- c:\windows\system32\MRT.exe
2012-10-10 20:23 . 2012-10-10 20:23 1867112 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2012-10-10 20:23 . 2012-10-10 20:23 18252136 ----a-w- c:\windows\system32\nvd3dumx.dll
2012-10-10 20:23 . 2012-10-10 20:23 1482600 ----a-w- c:\windows\system32\nvdispgenco64.dll
2012-10-10 20:23 . 2012-10-10 20:23 6127464 ----a-w- c:\windows\SysWow64\nvopencl.dll
2012-10-10 20:23 . 2012-10-10 20:23 2574696 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2012-10-10 20:23 . 2012-10-10 20:23 25256296 ----a-w- c:\windows\system32\nvcompiler.dll
2012-10-10 20:23 . 2012-10-10 20:23 7414632 ----a-w- c:\windows\system32\nvopencl.dll
2012-10-10 20:23 . 2012-10-09 10:08 2731880 ----a-w- c:\windows\system32\nvapi64.dll
2012-10-10 20:23 . 2012-10-09 10:09 14922600 ----a-w- c:\windows\system32\nvwgf2umx.dll
2012-10-10 20:23 . 2012-10-10 20:23 9146728 ----a-w- c:\windows\system32\nvcuda.dll
2012-10-10 20:23 . 2012-10-10 20:23 7697768 ----a-w- c:\windows\SysWow64\nvcuda.dll
2012-10-10 20:23 . 2012-10-10 20:23 2218344 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-10-10 20:23 . 2012-10-10 20:23 12501352 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2012-10-10 20:22 . 2012-10-10 20:22 2428776 ----a-w- c:\windows\SysWow64\nvapi.dll
2012-10-10 20:22 . 2012-10-10 20:22 26331496 ----a-w- c:\windows\system32\nvoglv64.dll
2012-10-10 20:22 . 2012-10-09 10:12 1760104 ----a-w- c:\windows\system32\nvdispco64.dll
2012-10-10 20:22 . 2012-10-10 20:22 15309160 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2012-10-10 20:22 . 2012-10-10 20:22 2747240 ----a-w- c:\windows\system32\nvcuvid.dll
2012-10-10 20:22 . 2012-10-10 20:22 19906920 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2012-10-10 20:22 . 2012-10-10 20:22 13443944 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-10-10 20:22 . 2012-10-10 20:22 17559912 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2012-10-10 10:19 . 2012-10-10 10:19 2560 ----a-w- c:\windows\SysWow64\drivers\it-IT\qwavedrv.sys.mui
2012-10-10 10:18 . 2012-10-10 10:18 49152 ----a-w- c:\windows\SysWow64\drivers\it-IT\tcpip.sys.mui
2012-10-10 10:18 . 2012-10-10 10:18 30720 ----a-w- c:\windows\SysWow64\drivers\it-IT\bfe.dll.mui
2012-10-10 10:18 . 2012-10-10 10:18 16384 ----a-w- c:\windows\SysWow64\drivers\it-IT\pacer.sys.mui
2012-10-10 10:18 . 2012-10-10 10:18 2560 ----a-w- c:\windows\SysWow64\drivers\it-IT\scfilter.sys.mui
2012-10-10 10:18 . 2012-10-10 10:18 6144 ----a-w- c:\windows\SysWow64\drivers\it-IT\ndiscap.sys.mui
2012-10-10 09:56 . 2012-10-10 09:56 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-10 09:56 . 2012-10-10 09:56 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-09 16:03 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-10-09 16:03 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-10-09 14:14 . 2012-10-09 14:14 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-10-09 14:14 . 2012-10-09 14:14 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-10-09 14:14 . 2012-10-09 14:14 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-10-09 14:14 . 2012-10-09 14:14 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-10-09 14:14 . 2012-10-09 14:14 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-10-09 14:14 . 2012-10-09 14:14 82432 ----a-w- c:\windows\system32\icardie.dll
2012-10-09 14:14 . 2012-10-09 14:14 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-10-09 14:14 . 2012-10-09 14:14 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-10-09 14:14 . 2012-10-09 14:14 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-10-09 14:14 . 2012-10-09 14:14 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-10-09 14:14 . 2012-10-09 14:14 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-10-09 14:14 . 2012-10-09 14:14 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-10-09 14:14 . 2012-10-09 14:14 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-10-09 14:14 . 2012-10-09 14:14 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-10-09 14:14 . 2012-10-09 14:14 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-10-09 14:14 . 2012-10-09 14:14 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-10-09 14:14 . 2012-10-09 14:14 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-10-09 14:14 . 2012-10-09 14:14 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-10-09 14:14 . 2012-10-09 14:14 448512 ----a-w- c:\windows\system32\html.iec
2012-10-09 14:14 . 2012-10-09 14:14 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-10-09 14:14 . 2012-10-09 14:14 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-10-09 14:14 . 2012-10-09 14:14 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-10-09 14:14 . 2012-10-09 14:14 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-10-09 14:14 . 2012-10-09 14:14 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-10-09 14:14 . 2012-10-09 14:14 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-10-09 14:14 . 2012-10-09 14:14 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-10-09 14:14 . 2012-10-09 14:14 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-10-09 14:14 . 2012-10-09 14:14 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-10-09 14:14 . 2012-10-09 14:14 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-10-09 14:14 . 2012-10-09 14:14 222208 ----a-w- c:\windows\system32\msls31.dll
2012-10-09 14:14 . 2012-10-09 14:14 197120 ----a-w- c:\windows\system32\msrating.dll
2012-10-09 14:14 . 2012-10-09 14:14 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-10-09 14:14 . 2012-10-09 14:14 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-10-09 14:14 . 2012-10-09 14:14 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-10-09 14:14 . 2012-10-09 14:14 160256 ----a-w- c:\windows\system32\wextract.exe
2012-10-09 14:14 . 2012-10-09 14:14 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-10-09 14:14 . 2012-10-09 14:14 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-10-09 14:14 . 2012-10-09 14:14 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-10-09 14:14 . 2012-10-09 14:14 149504 ----a-w- c:\windows\system32\occache.dll
2012-10-09 14:14 . 2012-10-09 14:14 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-10-09 14:14 . 2012-10-09 14:14 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-10-09 14:14 . 2012-10-09 14:14 12288 ----a-w- c:\windows\system32\mshta.exe
2012-10-09 14:14 . 2012-10-09 14:14 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-10-09 14:14 . 2012-10-09 14:14 114176 ----a-w- c:\windows\system32\admparse.dll
2012-10-09 14:14 . 2012-10-09 14:14 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-10-09 14:14 . 2012-10-09 14:14 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-10-09 14:14 . 2012-10-09 14:14 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-10-09 14:14 . 2012-10-09 14:14 103936 ----a-w- c:\windows\system32\inseng.dll
2012-10-09 14:14 . 2012-10-09 14:14 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-10-09 13:23 . 2012-10-09 09:42 98848 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-10-09 13:23 . 2012-10-09 09:42 132832 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-10-02 19:51 . 2012-10-09 10:12 3293544 ----a-w- c:\windows\system32\nvsvc64.dll
2012-10-02 19:51 . 2012-10-09 10:12 6200680 ----a-w- c:\windows\system32\nvcpl.dll
2012-10-02 19:50 . 2012-10-09 10:12 891240 ----a-w- c:\windows\system32\nvvsvc.exe
2012-10-02 19:50 . 2012-10-09 10:12 63336 ----a-w- c:\windows\system32\nvshext.dll
2012-10-02 19:50 . 2012-10-09 10:12 2557800 ----a-w- c:\windows\system32\nvsvcr.dll
2012-10-02 19:50 . 2012-10-09 10:12 118120 ----a-w- c:\windows\system32\nvmctray.dll
2012-10-02 12:15 . 2012-10-02 12:15 430952 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2012-09-14 19:19 . 2012-10-09 17:09 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-14 18:28 . 2012-10-09 17:09 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-08-31 18:19 . 2012-10-09 17:07 1659760 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-08-30 18:03 . 2012-10-09 17:08 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-30 17:12 . 2012-10-09 17:08 3968880 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12 . 2012-10-09 17:08 3914096 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-10-09 348664]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 WatAdminSvc;Servizio Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-09 1255736]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-02-03 27760]
S2 AntiVirSchedulerService;Avira Pianificatore;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-10-09 86224]
S2 MSSQL$SIDIOPEN;SQL Server (SIDIOPEN);c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2009-12-09 1394504]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [2009-06-22 273072]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2012-08-24 1885792]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2009-10-14 11856]
.
.
Contenuto della cartella 'Scheduled Tasks'
.
2012-11-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-10 09:56]
.
2012-11-28 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2012-11-17 11:45]
.
2012-11-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-15 11:10]
.
2012-11-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-15 11:10]
.
.
--------- X64 Entries -----------
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Scansione supplementare -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.it/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&sporta in Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 195.78.215.228 195.78.223.228 8.8.8.8
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Ora fine scansione: 2012-11-28 09:54:15
ComboFix-quarantined-files.txt 2012-11-28 08:54
.
Pre-Run: 442.780.639.232 byte disponibili
Post-Run: 442.270.126.080 byte disponibili
.
- - End Of File - - 40A8441929856F61F849D77710070FEC
paolis
Utente Junior
 
Post: 36
Iscritto il: 09/10/12 14:13

Sponsor
 

Re: File log ComboFix su Packardbell

Postdi FrancescoFDAC » 28/11/12 14:46

Il log appare pulito.
Che problemi riscontri?

Scarica AdwCleaner: http://www.bleepingcomputer.com/download/adwcleaner/
● termina tutti i programmi aperti
● clicca sul pulsante Cerca
● attendi pazientemente il termine della scansione
● clicca sul pulsante Elimina e conferma cliccando OK
● prosegui cliccando OK per altre due volte: il sistema si riavvia automaticamente
allega il log che compare al riavvio
FrancescoFDAC
Utente Senior
 
Post: 1048
Iscritto il: 13/08/11 09:53

Re: File log ComboFix su Packardbell

Postdi paolis » 29/11/12 09:19

Il pc è estremamente lento... ora provo con quello che mi hai scritto e vi faccio sapere. grazie anticipatamente
paolis
Utente Junior
 
Post: 36
Iscritto il: 09/10/12 14:13

Re: File log ComboFix su Packardbell

Postdi paolis » 03/12/12 12:49

# AdwCleaner v2.011 - Logfile creato il 03/12/2012 alle 12:46:18
# Aggiornamento 02/12/2012 by Xplode
# Sistema Operativo : Windows 7 Home Premium Service Pack 1 (64 bits)
# Utente : user - USER-PC
# Modalità Avvio : Modalità Normale
# Eseguito da : C:\Users\user\Desktop\AdwCleaner.exe
# Opzioni [Elimina]


***** [Servizi] *****


***** [File / Cartelle] *****


***** [Registro] *****


***** [Browser Internet] *****

-\\ Internet Explorer v9.0.8112.16455

[OK] Registro Pulito.

-\\ Google Chrome v23.0.1271.95

*************************

AdwCleaner[R1].txt - [720 octets] - [29/11/2012 15:20:49]
AdwCleaner[R2].txt - [815 octets] - [03/12/2012 12:46:07]
AdwCleaner[S1].txt - [781 octets] - [29/11/2012 15:21:02]
AdwCleaner[S2].txt - [749 octets] - [03/12/2012 12:46:18]

########## EOF - C:\AdwCleaner[S2].txt - [808 octets] ##########
paolis
Utente Junior
 
Post: 36
Iscritto il: 09/10/12 14:13

Re: File log ComboFix su Packardbell

Postdi FrancescoFDAC » 03/12/12 13:45

Scarica Kaspersky TDSS Killer: http://support.kaspersky.com/downloads/ ... killer.exe
● posiziona il file scaricato sul Desktop
● clicca due volte sul file TDSSKiller.exe per avviare l'applicazione
● clicca sulla voce Change parameters
● metti il segno di spunta alla voce Loaded modules
● compare la seguente finestra:
Extended monitoring driver is required for this option.
Press "Reboot now" to install driver and reboot, or "Cancel" to continue.

● clicca sulla voce Reboot now
● il PC si riavvierà; compare nuovamente la finestra di Kaspersky TDSS Killer
● clicca ancora la voce Change parameters
● metti il segno di spunta alla voce Verify file digital signatures
● metti il segno di spunta alla voce Detect TDLFS file system
● successivamente premi il pulsante Start scan

Nota - riguardo al programma:
● non cliccare sul pulsante Stop scan per nessun motivo, la scansione si interromperebbe
● al termine della scansione ed eventuale rimozione di minacce, clicca sul pulsante Close

Giunti a questo punto, inizia la scansione del sistema alla ricerca di software malevolo:
● se viene trovato un file infetto, l'azione di default sarà Cure: clicca quindi su Continua
● se viene trovato un file sospetto, l'azione di default sarà Skip: clicca quindi su Continua
● se non viene rilevato nulla, chiudi semplicemente il programma al termine della scansione

Una volta terminata la scansione, si presenterà una di queste due opzioni:
non è necessario il riavvio del sistema: allega il Report situato nel Disco Locale C:, ha nome TDSSKiller.[Version]_[Date]_[Time]_log.txt (es: C:\TDSSKiller.2.8.13_22.10.2012_23.25.43_log.txt)
● è necessario riavviare il sistema: clicca su Riavvia ora, infine allega il risultato della scansione
FrancescoFDAC
Utente Senior
 
Post: 1048
Iscritto il: 13/08/11 09:53

Re: File log ComboFix su Packardbell

Postdi paolis » 10/12/12 18:51

paolis
Utente Junior
 
Post: 36
Iscritto il: 09/10/12 14:13

Re: File log ComboFix su Packardbell

Postdi FrancescoFDAC » 11/12/12 13:59

Ora come va?
FrancescoFDAC
Utente Senior
 
Post: 1048
Iscritto il: 13/08/11 09:53

Re: File log ComboFix su Packardbell

Postdi paolis » 12/12/12 09:07

meglio. grazie. riscontro ancora lievi problemi all'avvio, ci vuole un pò prima che si attivi completamente
paolis
Utente Junior
 
Post: 36
Iscritto il: 09/10/12 14:13

Re: File log ComboFix su Packardbell

Postdi FrancescoFDAC » 12/12/12 14:10

Scarica TFC by OldTimer: http://oldtimer.geekstogo.com/TFC.exe
● posiziona il tool sul Desktop
termina tutti i programmi attivi, comprese le pagine Internet
● avvia il tool con un doppio click
● clicca, in basso a sinistra, sul pulsante Start
scomparirà, per qualche istante, il Desktop: nulla di cui preoccuparsi
● attendi pazientemente il termine delle operazioni
● clicca, in basso a destra, sul pulsante Exit
● una volta terminate le operazioni, chiudi il programma

Nota - riguardo al programma:
TFC by OldTimer serve ad eliminare i file temporeanei di tutti gli utenti, con facilità e velocemente

Scarica OTC by OldTimer: http://oldtimer.geekstogo.com/OTC.exe
● posiziona il tool sul Desktop
● chiudi tutti i programmi attivi
● avvia il tool con un doppio click
● clicca sul pulsante CleanUp!
● il programma chiede di riavviare il sistema: consenti, cliccando sul pulsante Yes

Nota - riguardo al programma:
OTC by OldTimer serve ad eliminare i programmi che abbiamo utilizzato per la pulizia (ComboFix in particolare) in modo automatico e preciso: al riavvio non noterai più l'icona di ComboFix, è del tutto normale

Abbiamo finito!
Ciao e alla prossima.
FrancescoFDAC
Utente Senior
 
Post: 1048
Iscritto il: 13/08/11 09:53


Torna a Sistemi Operativi Windows


Topic correlati a "File log ComboFix su Packardbell":


Chi c’è in linea

Visitano il forum: Nessuno e 5 ospiti