Precedente :: Successivo |
Autore |
Messaggio |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 04 Lug 2006 01:26 Oggetto: |
|
|
ok allora avevo usato anche bene regrun platinum....trovava 7-8 cose gialle...ma a mio parere abbastanza normali....programmi del Vaio (modello della sony...portatile...)
HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\VAIO_VEDB\MSSQLServer\uptime_time_utc 04/07/2006 1.10 8 bytes Data mismatch between Windows API and raw hive data.
Ecco invece il piccolo log del Rootkit
GRAZIE ANCORA!
ps: sembra andare meglio....explorer ora è a 28mega...svchost a 16....
internet rifuziona...quindi già è qualcosa...
che dici faccio n'altra scansione online? e provo a fare anche l'altra oltre a kaspery? |
|
Top |
|
 |
holifay Dio maturo


Registrato: 08/03/05 10:48 Messaggi: 2912 Residenza: Milano
|
Inviato: 04 Lug 2006 01:43 Oggetto: |
|
|
Sì, mi sembra meglio.
Prova a fare una cosa: apri una finestra del dos (Start>esegui, digita CMD e poi premi invio)
Poi adesso apri task manager e termina il processo Explorer. Se non riparte da solo, avvialo tu dall finestra di dos digitando explorer (invio)
Questo nuovo explorer aperto adesso occupameno memoria?
Da una prima occhiata al log ho visto che hai il Download Accelerator Plus. Ti consiglio di rimuoverlo, secondo alcuni è un adware. Altro non ho visto, anche perchè in via preventiva ti avevo fatto resettare con Avenger la Appinit_DLLs
Il log di RKR è perfetto
Ti consiglio ancora:
1) scansione online con House call (o Panda)
2) Una passata dalla modalità provvisoria con Virit
3) se proprio vuoi strafare, scarica Ewido, aggiornalo e usalo dalla mod. provvisoria.
4) scarica winpfind e posta un log.
Se sopravvive qualcosa, saranno solo gli acari della polvere
Al termine, posta un nuovo log di HijackThis
Ciao! |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 04 Lug 2006 02:04 Oggetto: |
|
|
ci sto buttando il sangue senza un attimo di pausa da oggi alle 3 del pome.... per cui devono morire anche gli acari
Spero solo ke i valori di explorer tornino normali...perkè altrimenti non so proprio che sia
ora faccio tutto quello che mi hai detto....house call , virit e ewido
Poi posto il log di winp e di hijak e vediamo 1pò!
ps: con regrun...se faccio scan for virus..ora mi trova un maledetto file .sys che si va a creare nella cartella windows/driver...ogni volta con un nome diverso... |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 04 Lug 2006 08:45 Oggetto: |
|
|
Avrò dormito 1-2 ore per seguire passo passo tutti i processi... virit ha trovato 4 file infetti e li ha tolti...ecco i due log
Purtroppo per far funzionare l'adsl in wireless (e non attaccandomi al router con il cavo) ho dovuto attivare TUTTI I SERVIZI di services.msc ...perchè non riesco a capire quali posso disattivare...e non appena ne disattivo qualcuno il wireless non funziona +....
WINPFind
Codice: | WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.
If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.
»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180
»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»
Checking %SystemDrive% folder...
Checking %ProgramFilesDir% folder...
Checking %WinDir% folder...
UPX! 29/03/2006 12.09.18 438272 C:\WINDOWS\RunGuard.exe
Checking %System% folder...
UPX! 20/12/2005 14.21.38 481280 C:\WINDOWS\SYSTEM32\aswBoot.exe
aspack 18/03/2005 17.19.58 2337488 C:\WINDOWS\SYSTEM32\d3dx9_25.dll
aspack 26/05/2005 16.34.52 2297552 C:\WINDOWS\SYSTEM32\d3dx9_26.dll
aspack 22/07/2005 20.59.04 2319568 C:\WINDOWS\SYSTEM32\d3dx9_27.dll
aspack 05/12/2005 18.09.18 2323664 C:\WINDOWS\SYSTEM32\d3dx9_28.dll
aspack 03/02/2006 8.43.16 2332368 C:\WINDOWS\SYSTEM32\d3dx9_29.dll
aspack 31/03/2006 12.40.58 2388176 C:\WINDOWS\SYSTEM32\d3dx9_30.dll
PEC2 19/08/2004 14.00.00 41144 C:\WINDOWS\SYSTEM32\dfrg.msc
PEC2 13/04/2006 8.57.00 619156 C:\WINDOWS\SYSTEM32\DivX.dll
PECompact2 13/04/2006 8.57.00 619156 C:\WINDOWS\SYSTEM32\DivX.dll
PTech 12/01/2006 12.32.12 543496 C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2 10/03/2006 2.10.36 4799320 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 10/03/2006 2.10.36 4799320 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 19/08/2004 14.00.00 729600 C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor 19/08/2004 14.00.00 674816 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 19/08/2004 14.00.00 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu
aspack 30/06/2006 12.50.46 H 699392 C:\WINDOWS\SYSTEM32\wodfamoh.dll
Checking %System%\Drivers folder and sub-folders...
Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts
Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
04/07/2006 6.59.40 S 2048 C:\WINDOWS\bootstat.dat
27/06/2006 11.54.08 H 0 C:\WINDOWS\msmasster11121.inf
21/06/2006 0.26.24 H 890 C:\WINDOWS\system32\vsconfig.xml
30/06/2006 12.50.46 H 699392 C:\WINDOWS\system32\wodfamoh.dll
04/07/2006 7.09.18 H 1024 C:\WINDOWS\system32\config\default.LOG
04/07/2006 7.00.16 H 1024 C:\WINDOWS\system32\config\SAM.LOG
04/07/2006 7.03.32 H 1024 C:\WINDOWS\system32\config\SECURITY.LOG
04/07/2006 7.09.18 H 1024 C:\WINDOWS\system32\config\software.LOG
04/07/2006 7.09.20 H 1024 C:\WINDOWS\system32\config\system.LOG
12/05/2006 14.05.20 HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\f6dcadeb-d356-448d-a8ad-9a85cfe6f902
12/05/2006 14.05.20 HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\Preferred
23/05/2006 18.42.14 HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\a810fec8-41b3-4247-8ae6-b0470e86fdb2
23/05/2006 18.42.14 HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
03/07/2006 23.21.16 H 6 C:\WINDOWS\Tasks\SA.DAT
Checking for CPL files...
25/05/2004 17.06.58 417792 C:\WINDOWS\SYSTEM32\ac3filter.cpl
Microsoft Corporation 19/08/2004 14.00.00 70656 C:\WINDOWS\SYSTEM32\access.cpl
Realtek Semiconductor Corp. 21/09/2005 11.25.50 299008 C:\WINDOWS\SYSTEM32\ALSndMgr.Cpl
Microsoft Corporation 19/08/2004 14.00.00 553472 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 19/08/2004 14.00.00 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation 19/08/2004 14.00.00 138240 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 19/08/2004 14.00.00 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 19/08/2004 14.00.00 156160 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Intel Corporation 29/06/2005 7.33.40 77824 C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Microsoft Corporation 19/08/2004 14.00.00 359424 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 19/08/2004 14.00.00 132608 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 19/08/2004 14.00.00 380928 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 19/08/2004 14.00.00 69632 C:\WINDOWS\SYSTEM32\joy.cpl
Microsoft Corporation 19/08/2004 14.00.00 188928 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 19/08/2004 14.00.00 623616 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 19/08/2004 14.00.00 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 19/08/2004 14.00.00 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation 19/08/2004 14.00.00 259072 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
NVIDIA Corporation 19/01/2006 9.43.00 73728 C:\WINDOWS\SYSTEM32\nvcpl.cpl
19/01/2006 9.43.00 73728 C:\WINDOWS\SYSTEM32\nvtuicpl.cpl
Microsoft Corporation 19/08/2004 14.00.00 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 19/08/2004 14.00.00 117248 C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc. 23/12/2003 17.12.58 324608 C:\WINDOWS\SYSTEM32\QuickTime.cpl
Realtek Semiconductor Corp. 02/11/2005 15.54.08 266240 C:\WINDOWS\SYSTEM32\RTSndMgr.Cpl
Microsoft Corporation 19/08/2004 14.00.00 301568 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 19/08/2004 14.00.00 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 19/08/2004 14.00.00 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
Sony Corporation 08/10/2004 18.00.28 86016 C:\WINDOWS\SYSTEM32\VCCenter.cpl
Microsoft Corporation 19/08/2004 14.00.00 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation 26/05/2005 5.16.32 174872 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 19/08/2004 14.00.00 156160 C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
Microsoft Corporation 26/05/2005 5.16.32 174872 C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl
»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»
Checking files in %ALLUSERSPROFILE%\Startup folder...
14/07/2005 17.53.26 HS 84 C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\desktop.ini
Checking files in %ALLUSERSPROFILE%\Application Data folder...
14/07/2005 19.45.46 HS 62 C:\Documents and Settings\All Users\Dati applicazioni\desktop.ini
Checking files in %USERPROFILE%\Startup folder...
14/07/2005 17.53.26 HS 84 C:\Documents and Settings\utente\Menu Avvio\Programmi\Esecuzione automatica\desktop.ini
Checking files in %USERPROFILE%\Application Data folder...
14/07/2005 19.45.46 HS 62 C:\Documents and Settings\utente\Dati applicazioni\desktop.ini
»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
SV1 =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\avast
{472083B0-C522-11CF-8763-00608CC02F24} = C:\Programmi\Alwil Software\Avast4\ashShell.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Blocco menu Start
=
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido anti-spyware
{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmi\ewido anti-spyware 4.0\context.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ImageConverter2
{C6643EC0-49AC-4c15-A455-04104DB900A9} = C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\RhinoShExt
{C81DCBCA-8AE2-41FC-9C39-78B160393210} = C:\WINDOWS\system32\RhinoShExt.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Blocco menu Start = %SystemRoot%\system32\SHELL32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\avast
{472083B0-C522-11CF-8763-00608CC02F24} = C:\Programmi\Alwil Software\Avast4\ashShell.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ewido anti-spyware
{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmi\ewido anti-spyware 4.0\context.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ICQLiteMenu
{73B24247-042E-4EF5-ADC2-42F62E6FD654} =
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ImageConverter2
{C6643EC0-49AC-4c15-A455-04104DB900A9} = C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{F9DB5320-233E-11D1-9F84-707F02C10627}
= C:\Programmi\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
Adobe PDF Reader Link Helper = C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Suggerimenti = %SystemRoot%\system32\shdocvw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{6224f700-cba3-4071-b251-47cb894244cd}
ButtonText = ICQ Pro : C:\PROGRA~1\ICQ\ICQ.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{669695BC-A811-4A9D-8CDF-BA8C795F261C}
ButtonText = Run DAP : C:\PROGRA~1\DAP\DAP.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ButtonText = Messenger :
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}
&Discuss = shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = %SystemRoot%\system32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = %SystemRoot%\system32\shdocvw.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = :
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Indirizzo : %SystemRoot%\system32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = Co&llegamenti : %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Indirizzo : %SystemRoot%\system32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = Co&llegamenti : %SystemRoot%\system32\SHELL32.dll
{2318C2B1-4965-11D4-9B18-009027A5CD4F} = :
{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} = :
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = Yahoo! Toolbar :
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
{0228e555-4f9c-4e35-a3ec-b109a192b4c2} C:\Programmi\Google\Gmail Notifier\gnotify.exe
SonyPowerCfg C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
MessengerPlus3 "C:\Programmi\MessengerPlus! 3\MsgPlus.exe"
VIRIT LITE MONITOR C:\VEXPLITE\MONLITE.EXE
!ewido "C:\Programmi\ewido anti-spyware 4.0\ewido.exe" /minimized
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services
wuauserv 3
wscsvc 2
stisvc 2
SrvQzf 2
Image Converter video recording monitor for VAIO Entertainment 3
IDriverT 3
BITS 3
avast! Web Scanner 3
avast! Mail Scanner 3
avast! Antivirus 2
Adobe LM Service 3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma Loader.lnk
location Common Startup
command C:\PROGRA~1\FILECO~1\Adobe\CALIBR~1\ADOBEG~1.EXE
item Adobe Gamma Loader
location Common Startup
command C:\PROGRA~1\FILECO~1\Adobe\CALIBR~1\ADOBEG~1.EXE
item Adobe Gamma Loader
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Microsoft Office.lnk
location Common Startup
command C:\PROGRA~1\MICROS~4\Office10\OSA.EXE -b -l
item Microsoft Office
location Common Startup
command C:\PROGRA~1\MICROS~4\Office10\OSA.EXE -b -l
item Microsoft Office
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^PCSuiteperNokia6600 Detect.lnk
location Common Startup
command C:\PROGRA~1\Nokia\PCSUIT~1\CONNMN~1.EXE
item PCSuiteperNokia6600 Detect
location Common Startup
command C:\PROGRA~1\Nokia\PCSUIT~1\CONNMN~1.EXE
item PCSuiteperNokia6600 Detect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^PCSuiteperNokia6600 TS.lnk
location Common Startup
command C:\PROGRA~1\Nokia\PCSUIT~1\ECTASK~1.EXE
item PCSuiteperNokia6600 TS
location Common Startup
command C:\PROGRA~1\Nokia\PCSUIT~1\ECTASK~1.EXE
item PCSuiteperNokia6600 TS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^CRONO 2^Menu Avvio^Programmi^Esecuzione automatica^VAIO Launcher.lnk
location Startup
command C:\PROGRA~1\Sony\VAIOLA~1\Launcher.exe reset
item VAIO Launcher
location Startup
command C:\PROGRA~1\Sony\VAIOLA~1\Launcher.exe reset
item VAIO Launcher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^utente^Menu Avvio^Programmi^Esecuzione automatica^Adobe Gamma.lnk
location Startup
command C:\PROGRA~1\FILECO~1\Adobe\CALIBR~1\ADOBEG~1.EXE
item Adobe Gamma
location Startup
command C:\PROGRA~1\FILECO~1\Adobe\CALIBR~1\ADOBEG~1.EXE
item Adobe Gamma
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^utente^Menu Avvio^Programmi^Esecuzione automatica^BOINC Manager.lnk
location Startup
item BOINC Manager
location Startup
item BOINC Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^utente^Menu Avvio^Programmi^Esecuzione automatica^Gmail Notifier Srt.lnk
path C:\Documents and Settings\utente\Menu Avvio\Programmi\Esecuzione automatica\Gmail Notifier Srt.lnk
backup C:\WINDOWS\pss\Gmail Notifier Srt.lnkStartup
location Startup
command C:\PROGRA~1\Google\GMAILN~1\gnotify.exe
item Gmail Notifier Srt
path C:\Documents and Settings\utente\Menu Avvio\Programmi\Esecuzione automatica\Gmail Notifier Srt.lnk
backup C:\WINDOWS\pss\Gmail Notifier Srt.lnkStartup
location Startup
command C:\PROGRA~1\Google\GMAILN~1\gnotify.exe
item Gmail Notifier Srt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^utente^Menu Avvio^Programmi^Esecuzione automatica^Stardock ObjectDock.lnk
location Startup
item Stardock ObjectDock
location Startup
item Stardock ObjectDock
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^utente^Menu Avvio^Programmi^Esecuzione automatica^ubisoft register.lnk
location Startup
item ubisoft register
location Startup
item ubisoft register
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^utente^Menu Avvio^Programmi^Esecuzione automatica^Y'z Shadow.lnk
location Startup
item Y'z Shadow
location Startup
item Y'z Shadow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^utente^Menu Avvio^Programmi^Esecuzione automatica^Y'z ToolBar.lnk
location Startup
item Y'z ToolBar
location Startup
item Y'z ToolBar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item
hkey HKLM
command
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Acrobat Assistant 7.0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Acrotray
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Acrotray
hkey HKLM
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Alcmtr
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ALCMTR
hkey HKLM
command ALCMTR.EXE
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ALCMTR
hkey HKLM
command ALCMTR.EXE
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Apoint
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Apoint
hkey HKLM
command C:\Programmi\Apoint\Apoint.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Apoint
hkey HKLM
command C:\Programmi\Apoint\Apoint.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\avast!
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ashDisp
hkey HKLM
command C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ashDisp
hkey HKLM
command C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AzMixerSel
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AzMixerSel
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AzMixerSel
hkey HKLM
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BluetoothAuthenticationAgent
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rundll32
hkey HKLM
command rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rundll32
hkey HKLM
command rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DAEMON Tools
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item daemon
hkey HKLM
command "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item daemon
hkey HKLM
command "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DataLayer
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item DataLayer
hkey HKLM
command C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item DataLayer
hkey HKLM
command C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DownloadAccelerator
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item DAP
hkey HKLM
command C:\PROGRA~1\DAP\DAP.EXE /STARTUP
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item DAP
hkey HKLM
command C:\PROGRA~1\DAP\DAP.EXE /STARTUP
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\High Definition Audio Property Page Shortcut
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item HDAShCut
hkey HKLM
command HDAShCut.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item HDAShCut
hkey HKLM
command HDAShCut.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HotKeysCmds
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hkcmd
hkey HKLM
command C:\WINDOWS\system32\hkcmd.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hkcmd
hkey HKLM
command C:\WINDOWS\system32\hkcmd.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IgfxTray
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item igfxtray
hkey HKLM
command C:\WINDOWS\system32\igfxtray.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item igfxtray
hkey HKLM
command C:\WINDOWS\system32\igfxtray.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ImMsn
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msncomm
hkey HKLM
command C:\WINDOWS\msncomm.exe /i
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msncomm
hkey HKLM
command C:\WINDOWS\msncomm.exe /i
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ISBMgr.exe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ISBMgr
hkey HKLM
command C:\Programmi\Sony\ISB Utility\ISBMgr.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ISBMgr
hkey HKLM
command C:\Programmi\Sony\ISB Utility\ISBMgr.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KernelFaultCheck
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item dumprep 0 -k
hkey HKLM
command %systemroot%\system32\dumprep 0 -k
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item dumprep 0 -k
hkey HKLM
command %systemroot%\system32\dumprep 0 -k
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MediaCtr
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mediacon
hkey HKLM
command C:\WINDOWS\mediacon.exe -i
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mediacon
hkey HKLM
command C:\WINDOWS\mediacon.exe -i
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Mirabilis ICQ
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ICQNet
hkey HKLM
command C:\PROGRA~1\ICQ\ICQNet.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ICQNet
hkey HKLM
command C:\PROGRA~1\ICQ\ICQNet.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Mouse Suite 98 Daemon
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ICO
hkey HKLM
command ICO.EXE
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ICO
hkey HKLM
command ICO.EXE
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msmsgs
hkey HKCU
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msmsgs
hkey HKCU
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msnmsgr
hkey HKCU
command "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msnmsgr
hkey HKCU
command "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NBJ
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NBJ
hkey HKCU
command "C:\Programmi\Ahead\Nero BackItUp\NBJ.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NBJ
hkey HKCU
command "C:\Programmi\Ahead\Nero BackItUp\NBJ.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NeroFilterCheck
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NeroCheck
hkey HKLM
command C:\WINDOWS\system32\NeroCheck.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NeroCheck
hkey HKLM
command C:\WINDOWS\system32\NeroCheck.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Nokia Tray Application
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NclTray
hkey HKLM
command C:\Programmi\File comuni\Nokia\Tools\NclTray.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NclTray
hkey HKLM
command C:\Programmi\File comuni\Nokia\Tools\NclTray.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NvCplDaemon
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NvCpl
hkey HKLM
command RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NvCpl
hkey HKLM
command RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NVHotkey
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rundll32
hkey HKLM
command rundll32.exe nvHotkey.dll,Start
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rundll32
hkey HKLM
command rundll32.exe nvHotkey.dll,Start
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NvMediaCenter
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NvMcTray
hkey HKLM
command RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NvMcTray
hkey HKLM
command RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\nwiz
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item nwiz
hkey HKLM
command nwiz.exe /install
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item nwiz
hkey HKLM
command nwiz.exe /install
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PDService.exe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item pdservice
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item pdservice
hkey HKLM
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Persistence
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item igfxpers
hkey HKLM
command C:\WINDOWS\system32\igfxpers.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item igfxpers
hkey HKLM
command C:\WINDOWS\system32\igfxpers.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Quick To-Do Light
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item qtodolight
hkey HKCU
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item qtodolight
hkey HKCU
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item qttask
hkey HKLM
command "C:\Programmi\QuickTime\qttask.exe" -atboottime
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item qttask
hkey HKLM
command "C:\Programmi\QuickTime\qttask.exe" -atboottime
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RamBooster
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Rambooster
hkey HKCU
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Rambooster
hkey HKCU
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RegistryMechanic
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item
hkey HKLM
command
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item
hkey HKLM
command
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\REGSHAVE
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item REGSHAVE
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item REGSHAVE
hkey HKLM
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RemoteControl
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item PDVDServ
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item PDVDServ
hkey HKLM
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RTHDCPL
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RTHDCPL
hkey HKLM
command RTHDCPL.EXE
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RTHDCPL
hkey HKLM
command RTHDCPL.EXE
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SoundMan
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item sndman
hkey HKLM
command C:\WINDOWS\sndman.exe -i
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item sndman
hkey HKLM
command C:\WINDOWS\sndman.exe -i
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item jusched
hkey HKLM
command C:\Programmi\Java\jre1.5.0_07\bin\jusched.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item jusched
hkey HKLM
command C:\Programmi\Java\jre1.5.0_07\bin\jusched.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Timer
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msncomm
hkey HKLM
command C:\WINDOWS\msncomm.exe /i
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msncomm
hkey HKLM
command C:\WINDOWS\msncomm.exe /i
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\VAIO Update 2
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item VAIOUpdt
hkey HKLM
command "C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item VAIOUpdt
hkey HKLM
command "C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
system.ini 0
win.ini 0
bootini 0
services 2
startup 2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
DisableRegistryTools 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = Explorer.exe
System =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
= igfxdev.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon
= VESWinlogon.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs
»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 04/07/2006 7.09.27 |
E quello di hijack
Codice: | Logfile of HijackThis v1.99.1
Scan saved at 8.44.00, on 04/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
C:\Programmi\Google\Gmail Notifier\gnotify.exe
C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE
C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
C:\Programmi\MessengerPlus! 3\MsgPlus.exe
C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
C:\Programmi\Sony\VAIO Entertainment\VzTaskScheduler.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
C:\Programmi\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\vssvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Programmi\Sony\Image Converter 2\IcVzMon.exe
C:\Programmi\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Programmi\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\DOCUME~1\utente\IMPOST~1\Temp\ICD1.tmp\jinstall.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\MsiExec.exe
C:\Documents and Settings\utente\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Programmi\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} (DownloaderActiveX Control) - http://c6.community.alice.it/download/DownloaderActiveX.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://creative.com/su/ocx/15016/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2554FD64-19FE-43B9-AD17-AC924003E065}: NameServer = 195.32.107.46,212.216.112.112
O17 - HKLM\System\CCS\Services\Tcpip\..\{83286115-D32D-4D31-8FBA-F04C83C27D2A}: NameServer = 192.168.1.1,192.168.1.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{2554FD64-19FE-43B9-AD17-AC924003E065}: NameServer = 195.32.107.46,212.216.112.112
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: EvtEng - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Programmi\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Programmi\Sony\VAIO Entertainment\VzTaskScheduler.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Programmi\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
|
|
|
Top |
|
 |
holifay Dio maturo


Registrato: 08/03/05 10:48 Messaggi: 2912 Residenza: Milano
|
Inviato: 04 Lug 2006 11:53 Oggetto: |
|
|
Ok, riesci a mandarmi questa dll? Non mi piace molto...
C:\WINDOWS\SYSTEM32\wodfamoh.dll
Zippala e mandala per favore a www.suspectfile.com
Queste chiavi sono da eliminare, sono relative ai file già cancellati. Puoi farlo tu da regedit oppure usare Avenger come prima, in questo caso lo script che dovrai incollare è questo:
Citazione: | registry keys to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Timer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ImMsn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MediaCtr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SoundMan |
Il log di HijackThis mi sembra a posto. |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 04 Lug 2006 13:29 Oggetto: |
|
|
fatto mandato
senti avevo fatto la scansione con housecall e mi aveva trovato 2 grayware... uno mi sa ke lo ha tolto, l'altro per vedere le info specifiche del file non mi ha fatto + tornare indietro...
mi conviene rifarla? non c'è un modo per salvare il log di house call..
poi mi ha trovato molte vulnerabilità...penso di dover fare 1pò di updgrade del SP2...
una domanda...ma quando scarico gli aggiornamenti ''con windows update''....poi devo installarli a mano?
Roba tipo strumento di rimozione malaware per windows...dove me lo mette?
-----------------
Ok sto scaricando gli aggiornamenti e sto facendo una scansione con PANDA ...che mi sembra + facile di house call ed è in italiano  |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 04 Lug 2006 14:56 Oggetto: |
|
|
Panda non ha rilevato minacce.
Mo faccio di nuovo house call... |
|
Top |
|
 |
holifay Dio maturo


Registrato: 08/03/05 10:48 Messaggi: 2912 Residenza: Milano
|
Inviato: 04 Lug 2006 15:04 Oggetto: |
|
|
sicuro di averlo inviato? Non lo trovo... a meno che non lo stia già analizzando qualcun altro
Sì, devi ripetere la scansione online, ma questa volta farà prima perchè ha già scaricato il database con le impronte virali. Non ricordo se c´è un modo per salvare il log di House call... |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 04 Lug 2006 17:50 Oggetto: |
|
|
Probabilmente lo starà analizzando qualcunaltro, cmq te lo invio di nuovo....? o si incazzano?
Ho anche la ricevuta della mail...
Ho finito ora house call e finalmente ha tolto tutto ora dice solo di togliere le vulnerabilità...e penso che quelle le tolgo con le varie patch da windows update...ke non ho capito se una volta scaricate devo installarle manualmente..o fa tutto lui
Diciamo che il pc dovrebbe essere pulito, mi manca solo da disattivare i servizi inutili da services.msc dato che ora sono tutti attivi e quando parte il file di pagin è già a 300....giustamente. Mo devo capire bene quali posso togliere... cercando di non togliere quelli che facciano disabilitare il router.
Stranamente però...avrò il pc pulito, ma explorer e svchost continuano ad avere valori altini.. 24 explorer e 24 svchost...
Quello che vedo è ke appena si avvia il pc, parte tipo da 12 e poi inizia a salire a botte di 1 mega al secondo...fino a bloccarsi a 24...boh!
Cmq, la cosa positiva è ke se il pc è fermo senza far nulla Utilizzo della CPU è fermo a 0% , ogni tanto va a 2%...3% ma torna subito a 0.
Penso sia normale...
fammi sapere come possiamo continuare ad indagare
(potrebbe essere il caldo...e il processore ''stanco''? io ho un centrino, Sony Vaio...di solito non è mai stato caldo... però ultimamente...sarà il caldo maledetto ke fa...è bello calduccio... )
Senti...in c:\ mi sono apparsi 1pò di programmi alcuni .exe altri .bat e i log di alcune applicazioni che abbiamo fatto... è normale? gli exe e i bat.
Li ho controllati con kaspersky file scanner e dice ke sono puliti... e sono tutti con data di creazione oggi...
avexport.bat
rkbkcdam.bat
saf^tjdr.bat [questo è stato anche messo in avvio automatico..probabilmente è un programma ke toglie i virus ke bisogna cancellare all'avvio di windows automaticamente...di house call forse...)
zip.exe
mmmmmmmmmmmmmmmmmmm |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 04 Lug 2006 19:27 Oggetto: |
|
|
Inizio ad essere soddisfatto di tutta la pulizia... explorer gira sui 10 mega e quel svchost [ke cmq anche prima degli ''ipotetici problemi'' non era da meno se non sbaglio...] gira sui 20 mega.
Non c'è cmq l'incremento vertiginoso all'inizio.. e il pc va bene in tutto.
Sto ricontrollando piano piano tutti i programmi se funzionano [avendo tolto alcuni file...]
e finalmente sembra di aver trovato una impostazione giusta per i servizi di windows...FINALMENTE.
Parto con circa 200 mega di file di paging... va bene no?
Grazie mille a te !!
Senti ti metto nuovamente il file hijack...per controllare DEFINITIVAMENTE...
Codice: | Logfile of HijackThis v1.99.1
Scan saved at 19.51.42, on 04/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Google\Gmail Notifier\gnotify.exe
C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
C:\Programmi\MessengerPlus! 3\MsgPlus.exe
C:\Programmi\DAEMON Tools\daemon.exe
C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
D:\eMule\emule.exe
C:\Programmi\Winamp2\winamp.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Pulizia\Registry Mechanic\RegMech.exe
C:\Documents and Settings\utente\Documenti\UTILITY CONTRO I VIRUS\HijackThis.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Programmi\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} (DownloaderActiveX Control) - http://c6.community.alice.it/download/DownloaderActiveX.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://creative.com/su/ocx/15016/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2554FD64-19FE-43B9-AD17-AC924003E065}: NameServer = 195.32.107.46,212.216.112.112
O17 - HKLM\System\CCS\Services\Tcpip\..\{83286115-D32D-4D31-8FBA-F04C83C27D2A}: NameServer = 192.168.1.1,192.168.1.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{2554FD64-19FE-43B9-AD17-AC924003E065}: NameServer = 195.32.107.46,212.216.112.112
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe |
|
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 04 Lug 2006 20:19 Oggetto: |
|
|
Non capisco perchè ho riavviato e explorer è di nuovo a 25....
mmmm ora faccio un altra scansione con kasper e vediamo cosa fa...
-----------
Clamoroso...ho letto girando su internet di un ''ipotetico'' problema del Nokia Pc Suite..l'ho disinstallato e stranamente i valori di explorer sono tornati normali... prima era a 5...ora a 9... oddio
Invece n'altro coso del nokia non riesco a toglierlo...nel pannello di controllo, installazioni applicazioni clicco su
NOKIA PC CONNECTIVITY SDK 3.0 ....se blocca per 10 secondi...e poi torna normale senza aver cancellato niente.... mmmmmmmmm
come faccio a cancellare con forza questo programma? |
|
Top |
|
 |
holifay Dio maturo


Registrato: 08/03/05 10:48 Messaggi: 2912 Residenza: Milano
|
Inviato: 05 Lug 2006 00:42 Oggetto: |
|
|
Sono contenta che hai risolto
Ma se la suite di nokia ti serve, prova a scaricare l´ultima versione aggiornata e reinstallarla sopra quella, magari va a posto.
Io non sono molto brava con le disinstallazioni manuali: elimino le cartelle brutalmente e poi faccio una passata on regcleaner... ti consiglio di chiedere nel forum software.
Il tuo log è pulito e secondo me anche il PC. Prova solo ad aprire i file bat che mi segnalavi, basta che apri il blocco note e li trascini lì dentro. Almeno sappiamo cosa contengono
Ciao  |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 05 Lug 2006 01:05 Oggetto: |
|
|
mmmm forse era un caso boh, adesso sono di nuovo sulla 20... cmq sia ho provato 1pò di programmi e sembra andare fluido...
il sistema è pulito con tutti i programmi e scansioni online... |
|
Top |
|
 |
holifay Dio maturo


Registrato: 08/03/05 10:48 Messaggi: 2912 Residenza: Milano
|
Inviato: 05 Lug 2006 12:28 Oggetto: |
|
|
OK
Per favore, faresti ancora qualche controllo?
1) Scarica GMER.EXE. Avvialo, vai sul Tab Rootkit , clicchi su Scan . Al termine della scansione posta il contenuto.
2) Posta per favore anche il contenuto del tab Autostart di GMER. Aprilo, clicca Scan, poi Copy e poi incollalo qui (Ctrl + V)
3) posta il contenuto degli ADS con HijackThis. Apri HijackThis, premi Open the misc tools section, poi clicchi su Open Ads Spy... e togli il segno di spunta sulla casella Quick Scan. Fai riferimento a questa parte della guida: http://www.zeusnews.it/index.php3?a...pa&cod=4696
Al termine salva il log e posta qui il contenuto
Verifica poi se hai una strana cartella di 3 cifre in C:>Documents and Settings> che contiene una serie di altre cartelle, simile a quella del tuo profilo
Infine verifica se hai dei file eseguibili nascosti in C:>programmi
Dopo di che, possiamo riposare tranquilli  |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 05 Lug 2006 21:16 Oggetto: |
|
|
[non ho ancora letto tutto il tuo msg...solo l'inizio con il per favore ]
Scherzi certo che faccio tutti i controlli che mi chiedi
Mi hai aiutato tu... come posso dirti di no
Ora leggo le rikieste  |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 05 Lug 2006 21:27 Oggetto: |
|
|
Bene partiamo! Li metto separati così li puoi studiare per bene...allora!
Rootkit
GMER 1.0.10.10122 - http://www.gmer.net
Rootkit 2006-07-05 21:27:19
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.10 ----
SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT \??\C:\Programmi\ewido anti-spyware 4.0\guard.sys ZwOpenProcess
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
SSDT \??\C:\Programmi\ewido anti-spyware 4.0\guard.sys ZwTerminateProcess
---- Devices - GMER 1.0.10 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 82D8FBF8
Device \Driver\tifmsony \Device\TIFMDEVICE-0 IRP_MJ_SHUTDOWN [F85E795C] sfsync03.sys
Device \Driver\00000053 \Device\00000051 IRP_MJ_SYSTEM_CONTROL [F83E0F68] sptd.sys
Device \Driver\00000053 \Device\00000051 IRP_MJ_DEVICE_CHANGE [F83F5A70] sptd.sys
Device \Driver\00000053 \Device\00000051 IRP_MJ_PNP_POWER [F83EE728] sptd.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 82DD81D0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 82DD81D0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 82D648E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSEIRP_MJ_READ 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 8212CA90
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_PNP 8212CA90
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 82DD81D0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 82D648E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN [F85E795C] sfsync03.sys
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SHUTDOWN [F85E795C] sfsync03.sys
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SHUTDOWN [F85E795C] sfsync03.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 820FBA58
Device \Driver\NetBT \Device\NetBT_Tcpip_{2554FD64-19FE-43B9-AD17-AC924003E065} IRP_MJ_CREATE 820FBA58
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 820FBA58
Device \Driver\NetBT \Device\NetBT_Tcpip_{83286115-D32D-4D31-8FBA-F04C83C27D2A} IRP_MJ_CREATE 820FBA58
Device \Driver\tifmsony \Device\00000089 IRP_MJ_SHUTDOWN [F85E795C] sfsync03.sys
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 82D8FEB0
Device \Driver\Disk \Device\Harddisk1\DR4 IRP_MJ_CREATE 82D8FEB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+5 IRP_MJ_CREATE 82D8FEB0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSEIRP_MJ_READ 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP_POWER 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSEIRP_MJ_READ 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 8212B9C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP_POWER 8212B9C0
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 82137AD8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 82137AD8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSEIRP_MJ_READ 82137AD8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 82137AD8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 82137AD8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION 82137AD8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_EA 82137AD8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 82DD81D0
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE 82137EB0
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port1Path0Target0Lun0 IRP_MJ_CREATE 82C3CE40
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port1Path0Target0Lun0 IRP_MJ_SHUTDOWN [F85E795C] sfsync03.sys
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE 82C3CE40
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SHUTDOWN [F85E795C] sfsync03.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 820DEDB8
---- Files - GMER 1.0.10 ----
File C:\System Volume Information\catalog.wci
File C:\System Volume Information\MountPointManagerRemoteDatabase
File C:\System Volume Information\tracking.log
File C:\System Volume Information\_restore{C2ED04C9-B483-4D4F-83BF-03B22D5ED687}
File D:\System Volume Information\MountPointManagerRemoteDatabase
File D:\System Volume Information\tracking.log
---- EOF - GMER 1.0.10 ---- |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 05 Lug 2006 21:28 Oggetto: |
|
|
Autostart
GMER 1.0.10.10122 - http://www.gmer.net
Autostart 2006-07-05 21:27:58
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
igfxcui@DLLName = igfxdev.dll
VESWinlogon@DLLName = VESWinlogon.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Adobe LM Service /*Adobe LM Service*/@ = "C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe"
MSCSPTISRV /*MSCSPTISRV*/@ = "C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe"
MSSQL$VAIO_VEDB /*MSSQL$VAIO_VEDB*/@ = C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB /*file not found*/
MSSQLServerADHelper /*MSSQLServerADHelper*/@ = C:\Programmi\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe
PACSPTISVR /*PACSPTISVR*/@ = "C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe"
RegSrvc /*RegSrvc*/@ = C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
VAIO Event Service /*VAIO Event Service*/@ = C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@{0228e555-4f9c-4e35-a3ec-b109a192b4c2}C:\Programmi\Google\Gmail Notifier\gnotify.exe = C:\Programmi\Google\Gmail Notifier\gnotify.exe
@SonyPowerCfgC:\Programmi\Sony\VAIO Power Management\SPMgr.exe = C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
@MessengerPlus3"C:\Programmi\MessengerPlus! 3\MsgPlus.exe" = "C:\Programmi\MessengerPlus! 3\MsgPlus.exe"
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKCU\Software\Microsoft\Windows\CurrentVersion\Run@msnmsgr = "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks >>>
@{F552DDE6-2090-4bf4-B924-6141E87789A5}C:\Programmi\RegRunSuite\RRShell.dll = C:\Programmi\RegRunSuite\RRShell.dll
@{57B86673-276A-48B2-BAE7-C6DBB3020EB8}C:\Programmi\ewido anti-spyware 4.0\shellexecutehook.dll = C:\Programmi\ewido anti-spyware 4.0\shellexecutehook.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/(null) =
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Pagina proprietà versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{ED58A35B-B554-42AF-A26C-6F3D424200D3} /*Sony Power Management Extensiond*/C:\Programmi\Sony\VAIO Power Management\SPMPanel.dll = C:\Programmi\Sony\VAIO Power Management\SPMPanel.dll
@{C6643EC0-49AC-4c15-A455-04104DB900A9} /*Image Converter context menu extension*/C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll = C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRAR\rarext.dll = C:\Programmi\WinRAR\rarext.dll
@{E0D79304-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79305-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79306-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79307-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Outlook Custom Icon Handler*/C:\Programmi\Microsoft Office\Office10\OLKFSTUB.DLL = C:\Programmi\Microsoft Office\Office10\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\Office10\msohev.dll = C:\Programmi\Microsoft Office\Office10\msohev.dll
@{472083B0-C522-11CF-8763-00608CC02F24} /*avast*/C:\Programmi\Alwil Software\Avast4\ashShell.dll = C:\Programmi\Alwil Software\Avast4\ashShell.dll
@{C81DCBCA-8AE2-41FC-9C39-78B160393210} /*RhinoShExt*/C:\WINDOWS\system32\RhinoShExt.dll = C:\WINDOWS\system32\RhinoShExt.dll
@{F802F260-519B-11D1-BB5D-0060974C6013} /*ICQ Shell Extension*/C:\Programmi\ICQ\ICQShExt.dll = C:\Programmi\ICQ\ICQShExt.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
avast@{472083B0-C522-11CF-8763-00608CC02F24} = C:\Programmi\Alwil Software\Avast4\ashShell.dll
ewido anti-spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmi\ewido anti-spyware 4.0\context.dll
ImageConverter2@{C6643EC0-49AC-4c15-A455-04104DB900A9} = C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll
RhinoShExt@{C81DCBCA-8AE2-41FC-9C39-78B160393210} = C:\WINDOWS\system32\RhinoShExt.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
ewido anti-spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmi\ewido anti-spyware 4.0\context.dll
ICQLiteMenu@{73B24247-042E-4EF5-ADC2-42F62E6FD654} =
ImageConverter2@{C6643EC0-49AC-4c15-A455-04104DB900A9} = C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
avast@{472083B0-C522-11CF-8763-00608CC02F24} = C:\Programmi\Alwil Software\Avast4\ashShell.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll = C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Programmi\Java\jre1.5.0_07\bin\ssv.dll = C:\Programmi\Java\jre1.5.0_07\bin\ssv.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
@Start Pageabout:blank = about:blank
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
cdo@CLSID = C:\Programmi\File comuni\Microsoft Shared\Web Folders\PKMCDO.DLL
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
msnim@CLSID = "C:\PROGRA~1\MSNMES~1\msgrapp.dll"
mso-offdap@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\system32\wiascr.dll
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2554FD64-19FE-43B9-AD17-AC924003E065} /*Connessione alla rete locale (LAN)*/ >>>
@IPAddress192.168.1.22 = 192.168.1.22
@NameServer195.32.107.46,212.216.112.112 = 195.32.107.46,212.216.112.112
@DefaultGateway192.168.1.1 = 192.168.1.1
@Domain =
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{83286115-D32D-4D31-8FBA-F04C83C27D2A} /*Connessione rete senza fili*/ >>>
@IPAddress192.168.1.3 = 192.168.1.3
@NameServer192.168.1.1,192.168.1.2 = 192.168.1.1,192.168.1.2
@DefaultGateway192.168.1.1 = 192.168.1.1
@Domain =
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004@LibraryPath = %SystemRoot%\system32\wshbth.dll
---- EOF - GMER 1.0.10 ---- |
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 05 Lug 2006 21:33 Oggetto: |
|
|
ADS con HijackThis
[ho fatto solo open the misc, open ads spy , tolto la spunta su quick scan...e nient\'altro...nel link ke mi hai dato..non ci sono guide.. ^^]
ho fatto scan...ha fatto tutto...ma non mi ha dato niente da salvare...se clicco su save log non da niente....
ho dovuto togliere la v anche a ignore safe... quindi niente V su nessuna delle tre opzioni!
è 1pò lunghetto....lo metto in carattere piccolo...
Citazione: | log eliminato - holifay |
|
|
Top |
|
 |
Dink the Boss Eroe in grazia degli dei

Registrato: 03/07/06 10:33 Messaggi: 136
|
Inviato: 05 Lug 2006 21:44 Oggetto: |
|
|
Per le altre due richieste....
Verifica poi se hai una strana cartella di 3 cifre in C:>Documents and Settings> che contiene una serie di altre cartelle, simile a quella del tuo profilo
Guarda ho esattamente 4 cartelle
- Administrator
- All users
- Default user [nascosta]
- utente
Infine verifica se hai dei file eseguibili nascosti in C:>programmi
Allora in c programmi nessun eseguibile ne nascosto ne altro.
Ci sono tre cartelle nascoste
- Unistall Information
- Windows Update
- InstallShield Installation Information
Dal fronte...è tutto  |
|
Top |
|
 |
holifay Dio maturo


Registrato: 08/03/05 10:48 Messaggi: 2912 Residenza: Milano
|
Inviato: 06 Lug 2006 16:52 Oggetto: |
|
|
Mi sembra proprio tutto a posto.
Hai mica qualche problema a sentire i CD, vedere i DVD o installare giochi?  |
|
Top |
|
 |
|