Indice del forum Olimpo Informatico
I Forum di Zeus News
Leggi la newsletter gratuita - Attiva il Menu compatto
 
 FAQFAQ   CercaCerca   Lista utentiLista utenti   GruppiGruppi   RegistratiRegistrati 
 ProfiloProfilo   Messaggi privatiMessaggi privati   Log inLog in 

    Newsletter RSS Facebook Twitter Contatti Ricerca
virus Spoolsvc.exe
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus
Precedente :: Successivo  
Autore Messaggio
emanuelagenova
Mortale devoto
Mortale devoto


Registrato: 27/09/06 19:10
Messaggi: 6

MessaggioInviato: 27 Set 2006 19:27    Oggetto: virus Spoolsvc.exe Rispondi citando

Crying or Very sad SONO DISPERATA Crying or Very sad
non riesco ad eliminare il virus SPOOLSV.EXE
capisco poco di computer
facendo scan con antivirus mcafee mi sono stati segnalati diversi virus ma questi 5 non riesco ad eliminarli in quanto penso siano protetti da scrittura:
- windows\system32\spoolsvc.exe
- document&settings\dati applicazione\rator..\system.exe
- document&settings\dati applicazione\tack.exe
- windows\appunti.exe

ho provato con KILLBOX ma riavviando con nessun risultato

ecco il log di hijackthis_199:

Logfile of HijackThis v1.99.1
Scan saved at 19.25.37, on 27/09/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
c:\programmi\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\Java\j2re1.4.2_04\bin\jusched.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\QuickTime\qttask.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\iPod\bin\iPodService.exe
c:\progra~1\intern~1\iexplore.exe
C:\WINDOWS\TEMP\qisb1.exe
C:\Programmi\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Programmi\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\DOCUME~1\alessio\IMPOST~1\Temp\Directory temporanea 3 per hijackthis_199.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=IT&range=AD&phase=6&key=SEARCH
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.1987324.com?301
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\it.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://format.packardbell.com/cgi-bin/redirect/?country=IT&range=AD&phase=6&key=OEM2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: m1a2 - {521693AA-7453-47ED-9959-3BD47DAA1B1A} - C:\WINDOWS\system32\msx.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmi\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: (no name) - {AB4EF161-63CE-9AF6-C20F-2B7EAEBA3DBC} - C:\DOCUME~1\alessio\DATIAP~1\INTRAT~1\AboutByte.exe
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O2 - BHO: ComCap - {E1B2E864-8BFC-4072-AE11-924E0F8BBA96} - C:\WINDOWS\system32\comcap16.dll
O2 - BHO: Dredge - {EB870508-E2B7-4169-8120-760F69703776} - C:\WINDOWS\system32\kaboom.dll
O2 - BHO: Intense - {FB47056B-B34D-410E-819A-E8A51CC8E2EB} - C:\WINDOWS\system32\Kaboom.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Programmi\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Wxp4] C:\WINDOWS\System32\Norton Update.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [Olympic] C:\Documents and Settings\mauro\Dati applicazioni\sgrunt\IE4321.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [that manager 4 mfcd] C:\Documents and Settings\All Users\Dati applicazioni\SLOWHOPETHATMANAGER\copywin.exe
O4 - HKLM\..\Run: [NI.UERST_0001_N86M1107] "c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe" -nag
O4 - HKLM\..\Run: [aouei] C:\Documents and Settings\alessio\Dati applicazioni\ratorefaci\sysrtmvs.exe
O4 - HKLM\..\Run: [qisb1.exe] C:\WINDOWS\TEMP\qisb1.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Programmi\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Programmi\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DriveLogo] C:\DOCUME~1\alessio\DATIAP~1\BIKEDV~1\VGA NOUN.exe
O4 - HKCU\..\Run: [Shellapi32] svcnet.exe
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\microsoft office\Office\OSA9.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\it.htm
O15 - Trusted Zone: www.1987324.com
O15 - Trusted Zone: *.3
O15 - Trusted Zone: www.adslconnection.name
O15 - Trusted Zone: *.aflashcounter.com
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.sgrunt.biz
O15 - Trusted Zone: www.skymasters.biz
O15 - Trusted Zone: www.softlab.name
O15 - Trusted Zone: www.xbeta69.com
O15 - Trusted Zone: www.xxx-content.name
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bokkadasse.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B2F49FB} - http://www.softlab.name/closer/close.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\programmi\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SecJez - Unknown owner - \\?\C:\Programmi\File comuni\Services\lpt3.exe (file missing)
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: SrvImj - Unknown owner - \\?\C:\Programmi\File comuni\Services\con.exe (file missing)

------------


SONO DISPERATA HO DATI IMPORTANTISSIMI NEL PC .... VI PREGO AIUTATEMI !!!!

emanuela
Top
Profilo Invia messaggio privato
Typhoon90
Dio maturo
Dio maturo


Registrato: 01/06/06 16:17
Messaggi: 1019
Residenza: Vivere per niente o morire per qualcosa. Scegli tu.

MessaggioInviato: 27 Set 2006 20:40    Oggetto: Rispondi citando

chiavi sicuramente da eliminare

O15 - Trusted Zone: www.1987324.com
O15 - Trusted Zone: *.3
O15 - Trusted Zone: www.adslconnection.name
O15 - Trusted Zone: *.aflashcounter.com
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.sgrunt.biz
O15 - Trusted Zone: www.skymasters.biz
O15 - Trusted Zone: www.softlab.name
O15 - Trusted Zone: www.xbeta69.com
O15 - Trusted Zone: www.xxx-content.name

poi aspetta i pareri delgli esperotni Wink
Top
Profilo Invia messaggio privato HomePage
Smjert
Dio maturo
Dio maturo


Registrato: 01/04/06 18:19
Messaggi: 1619
Residenza: Perso nella rete

MessaggioInviato: 27 Set 2006 21:06    Oggetto: Rispondi citando

Credo che ti sia presa, oltre a spoolsvc.exe, un worm che si può chiamare Zafi.D, W32/Zafi.D, W32/Zafi.D@mm, Email-Worm.Win32.Zafi.d, W32/Zafi-D, W32/Zafi.d@MM.
Quindi procediamo alla sua rimozione:
Scarica questo programma, scompatta l'archivio e fai fare la scansione di tutti i drive al programmino, cancella tutto quello che trova di infetto.
Dopodichè riposta un log di hijackthis così vediamo cosa è rimasto (per semplificare la lettura del log chiudi tutti i programmi che puoi).
Top
Profilo Invia messaggio privato HomePage
holifay
Dio maturo
Dio maturo


Registrato: 08/03/05 10:48
Messaggi: 2912
Residenza: Milano

MessaggioInviato: 27 Set 2006 22:29    Oggetto: Rispondi citando

Ciao e benvenuta. Smile

sarò diretta: il tuo PC è un vero ricettacolo di schifezze Shocked
Hai diversi trojan e almeno un paio di rootkit. Non so se fai prima a formattare, la cura sarà un po´ lunga. Te la posto tutta intera, perchè fatta a pezzi potrebbe non risolvere (si reinstallano da internet).

Allora, dopo che hai fatto quanto ti hanno suggerito prima, fai questo:

Scarica avenger ed estrai l´eseguibile sul desktop. Per ora lascialo lì
http://swandog46.geekstogo.com/avenger.zip

Scarica questo e avvialo. Premi Start e aspetta che abbia finito
http://smallbiz.symantec.com/security_response/writeup.jsp?docid=2006-092316-4153-99

Al termine, apri HijackThis, chiudi tutte le altre applicazioni e le finestre, premi Do a system scan only. Fatto il log, metti un segno di spunta accanto a queste voci e poi premi fix checked
Citazione:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.1987324.com?301
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\it.htm
O2 - BHO: m1a2 - {521693AA-7453-47ED-9959-3BD47DAA1B1A} - C:\WINDOWS\system32\msx.dll
O2 - BHO: (no name) - {AB4EF161-63CE-9AF6-C20F-2B7EAEBA3DBC} - C:\DOCUME~1\alessio\DATIAP~1\INTRAT~1\AboutByte.exe
O2 - BHO: ComCap - {E1B2E864-8BFC-4072-AE11-924E0F8BBA96} - C:\WINDOWS\system32\comcap16.dll
O2 - BHO: Dredge - {EB870508-E2B7-4169-8120-760F69703776} - C:\WINDOWS\system32\kaboom.dll
O2 - BHO: Intense - {FB47056B-B34D-410E-819A-E8A51CC8E2EB} - C:\WINDOWS\system32\Kaboom.dll
O4 - HKLM\..\Run: [Wxp4] C:\WINDOWS\System32\Norton Update.exe
O4 - HKLM\..\Run: [Olympic]
O4 - HKLM\..\Run: [that manager 4 mfcd] C:\Documents and Settings\All Users\Dati applicazioni\SLOWHOPETHATMANAGER\copywin.exe
O4 - HKLM\..\Run: [NI.UERST_0001_N86M1107] "c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe" -nag
O4 - HKLM\..\Run: [aouei] C:\Documents and Settings\alessio\Dati applicazioni\ratorefaci\sysrtmvs.exe
O4 - HKLM\..\Run: [qisb1.exe] C:\WINDOWS\TEMP\qisb1.exe
O4 - HKCU\..\Run: [DriveLogo] C:\DOCUME~1\alessio\DATIAP~1\BIKEDV~1\VGA NOUN.exe
O4 - HKCU\..\Run: [Shellapi32] svcnet.exe
O15 - Trusted Zone: www.1987324.com
O15 - Trusted Zone: *.3
O15 - Trusted Zone: www.adslconnection.name
O15 - Trusted Zone: *.aflashcounter.com
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.sgrunt.biz
O15 - Trusted Zone: www.skymasters.biz
O15 - Trusted Zone: www.softlab.name
O15 - Trusted Zone: www.xbeta69.com
O15 - Trusted Zone: www.xxx-content.name
O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B2F49FB} - http://www.softlab.name/closer/close.exe
O23 - Service: SecJez - Unknown owner - \\?\C:\Programmi\File comuni\Services\lpt3.exe (file missing)
O23 - Service: SrvImj - Unknown owner - \\?\C:\Programmi\File comuni\Services\con.exe (file missing)


Adesso avvia il file avenger.exe
Seleziona l'opzione "Input Script Manually"
Clicca sulla lente di ingrandimento

Ti si apre una finestra "View/edit script"
All'interno del box bianco,copia e incolla le scritte in rosso qui sotto:

Citazione:
files to delete:
C:\WINDOWS\TEMP\qisb1.exe
C:\APPS\IE\offline\it.htm
C:\WINDOWS\system32\msx.dll
C:\DOCUME~1\alessio\DATIAP~1\INTRAT~1\AboutByte.exe
C:\WINDOWS\system32\comcap16.dll
C:\WINDOWS\system32\kaboom.dll
C:\WINDOWS\System32\Norton Update.exe
C:\Documents and Settings\mauro\Dati applicazioni\sgrunt\IE4321.exe
C:\Documents and Settings\All Users\Dati applicazioni\SLOWHOPETHATMANAGER\copywin.exe
c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe
C:\WINDOWS\TEMP\qisb1.exe
C:\DOCUME~1\alessio\DATIAP~1\BIKEDV~1\VGA NOUN.exe
C:\WINDOWS\System32\svcnet.exe
C:\WINDOWS\svcnet.exe
C:\Programmi\File comuni\Services\lpt3.exe
C:\Programmi\File comuni\Services\con.exe

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs

Registry Keys to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run


Clicca sul pulsante Done
Clicca sull'icona del semaforo verde
Rispondi Yes
Il pc dovrebbe riavviarsi da solo,se così non fosse riavvialo manualmente

Al riavvio scarica Ewido, installalo (deselezina la scansione real time) e aggiornalo
http://www.ewido.net/

Riavvia in modalità provvisoria, premendo F8 al boot. Dalla modalità provvisoria avvia Ewido e cancella tutto quello che trova

Poi fai una scansione con il tuo Antivirus e cancella ancora tutto quello che trovano

Riavvia in modalità normale e svuota la ctonologia e i file temporanei di Internet. Vai sul pannello di controllo, cerca l´icona java e cliccaci 2 volte sopra. Nella finestra che si apre cerca e premi elimina i file temporanei

Ora scarica GMER da www.gmer.net

Avvia GMER e fai due scansioni (tasto Scan) una dal tab rootkit e l´altra dal tab autostart. Copiale tutte e due premendo il tasto Copy nei rispettivi tab e incollali in un file di testo che salverai.

Infine posta (cioè copia qui):
- il log di Ewido
- il log di Symantec: il file FixLinkopt.log
- il contenuto del file c:/avenger.txt
- i due log di GMER


Ciao e in bocca al lupo Smile


L'ultima modifica di holifay il 27 Set 2006 22:33, modificato 2 volte
Top
Profilo Invia messaggio privato
chemicalbit
Dio maturo
Dio maturo


Registrato: 01/04/05 18:59
Messaggi: 18597
Residenza: Milano

MessaggioInviato: 27 Set 2006 22:29    Oggetto: Re: AIUTATEMI SONO DISPERATA !!!!!!!!!! Rispondi citando

emanuelagenova ha scritto:
facendo scan con antivirus mcafee mi sono stati segnalati diversi virus ma questi 5 non riesco ad eliminarli in quanto penso siano protetti da scrittura:
Prova da modalità provvisoria
(premi F8 all'accensione del computer, dopoil test di avvio, subito prima che inizi a caricare windows).

Purtroppo non conosco il mcAfee (lo usavo in dos, ma penso cha ormai sia alquanto Wink diverso)
non so se funzioni in modalità provvisoria (il Norton, ad es. no)
Top
Profilo Invia messaggio privato
emanuelagenova
Mortale devoto
Mortale devoto


Registrato: 27/09/06 19:10
Messaggi: 6

MessaggioInviato: 28 Set 2006 18:43    Oggetto: AIUTATEMI SONO DISPERATA (2) Rispondi citando

grazie mille a tutti !!
siamo sulla buona strada !!
facendo la scansione con mcafee non rileva virus

il sitema è rimasto cmq molto lento
ed in fase di riavvio devo aspetare almeno 5 minuti prima di poter lavorare

ecco i log:

il log di Ewido


Citazione:

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 18.41.10 28/09/2004

+ Scan result:



C:\Documents and Settings\alessio\Cookies\alessio@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\alessio\Cookies\alessio@e-2dj6wjliuhc5mfo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : No action taken.


::Report end





il log di Symantec: il file FixLinkopt.log

Citazione:

Symantec Trojan.Linkoptimizer Removal Tool 1.0.2
SeTakeOwnershipPrivilege acquired
Failed to acquire SeDebugPrivilege
service: SecJez (logon as: .\Bbb, passed filters)
service: SecJez (file path: \\?\C:\Programmi\File comuni\Services\lpt3.exe - infected)
file: \\?\C:\Programmi\File comuni\Services\lpt3.exe (deleted)
reg: ...\SYSTEM\CurrentControlSet\Services\SecJez\Security (key deleted)
reg: ...\SYSTEM\CurrentControlSet\Services\SecJez\Enum (key deleted)
reg: ...\SYSTEM\CurrentControlSet\Services\SecJez (key deleted)
reg: ...\SpecialAccounts\UserList\Bbb (value deleted)
folder: \\?\C:\Documents and Settings\Bbb (deleted)
user: Bbb (deleted)
service: SrvImj (logon as: .\TIsFVNwggbRIKXy, passed filters)
service: SrvImj (file path: \\?\C:\Programmi\File comuni\Services\con.exe - infected)
file: \\?\C:\Programmi\File comuni\Services\con.exe (deleted)
reg: ...\SYSTEM\CurrentControlSet\Services\SrvImj\Security (key deleted)
reg: ...\SYSTEM\CurrentControlSet\Services\SrvImj\Enum (key deleted)
reg: ...\SYSTEM\CurrentControlSet\Services\SrvImj (key deleted)
reg: ...\SpecialAccounts\UserList\TIsFVNwggbRIKXy (value deleted)
folder: \\?\C:\Documents and Settings\TIsFVNwggbRIKXy (deleted)
user: TIsFVNwggbRIKXy (deleted)


C:\Documents and Settings\alessio\Impostazioni locali\Temp\16A.tmp: (deleted)
C:\Documents and Settings\alessio\Impostazioni locali\Temp\17.tmp: (deleted)
C:\Documents and Settings\alessio\Impostazioni locali\Temp\s2m8.1.exe: (deleted)
C:\Documents and Settings\alessio\Impostazioni locali\Temp\s4k4.1.exe: (deleted)
C:\WINDOWS\system32\ffaa.dll: (deleted)
registry: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run: qisb1.exe (value deleted)
process: iexplore.exe (terminated)
process: iexplore.exe (terminated)
process: iexplore.exe (terminated)
process: iexplore.exe (terminated)


C:\WINDOWS\Temp\qisb1.exe: (will be deleted on next reboot)
The Trojan.Linkoptimizer removal was successful.
The system will delete 1 Trojan.Linkoptimizer files from your PC on next reboot.

Here is the report:

1 file(s) could not be deleted.
They will be deleted on next reboot.

The total number of the scanned files: 158024
The number of deleted threat files: 7
The number of directories deleted: 2
The number of threat processes terminated: 4
The number of registry entries fixed: 9
The number of threat services removed: 2
The number of accounts disabled: 2

The tool initiated a system reboot.








il contenuto del file c:/avenger.txt

Citazione:


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\breqdift

*******************

Script file located at: \??\C:\WINDOWS\gfeddnug.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\TEMP\qisb1.exe not found!
Deletion of file C:\WINDOWS\TEMP\qisb1.exe failed!

Could not process line:
C:\WINDOWS\TEMP\qisb1.exe
Status: 0xc0000034

File C:\APPS\IE\offline\it.htm deleted successfully.
File C:\WINDOWS\system32\msx.dll deleted successfully.
File C:\DOCUME~1\alessio\DATIAP~1\INTRAT~1\AboutByte.exe deleted successfully.


File C:\WINDOWS\system32\comcap16.dll not found!
Deletion of file C:\WINDOWS\system32\comcap16.dll failed!

Could not process line:
C:\WINDOWS\system32\comcap16.dll
Status: 0xc0000034



File C:\WINDOWS\system32\kaboom.dll not found!
Deletion of file C:\WINDOWS\system32\kaboom.dll failed!

Could not process line:
C:\WINDOWS\system32\kaboom.dll
Status: 0xc0000034



File C:\WINDOWS\System32\Norton Update.exe not found!
Deletion of file C:\WINDOWS\System32\Norton Update.exe failed!

Could not process line:
C:\WINDOWS\System32\Norton Update.exe
Status: 0xc0000034



File C:\Documents and Settings\mauro\Dati applicazioni\sgrunt\IE4321.exe not found!
Deletion of file C:\Documents and Settings\mauro\Dati applicazioni\sgrunt\IE4321.exe failed!

Could not process line:
C:\Documents and Settings\mauro\Dati applicazioni\sgrunt\IE4321.exe
Status: 0xc0000034

File C:\Documents and Settings\All Users\Dati applicazioni\SLOWHOPETHATMANAGER\copywin.exe deleted successfully.
File c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe deleted successfully.


File C:\WINDOWS\TEMP\qisb1.exe not found!
Deletion of file C:\WINDOWS\TEMP\qisb1.exe failed!

Could not process line:
C:\WINDOWS\TEMP\qisb1.exe
Status: 0xc0000034

File C:\DOCUME~1\alessio\DATIAP~1\BIKEDV~1\VGA NOUN.exe deleted successfully.


File C:\WINDOWS\System32\svcnet.exe not found!
Deletion of file C:\WINDOWS\System32\svcnet.exe failed!

Could not process line:
C:\WINDOWS\System32\svcnet.exe
Status: 0xc0000034



File C:\WINDOWS\svcnet.exe not found!
Deletion of file C:\WINDOWS\svcnet.exe failed!

Could not process line:
C:\WINDOWS\svcnet.exe
Status: 0xc0000034



File C:\Programmi\File comuni\Services\lpt3.exe not found!
Deletion of file C:\Programmi\File comuni\Services\lpt3.exe failed!

Could not process line:
C:\Programmi\File comuni\Services\lpt3.exe
Status: 0xc0000034



File C:\Programmi\File comuni\Services\con.exe not found!
Deletion of file C:\Programmi\File comuni\Services\con.exe failed!

Could not process line:
C:\Programmi\File comuni\Services\con.exe
Status: 0xc0000034

Registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs replaced with dummy successfully.


Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run not found!
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run failed!
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.








log di GMER

Citazione:


GMER 1.0.11.11384 - http://www.gmer.net
Autostart 2004-09-28 18:25:42
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@BootExecute = autocheck autochk * /*file not found*/

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\SYSTEM\CurrentControlSet\Control\WOW@cmdline = %SystemRoot%\system32\ntvdm.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon >>>
@UserinitC:\WINDOWS\system32\userinit.exe, = C:\WINDOWS\system32\userinit.exe,
@ShellExplorer.exe = Explorer.exe
@System =
@UIHostlogonui.exe = logonui.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
crypt32chain@DLLName = crypt32.dll
cryptnet@DLLName = cryptnet.dll
cscdll@DLLName = cscdll.dll
ScCertProp@DLLName = wlnotify.dll
Schedule@DLLName = wlnotify.dll
sclgntfy@DLLName = sclgntfy.dll
SensLogn@DLLName = WlNotify.dll
termsrv@DLLName = wlnotify.dll
WgaLogon@DLLName = WgaLogon.dll
wlballoon@DLLName = wlnotify.dll

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs =

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
ATI Smart /*ATI Smart*/@ = C:\WINDOWS\system32\ati2sgag.exe
AudioSrv /*Audio Windows*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
BITS /*Servizio trasferimento intelligente in background*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
Browser /*Browser di computer*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
ccEvtMgr /*Symantec Event Manager*/@ = "C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe"
ccSetMgr /*Symantec Settings Manager*/@ = "C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe"
CryptSvc /*Servizi di crittografia*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
DcomLaunch /*Utilità di avvio processo server DCOM*/@ = %SystemRoot%\system32\svchost -k DcomLaunch
Dhcp /*Client DHCP*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
Dnscache /*Client DNS*/@ = %SystemRoot%\System32\svchost.exe -k NetworkService
ERSvc /*Servizio di segnalazione errori*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
Eventlog /*Registro eventi*/@ = %SystemRoot%\system32\services.exe
ewido anti-spyware 4.0 guard /*ewido anti-spyware 4.0 guard*/@ = C:\Programmi\ewido anti-spyware 4.0\guard.exe
helpsvc /*Guida in linea e supporto tecnico*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
lanmanserver /*Server*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
lanmanworkstation /*Workstation*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
LmHosts /*Helper NetBIOS di TCP/IP*/@ = %SystemRoot%\System32\svchost.exe -k LocalService
McDetect.exe /*McAfee WSC Integration*/@ = c:\programmi\mcafee.com\agent\mcdetect.exe
McShield /*McAfee.com McShield*/@ = c:\PROGRA~1\mcafee.com\vso\mcshield.exe
McTskshd.exe /*McAfee Task Scheduler*/@ = c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
PlugPlay /*Plug and Play*/@ = %SystemRoot%\system32\services.exe
PolicyAgent /*Servizi IPSEC*/@ = %SystemRoot%\System32\lsass.exe
ProtectedStorage /*Archiviazione protetta*/@ = %SystemRoot%\system32\lsass.exe
RpcSs /*RPC (Remote Procedure Call)*/@ = %SystemRoot%\system32\svchost -k rpcss
SamSs /*Gestione account di protezione (SAM)*/@ = %SystemRoot%\system32\lsass.exe
Schedule /*Utilità di pianificazione*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
seclogon /*Accesso secondario*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
SENS /*Notifica eventi di sistema*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
SharedAccess /*Windows Firewall / Condivisione connessione Internet (ICS)*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
ShellHWDetection /*Rilevamento hardware shell*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
SLService /*SmartLinkService*/@ = slserv.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
srservice /*Servizio Ripristino configurazione di sistema*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
stisvc /*Acquisizione di immagini di Windows (WIA)*/@ = %SystemRoot%\System32\svchost.exe -k imgsvc
Themes /*Temi*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
TrkWks /*Manutenzione collegamenti distribuiti client*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\System32\wdfmgr.exe
W32Time /*Ora di Windows*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
WebClient /*WebClient*/@ = %SystemRoot%\System32\svchost.exe -k LocalService
winmgmt /*Strumentazione gestione Windows*/@ = %systemroot%\system32\svchost.exe -k netsvcs
wscsvc /*Centro sicurezza PC*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
wuauserv /*Aggiornamenti automatici*/@ = %systemroot%\system32\svchost.exe -k netsvcs
WZCSVC /*Zero Configuration reti senza fili*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@SoundManSOUNDMAN.EXE = SOUNDMAN.EXE
@ATIModeChangeAti2mdxx.exe = Ati2mdxx.exe
@ATIPTAC:\ATI Technologies\ATI Control Panel\atiptaxx.exe = C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
@SunJavaUpdateSchedC:\Programmi\Java\j2re1.4.2_04\bin\jusched.exe = C:\Programmi\Java\j2re1.4.2_04\bin\jusched.exe
@ccApp"C:\Programmi\File comuni\Symantec Shared\ccApp.exe" = "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
@URLLSTCK.exeC:\Programmi\Norton Internet Security\UrlLstCk.exe = C:\Programmi\Norton Internet Security\UrlLstCk.exe
@PCMService"c:\Apps\Powercinema\PCMService.exe" = "c:\Apps\Powercinema\PCMService.exe"
@ACTIVBOARDc:\apps\ABoard\ABoard.exe = c:\apps\ABoard\ABoard.exe
@TkBellExe"C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot = "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
@Symantec NetDriver MonitorC:\PROGRA~1\SYMNET~1\SNDMon.exe = C:\PROGRA~1\SYMNET~1\SNDMon.exe
@iTunesHelper"C:\Programmi\iTunes\iTunesHelper.exe" = "C:\Programmi\iTunes\iTunesHelper.exe"
@QuickTime Task"C:\Programmi\QuickTime\qttask.exe" -atboottime = "C:\Programmi\QuickTime\qttask.exe" -atboottime
@NI.UERST_0001_N86M1107"c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe" -nag /*file not found*/ = "c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe" -nag /*file not found*/
@aoueiC:\Documents and Settings\alessio\Dati applicazioni\ratorefaci\sysrtmvs.exe /*file not found*/ = C:\Documents and Settings\alessio\Dati applicazioni\ratorefaci\sysrtmvs.exe /*file not found*/
@VSOCheckTask"C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask = "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
@VirusScan OnlineC:\Programmi\McAfee.com\VSO\mcvsshld.exe = C:\Programmi\McAfee.com\VSO\mcvsshld.exe
@OASClntC:\Programmi\McAfee.com\VSO\oasclnt.exe = C:\Programmi\McAfee.com\VSO\oasclnt.exe
@MCAgentExec:\PROGRA~1\mcafee.com\agent\mcagent.exe = c:\PROGRA~1\mcafee.com\agent\mcagent.exe
@MCUpdateExeC:\PROGRA~1\mcafee.com\agent\McUpdate.exe = C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
@!ewido"C:\Programmi\ewido anti-spyware 4.0\ewido.exe" /minimized = "C:\Programmi\ewido anti-spyware 4.0\ewido.exe" /minimized
@KernelFaultCheck%systemroot%\system32\dumprep 0 -k = %systemroot%\system32\dumprep 0 -k

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@MsnMsgr"C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background = "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@DriveLogoC:\DOCUME~1\alessio\DATIAP~1\BIKEDV~1\VGA NOUN.exe /*file not found*/ = C:\DOCUME~1\alessio\DATIAP~1\BIKEDV~1\VGA NOUN.exe /*file not found*/
@Shellapi32svcnet.exe /*file not found*/ = svcnet.exe /*file not found*/

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad >>>
@PostBootReminder%SystemRoot%\system32\SHELL32.dll = %SystemRoot%\system32\SHELL32.dll
@CDBurn%SystemRoot%\system32\SHELL32.dll = %SystemRoot%\system32\SHELL32.dll
@WebCheck%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@SysTrayC:\WINDOWS\System32\stobject.dll = C:\WINDOWS\System32\stobject.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler >>>
@{438755C2-A8BA-11D1-B96B-00A0C90312E1}%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{8C7461EF-2B13-11d2-BE35-3078302C2030}%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll

HKLM\Software\Classes\Folder\shell\open\command@ = %SystemRoot%\Explorer.exe /idlist,%I,%L

HKLM\Software\Classes\Folder\shell\explore\command@ = %SystemRoot%\Explorer.exe /e,/idlist,%I,%L

HKLM\Software\Classes\ >>>
.exe@ = "%1" %*
.com@ = "%1" %*
.cmd@ = "%1" %*
.bat@ = "%1" %*
.pif@ = "%1" %*
.scr@ = "%1" /S
.hta@ = C:\WINDOWS\System32\mshta.exe "%1" %*

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks >>>
@{AEB6717E-7E19-11d0-97EE-00C04FD91972}shell32.dll = shell32.dll
@{57B86673-276A-48B2-BAE7-C6DBB3020EB8}C:\Programmi\ewido anti-spyware 4.0\shellexecutehook.dll = C:\Programmi\ewido anti-spyware 4.0\shellexecutehook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{00022613-0000-0000-C000-000000000046} /*Proprietà dei file Multimedia*/mmsys.cpl = mmsys.cpl
@{176d6597-26d3-11d1-b350-080036a75b03} /*Gestore scanner ICM*/icmui.dll = icmui.dll
@{1F2E5C40-9550-11CE-99D2-00AA006E086C} /*Pagina di protezione NTFS*/rshx32.dll = rshx32.dll
@{3EA48300-8CF6-101B-84FB-666CCB9BCD32} /*Pagina di proprietà di Docfile OLE*/docprop.dll = docprop.dll
@{40dd6e20-7c17-11ce-a804-00aa003ca9f6} /*Estensioni shell per la condivisione*/ntshrui.dll = ntshrui.dll
@{41E300E0-78B6-11ce-849B-444553540000} /*PlusPack CPL Extension*/%SystemRoot%\System32\themeui.dll = %SystemRoot%\System32\themeui.dll
@{42071712-76d4-11d1-8b24-00a0c9068ff3} /*Estensione scheda video del Pannello di controllo*/deskadp.dll = deskadp.dll
@{42071713-76d4-11d1-8b24-00a0c9068ff3} /*Estensione monitor del Pannello di controllo*/deskmon.dll = deskmon.dll
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{4E40F770-369C-11d0-8922-00A024AB2DBB} /*Pagina di protezione DS*/dssec.dll = dssec.dll
@{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} /*Pagina compatibilità*/SlayerXP.dll = SlayerXP.dll
@{56117100-C0CD-101B-81E2-00AA004AE837} /*Gestore dati dei ritagli di shell*/shscrap.dll = shscrap.dll
@{59099400-57FF-11CE-BD94-0020AF85B590} /*Estensione copia dischi*/diskcopy.dll = diskcopy.dll
@{59be4990-f85c-11ce-aff7-00aa003ca9f6} /*Estensioni shell per oggetti Rete Microsoft Windows*/ntlanui2.dll = ntlanui2.dll
@{5DB2625A-54DF-11D0-B6C4-0800091AA605} /*Gestore monitor ICM*/%SystemRoot%\System32\icmui.dll = %SystemRoot%\System32\icmui.dll
@{675F097E-4C4D-11D0-B6C1-0800091AA605} /*Gestore stampante ICM*/%SystemRoot%\system32\icmui.dll = %SystemRoot%\system32\icmui.dll
@{764BF0E1-F219-11ce-972D-00AA00A14F56} /*Estensioni shell per la compressione dei file*/(null) =
@{77597368-7b15-11d0-a0c2-080036af3f03} /*Estensione shell per la stampante Web*/printui.dll = printui.dll
@{7988B573-EC89-11cf-9C00-00AA00A14F56} /*Disk Quota UI*/dskquoui.dll = dskquoui.dll
@{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} /*Menu di scelta rapida di crittografia*/(null) =
@{85BBD920-42A0-1069-A2E4-08002B30309D} /*Sincronia file*/syncui.dll = syncui.dll
@{88895560-9AA2-1069-930E-00AA0030EBC8} /*Estensione di icona di HyperTerminal*/C:\WINDOWS\System32\hticons.dll = C:\WINDOWS\System32\hticons.dll
@{BD84B380-8CA2-1069-AB1D-08000948F534} /*Tipi di carattere*/fontext.dll = fontext.dll
@{DBCE2480-C732-101B-BE72-BA78E9AD5B27} /*Profilo ICC*/%SystemRoot%\system32\icmui.dll = %SystemRoot%\system32\icmui.dll
@{F37C5810-4D3F-11d0-B4BF-00AA00BBB723} /*Pagina di protezione della stampante*/rshx32.dll = rshx32.dll
@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} /*Estensioni shell per la condivisione*/ntshrui.dll = ntshrui.dll
@{f92e8c40-3d33-11d2-b1aa-080036a75b03} /*Display TroubleShoot CPL Extension*/deskperf.dll = deskperf.dll
@{7444C717-39BF-11D1-8CD9-00C04FC29D45} /*Estensione Crypto PKO*/C:\WINDOWS\system32\cryptext.dll = C:\WINDOWS\system32\cryptext.dll
@{7444C719-39BF-11D1-8CD9-00C04FC29D45} /*Estensione firma crittografata*/C:\WINDOWS\system32\cryptext.dll = C:\WINDOWS\system32\cryptext.dll
@{7007ACC7-3202-11D1-AAD2-00805FC1270E} /*Connessioni di rete*/C:\WINDOWS\system32\NETSHELL.dll = C:\WINDOWS\system32\NETSHELL.dll
@{992CFFA0-F557-101A-88EC-00DD010CCC48} /*Connessioni di rete*/C:\WINDOWS\system32\NETSHELL.dll = C:\WINDOWS\system32\NETSHELL.dll
@{E211B736-43FD-11D1-9EFB-0000F8757FCD} /*Scanner e fotocamere digitali*/wiashext.dll = wiashext.dll
@{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD} /*Scanner e fotocamere digitali*/wiashext.dll = wiashext.dll
@{905667aa-acd6-11d2-8080-00805f6596d2} /*Scanner e fotocamere digitali*/wiashext.dll = wiashext.dll
@{3F953603-1008-4f6e-A73A-04AAC7A992F1} /*Scanner e fotocamere digitali*/wiashext.dll = wiashext.dll
@{83bbcbf3-b28a-4919-a5aa-73027445d672} /*Scanner e fotocamere digitali*/wiashext.dll = wiashext.dll
@{F0152790-D56E-4445-850E-4F3117DB740C} /*Remote Sessions CPL Extension*/C:\WINDOWS\System32\remotepg.dll = C:\WINDOWS\System32\remotepg.dll
@{5F327514-6C5E-4d60-8F16-D07FA08A78ED} /*Auto Update Property Sheet Extension*/C:\WINDOWS\system32\wuaucpl.cpl = C:\WINDOWS\system32\wuaucpl.cpl
@{60254CA5-953B-11CF-8C96-00AA00B8708C} /*Estensione shell per Windows Script Host*/C:\WINDOWS\System32\wshext.dll = C:\WINDOWS\System32\wshext.dll
@{2206CDB2-19C1-11D1-89E0-00C04FD7A829} /*Microsoft Data Link*/C:\Programmi\File comuni\System\Ole DB\oledb32.dll = C:\Programmi\File comuni\System\Ole DB\oledb32.dll
@{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF} /*Tasks Folder Icon Handler*/C:\WINDOWS\System32\mstask.dll = C:\WINDOWS\System32\mstask.dll
@{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF} /*Tasks Folder Shell Extension*/C:\WINDOWS\System32\mstask.dll = C:\WINDOWS\System32\mstask.dll
@{D6277990-4C6A-11CF-8D87-00AA0060F5BF} /*Operazioni pianificate*/C:\WINDOWS\System32\mstask.dll = C:\WINDOWS\System32\mstask.dll
@{0DF44EAA-FF21-4412-828E-260A8728E7F1} /*Barra delle applicazioni e menu di avvio*/(null) =
@{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0} /*Cerca*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0} /*Guida in linea e supporto tecnico*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} /*Guida in linea e supporto tecnico*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} /*Esegui...*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0} /*Internet*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0} /*Posta elettronica*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{D20EA4E1-3957-11d2-A40B-0C5020524152} /*Tipi di carattere*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{D20EA4E1-3957-11d2-A40B-0C5020524153} /*Strumenti di amministrazione*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{875CB1A1-0F29-45de-A1AE-CFB4950D0B78} /*Audio Media Properties Handler*/%SystemRoot%\System32\shmedia.dll = %SystemRoot%\System32\shmedia.dll
@{40C3D757-D6E4-4b49-BB41-0E5BBEA28817} /*Video Media Properties Handler*/%SystemRoot%\System32\shmedia.dll = %SystemRoot%\System32\shmedia.dll
@{E4B29F9D-D390-480b-92FD-7DDB47101D71} /*Wav Properties Handler*/%SystemRoot%\System32\shmedia.dll = %SystemRoot%\System32\shmedia.dll
@{87D62D94-71B3-4b9a-9489-5FE6850DC73E} /*Avi Properties Handler*/%SystemRoot%\System32\shmedia.dll = %SystemRoot%\System32\shmedia.dll
@{A6FD9E45-6E44-43f9-8644-08598F5A74D9} /*Midi Properties Handler*/%SystemRoot%\System32\shmedia.dll = %SystemRoot%\System32\shmedia.dll
@{c5a40261-cd64-4ccf-84cb-c394da41d590} /*Video Thumbnail Extractor*/%SystemRoot%\System32\shmedia.dll = %SystemRoot%\System32\shmedia.dll
@{5E6AB780-7743-11CF-A12B-00AA004AE837} /*Barra degli strumenti Microsoft Internet*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{22BF0C20-6DA7-11D0-B373-00A0C9034938} /*Stato del download*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{91EA3F8B-C99B-11d0-9815-00C04FD91972} /*Shell Folder accresciuto*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{6413BA2C-B461-11d1-A18A-080036B11A03} /*Shell Folder 2 accresciuto*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{F61FFEC1-754F-11d0-80CA-00AA005B4383} /*BandProxy*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{7BA4C742-9E81-11CF-99D3-00AA004AE837} /*Microsoft BrowserBand*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*SearchBand*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{169A0691-8DF9-11d1-A1C4-00C04FD75D13} /*Ricerca all'interno*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{07798131-AF23-11d1-9111-00A0C98BA67D} /*Ricerca Web*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{AF4F6510-F982-11d0-8595-00AA004CD6D8} /*Utilità opzioni della struttura del Registro di sistema*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{01E04581-4EEE-11d0-BFE9-00AA005B4383} /*&Indirizzo*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{A08C11D2-A228-11d0-825B-00AA005B4383} /*Address EditBox*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{00BB2763-6A77-11D0-A535-00C04FD7D062} /*Completamento automatico Microsoft*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{7376D660-C583-11d0-A3A5-00C04FD706EC} /*TridentImageExtractor*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{6756A641-DE71-11d0-831B-00AA005B4383} /*Elenco di Completamento automatico MRU*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} /*Elenco di Completamento automatico MRU personalizzato*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{7e653215-fa25-46bd-a339-34a2790f3cb7} /*Accessibile*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{acf35015-526e-4230-9596-becbe19f0ac9} /*Indicatore di avanzamento popup*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{E0E11A09-5CB8-4B6C-8332-E00720A168F2} /*Parser della barra degli indirizzi*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{00BB2764-6A77-11D0-A535-00C04FD7D062} /*Elenco di Completamento automatico della Cronologia di Microsoft*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{03C036F1-A186-11D0-824A-00AA005B4383} /*Elenco di Completamento automatico di Shell Folder di Microsoft*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{00BB2765-6A77-11D0-A535-00C04FD7D062} /*Contenitore dell'elenco di Completamento automatico multiplo Microsoft*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{ECD4FC4E-521C-11D0-B792-00A0C90312E1} /*Shell Band Site Menu*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{3CCF8A41-5C85-11d0-9796-00AA00B90ADF} /*Shell DeskBarApp*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{ECD4FC4C-521C-11D0-B792-00A0C90312E1} /*Shell DeskBar*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{ECD4FC4D-521C-11D0-B792-00A0C90312E1} /*Shell Rebar BandSite*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{DD313E04-FEFF-11d1-8ECD-0000F87A470C} /*Assistenza utente*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} /*Impostazioni cartella globale*/%SystemRoot%\System32\browseui.dll = %SystemRoot%\System32\browseui.dll
@{EFA24E61-B078-11d0-89E4-00C04FC9E26E} /*Favorites Band*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{0A89A860-D7B1-11CE-8350-444553540000} /*Shell Automation Inproc Service*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{A5E46E3A-8849-11D1-9D8C-00C04FC99D61} /*Microsoft Browser Architecture*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/shdocvw.dll = shdocvw.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Servizio Cronologia Url Microsoft*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*Cronologia*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*File temporanei Internet*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*File temporanei Internet*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Hook per la ricerca di URL Microsoft*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC} /*Schermata iniziale applicazioni Internet Explorer 4*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{67EA19A0-CCEF-11d0-8024-00C04FD75D13} /*CDF Extension Copy Hook*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{131A6951-7F78-11D0-A979-00C04FD705A2} /*ISFBand OC*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{9461b922-3c5a-11d2-bf8b-00c04fb93661} /*Search Assistant OC*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*Internet*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{EFA24E64-B078-11d0-89E4-00C04FC9E26E} /*Explorer Band*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} /*Sendmail service*/C:\WINDOWS\System32\sendmail.dll = C:\WINDOWS\System32\sendmail.dll
@{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} /*Sendmail service*/C:\WINDOWS\System32\sendmail.dll = C:\WINDOWS\System32\sendmail.dll
@{88C6C381-2E85-11D0-94DE-444553540000} /*Cartella cache ActiveX*/%SystemRoot%\System32\occache.dll = %SystemRoot%\System32\occache.dll
@{E6FB5E20-DE35-11CF-9C87-00AA005127ED} /*WebCheck*/%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} /*Subscription Mgr*/%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@{F5175861-2688-11d0-9C5E-00AA00A45957} /*Cartella Subscription*/%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@{08165EA0-E946-11CF-9C87-00AA005127ED} /*WebCheckWebCrawler*/%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB} /*WebCheckChannelAgent*/%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7} /*TrayAgent*/%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@{7D559C10-9FE9-11d0-93F7-00AA0059CE02} /*Code Download Agent*/%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@{E6CC6978-6B6E-11D0-BECA-00C04FD940BE} /*ConnectionAgent*/%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@{D8BD2030-6FC9-11D0-864F-00AA006809D9} /*PostAgent*/%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} /*WebCheck SyncMgr Handler*/%SystemRoot%\System32\webcheck.dll = %SystemRoot%\System32\webcheck.dll
@{352EC2B7-8B9A-11D1-B8AE-006008059382} /*Gestione applicazioni shell*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{0B124F8F-91F0-11D1-B8B5-006008059382} /*Enumeratore applicazioni installate*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{CFCCC7A0-A282-11D1-9082-006008059382} /*Darwin App Publisher*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{e84fda7c-1d6a-45f6-b725-cb260c236066} /*Shell Image Verbs*/%SystemRoot%\System32\shimgvw.dll = %SystemRoot%\System32\shimgvw.dll
@{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178} /*Shell Image Data Factory*/%SystemRoot%\System32\shimgvw.dll = %SystemRoot%\System32\shimgvw.dll
@{3F30C968-480A-4C6C-862D-EFC0897BB84B} /*GDI + programma di estrazione file in anteprima*/C:\WINDOWS\System32\shimgvw.dll = C:\WINDOWS\System32\shimgvw.dll
@{9DBD2C50-62AD-11d0-B806-00C04FD706EC} /*Summary Info Thumbnail handler (DOCFILES)*/C:\WINDOWS\System32\shimgvw.dll = C:\WINDOWS\System32\shimgvw.dll
@{EAB841A0-9550-11cf-8C16-00805F1408F3} /*Programma di estrazione pagine HTML in anteprima*/C:\WINDOWS\System32\shimgvw.dll = C:\WINDOWS\System32\shimgvw.dll
@{eb9b1153-3b57-4e68-959a-a3266bc3d7fe} /*Shell Image Property Handler*/%SystemRoot%\System32\shimgvw.dll = %SystemRoot%\System32\shimgvw.dll
@{CC6EEFFB-43F6-46c5-9619-51D571967F7D} /*Pubblicazione guidata sul Web*/%SystemRoot%\System32\netplwiz.dll = %SystemRoot%\System32\netplwiz.dll
@{add36aa8-751a-4579-a266-d66f5202ccbb} /*Ordinazione di stampe tramite Web*/%SystemRoot%\System32\netplwiz.dll = %SystemRoot%\System32\netplwiz.dll
@{6b33163c-76a5-4b6c-bf21-45de9cd503a1} /*Oggetto Pubblicazione guidata sul Web*/%SystemRoot%\System32\netplwiz.dll = %SystemRoot%\System32\netplwiz.dll
@{58f1f272-9240-4f51-b6d4-fd63d1618591} /*Creazione guidata profilo Passport*/%SystemRoot%\System32\netplwiz.dll = %SystemRoot%\System32\netplwiz.dll
@{7A9D77BD-5403-11d2-8785-2E0420524153} /*Account utente*/(null) =
@{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} /*Cartella compressa*/%SystemRoot%\System32\zipfldr.dll = %SystemRoot%\System32\zipfldr.dll
@{BD472F60-27FA-11cf-B8B4-444553540000} /*Compressed (zipped) Folder Right Drag Handler*/%SystemRoot%\System32\zipfldr.dll = %SystemRoot%\System32\zipfldr.dll
@{888DCA60-FC0A-11CF-8F0F-00C04FD7D062} /*Compressed (zipped) Folder SendTo Target*/%SystemRoot%\System32\zipfldr.dll = %SystemRoot%\System32\zipfldr.dll
@{f39a0dc0-9cc8-11d0-a599-00c04fd64433} /*File del canale*/%SystemRoot%\System32\cdfview.dll = %SystemRoot%\System32\cdfview.dll
@{f3aa0dc0-9cc8-11d0-a599-00c04fd64434} /*Collegamento al canale*/%SystemRoot%\System32\cdfview.dll = %SystemRoot%\System32\cdfview.dll
@{f3ba0dc0-9cc8-11d0-a599-00c04fd64435} /*Channel Handler Object*/%SystemRoot%\System32\cdfview.dll = %SystemRoot%\System32\cdfview.dll
@{f3da0dc0-9cc8-11d0-a599-00c04fd64437} /*Channel Menu*/%SystemRoot%\System32\cdfview.dll = %SystemRoot%\System32\cdfview.dll
@{f3ea0dc0-9cc8-11d0-a599-00c04fd64438} /*Channel Properties*/%SystemRoot%\System32\cdfview.dll = %SystemRoot%\System32\cdfview.dll
@{63da6ec0-2e98-11cf-8d82-444553540000} /*FTP Folders Webview*/C:\WINDOWS\System32\msieftp.dll = C:\WINDOWS\System32\msieftp.dll
@{883373C3-BF89-11D1-BE35-080036B11A03} /*Microsoft DocProp Shell Ext*/C:\WINDOWS\System32\docprop2.dll = C:\WINDOWS\System32\docprop2.dll
@{A9CF0EAE-901A-4739-A481-E35B73E47F6D} /*Microsoft DocProp Inplace Edit Box Control*/C:\WINDOWS\System32\docprop2.dll = C:\WINDOWS\System32\docprop2.dll
@{8EE97210-FD1F-4B19-91DA-67914005F020} /*Microsoft DocProp Inplace ML Edit Box Control*/C:\WINDOWS\System32\docprop2.dll = C:\WINDOWS\System32\docprop2.dll
@{0EEA25CC-4362-4A12-850B-86EE61B0D3EB} /*Microsoft DocProp Inplace Droplist Combo Control*/C:\WINDOWS\System32\docprop2.dll = C:\WINDOWS\System32\docprop2.dll
@{6A205B57-2567-4A2C-B881-F787FAB579A3} /*Microsoft DocProp Inplace Calendar Control*/C:\WINDOWS\System32\docprop2.dll = C:\WINDOWS\System32\docprop2.dll
@{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33} /*Microsoft DocProp Inplace Time Control*/C:\WINDOWS\System32\docprop2.dll = C:\WINDOWS\System32\docprop2.dll
@{8A23E65E-31C2-11d0-891C-00A024AB2DBB} /*Directory Query UI*/%SystemRoot%\System32\dsquery.dll = %SystemRoot%\System32\dsquery.dll
@{9E51E0D0-6E0F-11d2-9601-00C04FA31A86} /*Shell properties for a DS object*/%SystemRoot%\System32\dsquery.dll = %SystemRoot%\System32\dsquery.dll
@{163FDC20-2ABC-11d0-88F0-00A024AB2DBB} /*Directory Object Find*/%SystemRoot%\System32\dsquery.dll = %SystemRoot%\System32\dsquery.dll
@{F020E586-5264-11d1-A532-0000F8757D7E} /*Directory Start/Search Find*/%SystemRoot%\System32\dsquery.dll = %SystemRoot%\System32\dsquery.dll
@{0D45D530-764B-11d0-A1CA-00AA00C16E65} /*Directory Property UI*/%SystemRoot%\System32\dsuiext.dll = %SystemRoot%\System32\dsuiext.dll
@{62AE1F9A-126A-11D0-A14B-0800361B1103} /*Directory Context Menu Verbs*/%SystemRoot%\System32\dsuiext.dll = %SystemRoot%\System32\dsuiext.dll
@{ECF03A33-103D-11d2-854D-006008059367} /*MyDocs Copy Hook*/%SystemRoot%\System32\mydocs.dll = %SystemRoot%\System32\mydocs.dll
@{ECF03A32-103D-11d2-854D-006008059367} /*MyDocs Drop Target*/%SystemRoot%\System32\mydocs.dll = %SystemRoot%\System32\mydocs.dll
@{4a7ded0a-ad25-11d0-98a8-0800361b1103} /*MyDocs Properties*/%SystemRoot%\System32\mydocs.dll = %SystemRoot%\System32\mydocs.dll
@{750fdf0e-2a26-11d1-a3ea-080036587f03} /*Offline Files Menu*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{10CFC467-4392-11d2-8DB4-00C04FA31A66} /*Offline Files Folder Options*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E} /*Cartella file non in linea*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{143A62C8-C33B-11D1-84FE-00C04FA34A14} /*Microsoft Agent Character Property Sheet Handler*/C:\WINDOWS\msagent\agentpsh.dll = C:\WINDOWS\msagent\agentpsh.dll
@{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} /*DfsShell*/C:\WINDOWS\System32\dfsshlex.dll = C:\WINDOWS\System32\dfsshlex.dll
@{60fd46de-f830-4894-a628-6fa81bc0190d} /*%DESC_PublishDropTarget%*/%SystemRoot%\System32\photowiz.dll = %SystemRoot%\System32\photowiz.dll
@{7A80E4A8-8005-11D2-BCF8-00C04F72C717} /*MMC Icon Handler*/%SystemRoot%\System32\mmcshext.dll = %SystemRoot%\System32\mmcshext.dll
@{0CD7A5C0-9F37-11CE-AE65-08002B2E1262} /*.CAB file viewer*/cabview.dll = cabview.dll
@{32714800-2E5F-11d0-8B85-00AA0044F941} /*&Contatti...*/C:\Programmi\Outlook Express\wabfind.dll = C:\Programmi\Outlook Express\wabfind.dll
@{8DD448E6-C188-4aed-AF92-44956194EB1F} /*Windows Media Player Play as Playlist Context Menu Handler*/C:\WINDOWS\system32\wmpshell.dll = C:\WINDOWS\system32\wmpshell.dll
@{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} /*Windows Media Player Burn Audio CD Context Menu Handler*/C:\WINDOWS\system32\wmpshell.dll = C:\WINDOWS\system32\wmpshell.dll
@{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD} /*Windows Media Player Add to Playlist Context Menu Handler*/C:\WINDOWS\system32\wmpshell.dll = C:\WINDOWS\system32\wmpshell.dll
@{1D2680C9-0E2A-469d-B787-065558BC7D43} /*Fusion Cache*/C:\WINDOWS\system32\mscoree.dll = C:\WINDOWS\system32\mscoree.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Programmi\Real\RealPlayer\rpshell.dll = C:\Programmi\Real\RealPlayer\rpshell.dll
@{DEE12703-6333-4D4E-8F34-738C4DCC2E04} /*RecordNow! SendToExt*/C:\Apps\RecordNow\shlext.dll = C:\Apps\RecordNow\shlext.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~3\Office\MLSHEXT.DLL /*file not found*/ = C:\PROGRA~1\MICROS~3\Office\MLSHEXT.DLL /*file not found*/
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~3\Office\OLKFSTUB.DLL /*file not found*/ = C:\PROGRA~1\MICROS~3\Office\OLKFSTUB.DLL /*file not found*/
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\OFFICE11\msohev.dll = C:\Programmi\Microsoft Office\OFFICE11\msohev.dll
@{640167b4-59b0-47a6-b335-a6b3c0695aea} /*Portable Media Devices*/%SystemRoot%\System32\Audiodev.dll = %SystemRoot%\System32\Audiodev.dll
@{cc86590a-b60a-48e6-996b-41d25ed39a1e} /*Portable Media Devices Menu*/%SystemRoot%\System32\Audiodev.dll = %SystemRoot%\System32\Audiodev.dll
@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} /*Adobe.Acrobat.ContextMenu*/C:\Programmi\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll = C:\Programmi\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/C:\Programmi\iTunes\iTunesMiniPlayer.dll = C:\Programmi\iTunes\iTunesMiniPlayer.dll
@{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0} /*Set Program Access and Defaults*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\System32\extmgr.dll = C:\WINDOWS\System32\extmgr.dll
@{21569614-B795-46b1-85F4-E737A8DC09AD} /*Shell Search Band*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{BDEADF00-C265-11d0-BCED-00A0C90AB50F} /*Cartelle Web*/ = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Adobe.Acrobat.ContextMenu@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Programmi\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
ewido anti-spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmi\ewido anti-spyware 4.0\context.dll
Offline Files@{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
Open With@{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
Open With EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
Resurrector@{3B177BCE-B599-4ABD-BECE-B57EE18187FA} = C:\WINDOWS\system32\iddqd.dll /*file not found*/

HKLM\Software\Classes\*\shellex\ContextMenuHandlers >>>
@{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}%SystemRoot%\system32\SHELL32.dll = %SystemRoot%\system32\SHELL32.dll
@{CFC7205E-2792-4378-9591-3879CC6C9022}c:\progra~1\mcafee.com\vso\mcvsshl.dll = c:\progra~1\mcafee.com\vso\mcvsshl.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
ewido anti-spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmi\ewido anti-spyware 4.0\context.dll
Offline Files@{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
Sharing@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers@{CFC7205E-2792-4378-9591-3879CC6C9022} = c:\progra~1\mcafee.com\vso\mcvsshl.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Programmi\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll = C:\Programmi\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
@{521693AA-7453-47ED-9959-3BD47DAA1B1A}C:\WINDOWS\system32\msx.dll /*file not found*/ = C:\WINDOWS\system32\msx.dll /*file not found*/
@{9394EDE7-C8B5-483E-8773-474BF36AF6E4}C:\Programmi\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll = C:\Programmi\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
@{9ECB9560-04F9-4bbc-943D-298DDF1699E1}C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll = C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
@{AA58ED58-01DD-4d91-8333-CF10577473F7}c:\programmi\google\googletoolbar1.dll = c:\programmi\google\googletoolbar1.dll
@{AB4EF161-63CE-9AF6-C20F-2B7EAEBA3DBC}C:\DOCUME~1\alessio\DATIAP~1\INTRAT~1\AboutByte.exe /*file not found*/ = C:\DOCUME~1\alessio\DATIAP~1\INTRAT~1\AboutByte.exe /*file not found*/
@{AE7CD045-E861-484f-8273-0445EE161910}C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll = C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
@{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll = C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll

HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\System32\ssmarque.scr

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.google.it/ = http://www.google.it/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Filter\ >>>
application/octet-stream@CLSID = C:\WINDOWS\System32\mscoree.dll
application/x-complus@CLSID = C:\WINDOWS\System32\mscoree.dll
application/x-msdownload@CLSID = C:\WINDOWS\System32\mscoree.dll
Class Install Handler@CLSID = C:\WINDOWS\system32\urlmon.dll
deflate@CLSID = C:\WINDOWS\system32\urlmon.dll
gzip@CLSID = C:\WINDOWS\system32\urlmon.dll
lzdhtml@CLSID = C:\WINDOWS\system32\urlmon.dll
text/webviewhtml@CLSID = %SystemRoot%\system32\SHELL32.dll
text/xml@CLSID = C:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
about@CLSID = %SystemRoot%\System32\mshtml.dll
cdl@CLSID = C:\WINDOWS\system32\urlmon.dll
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
file@CLSID = C:\WINDOWS\system32\urlmon.dll
ftp@CLSID = C:\WINDOWS\system32\urlmon.dll
gopher@CLSID = C:\WINDOWS\system32\urlmon.dll
http@CLSID = C:\WINDOWS\system32\urlmon.dll
https@CLSID = C:\WINDOWS\system32\urlmon.dll
its@CLSID = C:\WINDOWS\System32\itss.dll
javascript@CLSID = %SystemRoot%\System32\mshtml.dll
local@CLSID = C:\WINDOWS\system32\urlmon.dll
mailto@CLSID = %SystemRoot%\System32\mshtml.dll
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
mk@CLSID = C:\WINDOWS\system32\urlmon.dll
ms-its@CLSID = C:\WINDOWS\System32\itss.dll
ms-itss@CLSID = C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL
msnim@CLSID = "C:\PROGRA~1\MSNMES~1\msgrapp.dll"
mso-offdap11@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
res@CLSID = %SystemRoot%\System32\mshtml.dll
sysimage@CLSID = %SystemRoot%\System32\mshtml.dll
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
vbscript@CLSID = %SystemRoot%\System32\mshtml.dll
wia@CLSID = C:\WINDOWS\System32\wiascr.dll

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters@Domain =

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ >>>
000000000001@LibraryPath = %SystemRoot%\System32\mswsock.dll
000000000002@LibraryPath = %SystemRoot%\System32\winrnr.dll
000000000003@LibraryPath = %SystemRoot%\System32\mswsock.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000002@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000003@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000004@PackedCatalogItem = %SystemRoot%\system32\rsvpsp.dll
000000000005@PackedCatalogItem = %SystemRoot%\system32\rsvpsp.dll
000000000006@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000007@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000008@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000009@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000010@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000011@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000012@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll

C:\Documents and Settings\alessio\Menu Avvio\Programmi\Esecuzione automatica = Adobe Gamma.lnk

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica >>>
Acrobat Assistant.lnk = Acrobat Assistant.lnk
Adobe Gamma Loader.lnk = Adobe Gamma Loader.lnk
Microsoft Office.lnk = Microsoft Office.lnk

---- EOF - GMER 1.0.11 ----
Top
Profilo Invia messaggio privato
holifay
Dio maturo
Dio maturo


Registrato: 08/03/05 10:48
Messaggi: 2912
Residenza: Milano

MessaggioInviato: 29 Set 2006 00:54    Oggetto: Rispondi citando

OK, andiamo molto meglio Smile

Adesso usa di nuovo Avenger, con questo script:

Citazione:
Registry Keys to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NI.UERST_0001_N86M1107
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\aouei
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\DriveLogo
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Shellapi32
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Resurrector
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{521693AA-7453-47ED-9959-3BD47DAA1B1A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB4EF161-63CE-9AF6-C20F-2B7EAEBA3DBC}


Fatto questo ti consiglio, se non lo hai già fatto, di disinstallare dal pannello di controllo tutte le versioni di java che hai e poi di reinstallare l´ultima dal sito della sun http://java.com/it/

Installa anche la patch contro le vunerabilità wmf http://www.microsoft.com/technet/se...n/MS06-001.mspx

Al termine collegati al sito di Panda e fai una scansione online. Dovrai disabilitare temporaneamente la protezione di Ewido e del tuo antivirus. Quando Panda ha finito clicca "See report" e salva il log

Poi posta qui:
- nuovo log di Avenger
- log di Panda
- nuovo log di HijackThis

Ciao !
Top
Profilo Invia messaggio privato
emanuelagenova
Mortale devoto
Mortale devoto


Registrato: 27/09/06 19:10
Messaggi: 6

MessaggioInviato: 29 Set 2006 10:22    Oggetto: Rispondi citando

operazioni effettuate !!! GRAZIE MILLE PER LE DRITTE !!!
sembrano esserci ancora alcuni virus ...
ecco i log ...

HIJACKTHIS_________________________________________________
__________________________________________________________________________________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 10.16.21, on 29/09/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\QuickTime\qttask.exe
C:\apps\ABoard\AOSD.exe
C:\Programmi\ewido anti-spyware 4.0\guard.exe
C:\Programmi\McAfee.com\VSO\mcvsshld.exe
C:\Programmi\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Programmi\MSN Messenger\MsnMsgr.Exe
c:\programmi\mcafee.com\agent\mcdetect.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\DOCUME~1\alessio\IMPOST~1\Temp\Directory temporanea 6 per hijackthis_199.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=IT&range=AD&phase=6&key=SEARCH
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://format.packardbell.com/cgi-bin/redirect/?country=IT&range=AD&phase=6&key=OEM2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmi\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Programmi\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NI.UERST_0001_N86M1107] "c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe" -nag
O4 - HKLM\..\Run: [aouei] C:\Documents and Settings\alessio\Dati applicazioni\ratorefaci\sysrtmvs.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Programmi\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Programmi\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [!ewido] "C:\Programmi\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DriveLogo] C:\DOCUME~1\alessio\DATIAP~1\BIKEDV~1\VGA NOUN.exe
O4 - HKCU\..\Run: [Shellapi32] svcnet.exe
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\microsoft office\Office\OSA9.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\it.htm
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bokkadasse.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Programmi\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\programmi\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe




PANDA______________________________________________________
__________________________________________________________________________________________________________________________


Incidente Stato Percorso

Dialer:dialer.cos Non Disinfettato C:\Documents and Settings\alessio\Dati applicazioni\microsoft\internet explorer\quick launch\exsplorer.lnk
Dialer:dialer.akd Non Disinfettato C:\Documents and Settings\alessio\Dati applicazioni\microsoft\internet explorer\quick launch\W1inMoviePlugIn.lnk
Strumenti indesiderati:application/errorsafe Non Disinfettato hkey_local_machine\software\Error Safe Free
Adware:adware/ready2wear Non Disinfettato Registro di sistema di Windows
Virus:Trj/Downloader.JZJ Disinfettato C:\boot32.exe
Spyware:Cookie/2o7 Non Disinfettato C:\Documents and Settings\alessio\Cookies\alessio@2o7[1].txt
Spyware:Cookie/Atlas DMT Non Disinfettato C:\Documents and Settings\alessio\Cookies\alessio@atdmt[2].txt
Spyware:Cookie/Doubleclick Non Disinfettato C:\Documents and Settings\alessio\Cookies\alessio@doubleclick[1].txt
Spyware:Cookie/Hitbox Non Disinfettato C:\Documents and Settings\alessio\Cookies\alessio@hitbox[2].txt
Spyware:Cookie/Serving-sys Non Disinfettato C:\Documents and Settings\alessio\Cookies\alessio@serving-sys[2].txt
Spyware:Cookie/Cgi-bin Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\Cookies\alessio@cgi-bin[3].txt
Virus:Trj/Downloader.JZJ Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\s2fc.1.exe[²òÇ\boot32.dat]
Dialer:Dialer.HZH Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\s34g.2.exe
Virus:Trj/Clicker.QG Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\s3c4.1.exe[²èÇ]
Adware:Adware/RazeSpyware Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\s3dc.2.exe
Adware:Adware/ATNetwork Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\s3g8.1.exe[¦%%\comcap16.dll]
Adware:Adware/RazeSpyware Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\s3r8.1.exe
Dialer:Dialer.HZH Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\saj8.1.exe
Virus:Trj/Clicker.RV Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\sak8.2.exe[¦%%\kaboom.dll]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx10.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx101.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx102.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx107.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx108.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx109.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx111.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx12.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx124.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx125.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx127.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx13.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx139.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx14.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx142.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx153.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx154.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx158.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx159.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx162.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx164.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx168.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx17.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx170.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx177.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx18.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx185.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx188.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx190.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx2.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx228.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx23.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx233.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx240.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx245.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx248.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx253.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx26.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx3.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx34.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx35.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx41.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx42.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx44.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx45.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx5.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx53.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx54.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx6.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx61.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx62.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx65.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx7.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx70.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx75.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx76.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx84.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\tmpx87.exe[²èÇ]
Virus:Trj/Clicker.MQ Non Disinfettato C:\Documents and Settings\alessio\Impostazioni locali\Temp\wsx6C.tmp[²èÇ]
Spyware:Cookie/adultfriendfinder Non Disinfettato C:\Documents and Settings\emanuela\Cookies\emanuela@adultfriendfinder[2].txt
Spyware:Cookie/Atlas DMT Non Disinfettato C:\Documents and Settings\emanuela\Cookies\emanuela@atdmt[2].txt
Spyware:Cookie/Cgi-bin Non Disinfettato C:\Documents and Settings\emanuela\Cookies\emanuela@cgi-bin[1].txt
Spyware:Cookie/Cgi-bin Non Disinfettato C:\Documents and Settings\emanuela\Cookies\emanuela@cgi-bin[7].txt
Spyware:Cookie/Cgi-bin Non Disinfettato C:\Documents and Settings\emanuela\Cookies\emanuela@cgi-bin[9].txt
Spyware:Cookie/Doubleclick Non Disinfettato C:\Documents and Settings\emanuela\Cookies\emanuela@doubleclick[1].txt
Spyware:Cookie/ErrorSafe Non Disinfettato C:\Documents and Settings\emanuela\Cookies\emanuela@errorsafe[2].txt
Spyware:Cookie/OfferOptimizer Non Disinfettato C:\Documents and Settings\emanuela\Cookies\emanuela@offeroptimizer[1].txt
Spyware:Cookie/Xiti Non Disinfettato C:\Documents and Settings\emanuela\Cookies\emanuela@xiti[1].txt
Adware:Adware/RazeSpyware Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\s140.1.exe
Adware:Adware/RazeSpyware Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\s33s.1.exe
Adware:Adware/RazeSpyware Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\s3j0.1.exe
Adware:Adware/RazeSpyware Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\s3vo.1.exe
Adware:Adware/RazeSpyware Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\s84.1.exe
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\tmpx147.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\tmpx162.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\tmpx196.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\tmpx198.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\tmpx219.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\tmpx42.exe[²èÇ]
Virus:Trj/Kaboom.G Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\tmpx51.exe[²èÇ]
Virus:Trj/Clicker.MQ Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\wsx1.tmp[²èÇ]
Virus:Trj/Clicker.MQ Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\wsx4.tmp[²èÇ]
Virus:Trj/Clicker.MQ Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temp\wsxB.tmp[²èÇ]
Possibile Virus. Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temporary Internet Files\Content.IE5\0TUNOX6N\img_005v7_turbo[1].png
Possibile Virus. Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temporary Internet Files\Content.IE5\CDUNWHU7\pn005v2_turbo[1].png
Adware:Adware/RazeSpyware Non Disinfettato C:\Documents and Settings\emanuela\Impostazioni locali\Temporary Internet Files\Content.IE5\G5IN0DIV\0199[1].png
Spyware:Cookie/Xiti Non Disinfettato C:\Documents and Settings\mauro\Cookies\mauro@xiti[1].txt
Virus:Trj/Lowzones.BV Disinfettato C:\Documents and Settings\mauro\Dati applicazioni\sgrunt\disinstalla.htm
Dialer:Dialer.HEF Non Disinfettato C:\WINDOWS\Uninstall Plasma.exe




AVENGER ____________________________________________________
__________________________________________________________________________________________________________________________


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Syntax error in line --- does not appear to be a valid registry path. Line will be ignored.
Error code: 0
Line: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\DriveLogo


Syntax error in line --- does not appear to be a valid registry path. Line will be ignored.
Error code: 0
Line: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Shellapi32


Error: could not create zip file.
Error code: 0


//////////////////////////////////////////


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\blwfcpvt

*******************

Script file located at: \??\C:\uqtqg^rq.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NI.UERST_0001_N86M1107 not found!
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NI.UERST_0001_N86M1107 failed!
Status: 0xc0000034



Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run\aouei not found!
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run\aouei failed!
Status: 0xc0000034

Registry key HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Resurrector deleted successfully.
Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{521693AA-7453-47ED-9959-3BD47DAA1B1A} deleted successfully.
Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB4EF161-63CE-9AF6-C20F-2B7EAEBA3DBC} deleted successfully.

Completed script processing.

*******************

Finished! Terminate.//////////////////////////////////////////


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\hradnjsm

*******************

Script file located at: \??\C:\WINDOWS\system32\evmdysxi.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NI.UERST_0001_N86M1107 not found!
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NI.UERST_0001_N86M1107 failed!
Status: 0xc0000034



Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run\aouei not found!
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run\aouei failed!
Status: 0xc0000034



Registry key HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Resurrector not found!
Deletion of registry key HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Resurrector failed!
Status: 0xc0000034



Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{521693AA-7453-47ED-9959-3BD47DAA1B1A} not found!
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{521693AA-7453-47ED-9959-3BD47DAA1B1A} failed!
Status: 0xc0000034



Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB4EF161-63CE-9AF6-C20F-2B7EAEBA3DBC} not found!
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB4EF161-63CE-9AF6-C20F-2B7EAEBA3DBC} failed!
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.
Top
Profilo Invia messaggio privato
holifay
Dio maturo
Dio maturo


Registrato: 08/03/05 10:48
Messaggi: 2912
Residenza: Milano

MessaggioInviato: 29 Set 2006 12:39    Oggetto: Rispondi citando

Bene, abbiamo quasi finito Smile

Elimina da HijackThis queste voci:
Citazione:
O4 - HKLM\..\Run: [NI.UERST_0001_N86M1107] "c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe" -nag
O4 - HKLM\..\Run: [aouei] C:\Documents and Settings\alessio\Dati applicazioni\ratorefaci\sysrtmvs.exe
O4 - HKCU\..\Run: [DriveLogo] C:\DOCUME~1\alessio\DATIAP~1\BIKEDV~1\VGA NOUN.exe
O4 - HKCU\..\Run: [Shellapi32] svcnet.exe


Usa ancora Avenger, ormai sei esperta Wink
Citazione:
Folders to delete:
C:\Documents and Settings\alessio\Impostazioni locali\Temp
C:\Documents and Settings\emanuela\Impostazioni locali\Temp
C:\Documents and Settings\mauro\Dati applicazioni\sgrunt

Registry keys to delete:
hkey_local_machine\software\Error Safe Free

Files to delete:
C:\Documents and Settings\alessio\Dati applicazioni\microsoft\internet explorer\quick launch\exsplorer.lnk
C:\Documents and Settings\alessio\Dati applicazioni\microsoft\internet explorer\quick launch\W1inMoviePlugIn.lnk
C:\boot32.exe
C:\WINDOWS\Uninstall Plasma.exe


Dopo il riavvio, scarica Regsrch.zip, avvia il file vbs e scrivi nella finestra che si apre ready2wear. Attendi l´apertura di Wordpad e copia il contenuto

Apri Internet Explorer, clicca su Strumenti >> Opzioni Internet e cancella i cookies ed i File temporanei

Poi posta:
- nuovo log di Avenger
- nuovo log di HijackThis
- log di regsrch.vbs
Top
Profilo Invia messaggio privato
emanuelagenova
Mortale devoto
Mortale devoto


Registrato: 27/09/06 19:10
Messaggi: 6

MessaggioInviato: 29 Set 2006 18:10    Oggetto: Rispondi citando

grazie mille come sempre !!!

ecco i log ... e speriamo in bene !!!!!!!


- nuovo log di Avenger ___________________________________
_______________________________________________________
_______________________________________________________

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\clbdytix

*******************

Script file located at: \??\C:\bsbdupip.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Folder C:\Documents and Settings\alessio\Impostazioni locali\Temp deleted successfully.
Folder C:\Documents and Settings\emanuela\Impostazioni locali\Temp deleted successfully.
Folder C:\Documents and Settings\mauro\Dati applicazioni\sgrunt deleted successfully.
File C:\Documents and Settings\alessio\Dati applicazioni\microsoft\internet explorer\quick launch\exsplorer.lnk deleted successfully.
File C:\Documents and Settings\alessio\Dati applicazioni\microsoft\internet explorer\quick launch\W1inMoviePlugIn.lnk deleted successfully.


File C:\boot32.exe not found!
Deletion of file C:\boot32.exe failed!

Could not process line:
C:\boot32.exe
Status: 0xc0000034



- nuovo log di HijackThis ___________________________________
________________________________________________________
________________________________________________________

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\clbdytix

*******************

Script file located at: \??\C:\bsbdupip.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Folder C:\Documents and Settings\alessio\Impostazioni locali\Temp deleted successfully.
Folder C:\Documents and Settings\emanuela\Impostazioni locali\Temp deleted successfully.
Folder C:\Documents and Settings\mauro\Dati applicazioni\sgrunt deleted successfully.
File C:\Documents and Settings\alessio\Dati applicazioni\microsoft\internet explorer\quick launch\exsplorer.lnk deleted successfully.
File C:\Documents and Settings\alessio\Dati applicazioni\microsoft\internet explorer\quick launch\W1inMoviePlugIn.lnk deleted successfully.


File C:\boot32.exe not found!
Deletion of file C:\boot32.exe failed!

Could not process line:
C:\boot32.exe
Status: 0xc0000034





- log di regsrch.vbs ________________________________________
_________________________________________________________
_________________________________________________________
REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "ready2wear" 29/09/2004 18.00.59

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{521693AA-7453-47ED-9959-3BD47DAA1B1A}\ProgID]
@="xsmx.ready2wear.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{521693AA-7453-47ED-9959-3BD47DAA1B1A}\VersionIndependentProgID]
@="xsmx.ready2wear"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A25166AB-84F1-4636-B8C2-1D0366E8BB7B}]
@="Iready2wear"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\xsmx.ready2wear]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\xsmx.ready2wear\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\xsmx.ready2wear\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\xsmx.ready2wear\CurVer]
@="xsmx.ready2wear.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\xsmx.ready2wear.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\xsmx.ready2wear.1\CLSID]
Top
Profilo Invia messaggio privato
Smjert
Dio maturo
Dio maturo


Registrato: 01/04/06 18:19
Messaggi: 1619
Residenza: Perso nella rete

MessaggioInviato: 29 Set 2006 18:43    Oggetto: Rispondi citando

Attenzione!! vorrei far notare che Spoolsv.exe non è un virus.. è Spoolsvc.exe il virus quindi per non creare confusioni (ed errori) bisogna cambiare il titolo del topic.
Top
Profilo Invia messaggio privato HomePage
chemicalbit
Dio maturo
Dio maturo


Registrato: 01/04/05 18:59
Messaggi: 18597
Residenza: Milano

MessaggioInviato: 29 Set 2006 20:46    Oggetto: Rispondi citando

Smjert ha scritto:
Attenzione!! vorrei far notare che Spoolsv.exe non è un virus.. è Spoolsvc.exe il virus quindi per non creare confusioni (ed errori) bisogna cambiare il titolo del topic.
Sistemato.

p.s.: occhio che così rischi che ti nominino moderatore e ti dicano "ora sistema tu!" Wink Smile
Top
Profilo Invia messaggio privato
Smjert
Dio maturo
Dio maturo


Registrato: 01/04/06 18:19
Messaggi: 1619
Residenza: Perso nella rete

MessaggioInviato: 29 Set 2006 21:13    Oggetto: Rispondi citando

chemicalbit ha scritto:

p.s.: occhio che così rischi che ti nominino moderatore e ti dicano "ora sistema tu!" Wink Smile


Ihih io sono sempre disponibile Razz.
Top
Profilo Invia messaggio privato HomePage
holifay
Dio maturo
Dio maturo


Registrato: 08/03/05 10:48
Messaggi: 2912
Residenza: Milano

MessaggioInviato: 01 Ott 2006 18:57    Oggetto: Rispondi citando

Copia il contenuto qui sotto in grassetto in un file di testo che chiamerai fix.reg. Salva il file sul desktop, poi avvialo cliccandoci sopra due volte e rispondi OK

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{521693AA-7453-47ED-9959-3BD47DAA1B1A}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A25166AB-84F1-4636-B8C2-1D0366E8BB7B}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\xsmx.ready2wear]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\xsmx.ready2wear.1]


Dovrebbe dirti che le informazioni sono state aggiunte nel registro.

Dopo di che cerca ed elimina questo file: C:\WINDOWS\Uninstall Plasma.exe

Poi per me sei a posto, come va il PC? Occhio a non infettarti più, segliendo con attenzione cosa installare e su quali link cliccare! Wink
Top
Profilo Invia messaggio privato
emanuelagenova
Mortale devoto
Mortale devoto


Registrato: 27/09/06 19:10
Messaggi: 6

MessaggioInviato: 04 Ott 2006 17:57    Oggetto: Rispondi citando

fatto tutto ... ma non sono riuscita a trovare il file C:\WINDOWS\Uninstall Plasma.exe per cancellarlo ...

il pc va molto molto molto meglio ... adesso riesco ad usarlo !!!

ho solo problemini in fase di avvio e qualche altra volta che mi si ferma senza motivo, per poi sbloccarsi dopo 4 o 5 minuti ....
centra mica qualcosa l'antivirus?

cmq questo è il mio log attuale :

Logfile of HijackThis v1.99.1
Scan saved at 17.56.53, on 04/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\ewido anti-spyware 4.0\guard.exe
c:\programmi\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmi\QuickTime\qttask.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Programmi\iPod\bin\iPodService.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\iTunes\iTunes.exe
C:\Programmi\MSN Messenger\msnmsgr.exe
c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\DOCUME~1\alessio\IMPOST~1\Temp\Directory temporanea 2 per hijackthis_199.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=IT&range=AD&phase=6&key=SEARCH
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://format.packardbell.com/cgi-bin/redirect/?country=IT&range=AD&phase=6&key=OEM2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmi\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Programmi\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NI.UERST_0001_N86M1107] "c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe" -nag
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Programmi\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Programmi\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\microsoft office\Office\OSA9.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\it.htm
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bokkadasse.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Programmi\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\programmi\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe

_____________________________________________________

GRAZIE MILLE ... SEI STATA SPLENDIDA COME SEMPRE !!!!
Top
Profilo Invia messaggio privato
Smjert
Dio maturo
Dio maturo


Registrato: 01/04/06 18:19
Messaggi: 1619
Residenza: Perso nella rete

MessaggioInviato: 04 Ott 2006 18:52    Oggetto: Rispondi citando

Hai ancora una voce che rischia di ripristinare/aggiungere altri malware..
Apri HijackThis e premi Do a system scan only poi spunta questa voce e clicca Fix Checked:

Citazione:
O4 - HKLM\..\Run: [NI.UERST_0001_N86M1107] "c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe" -nag


Poi dovresti sapere come si usa avenger (se non ti ricordi guarda la pagina precedente Razz).
Usa questo script:

Citazione:
files to delete:
c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe


Poi posta il log di avenger e un nuovo log di HijackThis (perchè non sempre si riesce a fixare quella voce).
Top
Profilo Invia messaggio privato HomePage
emanuelagenova
Mortale devoto
Mortale devoto


Registrato: 27/09/06 19:10
Messaggi: 6

MessaggioInviato: 05 Ott 2006 01:52    Oggetto: Rispondi citando

ecco fatto ...
speriamo in bene !!


__________________________________________________________

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\bodpdogy

*******************

Script file located at: \??\C:\enejtqoc.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe not found!
Deletion of file c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe failed!

Could not process line:
c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.




__________________________________________________________-

Logfile of HijackThis v1.99.1
Scan saved at 1.51.24, on 05/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\ewido anti-spyware 4.0\guard.exe
c:\programmi\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\apps\ABoard\AOSD.exe
C:\Programmi\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmi\QuickTime\qttask.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Programmi\Messenger\msmsgs.exe
C:\DOCUME~1\alessio\IMPOST~1\Temp\Directory temporanea 3 per hijackthis_199.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=IT&range=AD&phase=6&key=SEARCH
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://format.packardbell.com/cgi-bin/redirect/?country=IT&range=AD&phase=6&key=OEM2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmi\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\it\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Programmi\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NI.UERST_0001_N86M1107] "c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe" -nag
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Programmi\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Programmi\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\microsoft office\Office\OSA9.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\it.htm
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bokkadasse.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Programmi\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\programmi\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
Top
Profilo Invia messaggio privato
Smjert
Dio maturo
Dio maturo


Registrato: 01/04/06 18:19
Messaggi: 1619
Residenza: Perso nella rete

MessaggioInviato: 05 Ott 2006 12:05    Oggetto: Rispondi citando

Ecco lo sapevo... non si è levata Neutral allora rifixa quella voce con HijackThis e poi riavvia il pc in Modalità Provvisoria.

Citazione:
Apri una cartella qualunque, vai su
Strumenti->Opzioni Cartella->scheda Visualizzazione,
spunta la voce "Visualizza cartelle e file nascosti", togli la spunta a
"Nascondi file protetti di sistema" (digli di sì).


Cancella questo file c:\documents and settings\emanuela\dati applicazioni\errorsafescannerinstall_it[1].exe

Poi riavvia in modalità normale, fai una scansione con HijackThis e se c'è ancora quella voce avvertimi che troviamo un altro modo per levarlo.
Top
Profilo Invia messaggio privato HomePage
holifay
Dio maturo
Dio maturo


Registrato: 08/03/05 10:48
Messaggi: 2912
Residenza: Milano

MessaggioInviato: 05 Ott 2006 17:49    Oggetto: Rispondi citando

il file errorsafescannerinstall_it[1].exe è già stato cancellato da Avenger, qualche post fa Wink

Non riesci a fixare quella voce da HijackThis?
Top
Profilo Invia messaggio privato
Smjert
Dio maturo
Dio maturo


Registrato: 01/04/06 18:19
Messaggi: 1619
Residenza: Perso nella rete

MessaggioInviato: 05 Ott 2006 18:30    Oggetto: Rispondi

Cmq quel file appartiene al trojan Rogue.ErrorSafe o + semplicemente ErrorSafe ma non trovo un tool automatico per fare la pulizia (dato che ci sarebbero da controllare e, se ci sono, rimuovere tipo 30 chiavi di registro e una decina di file...)
Top
Profilo Invia messaggio privato HomePage
Mostra prima i messaggi di:   
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus Tutti i fusi orari sono GMT + 2 ore
Pagina 1 di 1

 
Vai a:  
Non puoi inserire nuovi argomenti
Non puoi rispondere a nessun argomento
Non puoi modificare i tuoi messaggi
Non puoi cancellare i tuoi messaggi
Non puoi votare nei sondaggi