Precedente :: Successivo |
Autore |
Messaggio |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 18 Mar 2008 23:22 Oggetto: [RISOLTO] Internet Connection...Di Nuovo... |
|
|
Ciao a tutti, ho il seguente problema.
La mia connessione internet viene improvvisamente interrotta da una nuova connessione, autogeneratasi, col nome Internet Connection.
Questa non pare in effetti collegarmi ad alcun sito: il numero che compone è di sole tre cifre "000" e la linea telefonica è libera.
Questo disturbo, non colpisce il mio pc per la prima volta oggi.
Si era in effetti già presentato alla fine di gennaio scorso, ma pensavo di averlo eliminato all?inizio del mese di febbraio.
Purtroppo non è così.
Oggi la nefasta Internet Connection è tornata a colpire.
C?è una novità rispetto a due mesi fa: sul desktop è comparsa un?icona, assente sino a ieri, che corrisponde al seguente file:
rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
Chiunque voglia e/o possa aiutarmi, suggerendomi cosa fare per risolvere questo problema, ha sin d?ora la mia riconoscenza.
Allego il log di hijackthis, nel quale compare il file sospetto di cui sopra
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20.34.22, on 18/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\Casio\Photo Loader\Plauto.exe
C:\Programmi\Sony\VAIO Action Setup\VAServ.exe
C:\Programmi\HP\Digital Imaging\bin\hpqgalry.exe
C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Programmi\Outlook Express\msimn.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com/en/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Liquid Surf for VAIO TV Entertainment - {EC5BB10A-FDA1-41d6-8CE4-C00C1E5DC464} - C:\Programmi\Portrait Displays\Liquid Surf for VAIO TV Entertainment\sybil.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Programmi\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmi\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Programmi\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [AppMon Utility] "C:\Programmi\Sony\AppMonUtil\AppMonUtility.exe" @@@Start
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Audio Filter.lnk = C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe
O4 - Global Startup: Avvio rapido di HP Image Zone.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Photo Loader residente.lnk = C:\Programmi\Casio\Photo Loader\Plauto.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = C:\Programmi\Sony\VAIO Action Setup\VAServ.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmi\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Programmi\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Servizio Auto-Protect di Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Programmi\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
--
End of file - 12414 bytes |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 18 Mar 2008 23:31 Oggetto: |
|
|
Ciao Irnerio,
PS: ti sposto al Pronto Soccorso Virus. |
|
Top |
|
 |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 19 Mar 2008 21:41 Oggetto: Internet Connection...Di Nuovo... |
|
|
Ciao Bdoriano
di nuovo tu...confesso che ci speravo!
Grazie sin d'ora per l'aiuto che mi dai!!
Mi metto subito al lavoro e ti faccio sapere quanto prima.
Ciao |
|
Top |
|
 |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 26 Mar 2008 23:46 Oggetto: Internet Connectio...Di Nuovo... |
|
|
Ciao bdoriano,
eccomi qui di nuovo.
Ho seguito le tue istruzioni, ma non sono riuscito a scaricare nod 32 : il server chiude il download prima dello scaricamento.
Ho invece scaricato Norman Malware e l'ho eseguito in modalità provvisoria.
Il log che è stato generato, si trova su free file hosting.
Questo è l'indirizzo:
Forum Link:
NFix_2008-03-26_20-45-07.log
Spero che tu possa suggerirmi sul da farsi.
Nel frattempo, provvedo a scaricare combofix, così da postare quanto prima il log che verrà generato.
Ciao |
|
Top |
|
 |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 27 Mar 2008 23:38 Oggetto: Internet Connection...Di Nuovo... |
|
|
Ciao bdoriano,
ho scaricato ed eseguito anche combofix , questo è il log generato:
ComboFix 08-03-25.4 - LORENZO 2008-03-27 22.10.45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.566 [GMT 1:00]
Eseguito da: C:\Documents and Settings\LORENZO\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Creati Da 2008-02-27 al 2008-03-27 )))))))))))))))))))))))))))))))))))
.
2008-03-20 21:06 . 2008-03-20 21:06 16,648,248 --a------ C:\Programmi\Norman_Malware_Cleaner.exe
2008-03-19 21:24 . 2008-03-19 21:24 <DIR> d-------- C:\Programmi\CCleaner
2008-03-19 21:10 . 2008-03-19 21:10 671,968 --a------ C:\Programmi\ccsetup205_slim.exe
2008-03-19 21:05 . 2008-03-19 21:05 50,688 --a------ C:\Programmi\ATF-Cleaner.exe
2008-03-18 22:11 . 2008-03-18 20:28 14,348 --a------ C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-27 19:41 --------- d-----w C:\Programmi\File comuni\Symantec Shared
2008-03-21 11:40 --------- d-----w C:\Programmi\Norton Internet Security
2008-03-18 19:34 12,416 ----a-w C:\Programmi\hijackthis.log
2008-03-15 14:30 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-03-15 14:12 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-03-15 14:12 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-03-15 14:12 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-02-08 22:18 53,248 ----a-w C:\Programmi\Process.exe
2008-01-25 17:19 127,378 ----a-w C:\Programmi\avenger.zip
2008-01-24 21:17 189,718 ----a-w C:\Programmi\FindAWF.exe
2008-01-15 21:47 143,428 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2008-01-15 14:09 401,720 ----a-w C:\Programmi\HiJackThis.exe
2008-01-13 11:45 17,990,864 ----a-w C:\Programmi\AAW2007.EXE
2007-03-18 17:11 35,248 ------w C:\Documents and Settings\LORENZO\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
Codice: | <pre>
----a-w 14,348 2008-03-18 19:28:19 C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
----a-w 81,920 2008-02-08 22:12:18 C:\Programmi\Sony\SonicStage\SsAAD .exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray .exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon .exe
</pre> |
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 1,019,392 2004-09-23 09:33:44 C:\Programmi\File comuni\PCSuite\DataLayer\bak\DATALA~1.EXE
----a-w 171,448 2007-01-27 15:49:00 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe
----a-w 49,152 2004-02-12 12:38:56 C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 241,664 2004-05-12 14:18:56 C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe
----a-w 36,975 2005-11-10 11:03:52 C:\Programmi\Java\jre1.5.0_06\bin\bak\jusched.exe
----a-w 148,992 2004-09-15 14:36:06 C:\Programmi\Nokia\Nokia PC Suite 6\bak\TRAYAP~1.EXE
----a-w 29,696 2006-06-22 14:11:18 C:\Programmi\Sony\AppMonUtil\bak\AppMonUtility.exe
----a-w 69,632 2005-12-27 11:58:10 C:\Programmi\Sony\VAIO Camera Utility\bak\VCUServe.exe
----a-w 151,552 2005-10-11 19:36:38 C:\Programmi\Sony\VAIO Update 2\bak\VAIOUpdt.exe
----a-w 64,512 2005-08-17 20:40:06 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-07 13:00 15360]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [ ]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-23 00:32 7561216]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 04:04 59392]
"ccApp"="C:\Programmi\File comuni\Symantec Shared\ccApp.exe" [2007-02-22 12:11 52840]
"URLLSTCK.exe"="C:\Programmi\Norton Internet Security\UrlLstCk.exe" [2007-02-01 17:21 23168]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-09-07 13:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"Symantec PIF AlertEng"="C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 09:22 517768]
"Acrobat Assistant 7.0"="C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 20:47 483328]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [ ]
"VAIOCameraUtility"="C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe" [ ]
"VAIO Update 2"="C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" [ ]
"HP Component Manager"="C:\Programmi\HP\hpcoretech\hpcmpmgr.exe" [ ]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe" [ ]
"Norton Ghost 10.0"="C:\Programmi\Norton Ghost\Agent\GhostTray.exe" [ ]
"AppMon Utility"="C:\Programmi\Sony\AppMonUtil\AppMonUtility.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-07 13:00 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Audio Filter.lnk - C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe [2006-08-19 08:16:02 5649408]
Avvio rapido di HP Image Zone.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 23:06:36 53248]
Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 22:31:38 241664]
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]
Photo Loader residente.lnk - C:\Programmi\Casio\Photo Loader\Plauto.exe [2006-12-29 18:03:56 229376]
VAIO Action Setup (Server).lnk - C:\Programmi\Sony\VAIO Action Setup\VAServ.exe [2006-07-17 14:21:26 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2005-05-20 16:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 16:56]
R2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;"C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 17:45]
R3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\DRIVERS\AVerM115S.sys [2006-06-14 09:22]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2006-03-06 10:39]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 10:32]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Programmi\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 18:10]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 16:23]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
*Newly Created Service* - COMHOST
.
Contenuto della cartella 'Scheduled Tasks'
"2008-03-21 21:55:13 C:\WINDOWS\Tasks\Norton AntiVirus - Esegui scansione completa del sistema - LORENZO.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exei/TASK:
"2007-06-16 07:00:41 C:\WINDOWS\Tasks\WebReg 20070616090041.job"
- C:\Programmi\HP\Digital Imaging\bin\hpqwrg.exe`/TaskName 20070616090041 /N
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-27 22:13:03
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-03-27 22.13.42
ComboFix-quarantined-files.txt 2008-03-27 21:13:32
.
2008-03-15 14:33:53 --- E O F ---
Di seguito, inoltre, il log aggiornato di hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22.19.54, on 27/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\Casio\Photo Loader\Plauto.exe
C:\Programmi\Sony\VAIO Action Setup\VAServ.exe
C:\Programmi\HP\Digital Imaging\bin\hpqgalry.exe
C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\explorer.exe
C:\Programmi\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Liquid Surf for VAIO TV Entertainment - {EC5BB10A-FDA1-41d6-8CE4-C00C1E5DC464} - C:\Programmi\Portrait Displays\Liquid Surf for VAIO TV Entertainment\sybil.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Programmi\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmi\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Programmi\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [AppMon Utility] "C:\Programmi\Sony\AppMonUtil\AppMonUtility.exe" @@@Start
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Audio Filter.lnk = C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe
O4 - Global Startup: Avvio rapido di HP Image Zone.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Photo Loader residente.lnk = C:\Programmi\Casio\Photo Loader\Plauto.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = C:\Programmi\Sony\VAIO Action Setup\VAServ.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmi\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Programmi\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Servizio Auto-Protect di Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Programmi\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
--
End of file - 12391 bytes
E ora cosa devo fare?
p.s.
Al termine della scansione di combofix, sul desktop è apparsa un'icona di internet explorer che prima, non era presente.
Non ho idea del perchè . |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 28 Mar 2008 12:01 Oggetto: |
|
|
Crea un file di testo con le seguenti istruzioni:
Codice: | RenV::
C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
C:\Programmi\Sony\SonicStage\SsAAD .exe
C:\WINDOWS\ehome\ehtray .exe
C:\WINDOWS\system32\ctfmon .exe |
Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:
Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro.
Posta i logs aggiornati di combofix e di hijackthis
Per quanto riguarda l'icona di Internet Explorer non ti so dire... puoi fare uno screenshot della tua videata? Hai provato a cliccarci con il tasto dx del mouse e verificare le proprietà dell'icona? |
|
Top |
|
 |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 28 Mar 2008 20:35 Oggetto: Internet Connection...Di Nuovo... |
|
|
Ciao
ho fatto quanto mi hai consigliato .
Posto qui per primo il log di combofix, poi a seguire quello di hijackthis:
ComboFix 08-03-25.4 - LORENZO 2008-03-28 17.46.18.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.511 [GMT 1:00]
Eseguito da: C:\Documents and Settings\LORENZO\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\LORENZO\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Creati Da 2008-02-28 al 2008-03-28 )))))))))))))))))))))))))))))))))))
.
2008-03-20 21:06 . 2008-03-20 21:06 16,648,248 --a------ C:\Programmi\Norman_Malware_Cleaner.exe
2008-03-19 21:24 . 2008-03-19 21:24 <DIR> d-------- C:\Programmi\CCleaner
2008-03-19 21:10 . 2008-03-19 21:10 671,968 --a------ C:\Programmi\ccsetup205_slim.exe
2008-03-19 21:05 . 2008-03-19 21:05 50,688 --a------ C:\Programmi\ATF-Cleaner.exe
2008-03-18 22:11 . 2008-03-18 20:28 14,348 --a------ C:\Documents and Settings\LORENZO\rundll32.exe bthprops.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-28 16:50 --------- d-----w C:\Programmi\File comuni\Symantec Shared
2008-03-27 21:19 12,393 ----a-w C:\Programmi\hijackthis.log
2008-03-21 11:40 --------- d-----w C:\Programmi\Norton Internet Security
2008-03-15 14:30 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-03-15 14:12 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-03-15 14:12 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-02-08 22:18 53,248 ----a-w C:\Programmi\Process.exe
2008-01-25 17:19 127,378 ----a-w C:\Programmi\avenger.zip
2008-01-24 21:17 189,718 ----a-w C:\Programmi\FindAWF.exe
2008-01-15 14:09 401,720 ----a-w C:\Programmi\HiJackThis.exe
2008-01-13 11:45 17,990,864 ----a-w C:\Programmi\AAW2007.EXE
2007-03-18 17:11 35,248 ------w C:\Documents and Settings\LORENZO\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
Codice: | <pre>
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
----a-w 81,920 2008-02-08 22:12:18 C:\Programmi\Sony\SonicStage\SsAAD .exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray .exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon .exe
</pre> |
((((((((((((((((((((((((((((( snapshot@2008-03-27_22.13.19,16 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-09 13:49:53 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-03-28 17:00:20 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-03-09 13:49:53 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\index.dat
+ 2008-03-28 17:00:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\index.dat
- 2008-03-09 13:49:53 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-28 17:00:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 1,019,392 2004-09-23 09:33:44 C:\Programmi\File comuni\PCSuite\DataLayer\bak\DATALA~1.EXE
----a-w 171,448 2007-01-27 15:49:00 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
----a-w 49,152 2004-02-12 12:38:56 C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 241,664 2004-05-12 14:18:56 C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe
----a-w 36,975 2005-11-10 11:03:52 C:\Programmi\Java\jre1.5.0_06\bin\bak\jusched.exe
----a-w 148,992 2004-09-15 14:36:06 C:\Programmi\Nokia\Nokia PC Suite 6\bak\TRAYAP~1.EXE
----a-w 29,696 2006-06-22 14:11:18 C:\Programmi\Sony\AppMonUtil\bak\AppMonUtility.exe
----a-w 69,632 2005-12-27 11:58:10 C:\Programmi\Sony\VAIO Camera Utility\bak\VCUServe.exe
----a-w 151,552 2005-10-11 19:36:38 C:\Programmi\Sony\VAIO Update 2\bak\VAIOUpdt.exe
----a-w 64,512 2005-08-17 20:40:06 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-07 13:00 15360]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2008-03-18 20:28 14348]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-03-18 20:28 14348]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-23 00:32 7561216]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 04:04 59392]
"ccApp"="C:\Programmi\File comuni\Symantec Shared\ccApp.exe" [2007-02-22 12:11 52840]
"URLLSTCK.exe"="C:\Programmi\Norton Internet Security\UrlLstCk.exe" [2007-02-01 17:21 23168]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-09-07 13:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"Symantec PIF AlertEng"="C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 09:22 517768]
"Acrobat Assistant 7.0"="C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 20:47 483328]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [ ]
"VAIOCameraUtility"="C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe" [ ]
"VAIO Update 2"="C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" [ ]
"HP Component Manager"="C:\Programmi\HP\hpcoretech\hpcmpmgr.exe" [ ]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe" [ ]
"Norton Ghost 10.0"="C:\Programmi\Norton Ghost\Agent\GhostTray.exe" [ ]
"AppMon Utility"="C:\Programmi\Sony\AppMonUtil\AppMonUtility.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-07 13:00 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Audio Filter.lnk - C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe [2006-08-19 08:16:02 5649408]
Avvio rapido di HP Image Zone.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 23:06:36 53248]
Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 22:31:38 241664]
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]
Photo Loader residente.lnk - C:\Programmi\Casio\Photo Loader\Plauto.exe [2006-12-29 18:03:56 229376]
VAIO Action Setup (Server).lnk - C:\Programmi\Sony\VAIO Action Setup\VAServ.exe [2006-07-17 14:21:26 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2005-05-20 16:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 16:56]
R2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;"C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 17:45]
R3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\DRIVERS\AVerM115S.sys [2006-06-14 09:22]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2006-03-06 10:39]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 10:32]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Programmi\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 18:10]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 16:23]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
*Newly Created Service* - COMHOST
.
Contenuto della cartella 'Scheduled Tasks'
"2008-03-21 21:55:13 C:\WINDOWS\Tasks\Norton AntiVirus - Esegui scansione completa del sistema - LORENZO.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exei/TASK:
"2007-06-16 07:00:41 C:\WINDOWS\Tasks\WebReg 20070616090041.job"
- C:\Programmi\HP\Digital Imaging\bin\hpqwrg.exe`/TaskName 20070616090041 /N
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-28 19:07:30
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Programmi\HP\Digital Imaging\bin\hpqgalry.exe
C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
.
**************************************************************************
.
Ora fine scansione: 2008-03-28 19:10:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-28 18:10:18
ComboFix2.txt 2008-03-27 21:13:43
.
2008-03-15 14:33:53 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19.17.23, on 28/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\Casio\Photo Loader\Plauto.exe
C:\Programmi\Sony\VAIO Action Setup\VAServ.exe
C:\Programmi\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\explorer.exe
C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Programmi\Microsoft Office\Office10\WINWORD.EXE
C:\Programmi\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programmi\File comuni\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmi\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Liquid Surf for VAIO TV Entertainment - {EC5BB10A-FDA1-41d6-8CE4-C00C1E5DC464} - C:\Programmi\Portrait Displays\Liquid Surf for VAIO TV Entertainment\sybil.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Programmi\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmi\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Programmi\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [AppMon Utility] "C:\Programmi\Sony\AppMonUtil\AppMonUtility.exe" @@@Start
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Audio Filter.lnk = C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe
O4 - Global Startup: Avvio rapido di HP Image Zone.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Photo Loader residente.lnk = C:\Programmi\Casio\Photo Loader\Plauto.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = C:\Programmi\Sony\VAIO Action Setup\VAServ.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programmi\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Programmi\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Servizio Auto-Protect di Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmi\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Programmi\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
--
End of file - 12627 bytes
Ho verificato anche la proprietà dell'icona di internet explorer apparsa sul desktop: a parte la presenza di Internet Connection tra le connessioni predefinite, non c'è nulla di strano.
Ti farei anche lo screenshot se sapessi cos'è e come si fa... . Però se me lo spieghi, posso provarci.
Ti lascio esaminare gli ultimi logs e, aspetto la diagnosi...
P.S.
Ho notato, da qualche giorno, che riesco a rimanere connesso a lungo tramite Libero, senza che Internet Connection intervenga disconnettendomi.
Era accaduto anche nel gennaio scorso, quando il problema si era manifestato la prima volta.
Non so dire però perchè. |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 28 Mar 2008 21:48 Oggetto: |
|
|
Ha funzionato parzialmente...
Rifacciamo. Crea un file di testo con le seguenti istruzioni:
Codice: | RenV::
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
C:\Programmi\Sony\SonicStage\SsAAD .exe
C:\WINDOWS\ehome\ehtray .exe
C:\WINDOWS\system32\ctfmon .exe |
Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:
Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro.
Posta il log aggiornato di combofix.
Per come fare gli screenshot, dai un'occhiata a questo topic o a quest'altro. |
|
Top |
|
 |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 30 Mar 2008 00:00 Oggetto: Internet Connection...Di Nuovo... |
|
|
Ciao
ho creato il file di testo che mi hai indicato e l'ho trascinato su combofix.
Questo è il log che ne è uscito:
ComboFix 08-03-29.1 - LORENZO 2008-03-29 21.04.33.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.391 [GMT 1:00]
Eseguito da: C:\Documents and Settings\LORENZO\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\LORENZO\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Creati Da 2008-02-28 al 2008-03-29 )))))))))))))))))))))))))))))))))))
.
2008-03-29 20:55 . 2008-03-29 20:55 <DIR> d-------- C:\Programmi\TechSmith
2008-03-29 20:50 . 2008-03-29 20:50 <DIR> d-------- C:\WINDOWS\system32\it-IT
2008-03-29 20:49 . 2008-03-29 20:49 <DIR> d-------- C:\Programmi\MSBuild
2008-03-29 20:46 . 2008-03-29 20:50 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-03-29 20:45 . 2008-03-29 20:45 <DIR> d-------- C:\Programmi\Reference Assemblies
2008-03-29 20:45 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-03-29 20:42 . 2008-03-29 20:42 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-03-29 17:06 . 2008-03-29 17:07 2,945,816 --a------ C:\Programmi\Net Framework 3.0 dotnetfx3setup.exe
2008-03-29 15:08 . 2008-03-29 15:08 5,549,888 --a------ C:\Programmi\jing_setup.exe
2008-03-20 21:06 . 2008-03-20 21:06 16,648,248 --a------ C:\Programmi\Norman_Malware_Cleaner.exe
2008-03-19 21:24 . 2008-03-19 21:24 <DIR> d-------- C:\Programmi\CCleaner
2008-03-19 21:10 . 2008-03-19 21:10 671,968 --a------ C:\Programmi\ccsetup205_slim.exe
2008-03-19 21:05 . 2008-03-19 21:05 50,688 --a------ C:\Programmi\ATF-Cleaner.exe
2008-03-18 22:11 . 2008-03-18 20:28 14,348 --a------ C:\Documents and Settings\LORENZO\rundll32.exe bthprops.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-29 20:08 --------- d-----w C:\Programmi\File comuni\Symantec Shared
2008-03-29 15:47 --------- d-----w C:\Programmi\File comuni\Wise Installation Wizard
2008-03-28 18:17 12,629 ----a-w C:\Programmi\hijackthis.log
2008-03-21 11:40 --------- d-----w C:\Programmi\Norton Internet Security
2008-03-15 14:30 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-03-15 14:12 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-03-15 14:12 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-02-08 22:18 53,248 ----a-w C:\Programmi\Process.exe
2008-01-25 17:19 127,378 ----a-w C:\Programmi\avenger.zip
2008-01-24 21:17 189,718 ----a-w C:\Programmi\FindAWF.exe
2008-01-15 14:09 401,720 ----a-w C:\Programmi\HiJackThis.exe
2008-01-13 11:45 17,990,864 ----a-w C:\Programmi\AAW2007.EXE
2007-03-18 17:11 35,248 ------w C:\Documents and Settings\LORENZO\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
Codice: | <pre>
----a-w 14,348 2008-03-18 19:28:19 C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
----a-w 81,920 2008-02-08 22:12:18 C:\Programmi\Sony\SonicStage\SsAAD .exe
----a-w 709,888 2008-01-28 11:48:58 C:\Programmi\TechSmith\Jing\Jing .exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray .exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon .exe
</pre> |
((((((((((((((((((((((((((((( snapshot@2008-03-27_22.13.19,16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-29 19:43:27 68,608 ----a-w C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2008-03-29 19:43:32 72,192 ----a-w C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2008-03-29 19:45:47 151,552 ----a-w C:\WINDOWS\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2008-03-29 19:43:33 4,308,992 ----a-w C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2008-03-29 19:46:16 3,915,776 ----a-w C:\WINDOWS\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2008-03-29 19:43:33 482,304 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2008-03-29 19:43:30 2,878,976 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2008-03-29 19:43:24 258,048 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2008-03-29 19:43:24 114,176 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2008-03-29 19:46:17 344,064 ----a-w C:\WINDOWS\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2008-03-29 19:43:36 260,096 ----a-w C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2008-03-29 19:43:28 5,025,792 ----a-w C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-03-29 19:43:26 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2008-03-29 19:50:54 315,392 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt.resources\2.0.0.0_it_b03f5f7f11d50a3a\aspnetmmcext.resources.dll
+ 2008-03-29 19:43:23 503,808 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2008-03-29 19:43:25 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2008-03-29 19:43:31 8,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2008-03-29 19:43:32 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2008-03-29 19:43:32 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2008-03-29 19:50:59 53,248 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine.resources\2.0.0.0_it_b03f5f7f11d50a3a\Microsoft.Build.Engine.resources.dll
+ 2008-03-29 19:43:25 413,696 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2008-03-29 19:43:25 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2008-03-29 19:50:59 139,264 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks.resources\2.0.0.0_it_b03f5f7f11d50a3a\Microsoft.Build.Tasks.resources.dll
+ 2008-03-29 19:43:26 647,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2008-03-29 19:50:59 10,240 ----a-w C:\WINDOWS\assembly\GAC_MSIL\microsoft.build.utilities.resources\2.0.0.0_it_b03f5f7f11d50a3a\Microsoft.Build.Utilities.Resources.dll
+ 2008-03-29 19:43:26 73,728 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2008-03-29 19:50:55 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Jscript.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.JScript.Resources.dll
+ 2008-03-29 19:43:25 745,472 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2008-03-29 19:50:20 5,120 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Transactions.Bridge.Dtc.resources\3.0.0.0_it_b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.Resources.dll
+ 2008-03-29 19:50:20 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Transactions.Bridge.resources\3.0.0.0_it_b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Resources.dll
+ 2008-03-29 19:45:47 352,256 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2008-03-29 19:51:03 9,216 ----a-w C:\WINDOWS\assembly\GAC_MSIL\microsoft.visualbasic.compatibility.data.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.resources.dll
+ 2008-03-29 19:43:38 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2008-03-29 19:51:03 9,216 ----a-w C:\WINDOWS\assembly\GAC_MSIL\microsoft.visualbasic.compatibility.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.resources.dll
+ 2008-03-29 19:43:38 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2008-03-29 19:51:02 61,440 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll
+ 2008-03-29 19:43:21 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2008-03-29 19:43:38 667,648 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2008-03-29 19:43:38 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2008-03-29 19:43:23 12,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2008-03-29 19:43:23 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2008-03-29 19:43:23 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2008-03-29 19:51:00 303,104 ----a-w C:\WINDOWS\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.Resources.dll
+ 2008-03-29 19:50:15 53,248 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationBuildTasks.resources\3.0.0.0_it_31bf3856ad364e35\PresentationBuildTasks.resources.dll
+ 2008-03-29 19:46:15 593,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
+ 2008-03-29 19:46:15 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
+ 2008-03-29 19:50:15 106,496 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationCore.resources\3.0.0.0_it_31bf3856ad364e35\PresentationCore.resources.dll
+ 2008-03-29 19:46:17 184,320 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2008-03-29 19:46:17 126,976 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2008-03-29 19:46:17 376,832 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2008-03-29 19:50:15 245,760 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_it_31bf3856ad364e35\PresentationFramework.resources.dll
+ 2008-03-29 19:46:17 151,552 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2008-03-29 19:46:16 4,972,544 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2008-03-29 19:50:15 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationUI.resources\3.0.0.0_it_31bf3856ad364e35\PresentationUI.resources.dll
+ 2008-03-29 19:46:16 897,024 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2008-03-29 19:50:15 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\ReachFramework.resources\3.0.0.0_it_31bf3856ad364e35\ReachFramework.resources.dll
+ 2008-03-29 19:46:17 528,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2008-03-29 19:50:20 5,120 ----a-w C:\WINDOWS\assembly\GAC_MSIL\SMDiagnostics.resources\3.0.0.0_it_b77a5c561934e089\SMDiagnostics.resources.dll
+ 2008-03-29 19:45:47 94,208 ----a-w C:\WINDOWS\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2008-03-29 19:51:02 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl.resources\2.0.0.0_it_b03f5f7f11d50a3a\sysglobl.resources.dll
+ 2008-03-29 19:43:35 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2008-03-29 19:51:00 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Configuration.Install.Resources.dll
+ 2008-03-29 19:43:27 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2008-03-29 19:51:02 49,152 ----a-w C:\WINDOWS\assembly\GAC_MSIL\SYSTEM.CONFIGURATION.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Configuration.resources.dll
+ 2008-03-29 19:43:35 389,120 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2008-03-29 19:51:00 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.OracleClient.resources\2.0.0.0_it_b77a5c561934e089\System.Data.OracleClient.resources.dll
+ 2008-03-29 19:50:58 327,680 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.resources\2.0.0.0_it_b77a5c561934e089\System.Data.Resources.dll
+ 2008-03-29 19:51:00 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml.resources\2.0.0.0_it_b77a5c561934e089\system.data.sqlxml.resources.dll
+ 2008-03-29 19:43:33 716,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2008-03-29 19:50:55 380,928 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Deployment.resources.dll
+ 2008-03-29 19:43:24 884,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2008-03-29 19:50:58 540,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Design.Resources.dll
+ 2008-03-29 19:43:31 5,050,368 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2008-03-29 19:50:56 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.DirectoryServices.Protocols.resources.dll
+ 2008-03-29 19:43:28 188,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2008-03-29 19:50:56 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.DirectoryServices.Resources.dll
+ 2008-03-29 19:43:27 397,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2008-03-29 19:51:01 6,144 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Drawing.Design.Resources.dll
+ 2008-03-29 19:43:28 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2008-03-29 19:50:58 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2008-03-29 19:43:36 700,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2008-03-29 19:50:55 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.EnterpriseServices.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.EnterpriseServices.Resources.dll
+ 2008-03-29 19:50:20 61,440 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel.resources\3.0.0.0_it_b77a5c561934e089\System.IdentityModel.Resources.dll
+ 2008-03-29 19:50:20 53,248 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel.Selectors.resources\3.0.0.0_it_b77a5c561934e089\System.IdentityModel.Selectors.Resources.dll
+ 2008-03-29 19:45:48 126,976 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2008-03-29 19:45:48 401,408 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2008-03-29 19:50:20 11,264 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.IO.Log.resources\3.0.0.0_it_b03f5f7f11d50a3a\System.IO.Log.Resources.dll
+ 2008-03-29 19:45:48 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2008-03-29 19:51:01 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\system.management.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Management.Resources.dll
+ 2008-03-29 19:43:34 368,640 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2008-03-29 19:50:59 61,440 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Messaging.Resources.dll
+ 2008-03-29 19:43:36 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2008-03-29 19:50:15 16,896 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Printing.resources\3.0.0.0_it_31bf3856ad364e35\System.Printing.resources.dll
+ 2008-03-29 19:50:59 204,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\system.Resources.dll
+ 2008-03-29 19:51:01 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_it_b77a5c561934e089\System.Runtime.Remoting.Resources.dll
+ 2008-03-29 19:43:34 299,008 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2008-03-29 19:51:01 11,776 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.Resources.dll
+ 2008-03-29 19:43:34 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-03-29 19:50:20 86,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.resources\3.0.0.0_it_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
+ 2008-03-29 19:45:48 884,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2008-03-29 19:50:55 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Security.Resources.dll
+ 2008-03-29 19:43:27 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2008-03-29 19:50:20 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.Install.resources\3.0.0.0_it_b77a5c561934e089\System.ServiceModel.Install.Resources.dll
+ 2008-03-29 19:45:51 159,744 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
+ 2008-03-29 19:50:21 438,272 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.resources\3.0.0.0_it_b77a5c561934e089\System.ServiceModel.Resources.dll
+ 2008-03-29 19:45:51 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2008-03-29 19:45:49 5,623,808 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2008-03-29 19:50:56 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.ServiceProcess.Resources.dll
+ 2008-03-29 19:43:28 114,688 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2008-03-29 19:50:15 61,440 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Speech.resources\3.0.0.0_it_31bf3856ad364e35\System.Speech.resources.dll
+ 2008-03-29 19:46:17 688,128 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2008-03-29 19:51:02 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Transactions.resources\2.0.0.0_it_b77a5c561934e089\System.Transactions.resources.dll
+ 2008-03-29 19:51:02 77,824 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Web.Mobile.resources.dll
+ 2008-03-29 19:43:37 835,584 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2008-03-29 19:43:29 86,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2008-03-29 19:50:57 598,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Web.Resources.dll
+ 2008-03-29 19:50:57 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services.resources\2.0.0.0_it_b03f5f7f11d50a3a\System.Web.Services.Resources.dll
+ 2008-03-29 19:43:29 823,296 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2008-03-29 19:50:57 425,984 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_it_b77a5c561934e089\System.Windows.Forms.Resources.dll
+ 2008-03-29 19:43:30 5,316,608 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2008-03-29 19:50:24 187,208 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.Activities.resources\3.0.0.0_it_31bf3856ad364e35\System.Workflow.Activities.resources.dll
+ 2008-03-29 19:49:21 1,108,784 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2008-03-29 19:50:24 318,288 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.ComponentModel.resources\3.0.0.0_it_31bf3856ad364e35\System.Workflow.ComponentModel.resources.dll
+ 2008-03-29 19:49:21 1,641,272 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2008-03-29 19:50:24 43,840 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.Runtime.resources\3.0.0.0_it_31bf3856ad364e35\System.Workflow.Runtime.resources.dll
+ 2008-03-29 19:49:21 588,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
+ 2008-03-29 19:50:57 163,840 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.XML.resources\2.0.0.0_it_b77a5c561934e089\System.xml.Resources.dll
+ 2008-03-29 19:43:30 2,035,712 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2008-03-29 19:43:35 3,018,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2008-03-29 19:50:15 9,728 ----a-w C:\WINDOWS\assembly\GAC_MSIL\UIAutomationClient.resources\3.0.0.0_it_31bf3856ad364e35\UIAutomationClient.resources.dll
+ 2008-03-29 19:46:16 163,840 ----a-w C:\WINDOWS\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2008-03-29 19:50:15 10,240 ----a-w C:\WINDOWS\assembly\GAC_MSIL\UIAutomationClientsideProviders.resources\3.0.0.0_it_31bf3856ad364e35\UIAutomationClientsideProviders.resources.dll
+ 2008-03-29 19:46:16 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2008-03-29 19:50:15 4,096 ----a-w C:\WINDOWS\assembly\GAC_MSIL\UIAutomationProvider.resources\3.0.0.0_it_31bf3856ad364e35\UIAutomationProvider.resources.dll
+ 2008-03-29 19:46:16 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2008-03-29 19:50:15 7,680 ----a-w C:\WINDOWS\assembly\GAC_MSIL\UIAutomationTypes.resources\3.0.0.0_it_31bf3856ad364e35\UIAutomationTypes.resources.dll
+ 2008-03-29 19:46:16 86,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2008-03-29 19:50:15 86,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\WindowsBase.resources\3.0.0.0_it_31bf3856ad364e35\WindowsBase.resources.dll
+ 2008-03-29 19:46:15 1,167,360 ----a-w C:\WINDOWS\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2008-03-29 19:50:16 4,608 ----a-w C:\WINDOWS\assembly\GAC_MSIL\WindowsFormsIntegration.resources\3.0.0.0_it_31bf3856ad364e35\WindowsFormsIntegration.resources.dll
+ 2008-03-29 19:46:17 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2008-03-29 19:47:06 26,624 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\c8dae7e972c7494d9a02e7177ee62fa4\Accessibility.ni.dll
+ 2008-03-29 20:14:59 860,160 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\e7cd5ae320efc44fac1fcdca9f5d7283\AspNetMMCExt.ni.dll
+ 2008-03-29 20:14:29 434,176 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\6e7d042486eece49be043eedc4a1bf61\ComSvcConfig.ni.exe
+ 2008-03-29 20:15:00 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\8d654cc11ef0cc46b7f7317b1bfe2075\CustomMarshalers.ni.dll
+ 2008-03-29 20:14:59 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\f233bd2273bc514d95fdeab625f2729a\dfsvc.ni.exe
+ 2008-03-29 20:15:00 880,640 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\c3f03a1e5d60cb43ae34733c21d77c71\Microsoft.Build.Engine.ni.dll
+ 2008-03-29 19:49:33 81,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\6a77839146680f4f9936967e03c75f0b\Microsoft.Build.Framework.ni.dll
+ 2008-03-29 19:49:35 1,691,648 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\000a95a7d177e549bec8d57763d67966\Microsoft.Build.Tasks.ni.dll
+ 2008-03-29 19:49:33 163,840 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\a7c392e3d017bf40afc3e1057844f49f\Microsoft.Build.Utilities.ni.dll
+ 2008-03-29 20:14:31 1,069,056 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\352ac2c649121649b480a19bdc54f35f\Microsoft.Transactions.Bridge.ni.dll
+ 2008-03-29 20:14:32 405,504 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\eee3a2488857e8429e88a84f29c6eddd\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2008-03-29 20:15:02 1,724,416 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\954a68c85c92384b9e5e0ed051527efd\Microsoft.VisualBasic.ni.dll
+ 2008-03-29 19:46:43 17,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\389d24eec8c5f14d83758f2f67e70553\Microsoft.VisualC.ni.dll
+ 2008-03-29 19:44:05 11,415,552 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7602ff681abe134b80d693a1e95054f1\mscorlib.ni.dll
+ 2008-03-29 20:15:04 1,576,960 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\2089548c83119540adaa612c8f587b49\PresentationBuildTasks.ni.dll
+ 2008-03-29 19:47:51 40,448 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5f3ab10b8a33c64596a50631beb7286c\PresentationCFFRasterizer.ni.dll
+ 2008-03-29 19:47:50 12,038,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\ff3591b2ece05d488390693eb5815958\PresentationCore.ni.dll
+ 2008-03-29 19:49:11 49,152 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\b678a1df52b138428e405bcf7572c771\PresentationFontCache.ni.exe
+ 2008-03-29 19:49:10 393,216 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1d83b61ad34146408ec11de66533e2ae\PresentationFramework.Aero.ni.dll
+ 2008-03-29 19:48:51 14,643,200 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\339a7729a978e743b75a1278958e9727\PresentationFramework.ni.dll
+ 2008-03-29 19:49:09 266,240 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\37c474d994667b4e8d0fe4aee729f226\PresentationFramework.Royale.ni.dll
+ 2008-03-29 19:49:08 548,864 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\88890d27033be749b416282c9a55336c\PresentationFramework.Luna.ni.dll
+ 2008-03-29 19:49:07 204,800 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8a64ec2cf5f249479e82db8c740eca22\PresentationFramework.Classic.ni.dll
+ 2008-03-29 19:48:57 1,757,184 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationUI\132f9a017daca14e81f4de961e64e8c2\PresentationUI.ni.dll
+ 2008-03-29 19:49:03 2,338,816 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\ReachFramework\bccdea5431a5ae479c5d112bd9797a15\ReachFramework.ni.dll
+ 2008-03-29 20:14:32 139,264 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\7e7dfc2ba74fbe429c57ca0386698340\ServiceModelReg.ni.exe
+ 2008-03-29 20:14:33 286,720 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\6c569cb52c2cce4390fab3fc22deeb96\SMDiagnostics.ni.dll
+ 2008-03-29 20:14:34 323,584 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMSvcHost\d44b4eca6006f8419a6a02ea7cf5816d\SMSvcHost.ni.exe
+ 2008-03-29 20:15:07 262,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\sysglobl\ad9856a7ce53f44a85ab84e2888c7893\sysglobl.ni.dll
+ 2008-03-29 19:47:13 167,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\33b165eb8ffa1341b94d172d603db442\System.Configuration.Install.ni.dll
+ 2008-03-29 19:46:38 962,560 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\a22584017a5baa4891b143851a57d6c6\System.Configuration.ni.dll
+ 2008-03-29 19:47:11 1,183,744 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\f80193105c35f34faf22c55134e8f1c2\System.Data.OracleClient.ni.dll
+ 2008-03-29 19:46:42 2,703,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\aeb011e42f588d4a8286c9204364922d\System.Data.SqlXml.ni.dll
+ 2008-03-29 19:44:51 6,688,768 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\d2868033fb05174696e8cce19c806660\System.Data.ni.dll
+ 2008-03-29 19:47:09 1,712,128 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\04561223adf3404e9334d6cffdbe9e39\System.Deployment.ni.dll
+ 2008-03-29 19:45:06 10,723,328 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\66f19daaf7438a4a8d34d08a8e477385\System.Design.ni.dll
+ 2008-03-29 19:46:47 1,220,608 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\5231f7b12e52134f93efe25312f27241\System.DirectoryServices.ni.dll
+ 2008-03-29 19:47:12 512,000 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\eed0a2f9946226428a4304416ce3e373\System.DirectoryServices.Protocols.ni.dll
+ 2008-03-29 19:44:21 229,376 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\4b974de73d6155468285c88a0744652b\System.Drawing.Design.ni.dll
+ 2008-03-29 19:44:24 1,626,112 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\ebb6db7069b6614c933482c763518e67\System.Drawing.ni.dll
+ 2008-03-29 19:46:46 659,456 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\2521f3b7badd674c8cf02193f76e2f60\System.EnterpriseServices.ni.dll
+ 2008-03-29 19:46:46 294,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\2521f3b7badd674c8cf02193f76e2f60\System.EnterpriseServices.Wrapper.dll
+ 2008-03-29 20:14:00 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\cd146aa2f638224083dbac8d3621c032\System.IdentityModel.Selectors.ni.dll
+ 2008-03-29 20:13:59 995,328 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\b2803af511dc1c45a24a46a6fe9bc728\System.IdentityModel.ni.dll
+ 2008-03-29 20:14:01 425,984 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IO.Log\29004266a39812428faba0a30f26d27f\System.IO.Log.ni.dll
+ 2008-03-29 19:49:40 655,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Messaging\cba5b05c7e3d864aae730c2c9606d462\System.Messaging.ni.dll
+ 2008-03-29 19:49:05 1,052,672 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Printing\48c53ed1779cdb4eb8040aadecb22666\System.Printing.ni.dll
+ 2008-03-29 19:46:49 815,104 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\59a779b35e210144be81e817ea96a536\System.Runtime.Remoting.ni.dll
+ 2008-03-29 20:14:05 2,371,584 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\276e36d1880c7046bcb84921452cba1c\System.Runtime.Serialization.ni.dll
+ 2008-03-29 19:47:06 339,968 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\b4b2825e69cb004ab6f6136cff558c66\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2008-03-29 19:46:43 729,088 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\028b76e04c4eb14d84596105f418ecaf\System.Security.ni.dll
+ 2008-03-29 20:14:28 17,506,304 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\c3a91a81ed76434b8d293cfd1c2dea1a\System.ServiceModel.ni.dll
+ 2008-03-29 19:47:12 233,472 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\fc58a8b5a448884b80e14b52c1ded60c\System.ServiceProcess.ni.dll
+ 2008-03-29 20:15:06 2,043,904 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Speech\44cc1f538c52b948a65db454074a3205\System.Speech.ni.dll
+ 2008-03-29 19:46:44 684,032 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\5713a85a014bc040bfe851eb4bdeb25a\System.Transactions.ni.dll
+ 2008-03-29 20:15:10 2,310,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\e19df3135105f24f870b343f9b080ad5\System.Web.Mobile.ni.dll
+ 2008-03-29 19:47:11 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\53065ee346f1714ba972966439032781\System.Web.RegularExpressions.ni.dll
+ 2008-03-29 19:47:05 1,945,600 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\851b0777a108f14590ec3897676c114d\System.Web.Services.ni.dll
+ 2008-03-29 19:47:02 11,808,768 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\90d0255b94a61549ac3d21101b69ad52\System.Web.ni.dll
+ 2008-03-29 19:44:37 13,107,200 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fb6262936307364290411eadb8dc78a9\System.Windows.Forms.ni.dll
+ 2008-03-29 19:49:27 2,965,504 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\5d52cfb1ef992a47ab034501ed50c507\System.Workflow.Activities.ni.dll
+ 2008-03-29 19:49:32 4,599,808 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\e50ac728c665a040a212ee3b8d8b9421\System.Workflow.ComponentModel.ni.dll
+ 2008-03-29 19:49:38 2,064,384 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\3b64a33a95fc844c9be3b53e02b67ad1\System.Workflow.Runtime.ni.dll
+ 2008-03-29 19:44:43 5,640,192 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\906e698bedd0954ab0cd89ebcdd01b0d\System.Xml.ni.dll
+ 2008-03-29 19:44:19 8,093,696 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\3dd47b59bd65374c8360a36ffdc27d13\System.ni.dll
+ 2008-03-29 20:15:12 483,328 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\2227efb94a21a4429235c59e5361d594\UIAutomationClient.ni.dll
+ 2008-03-29 20:15:13 1,122,304 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\bfb96d27d505464293aaaef50a4cc451\UIAutomationClientsideProviders.ni.dll
+ 2008-03-29 19:47:50 51,200 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\6f32b1b6b7453a4ea7a5dd9832180cf7\UIAutomationProvider.ni.dll
+ 2008-03-29 19:47:51 196,608 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\17ac7ef2442e8b419776d008ff11416f\UIAutomationTypes.ni.dll
+ 2008-03-29 19:46:36 3,289,088 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\d735194309a9244190763c4cfa00166c\WindowsBase.ni.dll
+ 2008-03-29 20:15:15 245,760 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\1263d58df4f1f14d8ce0390b17130806\WindowsFormsIntegration.ni.dll
+ 2008-03-29 20:14:34 380,928 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WsatConfig\9faa4cae5ab94849b54f9254e949c748\WsatConfig.ni.exe
+ 2008-03-29 19:55:13 59,904 ----a-r C:\WINDOWS\Installer\{0AF0F8DC-7C92-4B7C-A376-127B9AD061D2}\IconA3AFE979.exe
- 2003-02-20 17:09:46 57,344 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2005-09-23 06:28:52 72,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe
- 2003-02-20 17:09:32 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll
+ 2005-09-23 06:28:52 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll
+ 2005-09-23 06:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2005-09-23 06:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2005-09-23 06:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll
- 2003-02-20 16:43:50 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2005-09-23 06:28:52 86,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2005-09-23 06:28:36 18,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
+ 2005-09-23 06:28:42 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
+ 2005-09-23 06:28:44 4,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
+ 2005-09-23 06:29:04 183,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
+ 2005-09-23 06:28:28 208,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
+ 2006-01-07 07:53:28 22,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1040\alinkui.dll
+ 2006-01-07 07:53:30 161,792 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1040\cscompui.dll
+ 2006-01-07 07:53:30 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1040\CvtResUI.dll
+ 2006-01-07 07:53:36 212,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1040\vbc7ui.dll
+ 2006-01-07 07:53:24 241,664 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1040\Vsavb7rtUI.dll
+ 2005-09-23 06:28:56 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
+ 2005-09-23 06:28:58 138,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
+ 2005-09-23 06:28:36 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll
+ 2005-09-23 06:28:58 55,488 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
+ 2005-09-23 06:28:32 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
+ 2005-09-23 06:28:32 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
+ 2005-09-23 06:28:32 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
+ 2005-09-23 06:28:32 23,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
+ 2005-09-23 06:28:32 70,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
+ 2005-09-23 06:28:32 13,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
+ 2005-09-23 06:28:32 26,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
+ 2005-09-23 06:28:32 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
+ 2005-09-23 06:28:32 29,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
+ 2005-09-23 06:28:32 29,888 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2005-09-23 06:28:32 503,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
+ 2005-09-23 06:28:56 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
+ 2005-09-23 06:28:56 88,576 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
+ 2005-09-23 06:28:42 76,984 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe
+ 2005-09-23 06:28:42 1,144,832 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
+ 2005-09-23 06:28:42 13,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
+ 2005-09-23 06:28:58 17,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll
+ 2005-09-23 06:28:56 68,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
+ 2005-09-23 06:28:44 31,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
+ 2005-09-23 06:28:38 52,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
+ 2005-09-23 06:28:38 4,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
+ 2005-09-23 06:29:12 547,840 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
+ 2005-09-23 06:28:56 788,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
+ 2005-09-23 06:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll
+ 2006-01-07 07:53:38 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\GAC\it\Microsoft.VisualBasic.Compatibility.Data.resources.dll
+ 2006-01-07 07:53:38 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\GAC\it\Microsoft.VisualBasic.Compatibility.resources.dll
+ 2005-09-23 06:28:56 9,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
+ 2005-09-23 06:28:56 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
+ 2005-09-23 06:28:56 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
+ 2005-09-23 06:28:56 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
+ 2005-09-23 06:28:56 224,952 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
+ 2005-09-23 06:28:56 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
+ 2005-09-23 06:28:56 55,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
+ 2005-09-23 06:28:56 72,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
+ 2006-01-07 07:53:26 8,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\aspnet_compiler.resources.dll
+ 2006-01-07 07:53:26 82,432 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\aspnet_rc.dll
+ 2006-01-07 07:53:26 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\aspnet_regbrowsers.resources.dll
+ 2006-01-07 07:53:26 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\aspnet_regsql.resources.dll
+ 2006-01-07 07:53:26 315,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\aspnetmmcext.resources.dll
+ 2006-01-07 07:53:34 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\caspol.resources.dll
+ 2006-01-07 07:53:34 4,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\InstallUtil.resources.dll
+ 2006-01-07 07:53:32 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\JSC.Resources.dll
+ 2006-01-07 07:53:34 53,248 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\Microsoft.Build.Engine.resources.dll
+ 2006-01-07 07:53:34 139,264 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\Microsoft.Build.Tasks.resources.dll
+ 2006-01-07 07:53:34 10,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\Microsoft.Build.Utilities.Resources.dll
+ 2006-01-07 07:53:32 45,056 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\Microsoft.JScript.Resources.dll
+ 2006-01-07 07:53:36 61,440 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\Microsoft.VisualBasic.resources.dll
+ 2006-01-07 07:53:34 12,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\MSBuild.resources.dll
+ 2006-01-07 07:53:34 303,104 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\mscorlib.Resources.dll
+ 2006-01-07 07:53:34 389,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
+ 2006-01-07 07:53:34 11,264 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\Regasm.resources.dll
+ 2006-01-07 07:53:34 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\ShFusRes.dll
+ 2006-01-07 07:53:34 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\sysglobl.resources.dll
+ 2006-01-07 07:53:34 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Configuration.Install.Resources.dll
+ 2006-01-07 07:53:34 49,152 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Configuration.resources.dll
+ 2006-01-07 07:53:34 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Data.OracleClient.resources.dll
+ 2006-01-07 07:53:34 327,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Data.Resources.dll
+ 2006-01-07 07:53:34 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\system.data.sqlxml.resources.dll
+ 2006-01-07 07:53:28 380,928 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Deployment.resources.dll
+ 2006-01-07 07:53:34 540,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Design.Resources.dll
+ 2006-01-07 07:53:34 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.DirectoryServices.Protocols.resources.dll
+ 2006-01-07 07:53:34 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.DirectoryServices.Resources.dll
+ 2006-01-07 07:53:34 6,144 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Drawing.Design.Resources.dll
+ 2006-01-07 07:53:34 24,576 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Drawing.Resources.dll
+ 2006-01-07 07:53:34 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.EnterpriseServices.Resources.dll
+ 2006-01-07 07:53:34 13,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Management.Resources.dll
+ 2006-01-07 07:53:34 61,440 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Messaging.Resources.dll
+ 2006-01-07 07:53:34 204,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\system.Resources.dll
+ 2006-01-07 07:53:34 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Runtime.Remoting.Resources.dll
+ 2006-01-07 07:53:34 11,776 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Runtime.Serialization.Formatters.Soap.Resources.dll
+ 2006-01-07 07:53:34 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Security.Resources.dll
+ 2006-01-07 07:53:34 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.ServiceProcess.Resources.dll
+ 2006-01-07 07:53:34 16,384 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Transactions.resources.dll
+ 2006-01-07 07:53:34 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Web.Mobile.resources.dll
+ 2006-01-07 07:53:34 598,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Web.Resources.dll
+ 2006-01-07 07:53:34 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Web.Services.Resources.dll
+ 2006-01-07 07:53:34 425,984 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.Windows.Forms.Resources.dll
+ 2006-01-07 07:53:34 163,840 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\it\System.xml.Resources.dll
+ 2005-09-23 06:28:48 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe
+ 2008-03-29 19:50:41 609,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - ITA\install.exe
+ 2008-03-29 19:50:41 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - ITA\install.res.1040.dll
+ 2008-03-29 19:50:41 245,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - ITA\unicows.dll
+ 2008-03-29 19:42:27 609,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
+ 2008-03-29 19:42:27 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1025.dll
+ 2008-03-29 19:42:27 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1028.dll
+ 2008-03-29 19:42:27 82,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1029.dll
+ 2008-03-29 19:42:27 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1030.dll
+ 2008-03-29 19:42:27 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1031.dll
+ 2008-03-29 19:42:27 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1032.dll
+ 2008-03-29 19:42:27 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1033.dll
+ 2008-03-29 19:42:27 81,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1035.dll
+ 2008-03-29 19:42:27 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1036.dll
+ 2008-03-29 19:42:27 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1037.dll
+ 2008-03-29 19:42:27 83,968 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1038.dll
+ 2008-03-29 19:42:27 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1040.dll
+ 2008-03-29 19:42:27 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1041.dll
+ 2008-03-29 19:42:27 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1042.dll
+ 2008-03-29 19:42:27 83,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1043.dll
+ 2008-03-29 19:42:27 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1044.dll
+ 2008-03-29 19:42:27 83,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1045.dll
+ 2008-03-29 19:42:27 82,432 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1046.dll
+ 2008-03-29 19:42:27 82,432 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1049.dll
+ 2008-03-29 19:42:27 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1053.dll
+ 2008-03-29 19:42:27 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1055.dll
+ 2008-03-29 19:42:27 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2052.dll
+ 2008-03-29 19:42:27 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2070.dll
+ 2008-03-29 19:42:27 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3076.dll
+ 2008-03-29 19:42:27 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3082.dll
+ 2008-03-29 19:42:29 245,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\unicows.dll
+ 2005-09-23 06:28:48 413,696 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
+ 2005-09-23 06:28:48 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
+ 2005-09-23 06:28:48 647,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
+ 2005-09-23 06:28:48 73,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
+ 2005-09-23 06:28:48 745,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
+ 2005-09-23 06:29:10 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2005-09-23 06:29:10 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
+ 2005-09-23 06:29:08 667,648 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
+ 2005-09-23 06:28:30 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
+ 2005-09-23 06:29:10 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
+ 2005-09-23 06:28:30 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
+ 2005-09-23 06:28:30 12,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2005-09-23 06:28:30 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
+ 2005-09-23 06:28:32 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
+ 2005-09-23 06:28:48 69,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
+ 2005-09-23 06:28:56 800,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2005-09-23 06:28:56 73,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
+ 2005-09-23 06:28:56 288,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
+ 2005-09-23 06:28:56 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
+ 2005-09-23 06:28:56 326,144 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2005-09-23 06:28:56 81,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
+ 2005-09-23 06:28:56 4,308,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2005-09-23 06:28:56 102,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
+ 2005-09-23 06:29:00 330,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
+ 2005-09-23 06:28:56 67,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
+ 2005-09-23 06:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
+ 2005-09-23 06:28:56 226,816 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
+ 2005-09-23 06:28:56 66,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
+ 2005-09-23 06:28:56 10,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
+ 2005-09-23 06:28:50 5,615,616 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2005-09-23 06:29:00 22,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
+ 2006-01-07 07:53:34 22,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\0410\mscorsecr.dll
+ 2005-09-23 06:28:56 96,440 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe
+ 2005-09-23 06:28:56 14,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll
+ 2005-09-23 06:28:56 78,336 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
+ 2005-09-23 06:28:50 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll
+ 2005-09-23 06:28:56 53,248 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
+ 2005-09-23 06:28:56 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
+ 2005-09-23 06:29:02 59,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
+ 2005-09-23 06:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2005-09-23 06:28:56 107,520 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
+ 2005-09-23 06:29:00 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
+ 2005-09-23 06:28:56 377,344 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2005-09-23 06:28:56 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
+ 2005-09-23 06:28:58 389,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
+ 2005-09-23 06:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
+ 2005-09-23 06:28:56 2,878,976 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
+ 2005-09-23 06:28:56 482,304 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
+ 2005-09-23 06:28:56 716,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
+ 2005-09-23 06:28:38 884,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
+ 2005-09-23 06:28:56 5,050,368 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2005-09-23 06:28:56 397,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
+ 2005-09-23 06:28:56 188,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
+ 2005-09-23 06:28:56 3,018,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2005-09-23 06:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
+ 2005-09-23 06:28:56 700,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
+ 2005-09-23 06:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
+ 2005-09-23 06:28:56 47,616 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
+ 2005-09-23 06:28:56 114,176 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
+ 2005-09-23 06:28:56 368,640 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
+ 2005-09-23 06:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
+ 2005-09-23 06:28:56 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
+ 2005-09-23 06:28:56 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
+ 2005-09-23 06:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2005-09-23 06:28:56 114,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
+ 2005-09-23 06:28:56 260,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
+ 2005-09-23 06:28:56 5,025,792 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2005-09-23 06:28:56 835,584 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
+ 2005-09-23 06:28:56 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
+ 2005-09-23 06:28:56 823,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
+ 2005-09-23 06:28:56 5,316,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2005-09-23 06:28:56 2,035,712 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
+ 2005-09-23 06:28:56 71,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
+ 2005-09-23 06:29:06 1,140,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe
+ 2005-09-23 06:28:30 1,306,624 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
+ 2005-09-23 06:28:32 298,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2005-09-23 06:28:56 28,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
+ 2006-10-31 09:15:08 14,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\baseline.dat
+ 2006-10-20 16:57:16 99,600 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\DeleteTemp.exe
+ 2006-10-20 14:17:16 220,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\dlmgr.dll
+ 2006-10-20 14:19:18 1,054,720 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\gencomp.dll
+ 2006-10-20 14:16:24 163,328 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\HtmlLite.dll
+ 2006-10-20 16:57:16 194,320 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\RebootStub.exe
+ 2006-10-20 16:57:16 167,176 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\runmsi.exe
+ 2006-10-20 16:57:16 365,320 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\setup.exe
+ 2006-10-20 16:45:38 88,064 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\setupres.1040.dll
+ 2006-10-20 14:17:20 80,384 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\setupres.dll
+ 2006-10-20 14:17:26 1,621,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\SITSetup.dll
+ 2006-10-20 14:18:26 1,139,712 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\vs_setup.dll
+ 2006-10-20 14:19:44 590,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\vs70uimgr.dll
+ 2006-10-20 14:22:20 541,184 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\vsbasereqs.dll
+ 2006-10-20 14:19:48 816,128 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\vsscenario.dll
+ 2006-10-20 16:45:38 101,376 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\WapRes.1040.dll
+ 2006-10-20 14:19:50 98,816 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\WapRes.dll
+ 2006-10-20 14:21:22 1,103,872 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Italian Language Pack\WapUI.dll
+ 2006-10-30 03:06:28 189,828 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\baseline.dat
+ 2006-10-30 02:25:56 99,600 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\DeleteTemp.exe
+ 2006-10-29 22:15:06 220,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\dlmgr.dll
+ 2006-10-29 22:17:56 1,054,720 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\gencomp.dll
+ 2006-10-29 22:14:26 163,328 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\HtmlLite.dll
+ 2006-10-30 02:25:54 194,320 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\RebootStub.exe
+ 2006-10-30 02:25:56 167,176 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\runmsi.exe
+ 2006-10-30 02:25:56 365,320 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
+ 2006-10-30 02:17:12 80,384 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1025.dll
+ 2006-10-30 02:17:30 80,384 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1028.dll
+ 2006-10-30 02:17:36 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1029.dll
+ 2006-10-30 02:17:44 87,040 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1030.dll
+ 2006-10-30 02:17:50 89,600 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1031.dll
+ 2006-10-30 02:17:56 94,208 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1032.dll
+ 2006-10-30 02:18:10 82,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1035.dll
+ 2006-10-30 02:18:16 91,648 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1036.dll
+ 2006-10-30 02:18:22 80,384 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1037.dll
+ 2006-10-30 02:18:30 89,600 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1038.dll
+ 2006-10-30 02:18:36 88,064 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1040.dll
+ 2006-10-30 02:18:42 80,384 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1041.dll
+ 2006-10-30 02:18:48 80,384 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1042.dll
+ 2006-10-30 02:18:56 87,0 |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 31 Mar 2008 09:13 Oggetto: |
|
|
Che nervi... si sta moltiplicando...
Altro giro. Crea un file di testo con le seguenti istruzioni:
Codice: | RenV::
C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
C:\Programmi\Sony\SonicStage\SsAAD .exe
C:\Programmi\TechSmith\Jing\Jing .exe
C:\WINDOWS\ehome\ehtray .exe
C:\WINDOWS\system32\ctfmon .exe |
Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:
Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro.
Per sicurezza, riavvia il pc e ripeti l'operazione.
Posta il log aggiornato di combofix.
Dimenticavo: visto che il log di combofix comincia ad assumere dimensioni notevoli, caricalo su FreeFileHosting come indicato qui. |
|
Top |
|
 |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 31 Mar 2008 22:10 Oggetto: Internet Connection...Di Nuovo... |
|
|
Il virus si sta moltiplicando...
Credi che riusciremo ad eliminarlo
Ho eseguito le tue istruzioni, e il file di testo di combofix si trova su free file hosting, qui
log_31_marzo_2008.txt
P.S.
Ho anche scaricato jing, per fare la screencast del desktop, ma non sono sicuro di averne compreso il funzionamento : non ho capito come posso inviarti l'immagine dopo averla effettuata.
Se ci riesco, ti invio anche quella.
Ciao  |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 31 Mar 2008 22:37 Oggetto: |
|
|
Per inviare le immagini, devi caricarle su ImageShack e poi postare qui il link che ti viene assegnato.
Ah! Forse ho beccato il "replicante".
Crea un file di testo con le seguenti istruzioni:
Codice: | File::
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
RenV::
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
C:\Programmi\Sony\SonicStage\SsAAD .exe
C:\Programmi\TechSmith\Jing\Jing .exe
C:\WINDOWS\ehome\ehtray .exe
C:\WINDOWS\system32\ctfmon .exe |
Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:
Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro.
Posta il log aggiornato di combofix. |
|
Top |
|
 |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 01 Apr 2008 22:03 Oggetto: Internet Connection...Di Nuovo... |
|
|
Ciao
ti posto l'ultimo log di combofix, come da tue istruzioni:
ComboFix 08-03-29.1 - LORENZO 2008-04-01 20.59.08.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.470 [GMT 2:00]
Eseguito da: C:\Documents and Settings\LORENZO\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\LORENZO\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
.
((((((((((((((((((((((((( Files Creati Da 2008-03-01 al 2008-04-01 )))))))))))))))))))))))))))))))))))
.
2008-03-31 21:43 . 2008-03-18 21:28 14,348 --a------ C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
2008-03-30 00:14 . 2008-03-30 21:43 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-29 21:55 . 2008-03-29 21:55 <DIR> d-------- C:\Programmi\TechSmith
2008-03-29 21:50 . 2008-03-29 21:50 <DIR> d-------- C:\WINDOWS\system32\it-IT
2008-03-29 21:49 . 2008-03-29 21:49 <DIR> d-------- C:\Programmi\MSBuild
2008-03-29 21:46 . 2008-03-29 21:50 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-03-29 21:45 . 2008-03-29 21:45 <DIR> d-------- C:\Programmi\Reference Assemblies
2008-03-29 21:45 . 2006-06-29 14:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-03-29 21:42 . 2008-03-29 21:50 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-03-29 18:06 . 2008-03-29 18:07 2,945,816 --a------ C:\Programmi\Net Framework 3.0 dotnetfx3setup.exe
2008-03-29 16:08 . 2008-03-29 16:08 5,549,888 --a------ C:\Programmi\jing_setup.exe
2008-03-28 20:08 . 2008-03-18 21:28 14,348 --a------ C:\Documents and Settings\LORENZO\rundll32.exe bthprops.exe
2008-03-20 22:06 . 2008-03-20 22:06 16,648,248 --a------ C:\Programmi\Norman_Malware_Cleaner.exe
2008-03-19 22:24 . 2008-03-19 22:24 <DIR> d-------- C:\Programmi\CCleaner
2008-03-19 22:10 . 2008-03-19 22:10 671,968 --a------ C:\Programmi\ccsetup205_slim.exe
2008-03-19 22:05 . 2008-03-19 22:05 50,688 --a------ C:\Programmi\ATF-Cleaner.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-01 18:39 --------- d-----w C:\Programmi\File comuni\Symantec Shared
2008-03-29 21:20 13,067 ----a-w C:\Programmi\hijackthis.log
2008-03-29 15:47 --------- d-----w C:\Programmi\File comuni\Wise Installation Wizard
2008-03-21 11:40 --------- d-----w C:\Programmi\Norton Internet Security
2008-03-15 14:30 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-03-15 14:12 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-03-15 14:12 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-03-15 14:12 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-02-08 22:18 53,248 ----a-w C:\Programmi\Process.exe
2008-01-25 17:19 127,378 ----a-w C:\Programmi\avenger.zip
2008-01-24 21:17 189,718 ----a-w C:\Programmi\FindAWF.exe
2008-01-15 21:47 143,428 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2008-01-15 14:09 401,720 ----a-w C:\Programmi\HiJackThis.exe
2008-01-13 11:45 17,990,864 ----a-w C:\Programmi\AAW2007.EXE
2007-03-18 17:11 35,248 ------w C:\Documents and Settings\LORENZO\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
Codice: | <pre>
----a-w 14,348 2008-03-18 19:28:19 C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
</pre> |
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 1,019,392 2004-09-23 09:33:44 C:\Programmi\File comuni\PCSuite\DataLayer\bak\DATALA~1.EXE
----a-w 171,448 2007-01-27 15:49:00 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe
----a-w 49,152 2004-02-12 12:38:56 C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 241,664 2004-05-12 14:18:56 C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe
----a-w 36,975 2005-11-10 11:03:52 C:\Programmi\Java\jre1.5.0_06\bin\bak\jusched.exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
----a-w 148,992 2004-09-15 14:36:06 C:\Programmi\Nokia\Nokia PC Suite 6\bak\TRAYAP~1.EXE
----a-w 29,696 2006-06-22 14:11:18 C:\Programmi\Sony\AppMonUtil\bak\AppMonUtility.exe
----a-w 69,632 2005-12-27 11:58:10 C:\Programmi\Sony\VAIO Camera Utility\bak\VCUServe.exe
----a-w 151,552 2005-10-11 19:36:38 C:\Programmi\Sony\VAIO Update 2\bak\VAIOUpdt.exe
----a-w 64,512 2005-08-17 20:40:06 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-07 14:00 15360]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2008-02-09 00:12 81920]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [ ]
"Jing"="C:\Programmi\TechSmith\Jing\Jing.exe" [2008-01-28 13:48 709888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-23 01:32 7561216]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 05:04 59392]
"ccApp"="C:\Programmi\File comuni\Symantec Shared\ccApp.exe" [2007-02-22 13:11 52840]
"URLLSTCK.exe"="C:\Programmi\Norton Internet Security\UrlLstCk.exe" [2007-02-01 18:21 23168]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-09-07 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"Symantec PIF AlertEng"="C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"Acrobat Assistant 7.0"="C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 21:47 483328]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [ ]
"VAIOCameraUtility"="C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe" [ ]
"VAIO Update 2"="C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" [ ]
"HP Component Manager"="C:\Programmi\HP\hpcoretech\hpcmpmgr.exe" [ ]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe" [2008-03-18 21:28 14348]
"Norton Ghost 10.0"="C:\Programmi\Norton Ghost\Agent\GhostTray.exe" [ ]
"AppMon Utility"="C:\Programmi\Sony\AppMonUtil\AppMonUtility.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-07 14:00 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Audio Filter.lnk - C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe [2006-08-19 09:16:02 5649408]
Avvio rapido di HP Image Zone.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-29 00:06:36 53248]
Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 23:31:38 241664]
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
Photo Loader residente.lnk - C:\Programmi\Casio\Photo Loader\Plauto.exe [2006-12-29 19:03:56 229376]
VAIO Action Setup (Server).lnk - C:\Programmi\Sony\VAIO Action Setup\VAServ.exe [2006-07-17 15:21:26 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2005-05-20 17:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 17:56]
R2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;"C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 18:45]
R3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\DRIVERS\AVerM115S.sys [2006-06-14 10:22]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2006-03-06 11:39]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 11:32]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Programmi\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 19:10]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
*Newly Created Service* - COMHOST
.
Contenuto della cartella 'Scheduled Tasks'
"2008-03-21 21:55:13 C:\WINDOWS\Tasks\Norton AntiVirus - Esegui scansione completa del sistema - LORENZO.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exei/TASK:
"2007-06-16 07:00:41 C:\WINDOWS\Tasks\WebReg 20070616090041.job"
- C:\Programmi\HP\Digital Imaging\bin\hpqwrg.exe`/TaskName 20070616090041 /N
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-01 21:00:26
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-04-01 21.01.03
ComboFix-quarantined-files.txt 2008-04-01 19:00:53
ComboFix2.txt 2008-04-01 18:46:03
ComboFix3.txt 2008-03-31 19:45:42
ComboFix4.txt 2008-03-29 21:13:18
ComboFix5.txt 2008-03-28 18:10:24
11 Directory 126,803,378,176 byte disponibili
15 Directory 126,792,445,952 byte disponibili
.
2008-03-31 20:49:54 --- E O F ---
Non ci sono file nascosti, mentre nella scansione di ieri, ce n'era uno.
E' un bene o un male?
Sinceramente non riesco a capire..  |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 01 Apr 2008 22:43 Oggetto: |
|
|
Finalmente sta funzionando...
- Crea un file di testo con le seguenti istruzioni:
Codice: | RenV::
C:\Windows\System32\bthprops .exe
File::
C:\Documents and Settings\LORENZO\rundll32.exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe |
Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:
Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro.
Scarica avenger e scompattalo in una sua cartella non temporanea e non sul desktop
Avvia AVENGER
Clicca Ok
Inserisci queste righe nel riquadro bianco:
Codice: | Files to move:
C:\Programmi\Java\jre1.5.0_06\bin\bak\jusched.exe | C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe | C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe |
Clicca su Execute
Il pc dovrebbe riavviarsi, se così non fosse, riavvialo tu.
Al termine dell'operazione, posta qui il risultato di Avenger con il log aggiornato di combofix
Irnerio ha scritto: | Non ci sono file nascosti, mentre nella scansione di ieri, ce n'era uno.
E' un bene o un male? |
E' un bene... visto che il file nascosto era un virus.  |
|
Top |
|
 |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 02 Apr 2008 23:01 Oggetto: Internet Connection...Di Nuovo... |
|
|
Grazie per il chiarimento sul file nascosto
Ti posto in successione i file di combofix ed avenger:
ComboFix 08-03-29.1 - LORENZO 2008-04-02 22.31.15.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.429 [GMT 2:00]
Eseguito da: C:\Documents and Settings\LORENZO\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\LORENZO\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Documents and Settings\LORENZO\rundll32.exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
.
((((((((((((((((((((((((( Files Creati Da 2008-03-02 al 2008-04-02 )))))))))))))))))))))))))))))))))))
.
2008-03-31 21:43 . 2008-03-18 21:28 14,348 --a------ C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
2008-03-30 00:14 . 2008-04-02 22:05 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-29 21:55 . 2008-03-29 21:55 <DIR> d-------- C:\Programmi\TechSmith
2008-03-29 21:50 . 2008-03-29 21:50 <DIR> d-------- C:\WINDOWS\system32\it-IT
2008-03-29 21:49 . 2008-03-29 21:49 <DIR> d-------- C:\Programmi\MSBuild
2008-03-29 21:46 . 2008-03-29 21:50 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-03-29 21:45 . 2008-03-29 21:45 <DIR> d-------- C:\Programmi\Reference Assemblies
2008-03-29 21:45 . 2006-06-29 14:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-03-29 21:42 . 2008-03-29 21:50 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-03-29 18:06 . 2008-03-29 18:07 2,945,816 --a------ C:\Programmi\Net Framework 3.0 dotnetfx3setup.exe
2008-03-29 16:08 . 2008-03-29 16:08 5,549,888 --a------ C:\Programmi\jing_setup.exe
2008-03-28 20:08 . 2008-03-18 21:28 14,348 --a------ C:\Documents and Settings\LORENZO\rundll32.exe bthprops.exe
2008-03-20 22:06 . 2008-03-20 22:06 16,648,248 --a------ C:\Programmi\Norman_Malware_Cleaner.exe
2008-03-19 22:24 . 2008-03-19 22:24 <DIR> d-------- C:\Programmi\CCleaner
2008-03-19 22:10 . 2008-03-19 22:10 671,968 --a------ C:\Programmi\ccsetup205_slim.exe
2008-03-19 22:05 . 2008-03-19 22:05 50,688 --a------ C:\Programmi\ATF-Cleaner.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-02 20:07 --------- d-----w C:\Programmi\File comuni\Symantec Shared
2008-03-29 21:20 13,067 ----a-w C:\Programmi\hijackthis.log
2008-03-29 15:47 --------- d-----w C:\Programmi\File comuni\Wise Installation Wizard
2008-03-21 11:40 --------- d-----w C:\Programmi\Norton Internet Security
2008-03-15 14:30 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-03-15 14:12 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-03-15 14:12 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-03-15 14:12 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-02-08 22:18 53,248 ----a-w C:\Programmi\Process.exe
2008-01-25 17:19 127,378 ----a-w C:\Programmi\avenger.zip
2008-01-24 21:17 189,718 ----a-w C:\Programmi\FindAWF.exe
2008-01-15 21:47 143,428 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2008-01-15 14:09 401,720 ----a-w C:\Programmi\HiJackThis.exe
2008-01-13 11:45 17,990,864 ----a-w C:\Programmi\AAW2007.EXE
2007-03-18 17:11 35,248 ------w C:\Documents and Settings\LORENZO\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
Codice: | <pre>
----a-w 14,348 2008-03-18 19:28:19 C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
----a-w 81,920 2008-02-08 22:12:18 C:\Programmi\Sony\SonicStage\SsAAD .exe
----a-w 709,888 2008-01-28 11:48:58 C:\Programmi\TechSmith\Jing\Jing .exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray .exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon .exe
</pre> |
((((((((((((((((((((((((((((( snapshot_2008-04-01_20.45.39,25 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-01 18:44:21 77,808 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-02 20:06:53 77,808 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-01 18:44:21 91,594 ----a-w C:\WINDOWS\system32\perfc010.dat
+ 2008-04-02 20:06:53 91,594 ----a-w C:\WINDOWS\system32\perfc010.dat
- 2008-04-01 18:44:21 454,326 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-02 20:06:53 454,326 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-04-01 18:44:21 504,598 ----a-w C:\WINDOWS\system32\perfh010.dat
+ 2008-04-02 20:06:53 504,598 ----a-w C:\WINDOWS\system32\perfh010.dat
+ 2008-04-02 18:58:36 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_318.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 1,019,392 2004-09-23 09:33:44 C:\Programmi\File comuni\PCSuite\DataLayer\bak\DATALA~1.EXE
----a-w 171,448 2007-01-27 15:49:00 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
----a-w 49,152 2004-02-12 12:38:56 C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 241,664 2004-05-12 14:18:56 C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe
----a-w 36,975 2005-11-10 11:03:52 C:\Programmi\Java\jre1.5.0_06\bin\bak\jusched.exe
----a-w 148,992 2004-09-15 14:36:06 C:\Programmi\Nokia\Nokia PC Suite 6\bak\TRAYAP~1.EXE
----a-w 29,696 2006-06-22 14:11:18 C:\Programmi\Sony\AppMonUtil\bak\AppMonUtility.exe
----a-w 69,632 2005-12-27 11:58:10 C:\Programmi\Sony\VAIO Camera Utility\bak\VCUServe.exe
----a-w 151,552 2005-10-11 19:36:38 C:\Programmi\Sony\VAIO Update 2\bak\VAIOUpdt.exe
----a-w 64,512 2005-08-17 20:40:06 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-07 14:00 15360]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2008-03-18 21:28 14348]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-03-18 21:28 14348]
"Jing"="C:\Programmi\TechSmith\Jing\Jing.exe" [2008-03-18 21:28 14348]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-23 01:32 7561216]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 05:04 59392]
"ccApp"="C:\Programmi\File comuni\Symantec Shared\ccApp.exe" [2007-02-22 13:11 52840]
"URLLSTCK.exe"="C:\Programmi\Norton Internet Security\UrlLstCk.exe" [2007-02-01 18:21 23168]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-09-07 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"Symantec PIF AlertEng"="C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"Acrobat Assistant 7.0"="C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 21:47 483328]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [ ]
"VAIOCameraUtility"="C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe" [ ]
"VAIO Update 2"="C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" [ ]
"HP Component Manager"="C:\Programmi\HP\hpcoretech\hpcmpmgr.exe" [ ]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe" [ ]
"Norton Ghost 10.0"="C:\Programmi\Norton Ghost\Agent\GhostTray.exe" [ ]
"AppMon Utility"="C:\Programmi\Sony\AppMonUtil\AppMonUtility.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-07 14:00 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Audio Filter.lnk - C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe [2006-08-19 09:16:02 5649408]
Avvio rapido di HP Image Zone.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-29 00:06:36 53248]
Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 23:31:38 241664]
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
Photo Loader residente.lnk - C:\Programmi\Casio\Photo Loader\Plauto.exe [2006-12-29 19:03:56 229376]
VAIO Action Setup (Server).lnk - C:\Programmi\Sony\VAIO Action Setup\VAServ.exe [2006-07-17 15:21:26 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2005-05-20 17:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 17:56]
R2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;"C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 18:45]
R3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\DRIVERS\AVerM115S.sys [2006-06-14 10:22]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2006-03-06 11:39]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 11:32]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Programmi\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 19:10]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
*Newly Created Service* - COMHOST
.
Contenuto della cartella 'Scheduled Tasks'
"2008-03-21 21:55:13 C:\WINDOWS\Tasks\Norton AntiVirus - Esegui scansione completa del sistema - LORENZO.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exei/TASK:
"2007-06-16 07:00:41 C:\WINDOWS\Tasks\WebReg 20070616090041.job"
- C:\Programmi\HP\Digital Imaging\bin\hpqwrg.exe`/TaskName 20070616090041 /N
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-02 22:33:42
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-04-02 22.34.20
ComboFix-quarantined-files.txt 2008-04-02 20:34:16
ComboFix2.txt 2008-04-01 19:01:04
ComboFix3.txt 2008-04-01 18:46:03
ComboFix4.txt 2008-03-31 19:45:42
ComboFix5.txt 2008-03-29 21:13:18
11 Directory 126,732,054,528 byte disponibili
15 Directory 126,721,941,504 byte disponibili
.
2008-03-31 20:49:54 --- E O F ---
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\lrrkctii
*******************
Script file located at: \??\C:\Documents and Settings\rafwrkai.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File move operation C:\Programmi\Java\jre1.5.0_06\bin\bak\jusched.exe|C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe completed successfully.
File move operation C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe|C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe completed successfully.
Completed script processing.
*******************
Finished! Terminate.
Che cosa ne dici?
Ti rivolgo una domanda dettata dalla curiosità: come fai a comprendere il significato dei log che ti invio e ad indicarmi i file di testo da scrivere per i programmi che poi lancio?
Per me, sono quasi arabo...  |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 04 Apr 2008 09:14 Oggetto: |
|
|
Ciao Irnerio,
scusa se ti rispondo solo ora.
Vedo che il ragazzaccio continua a replicarsi.
Appena puoi, posta un log aggiornato di combofix. Così vediamo di trovare la soluzione definitiva.  |
|
Top |
|
 |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 04 Apr 2008 22:37 Oggetto: Internet Connection...Di Nuovo... |
|
|
Ciao bdoriano
ti posto il log di combofix; l'ho fatto con il seguente file di testo
RenV::
C:\Windows\System32\bthprops .exe
File::
C:\Documents and Settings\LORENZO\rundll32.exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
Spero sia corretto...
Il log di Combofix, dicevamo, eccolo qua:
ComboFix 08-03-29.1 - LORENZO 2008-04-04 21.24.23.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.515 [GMT 2:00]
Eseguito da: C:\Documents and Settings\LORENZO\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\LORENZO\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Documents and Settings\LORENZO\rundll32.exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
.
TimedOut: Windir.dat
((((((((((((((((((((((((( Files Creati Da 2008-03-04 al 2008-04-04 )))))))))))))))))))))))))))))))))))
.
2008-03-31 21:43 . 2008-03-18 21:28 14,348 --a------ C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
2008-03-30 00:14 . 2008-04-02 22:05 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-29 21:55 . 2008-03-29 21:55 <DIR> d-------- C:\Programmi\TechSmith
2008-03-29 21:50 . 2008-03-29 21:50 <DIR> d-------- C:\WINDOWS\system32\it-IT
2008-03-29 21:49 . 2008-03-29 21:49 <DIR> d-------- C:\Programmi\MSBuild
2008-03-29 21:46 . 2008-03-29 21:50 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-03-29 21:45 . 2008-03-29 21:45 <DIR> d-------- C:\Programmi\Reference Assemblies
2008-03-29 21:45 . 2006-06-29 14:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-03-29 21:42 . 2008-03-29 21:50 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-03-29 18:06 . 2008-03-29 18:07 2,945,816 --a------ C:\Programmi\Net Framework 3.0 dotnetfx3setup.exe
2008-03-29 16:08 . 2008-03-29 16:08 5,549,888 --a------ C:\Programmi\jing_setup.exe
2008-03-28 20:08 . 2008-03-18 21:28 14,348 --a------ C:\Documents and Settings\LORENZO\rundll32.exe bthprops.exe
2008-03-20 22:06 . 2008-03-20 22:06 16,648,248 --a------ C:\Programmi\Norman_Malware_Cleaner.exe
2008-03-19 22:24 . 2008-03-19 22:24 <DIR> d-------- C:\Programmi\CCleaner
2008-03-19 22:10 . 2008-03-19 22:10 671,968 --a------ C:\Programmi\ccsetup205_slim.exe
2008-03-19 22:05 . 2008-03-19 22:05 50,688 --a------ C:\Programmi\ATF-Cleaner.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-04 19:01 --------- d-----w C:\Programmi\File comuni\Symantec Shared
2008-03-29 21:20 13,067 ----a-w C:\Programmi\hijackthis.log
2008-03-29 15:47 --------- d-----w C:\Programmi\File comuni\Wise Installation Wizard
2008-03-21 11:40 --------- d-----w C:\Programmi\Norton Internet Security
2008-03-15 14:30 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-03-15 14:12 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-03-15 14:12 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-03-15 14:12 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-02-08 22:18 53,248 ----a-w C:\Programmi\Process.exe
2008-01-25 17:19 127,378 ----a-w C:\Programmi\avenger.zip
2008-01-24 21:17 189,718 ----a-w C:\Programmi\FindAWF.exe
2008-01-15 21:47 143,428 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2008-01-15 14:09 401,720 ----a-w C:\Programmi\HiJackThis.exe
2008-01-13 11:45 17,990,864 ----a-w C:\Programmi\AAW2007.EXE
2007-03-18 17:11 35,248 ------w C:\Documents and Settings\LORENZO\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
Codice: | <pre>
----a-w 14,348 2008-03-18 19:28:19 C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
----a-w 171,448 2007-01-27 15:49:00 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
----a-w 81,920 2008-02-08 22:12:18 C:\Programmi\Sony\SonicStage\SsAAD .exe
----a-w 709,888 2008-01-28 11:48:58 C:\Programmi\TechSmith\Jing\Jing .exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray .exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon .exe
</pre> |
((((((((((((((((((((((((((((( snapshot_2008-04-01_20.45.39,25 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-01 18:44:21 77,808 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-04 19:06:23 77,808 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-01 18:44:21 91,594 ----a-w C:\WINDOWS\system32\perfc010.dat
+ 2008-04-04 19:06:23 91,594 ----a-w C:\WINDOWS\system32\perfc010.dat
- 2008-04-01 18:44:21 454,326 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-04 19:06:23 454,326 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-04-01 18:44:21 504,598 ----a-w C:\WINDOWS\system32\perfh010.dat
+ 2008-04-04 19:06:23 504,598 ----a-w C:\WINDOWS\system32\perfh010.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 1,019,392 2004-09-23 09:33:44 C:\Programmi\File comuni\PCSuite\DataLayer\bak\DATALA~1.EXE
----a-w 49,152 2004-02-12 12:38:56 C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 241,664 2004-05-12 14:18:56 C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe
----a-w 148,992 2004-09-15 14:36:06 C:\Programmi\Nokia\Nokia PC Suite 6\bak\TRAYAP~1.EXE
----a-w 29,696 2006-06-22 14:11:18 C:\Programmi\Sony\AppMonUtil\bak\AppMonUtility.exe
----a-w 69,632 2005-12-27 11:58:10 C:\Programmi\Sony\VAIO Camera Utility\bak\VCUServe.exe
----a-w 151,552 2005-10-11 19:36:38 C:\Programmi\Sony\VAIO Update 2\bak\VAIOUpdt.exe
----a-w 64,512 2005-08-17 20:40:06 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-07 14:00 15360]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [ ]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [ ]
"Jing"="C:\Programmi\TechSmith\Jing\Jing.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-23 01:32 7561216]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 05:04 59392]
"ccApp"="C:\Programmi\File comuni\Symantec Shared\ccApp.exe" [2007-02-22 13:11 52840]
"URLLSTCK.exe"="C:\Programmi\Norton Internet Security\UrlLstCk.exe" [2007-02-01 18:21 23168]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-09-07 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"Symantec PIF AlertEng"="C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"Acrobat Assistant 7.0"="C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 21:47 483328]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [ ]
"VAIOCameraUtility"="C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe" [ ]
"VAIO Update 2"="C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" [ ]
"HP Component Manager"="C:\Programmi\HP\hpcoretech\hpcmpmgr.exe" [ ]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe" [ ]
"Norton Ghost 10.0"="C:\Programmi\Norton Ghost\Agent\GhostTray.exe" [ ]
"AppMon Utility"="C:\Programmi\Sony\AppMonUtil\AppMonUtility.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-07 14:00 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Audio Filter.lnk - C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe [2006-08-19 09:16:02 5649408]
Avvio rapido di HP Image Zone.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-29 00:06:36 53248]
Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 23:31:38 241664]
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
Photo Loader residente.lnk - C:\Programmi\Casio\Photo Loader\Plauto.exe [2006-12-29 19:03:56 229376]
VAIO Action Setup (Server).lnk - C:\Programmi\Sony\VAIO Action Setup\VAServ.exe [2006-07-17 15:21:26 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2005-05-20 17:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 17:56]
R2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;"C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 18:45]
R3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\DRIVERS\AVerM115S.sys [2006-06-14 10:22]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2006-03-06 11:39]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 11:32]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Programmi\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 19:10]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
*Newly Created Service* - COMHOST
.
Contenuto della cartella 'Scheduled Tasks'
"2008-03-21 21:55:13 C:\WINDOWS\Tasks\Norton AntiVirus - Esegui scansione completa del sistema - LORENZO.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exei/TASK:
"2007-06-16 07:00:41 C:\WINDOWS\Tasks\WebReg 20070616090041.job"
- C:\Programmi\HP\Digital Imaging\bin\hpqwrg.exe`/TaskName 20070616090041 /N
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-04 21:27:33
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
Ora fine scansione: 2008-04-04 21.28.23
ComboFix-quarantined-files.txt 2008-04-04 19:28:06
ComboFix2.txt 2008-04-02 20:34:21
ComboFix3.txt 2008-04-01 19:01:04
ComboFix4.txt 2008-04-01 18:46:03
ComboFix5.txt 2008-03-31 19:45:42
12 Directory 126,694,309,888 byte disponibili
16 Directory 126,683,893,760 byte disponibili
.
2008-03-31 20:49:54 --- E O F ---
Mi sai dire cosa significa l'avviso "WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED" che appare in ogni scansione di Combofix?
E' preoccupante?  |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 05 Apr 2008 14:16 Oggetto: |
|
|
Ciao Irnerio,
scusa il ritardo, ma sono abbastanza incasinato.
Comincio a rispondere alle tue domande
Irnerio ha scritto: | Ti rivolgo una domanda dettata dalla curiosità: come fai a comprendere il significato dei log che ti invio e ad indicarmi i file di testo da scrivere per i programmi che poi lancio? |
Se hai notato, nel log di combofix, viene evidenziato un elenco di files tra i tag <pre></pre>
Quelli sono i files sostituiti dal virus, che vanno ripristinati.
Purtroppo, ho notato solo dopo che alcuni di quei files erano parte del virus.
Irnerio ha scritto: | Mi sai dire cosa significa l'avviso "WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED" che appare in ogni scansione di Combofix?
E' preoccupante? |
No, non è preoccupante.
Fa riferimento a una "funzione" di Windows che è la Console di ripristino
Se vuoi installarla, puoi vedere questo messaggio.
Adesso andiamo avanti con la pulizia
Crea un file di testo con le seguenti istruzioni:
Codice: | File::
C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
C:\Documents and Settings\LORENZO\rundll32.exe bthprops.exe
RenV::
C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
C:\Programmi\Sony\SonicStage\SsAAD .exe
C:\Programmi\TechSmith\Jing\Jing .exe
C:\WINDOWS\ehome\ehtray .exe
C:\WINDOWS\system32\ctfmon .exe |
Salva il file sul desktop con il nome CFScript.txt e trascinalo sull'icona di ComboFix, come indicato in seguito:
Attendi pazientemente la fine dei lavori senza toccare tastiera, mouse o altro.
Posta il logs aggiornato di combofix. |
|
Top |
|
 |
Irnerio Eroe


Registrato: 23/01/08 21:49 Messaggi: 44
|
Inviato: 05 Apr 2008 17:15 Oggetto: Internet Connection...Di Nuovo... |
|
|
Ciao e grazie per le tue risposte!
Non so se installare la Console di ripristino , ma credo che possa essere utile, e quindi forse lo farò.
Non sono invece riuscito a vedere l' elenco di files tra i tag <pre></pre> che mi hai segnalato.
Ho dato però solo un'occhiata approssimativa all'ultimo log, pertanto me lo devo essere perso: appena postato questo messaggio, guardo l'elenco con maggiore attenzione.
Ho creato il file di testo che mi hai indicato e l'ho trascinato su combofix.
Questo è il log che ne è uscito:
ComboFix 08-03-29.1 - LORENZO 2008-04-05 15.01.28.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.522 [GMT 2:00]
Eseguito da: C:\Documents and Settings\LORENZO\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\LORENZO\Desktop\CFScript.txt
* Creato nuovo punto di ripristino
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
C:\Documents and Settings\LORENZO\rundll32.exe bthprops.exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
C:\Documents and Settings\LORENZO\rundll32.exe bthprops.exe
C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
.
((((((((((((((((((((((((( Files Creati Da 2008-03-05 al 2008-04-05 )))))))))))))))))))))))))))))))))))
.
2008-04-04 23:19 . 2008-04-04 23:19 <DIR> d-------- C:\Programmi\MSXML 6.0
2008-03-30 00:14 . 2008-04-02 22:05 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-29 21:55 . 2008-03-29 21:55 <DIR> d-------- C:\Programmi\TechSmith
2008-03-29 21:50 . 2008-03-29 21:50 <DIR> d-------- C:\WINDOWS\system32\it-IT
2008-03-29 21:49 . 2008-03-29 21:49 <DIR> d-------- C:\Programmi\MSBuild
2008-03-29 21:46 . 2008-03-29 21:50 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-03-29 21:45 . 2008-03-29 21:45 <DIR> d-------- C:\Programmi\Reference Assemblies
2008-03-29 21:45 . 2006-06-29 14:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-03-29 21:42 . 2008-03-29 21:50 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-03-29 18:06 . 2008-03-29 18:07 2,945,816 --a------ C:\Programmi\Net Framework 3.0 dotnetfx3setup.exe
2008-03-29 16:08 . 2008-03-29 16:08 5,549,888 --a------ C:\Programmi\jing_setup.exe
2008-03-20 22:06 . 2008-03-20 22:06 16,648,248 --a------ C:\Programmi\Norman_Malware_Cleaner.exe
2008-03-19 22:24 . 2008-03-19 22:24 <DIR> d-------- C:\Programmi\CCleaner
2008-03-19 22:10 . 2008-03-19 22:10 671,968 --a------ C:\Programmi\ccsetup205_slim.exe
2008-03-19 22:05 . 2008-03-19 22:05 50,688 --a------ C:\Programmi\ATF-Cleaner.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-05 13:05 --------- d-----w C:\Programmi\File comuni\Symantec Shared
2008-03-29 21:20 13,067 ----a-w C:\Programmi\hijackthis.log
2008-03-29 15:47 --------- d-----w C:\Programmi\File comuni\Wise Installation Wizard
2008-03-21 11:40 --------- d-----w C:\Programmi\Norton Internet Security
2008-03-15 14:30 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-03-15 14:12 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-03-15 14:12 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-02-08 22:18 53,248 ----a-w C:\Programmi\Process.exe
2008-01-25 17:19 127,378 ----a-w C:\Programmi\avenger.zip
2008-01-24 21:17 189,718 ----a-w C:\Programmi\FindAWF.exe
2008-01-15 14:09 401,720 ----a-w C:\Programmi\HiJackThis.exe
2008-01-13 11:45 17,990,864 ----a-w C:\Programmi\AAW2007.EXE
2007-03-18 17:11 35,248 ------w C:\Documents and Settings\LORENZO\Dati applicazioni\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot_2008-04-01_20.45.39,25 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-30 18:25:18 59,904 ----a-r C:\WINDOWS\Installer\{0AF0F8DC-7C92-4B7C-A376-127B9AD061D2}\IconA3AFE979.exe
+ 2008-04-04 20:44:35 59,904 ----a-r C:\WINDOWS\Installer\{0AF0F8DC-7C92-4B7C-A376-127B9AD061D2}\IconA3AFE979.exe
- 2008-03-31 19:07:39 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-05 13:15:13 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-03-31 19:07:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\index.dat
+ 2008-04-05 13:15:13 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\index.dat
- 2008-03-31 19:07:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-05 13:15:13 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat
- 2006-09-01 11:08:02 1,334,032 ----a-w C:\WINDOWS\system32\msxml6.dll
+ 2007-05-15 13:43:10 1,320,800 ----a-w C:\WINDOWS\system32\msxml6.dll
- 2008-04-01 18:44:21 77,808 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-05 13:09:41 77,808 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-01 18:44:21 91,594 ----a-w C:\WINDOWS\system32\perfc010.dat
+ 2008-04-05 13:09:41 91,594 ----a-w C:\WINDOWS\system32\perfc010.dat
- 2008-04-01 18:44:21 454,326 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-05 13:09:41 454,326 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-04-01 18:44:21 504,598 ----a-w C:\WINDOWS\system32\perfh010.dat
+ 2008-04-05 13:09:41 504,598 ----a-w C:\WINDOWS\system32\perfh010.dat
+ 2008-04-05 13:05:16 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_1d8.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 1,019,392 2004-09-23 09:33:44 C:\Programmi\File comuni\PCSuite\DataLayer\bak\DATALA~1.EXE
----a-w 49,152 2004-02-12 12:38:56 C:\Programmi\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 241,664 2004-05-12 14:18:56 C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe
----a-w 148,992 2004-09-15 14:36:06 C:\Programmi\Nokia\Nokia PC Suite 6\bak\TRAYAP~1.EXE
----a-w 29,696 2006-06-22 14:11:18 C:\Programmi\Sony\AppMonUtil\bak\AppMonUtility.exe
----a-w 69,632 2005-12-27 11:58:10 C:\Programmi\Sony\VAIO Camera Utility\bak\VCUServe.exe
----a-w 151,552 2005-10-11 19:36:38 C:\Programmi\Sony\VAIO Update 2\bak\VAIOUpdt.exe
----a-w 64,512 2005-08-17 20:40:06 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-07 14:00 15360]
"MSMSGS"="C:\Programmi\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2008-02-09 00:12 81920]
"swg"="C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-01-27 17:49 171448]
"Jing"="C:\Programmi\TechSmith\Jing\Jing.exe" [2008-01-28 13:48 709888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-23 01:32 7561216]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 05:04 59392]
"ccApp"="C:\Programmi\File comuni\Symantec Shared\ccApp.exe" [2007-02-22 13:11 52840]
"URLLSTCK.exe"="C:\Programmi\Norton Internet Security\UrlLstCk.exe" [2007-02-01 18:21 23168]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-09-07 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"Symantec PIF AlertEng"="C:\Programmi\File comuni\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"Acrobat Assistant 7.0"="C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 21:47 483328]
"HP Software Update"="C:\Programmi\HP\HP Software Update\HPWuSchd2.exe" [ ]
"VAIOCameraUtility"="C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe" [ ]
"VAIO Update 2"="C:\Programmi\Sony\VAIO Update 2\VAIOUpdt.exe" [ ]
"HP Component Manager"="C:\Programmi\HP\hpcoretech\hpcmpmgr.exe" [ ]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe" [ ]
"Norton Ghost 10.0"="C:\Programmi\Norton Ghost\Agent\GhostTray.exe" [ ]
"AppMon Utility"="C:\Programmi\Sony\AppMonUtil\AppMonUtility.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-07 14:00 15360]
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Audio Filter.lnk - C:\Programmi\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe [2006-08-19 09:16:02 5649408]
Avvio rapido di HP Image Zone.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-29 00:06:36 53248]
Avvio veloce di Adobe Reader.lnk - C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 23:31:38 241664]
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
Photo Loader residente.lnk - C:\Programmi\Casio\Photo Loader\Plauto.exe [2006-12-29 19:03:56 229376]
VAIO Action Setup (Server).lnk - C:\Programmi\Sony\VAIO Action Setup\VAServ.exe [2006-07-17 15:21:26 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2005-05-20 17:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Programmi\\Messenger\\msmsgs.exe"=
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 17:56]
R2 Utilità di pianificazione di LiveUpdate automatico;Utilità di pianificazione di LiveUpdate automatico;"C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 18:45]
R3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\DRIVERS\AVerM115S.sys [2006-06-14 10:22]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2006-03-06 11:39]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 11:32]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Programmi\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 19:10]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 usbscan;Driver scanner USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
*Newly Created Service* - COMHOST
.
Contenuto della cartella 'Scheduled Tasks'
"2008-03-21 21:55:13 C:\WINDOWS\Tasks\Norton AntiVirus - Esegui scansione completa del sistema - LORENZO.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exei/TASK:
"2007-06-16 07:00:41 C:\WINDOWS\Tasks\WebReg 20070616090041.job"
- C:\Programmi\HP\Digital Imaging\bin\hpqwrg.exe`/TaskName 20070616090041 /N
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-05 16:40:47
Windows 5.1.2600 Service Pack 2 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccProxy.exe
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programmi\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Programmi\HP\Digital Imaging\bin\hpqgalry.exe
C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
C:\Programmi\File comuni\Symantec Shared\Security Console\NSCSRVCE.EXE
.
**************************************************************************
.
Ora fine scansione: 2008-04-05 16:44:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-05 14:44:22
ComboFix2.txt 2008-04-04 19:28:24
ComboFix3.txt 2008-04-02 20:34:21
ComboFix4.txt 2008-04-01 19:01:04
ComboFix5.txt 2008-04-01 18:46:03
12 Directory 126,628,233,216 byte disponibili
15 Directory 126,634,881,024 byte disponibili
.
2008-04-04 21:19:23 --- E O F ---
Io riesco solo avedere che non ci sono files nascosti.
Tuttavia ieri, dopo un paio di giorni di tregua, Internet Connection mi ha nuovamente disconnesso .
Ho dovuto riavviare il pc per riprendere il lavoro.
L'osso è duro, ma sono sicuro di riuscire a masticarlo col tuo aiuto.
Ciao |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 05 Apr 2008 17:24 Oggetto: |
|
|
Ok, ci siamo.
In quest'ultimo log non compaiono più le voci tipo queste qui di seguito:
Codice: | <pre>
----a-w 14,348 2008-03-18 19:28:19 C:\Documents and Settings\LORENZO\rundll32.exe bthprops .exe
----a-w 171,448 2007-01-27 15:49:00 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
----a-w 14,348 2008-03-18 19:28:19 C:\Programmi\Java\jre1.5.0_06\bin\jusched .exe
----a-w 81,920 2008-02-08 22:12:18 C:\Programmi\Sony\SonicStage\SsAAD .exe
----a-w 709,888 2008-01-28 11:48:58 C:\Programmi\TechSmith\Jing\Jing .exe
----a-w 59,392 2004-08-10 03:04:42 C:\WINDOWS\ehome\ehtray .exe
----a-w 15,360 2004-09-07 12:00:00 C:\WINDOWS\system32\ctfmon .exe
</pre> |
Ora possiamo procedere con altri controlli:
- Disabilita il tuo antivirus
- Collegati a BitDefender (con IE) e fai la scansione completa.
- Collegati a Kaspersky on-line scanner e fai la scansione estesa, come indicato qui.
Salva il risultato della scansione in un file (in formato HTML), carica il file su Freefilehosting e posta qui il link che ti viene assegnato.
|
|
Top |
|
 |
|
|
Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento Non puoi modificare i tuoi messaggi Non puoi cancellare i tuoi messaggi Non puoi votare nei sondaggi
|
|