PDA

View Full Version : (W32.tenga]ma che simpatica cosa...


Sajiuuk Kaar
15-10-2007, 13:25
ho appurato con certezza del 100% che arriva da e-mule, e non è colpa delle versioni. sembra che il primo file infettato sia SEMPRE e COSTANTEMENTE quello di e-mule e lo dico per diversi motivi:
1- sull'altro pc non ho e-mule e non l'ho preso. (non ho nemmeno firewall e antiivrus)
2- è l'unico file che dopo l'infezione diventa corrotto e totalmente inusabile oltre alla maggiorparte degli archivi autoestraenti.
3- ogni persona che usa e-mule che conosco l'ha preso almeno una volta.
Adesso: non so come sia possibile sta cosa, TEORICAMENTE con un firewall si risolve. Fortuna che nod 32 lo toglie e stratoglie. E' fastidioso come un foruncolo sulle chiappe sto virus...

Gle89
15-10-2007, 13:31
Io sinceramente non ho capito molto da questo 3d...
1) non ho capito se tu sei infetto e vuoi aiuto
2) non ho capito se hai trovato la soluzione e vuoi spiegarcela.

Inoltre avendo usato quel programma per molto tempo ti posso assicurare che non ho mai preso quel virus, ne altri. E anche tutti i miei amici.

Inoltre: sembra che il primo file infettato sia SEMPRE e COSTANTEMENTE quello di e-mule

quale primo file? quale secondo file?

xcdegasp
15-10-2007, 13:44
ho appurato con certezza del 100% che arriva da e-mule, e non è colpa delle versioni. sembra che il primo file infettato sia SEMPRE e COSTANTEMENTE quello di e-mule e lo dico per diversi motivi:
1- sull'altro pc non ho e-mule e non l'ho preso. (non ho nemmeno firewall e antiivrus)
2- è l'unico file che dopo l'infezione diventa corrotto e totalmente inusabile oltre alla maggiorparte degli archivi autoestraenti.
3- ogni persona che usa e-mule che conosco l'ha preso almeno una volta.
Adesso: non so come sia possibile sta cosa, TEORICAMENTE con un firewall si risolve. Fortuna che nod 32 lo toglie e stratoglie. E' fastidioso come un foruncolo sulle chiappe sto virus...
non per azzardare una risposta, ma credo tu NON abbia scaricato un eMule ritenuto valido dalla community emuliana.
o maldestramente ti sei affidato a quelche exe spacciato per "velocizzatore" ed ecco che ci si infetta :D

ti posso garantire che se scarichi una mod di eMule da lidi ufficiali non avrai di che temere, e nella guida che ho in firma ci soino dei link da cui attingere le nuove versioni..
anche dalla mia homepage linkata sempre in firma :)

Marci
15-10-2007, 13:46
mai visto sto virus;)

c.m.g
15-10-2007, 14:26
non per azzardare una risposta, ma credo tu NON abbia scaricato un eMule ritenuto valido dalla community emuliana.
o maldestramente ti sei affidato a quelche exe spacciato per "velocizzatore" ed ecco che ci si infetta :D

ti posso garantire che se scarichi una mod di eMule da lidi ufficiali non avrai di che temere, e nella guida che ho in firma ci soino dei link da cui attingere le nuove versioni..
anche dalla mia homepage linkata sempre in firma :)

credo che si possa propendere per questa ipotesi. inoltre non ti fidare molto dei programmi che trovi sul mulo o di altri magici trucchi per velocizzare il download, fidati solo di quello che è ufficiale.

Bugs Bunny
15-10-2007, 18:18
quoto gle....

credo che l'autore del thread sappia che se è infetto emule sono infetti molti altri
files e che il fatto che l'eseguibile di emule sia corrotto sia causato dal virus ma non significa niente in quanto questo malware TALVOLTA rovina i files che infetta

Sajiuuk Kaar
15-10-2007, 20:08
non per azzardare una risposta, ma credo tu NON abbia scaricato un eMule ritenuto valido dalla community emuliana.
o maldestramente ti sei affidato a quelche exe spacciato per "velocizzatore" ed ecco che ci si infetta :D

ti posso garantire che se scarichi una mod di eMule da lidi ufficiali non avrai di che temere, e nella guida che ho in firma ci soino dei link da cui attingere le nuove versioni..
anche dalla mia homepage linkata sempre in firma :)

Spiacente ma ODIO le versioni tarocche. Cmq anche quelle tarocche si infettano dopo un po. I miei amici preferiscono la MorphXT. Io uso quello normale, non so perchè mi fido di più... ma a quanto pare comunque sono stato infettato...

http://www.emule-project.net/

da qui si piglia e DA NESSUN'ALTRA PARTE imho.

Visto che c'è chi non lo conosce: E' questo (http://ca.com/it/securityadvisor/virusinfo/Browse.aspx?MODE=L&LTR=G&TYPE=&DATE=)

Conosciuto anhce come Gael. Infetta gli exe e NESSUNO ha ancora capito come si diffonda... la mia infatti è un'ipotesi.

xcdegasp
15-10-2007, 20:13
Spiacente ma ODIO le versioni tarocche. Cmq anche quelle tarocche si infettano dopo un po. I miei amici preferiscono la MorphXT. Io uso quello normale, non so perchè mi fido di più... ma a quanto pare comunque sono stato infettato...

http://www.emule-project.net/

da qui si piglia e DA NESSUN'ALTRA PARTE imho.

e allora non era un virus contenuto nell'exe...
lo avbrai preso a posteriori e cmq non l'ho mai sentito e ho sempre usato nod32 fino a 30 giorni fa' ;)
è anche vero che la morphXT non la uso, preferisco di gran lunga ScarAngel o epr stare il più vicino alla morphXT la StulleMule.
:)

Bugs Bunny
15-10-2007, 20:53
Visto che c'è chi non lo conosce
NESSUNO ha ancora capito come si diffonda... la mia infatti è un'ipotesi.

W32.Licum is a file-infecting worm that may spread by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026).

When W32.Licum is executed, it performs the following actions:
-Generates random list of IP addresses and attempts to spread by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026) through TCP port 139.
[symantec (http://www.symantec.com/security_response/writeup.jsp?docid=2005-071316-2523-99)]


W32/Tenga-A attempts to infect files at randomly chosen IP addresses via NetBIOS. [Sophos (http://www.sophos.com/security/analyses/w32tengaa.html)]

Hai windows aggiornato?

xcdegasp
15-10-2007, 21:49
W32.Licum is a file-infecting worm that may spread by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026).

When W32.Licum is executed, it performs the following actions:
-Generates random list of IP addresses and attempts to spread by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026) through TCP port 139.
[symantec (http://www.symantec.com/security_response/writeup.jsp?docid=2005-071316-2523-99)]


W32/Tenga-A attempts to infect files at randomly chosen IP addresses via NetBIOS. [Sophos (http://www.sophos.com/security/analyses/w32tengaa.html)]

Hai windows aggiornato?
e mi sa che qui gatta ci cova :)
addirittura del 2005 :D

lancetta
16-10-2007, 00:05
quoto..il virus in questione sfrutta la vulnerabilità di RPC COM di Windows.Inoltre scarica anche un file CBACK.EXE che è un trojan.Non è emule ma il tuo s.o. non aggiornato:rolleyes:

xcdegasp
16-10-2007, 07:08
sì ma significa che non sa nemmeno cosa sia un firewall :D

PacManZ
04-11-2007, 15:58
Vi assicuro che Sajiuuk usa win xp aggiornato

Vi assicuro che anche io con xp aggiornato non riuscivo a debellare il tenga (anche formattando)... Quel robo periodicamente tornava e mi infettava tutti gli exe.

E kasper si accorgeva quando ormai il virus ne aveva gia' infettati almeno una decina.


Ho risolto il problema passando a vista...

juninho85
04-11-2007, 16:15
3- ogni persona che usa e-mule che conosco l'ha preso almeno una volta.
.

sai quanti iscritti ci sono in questa community e quanti in percentuale utilizzano emule?!:D
prova a postare nel suo thread ufficiale,chiedi se è già accaduto a qualcuno,in seguito datti(e confermaci) una risposta :D

Sajiuuk Kaar
04-11-2007, 16:43
quoto..il virus in questione sfrutta la vulnerabilità di RPC COM di Windows.Inoltre scarica anche un file CBACK.EXE che è un trojan.Non è emule ma il tuo s.o. non aggiornato:rolleyes:

Guarda che NON E' ***QUEL*** "tenga"...
Sono infetto da W32.Tenga/gen che è una variante astrusa del Gael originale... *forse*... se non è uno completamente diverso che si diffonde in maniera completamente diversa come penso e ripeto penso... non sono sicuro di una mazza... neanche il pc è sicuro a quanto pare... L'unica cosa di cui sono sicuro è: "Apro e-mule. Lascio aperto 1 giorno o 2 = becco il tenga". Probabilmente con un firewall risolverei questo problema ma ne ho provati un fracco e buona parte mi causava problemi con gli installer e gli updater di varii giochi come, tanto per citarne uno, Trackmania Nations.

sai quanti iscritti ci sono in questa community e quanti in percentuale utilizzano emule?!:D
prova a postare nel suo thread ufficiale,chiedi se è già accaduto a qualcuno,in seguito datti(e confermaci) una risposta :D

vedi PacManZ.... abbiamo formulato assieme l'ipotesi...
Probabilmente sfrutta la lista degli IP connessi di e-mule per distribuirsi. Non usa il bug del blaster. Se il mio computer non fosse protetto dal blaster ogni 5 secondi dovrebbe aprirsi una finestra che mi avvisa del riavvio del pc e così non è. Tralaltro ho provato ad installare l'aggiornamento del blaster e mi dice che la versione installata è superiore a quella che si stà per installare causa SP2 installato...

xcdegasp
04-11-2007, 16:46
Guarda che NON E' ***QUEL*** "tenga"...
Sono infetto da W32.Tenga/gen che è una variante astrusa del Gael originale... *forse*... se non è uno completamente diverso che si diffonde in maniera completamente diversa come penso e ripeto penso... non sono sicuro di una mazza... neanche il pc è sicuro a quanto pare... L'unica cosa di cui sono sicuro è: "Apro e-mule. Lascio aperto 1 giorno o 2 = becco il tenga". Probabilmente con un firewall risolverei questo problema ma ne ho provati un fracco e buona parte mi causava problemi con gli installer e gli updater di varii giochi come, tanto per citarne uno, Trackmania Nations.



vedi PacManZ.... abbiamo formulato assieme l'ipotesi...
Probabilmente sfrutta la lista degli IP connessi di e-mule per distribuirsi. Non usa il bug del blaster. Se il mio computer non fosse protetto dal blaster ogni 5 secondi dovrebbe aprirsi una finestra che mi avvisa del riavvio del pc e così non è. Tralaltro ho provato ad installare l'aggiornamento del blaster e mi dice che la versione installata è superiore a quella che si stà per installare causa SP2 installato...

almeno usi un router?

juninho85
04-11-2007, 16:49
vedi PacManZ.... abbiamo formulato assieme l'ipotesi...
Probabilmente sfrutta la lista degli IP connessi di e-mule per distribuirsi. Non usa il bug del blaster. Se il mio computer non fosse protetto dal blaster ogni 5 secondi dovrebbe aprirsi una finestra che mi avvisa del riavvio del pc e così non è. Tralaltro ho provato ad installare l'aggiornamento del blaster e mi dice che la versione installata è superiore a quella che si stà per installare causa SP2 installato...

pacmanz non dice nulla che supporti/squalifichi la mia proposta.
ripeto:chiedi nel thread di emule(abbastanza frequentato) e chiedi se qualcun'altro ha avuto il vostro medesimo problema ;)

Sajiuuk Kaar
04-11-2007, 17:12
almeno usi un router?

...appena possibile ne prenderò uno... al momento no. Non uso un router.
Se ti può "consolare" cmq PacmanZ se l'è preso con un riuter. In ufficio dei miei è entrato. E C'è il router. Ovviamente con il firewall attivo...

pacmanz non dice nulla che supporti/squalifichi la mia proposta.
ripeto:chiedi nel thread di emule(abbastanza frequentato) e chiedi se qualcun'altro ha avuto il vostro medesimo problema ;)

Puoi linkare il thread plz? O.o con cerca non lo trovo... escludendo i 60 secondi tra una ricerca e l'altra ache causano cancro ed ictus...
Cmq non dicevo che aveva detto che hai detto una cacata, dicevo che abbiamo fatto questa ipotesi assieme un bel po' di tempo fa...

lancetta
04-11-2007, 17:18
Guarda che NON E' ***QUEL*** "tenga"...
Sono infetto da W32.Tenga/gen che è una variante astrusa del Gael originale... *forse*... se non è uno completamente diverso che si diffonde in maniera completamente diversa come penso e ripeto penso... non sono sicuro di una mazza... neanche il pc è sicuro a quanto pare... L'unica cosa di cui sono sicuro è: "Apro e-mule. Lascio aperto 1 giorno o 2 = becco il tenga". Probabilmente con un firewall risolverei questo problema ma ne ho provati un fracco e buona parte mi causava problemi con gli installer e gli updater di varii giochi come, tanto per citarne uno, Trackmania Nations.


Capisco che tu non ne sia sicuro.....però le info le dà anche il tuo stesso link postato più sù (post n°7) se vai al link successivo http://ca.com/it/securityadvisor/virusinfo/virus.aspx?ID=43319 ti dà altre info a riguardo che ti dirò sono le stesse degli altri...è una variante del 2006 e ti riporto acnhe questo a suffragio dle fatto che emule non ci azzecca niente
Metodo di distribuzione

Via File Infection/Network Shares

Gael spreads to remote machines by initially scanning random IP addresses on port 139, and then infecting target files on machines with open shares.
Poi come ti dicevo il famoso file CBACK.EXE..che poi non è solo ma c'è ne un altro a fargli compagniaElemento del codice infetto che ne produce gli effetti più o meno distruttivi

Downloads and Executes Arbitrary Files

The virus attempts to download the file dl.exe from the utenti.lycos.it domain and executes it. This file may be detected as Win32.Gael!downloader by CA Antivirus solutions.


This file, in turn downloads and executes two additional files from the same domain:

<root>\GAELICUM.EXE - a copy of the virus
< root>\CBACK.EXE - the backdoor component (this file may be detected as Win32.Gael.A by CA Antivirus solutions).
Backdoor Functionality

CBACK.EXE opens a backdoor on port 4321 which receives and executes commands from a remote controller using the Windows command prompt. It also sends a notification (presumably of the new system compromise) that contains the open port number to the vx9.users.freebsd.at domain.
Ripeto anche altre info in rete dicono più o meno la stessa cosa....

Saluti:cool:

juninho85
04-11-2007, 17:19
porta 139 che tra l'altro dovrebbe essere chiusa non appena installato il sistema operativo,assieme alle altre 3-4 dell'ave maria

lancetta
04-11-2007, 17:27
porta 139 che tra l'altro dovrebbe essere chiusa non appena installato il sistema operativo,assieme alle altre 3-4 dell'ave maria

esatto...;)

Bugs Bunny
04-11-2007, 17:36
io vorrei sapere cosa scaricate da emule tu e i tuoi conoscenti.

è possibile vedere un log di hijackthis?

lancetta
04-11-2007, 17:47
io vorrei sapere cosa scaricate da emule tu e i tuoi conoscenti.

è possibile vedere un log di hijackthis?

hem....quoto :stordita:

milady80
04-11-2007, 17:55
hem....quoto :stordita:
io proverei a far un pò di pulizia di ciò che hai scaricato, soprattutto quei film dove ci sono le donnine nude :)

gomax
04-11-2007, 18:00
Sto leggendo cose molto improbabili in questo thread... comunque io in due anni che uso emule sto "tenga" non l'ho mai beccato (e non uso firewall, sto dietro al router).
Poi vorrei sapere COSA scarichi da emule... perchè anche appena formattato se il primo file che scarichi è roba tipo warez, è naturale che ti entri il "tenga" (e non solo quello).
Il firewall di XP, quello almeno lo tieni attivo, visto che non hai un router? perchè il buon firewall di XP, nonostante sia denigrato come il peggior firewall esistente, blocca tutti gli attacchi dall'esterno, anche se non controlla il traffico in uscita, e un utente esperto che sa usare con buonsenso la rete può stare benissimo anche soltanto con quello.

Ciao

PacManZ
04-11-2007, 18:54
Io sicuramente non avevo il firewall di win attivo...


Pero' di certo avevo windows aggiornato (Il cd che avevo installava direttamente l'sp2 e la prima cosa che facevo era win update) e quindi non mi spiego come il virus potesse sfruttare il bug dell' RPC per entrare...


Eppure entrava... e nonostante avevo kaspersky attivo faceva in tempo a fottermi un po' di eseguibili...

Io avevo pensato in seguito che potesse essere la MorphXT la causa del problema, ma sajuuk usa la versione base di emule...

Quindi non so piu' cosa pensare...

gomax
04-11-2007, 18:59
Io sicuramente non avevo il firewall di win attivo...


Ecco il succo del problema... senza router e senza nessun tipo di firewall software, è un miracolo che tu sia anche solo riuscito ad avviarlo quel pc. XP può essere aggiornato con tutte le patch dell'ultimo secondo e puoi avere l'antivirus più potente che esista, ma sei non hai un minimo di protezione dagli attacchi esterni (il firewall appunto) tempo 30 secondi ti entra di tutto nel pc. Mistero risolto :D

Ciao

PacManZ
04-11-2007, 19:04
Daccordo, pero' dalla protezione in real-time di un antivirus mi aspetterei che sia veramente in real-time...

juninho85
04-11-2007, 19:05
Daccordo, pero' dalla protezione in real-time di un antivirus mi aspetterei che sia veramente in real-time...

l'antivirus non può sopperire alla non presenza di un firewall,che discorsi sono??:mbe:

PacManZ
04-11-2007, 19:14
l'antivirus non può sopperire alla non presenza di un firewall,che discorsi sono??:mbe:

Mi spiego meglio...

So che un antivirus non puo' impedire ad un virus di entrare... Ma almeno dovrebbe impedirgli di autoeseguirsi...


Almeno questo era quello che pensavo delle protezioni real time...

Bugs Bunny
04-11-2007, 19:17
IL LOG DI HIJACKTHIS PROPRIO NON VUOI POSTARLO?

Sajiuuk Kaar
04-11-2007, 20:29
allora parto di siluri:
Fuori uno!
Logfile of HijackThis v1.99.1
Scan saved at 21.26.35, on 04/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\Programmi\TuneUp Utilities 2007\MemOptimizer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Programmi\DAEMON Tools\daemon.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\DOCUME~1\IceThorn\IMPOST~1\Temp\Rar$EX00.922\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMax] "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Programmi\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: hamachi.lnk = C:\Programmi\Hamachi\hamachi.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Programmi\File comuni\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Programmi\File comuni\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Programmi\File comuni\SourceTec\SWF Catcher\InternetExplorer.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programmi\File comuni\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FILECO~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe

E fuori 2!

Non esistono file con quei nomi ne il nod trova file con nomi strani. NON è il Gael originale. Di questo ne sono certo al 100%.

Io sicuramente non avevo il firewall di win attivo...


Pero' di certo avevo windows aggiornato (Il cd che avevo installava direttamente l'sp2 e la prima cosa che facevo era win update) e quindi non mi spiego come il virus potesse sfruttare il bug dell' RPC per entrare...


Eppure entrava... e nonostante avevo kaspersky attivo faceva in tempo a fottermi un po' di eseguibili...

Io avevo pensato in seguito che potesse essere la MorphXT la causa del problema, ma sajuuk usa la versione base di emule...

Quindi non so piu' cosa pensare...

Si ma 8, il tuo router di default blocca tutte le connessioni in entrata ti ricordo.

EDIT: Lo so che era un modem sbloccato a router ma il SW ce l'ha comunque. Ce l'ha pure sto modemino che ho io della alice il che è tutto un dire...

io vorrei sapere cosa scaricate da emule tu e i tuoi conoscenti.

è possibile vedere un log di hijackthis?

Demo, basi musicali e roba che purtroppo non si trova più nei negozi di videogiochi da anni... Che brutto quando si rovinano i CD...
Te che cosa ci vorresti scaricare?

IL LOG DI HIJACKTHIS PROPRIO NON VUOI POSTARLO?

Un sec... ero andato a mangiare e poi sono entrato subito in FEAR :P

Mi spiego meglio...
So che un antivirus non puo' impedire ad un virus di entrare... Ma almeno dovrebbe impedirgli di autoeseguirsi...

Quoto... Ora cmq stò criptando gli eseguibili che questo virus infetta di solito. Sembra non tocchi i file eseguibili di windows ma solo i programmi installati... Non so perchè ma mi puzza...

PacManZ
04-11-2007, 20:38
il mio "router" era un modem e non faceva un bel niente...


Ora ho l'HAG di fastweb e anche questo credo non blocchi nulla...

Bugs Bunny
04-11-2007, 20:48
ti dispiacerebbe comprimere un file infetto e mandarmelo?

ps usi una vecchia versione di java

Sajiuuk Kaar
04-11-2007, 21:59
ti dispiacerebbe comprimere un file infetto e mandarmelo?

ps usi una vecchia versione di java

Non riesco acomprimerli con winrar. Il file stesso mi nega l'operazione. Qualunque sia. Ho provato un po' con tutti i quarantenizzati ma niente.
MST Is Used By però mi dice che non è in uso. questo a causa del fatto che il file è danneggiato. Se vuoi lo rinomino e te lo mando. Quello FORSE lo posso fare.

lancetta
04-11-2007, 22:11
giusto per dovere di cronaca:è più importante il firewall che l'antivirus un pc in rete Xp pro senza firewall dura circa 4/6 minuiti eppoi viene infettato.

:rolleyes:

juninho85
04-11-2007, 22:24
Non riesco acomprimerli con winrar. Il file stesso mi nega l'operazione. Qualunque sia. Ho provato un po' con tutti i quarantenizzati ma niente.
MST Is Used By però mi dice che non è in uso. questo a causa del fatto che il file è danneggiato. Se vuoi lo rinomino e te lo mando. Quello FORSE lo posso fare.

sono in esecuzione

lancetta
04-11-2007, 22:25
un'altra cosa disabilitate la condivisione di file e stampanti (naturalmente se non servono) e il servizio net bios che ormai è un vecchio protocollo...

Sajiuuk Kaar
04-11-2007, 22:28
giusto per dovere di cronaca:è più importante il firewall che l'antivirus un pc in rete Xp pro senza firewall dura circa 4/6 minuiti eppoi viene infettato.

:rolleyes:

Giusto per dovere di cronaca:

"un pc in rete Xp pro senza ***SP2*** dura circa 4/6 minuiti eppoi viene infettato." Se non ha firewall ma ha SP2 non c'è problema...
Re: io uso una versione non originale di win XP pur avendo quella originale perchè quella non originale ha l'SP2 già installato; il che evita millemila casini con sasser, blaster e gael (infatti questo vi ricordo che NON E' il gaelicum. E' inutile suggerire metodi per combattere il gaelicum se il Tenga/gen è un virus completamente differente...). Questo virus ho appurato con una buona probabilità che si prende a causa del mulo (ne sono sicuro all'80% circa il che basta ed avanza; la prova è che dopo aver installato e-mule in ufficio per fare una prova dopo mezz'ora mi sono ritrovato stò mattoncino lego nella scarpa chiamato tenga/gen; ricordo che uso solo la versione originale del mulo.). In ufficio ho firewall del router; Comodo e pure Nod32. Però è entrato. Ripeto: secondo me si serve della lista degli ip connessi di e-mule del server in cui si trova e poi si autoinvia per netbios o rottinc*late giù di li per porte aperte e sotto un protocollo che i firewall identificano come sicuro ad esempio protocollo FTP... :mc: Sono teorie... Comunque il virus sembra stia "muando" inquanto ora i file il NOD non li ripara sempre. Prima non c'era file che non riparasse. Ora alcuni non riesce a ripararli.

sono in esecuzione

Si... se cliccarci su con il TDM me lo chiami esecuzione... se poi il file è rinominato in *.asd...

un'altra cosa disabilitate la condivisione di file e stampanti (naturalmente se non servono) e il servizio net bios che ormai è un vecchio protocollo...

Quello l'ho fatto; anche perchè la stampante attuale è buttabile...
Ho disattivato anche netbios...

lancetta
04-11-2007, 22:45
Giusto per dovere di cronaca:

"un pc in rete Xp pro senza ***SP2*** dura circa 4/6 minuiti eppoi viene infettato." Se non ha firewall ma ha SP2 non c'è problema...
Giustissimo...solo che io dicevo una cosa completamente differente,visto che l'altro utente ha ammesso che era senza firewall......che il sp2 sia più sicuro..è ovvio visto che introduce un firewall software che controlla però solo il traffico in entrata ma non in uscita.......
Per quanto riguarda invece la tua teoria posta adesso in questo modo,ovvero che sfrutti il traffico generato per l'uso di emule...bè effettivamente potrebbe essere.....

Riverside
05-11-2007, 09:48
Probabilmente con un firewall risolverei questo problema ma ne ho provati un fracco e buona parte mi causava problemi con gli installer e gli updater di varii giochi come, tanto per citarne uno, Trackmania Nations
Outpost Pro (trial 30 giorni); poi, se non ti crea rogne [improbabile] con gli installer, gli updater ed giochi, ne acquisti la licenza (ma, forse, preferisci scaricarla, cercandola in qualche remoto angolo del Web o da Emule :sbonk: )
……… Sono infetto da W32.Tenga/gen ………..
A parte tutte le ipotesi e supposizioni fin qui prodotte, mi chiedo come mai, a nessuno, sia venuto in mente di chiederti di pubblicare un Report di una scansione eseguita da Kaspersky scanner online.
Una mia idea sulla questione che hai proposto la avrei ….. ma sarei curioso di vedere, prima quel Report (a volte, Nod32 è un pò bastardello ...... vero socio Lancetta? ;) :cool: ).

lancetta
05-11-2007, 10:20
Outpost Pro (trial 30 giorni); poi, se non ti crea rogne [improbabile] con gli installer, gli updater ed giochi, ne acquisti la licenza (ma, forse, preferisci scaricarla, cercandola in qualche remoto angolo del Web o da Emule :sbonk: )

A parte tutte le ipotesi e supposizioni fin qui prodotte, mi chiedo come mai, a nessuno, sia venuto in mente di chiederti di pubblicare un Report di una scansione eseguita da Kaspersky scanner online.
Una mia idea sulla questione che hai proposto la avrei ….. ma sarei curioso di vedere, prima quel Report (a volte, Nod32 è un pò bastardello ...... vero socio Lancetta? ;) :cool: ).

come no! tutto puo essere, anche se non credo in questo...caso Socio:D :D :D

xcdegasp
05-11-2007, 10:47
Giusto per dovere di cronaca:

"un pc in rete Xp pro senza ***SP2*** dura circa 4/6 minuiti eppoi viene infettato." Se non ha firewall ma ha SP2 non c'è problema...
Re: io uso una versione non originale di win XP pur avendo quella originale perchè quella non originale ha l'SP2 già installato; il che evita millemila casini con sasser, blaster e gael (infatti questo vi ricordo che NON E' il gaelicum. E' inutile suggerire metodi per combattere il gaelicum se il Tenga/gen è un virus completamente differente...). Questo virus ho appurato con una buona probabilità che si prende a causa del mulo (ne sono sicuro all'80% circa il che basta ed avanza; la prova è che dopo aver installato e-mule in ufficio per fare una prova dopo mezz'ora mi sono ritrovato stò mattoncino lego nella scarpa chiamato tenga/gen; ricordo che uso solo la versione originale del mulo.). In ufficio ho firewall del router; Comodo e pure Nod32. Però è entrato. Ripeto: secondo me si serve della lista degli ip connessi di e-mule del server in cui si trova e poi si autoinvia per netbios o rottinc*late giù di li per porte aperte e sotto un protocollo che i firewall identificano come sicuro ad esempio protocollo FTP... :mc: Sono teorie... Comunque il virus sembra stia "muando" inquanto ora i file il NOD non li ripara sempre. Prima non c'era file che non riparasse. Ora alcuni non riesce a ripararli.

ovviamente sse scarichi la stessa psazzatura che scarichi a casa è ovvio che prendi il Tenga (o per meglio dire il Tanga) mi sembra ovvio!
ti posso assicurare che nessuno nel thread ufficiale di eMule si è preso il Tenga, io stesso non sono mai stato infetto di questo worm..

è evidente allora che scarichi la stessa porcheria più volte e ti reinfetti :rolleyes:

aggiungo che dovresti aggiornare IE anche se usi solo Firefox (inquanto aggiorna componenti condivisi al sistema operativo e con outlook) e il log che hai postato mi sembra incompleto...

Sajiuuk Kaar
05-11-2007, 11:34
ovviamente sse scarichi la stessa psazzatura che scarichi a casa è ovvio che prendi il Tenga (o per meglio dire il Tanga) mi sembra ovvio!
ti posso assicurare che nessuno nel thread ufficiale di eMule si è preso il Tenga, io stesso non sono mai stato infetto di questo worm..

è evidente allora che scarichi la stessa porcheria più volte e ti reinfetti :rolleyes:

aggiungo che dovresti aggiornare IE anche se usi solo Firefox (inquanto aggiorna componenti condivisi al sistema operativo e con outlook) e il log che hai postato mi sembra incompleto...

Se vuoi rifaccio la scansione in questo momento e ti prendo pure screen ma il log è quello. Ne più ne meno. Comunque disabilito dall'avvio automatico parecchie cose che sono inutili o uso raramente e quelle poche volte che le uso le avvio manualmente. Ho sempre fatto così per non avere fottii e fottii di processi attivi.
Comunque in ufficio ho scaricato roba completamente differente da quella che scarico a casa proprio perchè era una prova. anche roba che non si dovrebbe scaricare legalmente e che poi, dopo la prova ho cancellato. Mi serviva per finire nella coda di upload di qualcuno. L'ho fatto per vedere se la teoria degli elenchi ip del mulo era valida. E a quanto pare lo era.

Riguardo ad i.e.: provo ad aggiornarlo...

Sajiuuk Kaar
05-11-2007, 11:37
Outpost Pro (trial 30 giorni); poi, se non ti crea rogne [improbabile] con gli installer, gli updater ed giochi, ne acquisti la licenza (ma, forse, preferisci scaricarla, cercandola in qualche remoto angolo del Web o da Emule :sbonk: )

A parte tutte le ipotesi e supposizioni fin qui prodotte, mi chiedo come mai, a nessuno, sia venuto in mente di chiederti di pubblicare un Report di una scansione eseguita da Kaspersky scanner online.
Una mia idea sulla questione che hai proposto la avrei ….. ma sarei curioso di vedere, prima quel Report (a volte, Nod32 è un pò bastardello ...... vero socio Lancetta? ;) :cool: ).

Ho provato quando me l'ero preso qualche settimana fa, me l'aveva suggerito anche pacmanz. Ieri torno dopo una settimana che ho lasciato aperto il mulo e ho trovato qualche file infetto... Medesimo risultato. W32.tenga/gen
Il virus è quello e c'è poco da fare. Cmq non trova file di sistema infetti. solo alcuni dei programmi.

Riverside
06-11-2007, 09:47
Hai aperto questa discussione il 15 ottobre; ce lo hai triturato come si fa con il prezzemolo per ben 45 reply.
Credo, anche, ti siano state rese tutte le informazioni e le indicazioni del caso per cercare di risolvere il problema che hai esposto.
Ti ho chiesto di pubblicare un Report di una scansione eseguita online, e la tua risposta è:
Ho provato quando me l'ero preso qualche settimana fa, me l'aveva suggerito anche pacmanz. Ieri torno dopo una settimana che ho lasciato aperto il mulo e ho trovato qualche file infetto... Medesimo risultato. W32.tenga/gen
Francamente, che la scansione online tu la abbia eseguita una settimana fa, mi interessa zero: mi interessa, al contrario, vederne un Report.
Ho anche sottolineato (e non a caso), che Nod32, a volte è un pò bastardo …… ma nulla, continui ad insistere sulla tua tesi (tra l’altro, se ne sei così convinto, non si capisce per quale ragione tu abbia aperto questa discussione ….. ah ….. si ….. dimenticavo ........ per rimuovere l’infezione :D ).
Sei certo di aver contratto e di continuare a contrarla, con una frequenza impressionante, quella infezione, scaricando da Emule?.
Hai due soluzioni:
1) disinstalli Emule e ci fai una croce, definitiva, sopra (suggerimento gratis);
2) impari a configurare Emule come deve essere configurato ed installi un firewall (straconsigliato); perché, anche tu non sei diverso da molti altri che, evitano, accuratamente, di installarne uno [i fireawall sono software di sicurezza, non caramelle] convinti che senza, Emule scarichi alla velocità della luce.
Ora decidi tu: o continui a perdere e farci perdere del tempo (che togli ad altri utenti che segnalano problemi, spesso più seri del tuo) oppure, pubblichi il Report che ti è stato richiesto.
Il virus è quello e c'è poco da fare. Cmq non trova file di sistema infetti. solo alcuni dei programmi.
Non ne dubito ma, scusa la franchezza, inizio seriamente a pensare che, per quanto ti riguarda, il virus più pericoloso per te, sia te medesimo.

Sajiuuk Kaar
06-11-2007, 13:23
Francamente, che la scansione online tu la abbia eseguita una settimana fa, mi interessa zero: mi interessa, al contrario, vederne un Report.

Trovati 3 virus... toh... una cosa non aveva beccato il nod, un trojannino, il motivo è che era già quarantinato... quindi lo aveva cattato dai tempi di Cesare...

Ho anche sottolineato (e non a caso), che Nod32, a volte è un pò bastardo

Non hai detto in che senso. Capisco solo che non capisco.

ma nulla, continui ad insistere sulla tua tesi (tra l’altro, se ne sei così convinto, non si capisce per quale ragione tu abbia aperto questa discussione ….. ah ….. si ….. dimenticavo ........ per rimuovere l’infezione :D ).

No, per capire come cavolo entra. Non per niente sto' continuando a proporre quell'ipotesi... Certo, ai tempi con anti-vir non lo toglieva, il nod poi riusciva a disinfettare. Ora manco il nod lo toglie...

Sei certo di aver contratto e di continuare a contrarla, con una frequenza impressionante, quella infezione, scaricando da Emule?

oramai si...

Hai due soluzioni:
1) disinstalli Emule e ci fai una croce, definitiva, sopra (suggerimento gratis);

preferirei evitare... Idem di passare a vista finchè non mettono a posto i problemi con la lan e soprattutto non lo ALLEGGERISCONO UN BEL PO'.

2) impari a configurare Emule come deve essere configurato

Ti assicuro che è configurato con la perfezione di un diamante ;)

ed installi un firewall (straconsigliato);

Suggerimenti su qualcosa hce no nrompa con praticamenet tutto?

perché, anche tu non sei diverso da molti altri che, evitano, accuratamente, di installarne uno [i fireawall sono software di sicurezza, non caramelle] convinti che senza, Emule scarichi alla velocità della luce.

Non è per quello ^_^ Semplicemente per la maggior parte dei giochi online da problemi quando gli hackfinder provano a connettersi ad un server diverso da quello del gioco per verificare che il client non sia modificato ^^

Ora decidi tu: o continui a perdere e farci perdere del tempo (che togli ad altri utenti che segnalano problemi, spesso più seri del tuo) oppure, pubblichi il Report che ti è stato richiesto.

Spe che arriva. Fra X ore, quando finisce...

Non ne dubito ma, scusa la franchezza, inizio seriamente a pensare che, per quanto ti riguarda, il virus più pericoloso per te, sia te medesimo.

Oppure certi commenti inutili che leggo e che quoto pure per sottolineare il pericolo che si corre a leggerli...

Sajiuuk Kaar
06-11-2007, 13:52
KASPERSKY ONLINE SCANNER REPORT
Tuesday, November 06, 2007 2:49:27 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/11/2007
Kaspersky Anti-Virus database records: 452320
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target Folders
C:\
Scan Statistics
Total number of scanned objects 50547
Number of viruses found 2
Number of infected objects 16
Number of suspicious objects 0
Duration of the scan process 00:25:27

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\IceThorn\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\IceThorn\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\cert8.db Object is locked skipped
C:\Documents and Settings\IceThorn\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\IceThorn\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\history.dat Object is locked skipped
C:\Documents and Settings\IceThorn\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\key3.db Object is locked skipped
C:\Documents and Settings\IceThorn\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\parent.lock Object is locked skipped
C:\Documents and Settings\IceThorn\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\search.sqlite Object is locked skipped
C:\Documents and Settings\IceThorn\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Cronologia\History.IE5\MSHist012007110620071107\index.dat Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Dati applicazioni\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Dati applicazioni\Microsoft\Windows Live Contacts\[email protected]\real\members.stg Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Dati applicazioni\Microsoft\Windows Live Contacts\[email protected]\shadow\members.stg Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\xdewmlxs.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Temp\~DF1A9A.tmp Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Temp\~DF1A9F.tmp Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Temp\~DFF67E.tmp Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Temp\~DFF6FD.tmp Object is locked skipped
C:\Documents and Settings\IceThorn\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\IceThorn\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\IceThorn\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Programmi\ESET\cache\CACHE.NDB Object is locked skipped
C:\Programmi\ESET\infected\0MDI11AA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\2QXRPTAA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\B5NPMSDA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\DB5XWWDA.NQF Infected: Backdoor.Win32.VB.boa skipped
C:\Programmi\ESET\infected\FT0RMYDA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\GLEQVQAA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\IATSC0DA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\MLOEULCA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\MWWOWNCA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\NEE5XRBA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\NPZWKEAA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\NVC3MJAA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\P3LUZWBA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\PTIZFICA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\WNDLLSDA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\infected\XWCCKHBA.NQF Infected: Virus.Win32.Tenga.b skipped
C:\Programmi\ESET\logs\virlog.dat Object is locked skipped
C:\Programmi\ESET\logs\warnlog.dat Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.

Taratata tataaaaaa! che caso... il nod aveva già pulito tutto...
N.B.:\Programmi\ESET\infected\*.NQF Infected: Virus.Win32.Tenga.b skipped sono i file in quarantena del nod...

Bugs Bunny
06-11-2007, 14:24
visto che ti rifiuti di tirare fuori un file dalla quarantena per spedirmelo, mi rifiuto di aiutarti ulteriormente.
allora o apri e scarichi sempre lo stesso file infetto o il tuo pc non è protetto adeguatamente. Inoltre outpost dovrebbe bloccare un processo che tenta di modificarne altri.
tenga non si può propagare tramite emule altrimenti 3/4 dei pc sarebbe infetto

PacManZ
06-11-2007, 14:27
Mi diceva che non ci riusciva...

Chill-Out
06-11-2007, 14:28
Il file di registro lo devi pulire a manina.

Sajiuuk Kaar
06-11-2007, 14:29
visto che ti rifiuti di tirare fuori un file dalla quarantena per spedirmelo, mi rifiuto di aiutarti ulteriormente.
allora o apri e scarichi sempre lo stesso file infetto o il tuo pc non è protetto adeguatamente. Inoltre outpost dovrebbe bloccare un processo che tenta di modificarne altri.
tenga non si può propagare tramite emule altrimenti 3/4 dei pc sarebbe infetto

MA PORCO CANE! NON ME LO FA NE COMPATTARE NE NIENTE, L'HO GIA' DETTO! COME TE LO MANDO??? ASSIEME A TUTTO IL COMPUTER???
EDIT3: non ho detto che SI INVIA TRAMITE E-MULE. Ma che usa la lista dei client connessi di e-mule per inviarsi in qualche modo. Se è derivato dal gael probabilmente tramite netbios. Che l'altro gg ho disattivato.

EDIT1:
Il file di registro lo devi pulire a manina.

Che file di registro scusa? O.o

EDIT2: notare che l'enciclopedia dei virus di kaspersky ha in lista tenga.a e tenga.b per l'"a" c'è la descrizione. Infatti QUELLO E' IL GAEL. Per il B non ci sono notizie. Quello è il tenga/gen.

PacManZ
06-11-2007, 14:51
Se digitate Virus.Win32.Tenga.b su google trovate una marea di gente che non ha risolto il problema...

Sajiuuk Kaar
06-11-2007, 14:57
Se digitate Virus.Win32.Tenga.b su google trovate una marea di gente che non ha risolto il problema...

Questo perchè non è il gael originale, esattamente come avevo detto. Il problema ora è: cos'è sta variante della grande schifezza tris? Come eliminarla???
N.B. ELIMINARLA, non nel senso cancello e aspetto che torni... cancello e NON DEVE TORNARE.

Chill-Out
06-11-2007, 14:59
Che file di registro scusa? O.o


sul sito della ESET ci sono le istruzioni

W32/Gael.worm.gen (McAfee), W32.Licum (Symantec), Win32.Gael.3666 (Doctor Web), W32/Tenga-A (Sophos), W32/Stanit (H+BEDV), W32/Tenga.3666 (FRISK), Win32/Gaelicum.A (Grisoft), Win32.Gael.3666 (SOFTWIN), Worm.Tenga.A (ClamAV), W32/Tenga.A (Panda), Win32/Tenga.B (Eset)

Riverside
06-11-2007, 15:16
Questo perchè non è il gael originale, esattamente come avevo detto. Il problema ora è: cos'è sta variante della grande schifezza tris? Come eliminarla???
N.B. eliminarla, non nel senso cancello e aspetto che torni... cancello e non deve tornare.
Se, al posto di alzare la voce (tralascio il resto) ti prendessi la briga di interpretare il Report che, finalmente, hai pubblicato, sapresti:
1) dove mettere le mani;
2) come procedere;
3) risolvere il problema, alla fonte.

Inizia con il disattivare il Ripristino configuazione di sistema e svuota, completamente C:\Programmi\ESET\infected e poi, esegui una scansione online da Bitdefender e rimuovi tutti quello che trova.

Poi segui i suggerimenti che ti ha fornito Chill.
E dammi retta, installa un Firewall.

P.S.: Socio Lancetta, che ti avevo detto??? ;)

Bugs Bunny
06-11-2007, 15:19
per curiosità... quante partizioni hai? le scansioni tutte?

sicuro di non avere il tenga su una pendrive o su un cd di backup (dal quale ti reinfetteresti)


copiare un file infetto in un'altra cartella e poi compattarlo no eh?

reinstalla outpost e tieni anti-leak e controllo componenti attivo. Ovviamente non devi disattivarli solo perchè rompono. Dovrebbe bloccare l'infezione dei files.

Poi se vuoi continuare a tenere questo catastrofico ed ignoto virus senza ascoltare i consigli... arrangiati

Sajiuuk Kaar
06-11-2007, 15:20
sul sito della ESET ci sono le istruzioni

W32/Gael.worm.gen (McAfee), W32.Licum (Symantec), Win32.Gael.3666 (Doctor Web), W32/Tenga-A (Sophos), W32/Stanit (H+BEDV), W32/Tenga.3666 (FRISK), Win32/Gaelicum.A (Grisoft), Win32.Gael.3666 (SOFTWIN), Worm.Tenga.A (ClamAV), W32/Tenga.A (Panda), Win32/Tenga.B (Eset)

peccato che:
Win32/Tenga.B (Eset) non è Win32.tenga/gen; il virus che ho io...
per curiosità... quante partizioni hai? le scansioni tutte?
sicuro di non avere il tenga su una pendrive o su un cd di backup (dal quale ti reinfetteresti)
copiare un file infetto in un'altra cartella e poi compattarlo no eh?

Nelle altre non ha trovato niente, faccio ripartire le scansioni per le altre 4 partizioni?
comunque: non posso ne copiarlo, ne incollarlo, ne comprimerlo, ne giocarci a calcio, ne a basket, ne niente. posso solo cancellarlo dopo il ripristino. PacManZ in msn mi ha detto che potrebbero essere settori del file danneggiati. Non mi sento di escluderlo, è possibile. Dovrebbe essere l'unico caso in cui winrar non puo' nemmeno tentare di comprimere un file... infatti non ci riesce...
Comunque ho controllato chiavetta e lettore mp3. Niente di niente. Anche perchè: 1- nella chiavetta non ho eseguibili, 2- nel lettore chissà perchè ci sono solo file audio. E le cose sono buone e giuste. Cmq per essere sicuro ho fatto una scansione e non ho trovato niente.

Se, al posto di alzare la voce (tralascio il resto) ti prendessi la briga di interpretare il Report che, finalmente, hai pubblicato, sapresti:
1) dove mettere le mani;
2) come procedere;
3) risolvere il problema, alla fonte.

1- non ci sono chiavi di registro nell'elenco e cmq so usare regedit.
2- è una derivazione di "dove mettere le mani" perchè per mettere le mani in qualcosa devi far qualcosa.
3- Formattare? E' l'ultima cosa che vorrei fare...

Inizia con il disattivare il Ripristino configuazione di sistema e svuota, completamente C:\Programmi\ESET\infected e poi, esegui una scansione online da Bitdefender e rimuovi tutti quello che trova.

Che è disattivato da 3 mesi... ora cancello anche la quarantena di NOD (sarebbero quei file se non l'hai capito)

Poi segui i suggerimenti che ti ha fornito Chill.
E dammi retta, installa un Firewall.

Chill ha fatto un piccolo errore. Quello che la eset, i produttori chiamano Win32/Tenga.B non è win32.tenga/gen... sono 2 virus differenti... Perchè DEVE essere il gael. NON E' IL GAEL... '-.-
Riguardo al firewall: Suggeriscimene uno decente e se ne riparla di installarlo... e due...

P.S.: Socio Lancetta, che ti avevo detto??? ;)

Continuo a non capire.

Riverside
06-11-2007, 15:33
Riguardo al firewall: Suggeriscimene uno decente e se ne riparla di installarlo... e due...
E due cosa???? leggi il post n° 41 (di ieri) e troverai il mio suggerimento in merito al firewall da installare.
Il tuo problema non è non capire è che non leggi.
Ah, piccola precisazone: Chill non ha, affatto sbagliato.
Ulteriore precisazione: io non ti ho mai suggerito di mettere le mani nel Registro di sistema (con quel dove mettere le mani, intendevo altro: ovvero, da dove iniziare).

Chill-Out
06-11-2007, 15:34
Chill ha fatto un piccolo errore. Quello che la eset, i produttori chiamano Win32/Tenga.B non è win32.tenga/gen... sono 2 virus differenti... Perchè DEVE essere il gael. NON E' IL GAEL... '-.-
Riguardo al firewall: Suggeriscimene uno decente e se ne riparla di installarlo... e due...

rileggiti quello che hai scritto al post #48 e chiudo

Cheers

Edit: thx River

Sajiuuk Kaar
06-11-2007, 15:40
E due cosa???? leggi il post n° 41 (di ieri) e troverai il mio suggerimento in merito al firewall da installare.
Il tuo problema non è non capire è che non leggi.

Hai ragione quel suggerimento mi è sfuggito...
Pensavo scherzassi inquanto mi hai praticamente suggerito di crakkarlo che è una cosa non ammessa su sto foro...
C'è qualcosa di completamente free?

[QUOTE=Riverside;19504089]Ah, piccola precisazone: Chill non ha, affatto sbagliato.

Rileggi bene. Cos'è che ha fatto quella scansione? la Eset che antivirus supporta? Ti risparmio la fatica: la scansione è quella di kaspersky, quindi la tag è di kaspersky, c'è un'omonimia con una nod 32 ma non si tratta dello stesso virus...

Ulteriore precisazione: io non ti ho mai suggerito di mettere le mani nel Registro di sistema (con quel dove mettere le mani, intendevo altro: ovvero, da dove iniziare).

Ah allora ho fatto male a cercare in ./currentversion/run ./currentversion/runonce per qualche chiave infame...

rileggiti quello che hai scritto al post #48 e chiudo

Cheers

Edit: thx River

Da quando kaspersky è della ESET???
NOD32 è della ESET...
Quella è la scansione fatta con kaspersky... che giustamente becca il virus con quella tag. NOD 32 che, ripeto, è della ESET lo becca come Win32.Tenga/gen

Chill-Out
06-11-2007, 15:48
Da quando kaspersky è della ESET???
NOD32 è della ESET...
Quella è la scansione fatta con kaspersky... che giustamente becca il virus con quella tag. NOD 32 che, ripeto, è della ESET lo becca come Win32.Tenga/gen

Mai detto che Kaspersky e della Eset, trovami il post e qui chiudo veramente.
Voglio essere buono :D Kaspersky lo rileva come Virus.Multi.Tenga.b o Virus.Win32.Tenga.b = Win32/Tenga.B (Eset)

Sajiuuk Kaar
06-11-2007, 15:56
Mai detto che Kaspersky e della Eset, trovami il post e qui chiudo veramente.
Voglio essere buono :D Kaspersky lo rileva come Virus.Multi.Tenga.b o Virus.Win32.Tenga.b = Win32/Tenga.B (Eset)

Non ho mai detto che l'hai detto ma semplicemente che hai fatto confusione.

sul sito della ESET ci sono le istruzioni

W32/Gael.worm.gen (McAfee), W32.Licum (Symantec), Win32.Gael.3666 (Doctor Web), W32/Tenga-A (Sophos), W32/Stanit (H+BEDV), W32/Tenga.3666 (FRISK), Win32/Gaelicum.A (Grisoft), Win32.Gael.3666 (SOFTWIN), Worm.Tenga.A (ClamAV), W32/Tenga.A (Panda), Win32/Tenga.B (Eset)

Quello che trova kaspersky è quello che la eset chiama così. Però non è quello che mi dice nod, il quale mi dice che si chiama win32.tenga/gen.
L'avevo scritto in prima pagina già...

citando:
Guarda che NON E' ***QUEL*** "tenga"...
Sono infetto da W32.Tenga/gen che è una variante astrusa del Gael originale... *forse*... se non è uno completamente diverso che si diffonde in maniera completamente diversa come penso e ripeto penso... non sono sicuro di una mazza... neanche il pc è sicuro a quanto pare... L'unica cosa di cui sono sicuro è: "Apro e-mule. Lascio aperto 1 giorno o 2 = becco il tenga". Probabilmente con un firewall risolverei questo problema ma ne ho provati un fracco e buona parte mi causava problemi con gli installer e gli updater di varii giochi come, tanto per citarne uno, Trackmania Nations.

C'è comunque un'altra ipotesi. Io sono stao infettato in totale 3 volte. la prima ho formattato, la seconda è quando avevo iniziato il post. La terza Probabilmente settimana scorsa che me ne sono andato da casa lasciando pc connesso e mulo aperto. La possibilità a cui non avevo pensato fino ad adesso è: il virus che ho preso in questi giorni non è lo stesso di quando avevo aperto il thread.

Altra cosa. Se fosse il gael dropperebbe il trojan. Invece quei file io non li ho mai visti in un report di scansione.

Riverside
06-11-2007, 15:58
Hai ragione quel suggerimento mi è sfuggito...
Pensavo scherzassi inquanto mi hai praticamente suggerito di crakkarlo che è una cosa non ammessa su sto foro...
Bene ora è provato che non sai leggere o (leggi come e quel che ti pare):
Le regole del Forum le conosco bene: io ti ho suggerito, esattamente questo:
Outpost Pro (trial 30 giorni); poi, se non ti crea rogne [improbabile] con gli installer, gli updater ed giochi, ne acquisti la licenza (ma, forse, preferisci scaricarla, cercandola in qualche remoto angolo del Web o da Emule :sbonk: )

A questo punto mi aggrego a Chill, e ti saluto.

Sajiuuk Kaar
06-11-2007, 16:01
Bene ora è provato che non sai leggere o (leggi come e quel che ti pare):
Le regole del Forum le conosco bene: io ti ho suggerito, esattamente questo:


A questo punto mi aggrego a Chill, e ti saluto.

e si che l'hai pure quotato:

(ma, forse, preferisci scaricarla, cercandola in qualche remoto angolo del Web o da Emule

edit: se era riferito alla mia firma, (che dovrebbe essere ironica ma purtroppo rispecchia la realtà) non era divertente. e la prova è che me l'hanno pure dovuta spiegare '-.-

xcdegasp
06-11-2007, 16:42
io ribadisco che questo virus sfrutta la vulnerabilità RPC come qui indicato:
http://www.wilderssecurity.com/showthread.php?t=157625

cmq hai provato a fare la scansione con quello suggerito nelle Regole di Sezione?
ossia con a-squared-free, prevx CSI, dr.web cureIT

Sajiuuk Kaar
06-11-2007, 22:32
io ribadisco che questo virus sfrutta la vulnerabilità RPC come qui indicato:
http://www.wilderssecurity.com/showthread.php?t=157625

Questo che ho preso l'altro gg può darsi; non so cosa sia. Quello di inizio topic... no...

cmq hai provato a fare la scansione con quello suggerito nelle Regole di Sezione?
ossia con a-squared-free, prevx CSI, dr.web cureIT

Si ed i risultati sono i medesimi. Non trovano niente. Avendo cancellato anche la quarantena di NOD non trovano manco i quarantenati come virus. E' una cosa inspiegabile. Entra, danneggia qualche file e poi sparisce...

xcdegasp
06-11-2007, 22:46
hai già provato WWDC?

Sajiuuk Kaar
06-11-2007, 22:49
hai già provato WWDC?

Quello no, anche perchè non riesco a trovarlo... e poi se non ho capito male ha poco a che fare con win...

xcdegasp
06-11-2007, 23:06
Quello no, anche perchè non riesco a trovarlo... e poi se non ho capito male ha poco a che fare con win...

sinceramente è un programma che ha tutto a che fare con windows visto che ti dice che porte critiche sono aperte e in un click le chiudi ;)
http://www.firewallleaktester.com/wwdc.htm

Sajiuuk Kaar
06-11-2007, 23:11
sinceramente è un programma che ha tutto a che fare con windows visto che ti dice che porte critiche sono aperte e in un click le chiudi ;)
http://www.firewallleaktester.com/wwdc.htm

non l'avevo mai sentito, ty per il link :)
Stò rifacendo la scansione con gmer. Ecco il risultato:

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-11-07 00:10:30
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.13 ----

SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey

---- Kernel code sections - GMER 1.0.13 ----

? C:\WINDOWS\system32\drivers\sptd.sys Impossibile accedere al file. Il file è utilizzato da un altro processo.
.text USBPORT.SYS!DllUnload B9EC362C 5 Bytes JMP 8995B1C8
? System32\Drivers\aox0pxsk.SYS Impossibile trovare il file specificato.
? C:\WINDOWS\system32\Drivers\PROCEXP100.SYS Impossibile trovare il file specificato.

---- User code sections - GMER 1.0.13 ----

.text C:\Programmi\MSN Messenger\msnmsgr.exe[1260] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 004DE392 C:\Programmi\MSN Messenger\msnmsgr.exe

---- Kernel IAT/EAT - GMER 1.0.13 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74EDAD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74EDC1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74EDB9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74EE748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74EE61E] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F750329A] sptd.sys

---- User IAT/EAT - GMER 1.0.13 ----

IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01B773CC] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\PROGRA~1\MOZILL~2\FIREFOX.EXE[1000] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [01B77376] C:\PROGRA~1\MOZILL~2\extensions\[email protected]\components\FULLSOFT.DLL

---- Devices - GMER 1.0.13 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 89B971E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 89B971E8

AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [B5157FE2] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [B5157BEC] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [B51583D4] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [B515867A] amon.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [B515867A] amon.sys

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 87717790
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 87717790
Device \Driver\usbehci \Device\USBFDO-9 IRP_MJ_CREATE 899431E8
Device \Driver\usbehci \Device\USBFDO-9 IRP_MJ_CLOSE 899431E8
Device \Driver\usbehci \Device\USBFDO-9 IRP_MJ_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBFDO-9 IRP_MJ_INTERNAL_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBFDO-9 IRP_MJ_POWER 899431E8
Device \Driver\usbehci \Device\USBFDO-9 IRP_MJ_SYSTEM_CONTROL 899431E8
Device \Driver\usbehci \Device\USBFDO-9 IRP_MJ_PNP 899431E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 8995A1E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 89B991E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 89B991E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 89B991E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 89B991E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 89B991E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 89B991E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 89B991E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 89B991E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 89B991E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 8995A1E8
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_CREATE 899431E8
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_CLOSE 899431E8
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_POWER 899431E8
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 899431E8
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_PNP 899431E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CREATE 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CLOSE 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_POWER 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_PNP 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_CREATE 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_CLOSE 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_POWER 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_SYSTEM_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_PNP 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_CREATE 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_CLOSE 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_INTERNAL_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_POWER 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_SYSTEM_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_PNP 8995A1E8
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_CREATE 899431E8
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_CLOSE 899431E8
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_INTERNAL_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_POWER 899431E8
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_SYSTEM_CONTROL 899431E8
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_PNP 899431E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 89C0B1E8
Device \Driver\usbohci \Device\USBPDO-7 IRP_MJ_CREATE 898F81E8
Device \Driver\usbohci \Device\USBPDO-7 IRP_MJ_CLOSE 898F81E8
Device \Driver\usbohci \Device\USBPDO-7 IRP_MJ_DEVICE_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBPDO-7 IRP_MJ_INTERNAL_DEVICE_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBPDO-7 IRP_MJ_POWER 898F81E8
Device \Driver\usbohci \Device\USBPDO-7 IRP_MJ_SYSTEM_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBPDO-7 IRP_MJ_PNP 898F81E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6D0644A2-A7C4-494A-9813-93E92BD58811} IRP_MJ_CREATE 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6D0644A2-A7C4-494A-9813-93E92BD58811} IRP_MJ_CLOSE 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6D0644A2-A7C4-494A-9813-93E92BD58811} IRP_MJ_DEVICE_CONTROL 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6D0644A2-A7C4-494A-9813-93E92BD58811} IRP_MJ_INTERNAL_DEVICE_CONTROL 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6D0644A2-A7C4-494A-9813-93E92BD58811} IRP_MJ_CLEANUP 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6D0644A2-A7C4-494A-9813-93E92BD58811} IRP_MJ_PNP 8940D1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 89C0B1E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 899311E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 899311E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 899311E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 899311E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 899311E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 899311E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 899311E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 899311E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 899311E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 899311E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 899311E8
Device \Driver\usbohci \Device\USBPDO-8 IRP_MJ_CREATE 898F81E8
Device \Driver\usbohci \Device\USBPDO-8 IRP_MJ_CLOSE 898F81E8
Device \Driver\usbohci \Device\USBPDO-8 IRP_MJ_DEVICE_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBPDO-8 IRP_MJ_INTERNAL_DEVICE_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBPDO-8 IRP_MJ_POWER 898F81E8
Device \Driver\usbohci \Device\USBPDO-8 IRP_MJ_SYSTEM_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBPDO-8 IRP_MJ_PNP 898F81E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 89C0B1E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 899311E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 899311E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 899311E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 899311E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 899311E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 899311E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 899311E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 899311E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 899311E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 899311E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 899311E8
Device \Driver\usbehci \Device\USBPDO-9 IRP_MJ_CREATE 899431E8
Device \Driver\usbehci \Device\USBPDO-9 IRP_MJ_CLOSE 899431E8
Device \Driver\usbehci \Device\USBPDO-9 IRP_MJ_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBPDO-9 IRP_MJ_INTERNAL_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBPDO-9 IRP_MJ_POWER 899431E8
Device \Driver\usbehci \Device\USBPDO-9 IRP_MJ_SYSTEM_CONTROL 899431E8
Device \Driver\usbehci \Device\USBPDO-9 IRP_MJ_PNP 899431E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLOSE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_POWER 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SYSTEM_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_PNP 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CLOSE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_POWER 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SYSTEM_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_PNP 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CREATE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CLOSE 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_POWER 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SYSTEM_CONTROL 89C0A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_PNP 89C0A1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_READ 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_WRITE 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_FLUSH_BUFFERS 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SHUTDOWN 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CLEANUP 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_POWER 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SYSTEM_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_PNP 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_CREATE 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_READ 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_WRITE 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_FLUSH_BUFFERS 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_SHUTDOWN 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_CLEANUP 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_POWER 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_SYSTEM_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_PNP 89C0B1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 8940D1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 8940D1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 8940D1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 8940D1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 8940D1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 8940D1E8
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_CREATE [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_CREATE_NAMED_PIPE [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_CLOSE [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_READ [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_WRITE [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_QUERY_INFORMATION [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_SET_INFORMATION [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_QUERY_EA [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_SET_EA [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_FLUSH_BUFFERS [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_QUERY_VOLUME_INFORMATION [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_SET_VOLUME_INFORMATION [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_DIRECTORY_CONTROL [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_FILE_SYSTEM_CONTROL [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_DEVICE_CONTROL [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_INTERNAL_DEVICE_CONTROL [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_SHUTDOWN [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_LOCK_CONTROL [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_CLEANUP [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_CREATE_MAILSLOT [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_QUERY_SECURITY [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_SET_SECURITY [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_POWER [F74FCEA8] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_SYSTEM_CONTROL [F75202C8] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_DEVICE_CHANGE [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_QUERY_QUOTA [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_SET_QUOTA [F7523B0E] sptd.sys
Device \Driver\PCI_NTPNP3186 \Device\0000004c IRP_MJ_PNP [F7521238] sptd.sys
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 8940D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 8940D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 8940D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 8940D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 8940D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{AB9159D6-1890-49D7-A77C-4C9AC1E98E39} IRP_MJ_CREATE 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{AB9159D6-1890-49D7-A77C-4C9AC1E98E39} IRP_MJ_CLOSE 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{AB9159D6-1890-49D7-A77C-4C9AC1E98E39} IRP_MJ_DEVICE_CONTROL 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{AB9159D6-1890-49D7-A77C-4C9AC1E98E39} IRP_MJ_INTERNAL_DEVICE_CONTROL 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{AB9159D6-1890-49D7-A77C-4C9AC1E98E39} IRP_MJ_CLEANUP 8940D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{AB9159D6-1890-49D7-A77C-4C9AC1E98E39} IRP_MJ_PNP 8940D1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CREATE 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CLOSE 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_POWER 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_PNP 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CREATE 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CLOSE 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_POWER 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_PNP 8995A1E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 893F71E8
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_CREATE 899431E8
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_CLOSE 899431E8
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_POWER 899431E8
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL 899431E8
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_PNP 899431E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 893F71E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 893F71E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CREATE 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CLOSE 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_POWER 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_SYSTEM_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_PNP 8995A1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 89C0B1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 89C0B1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 89C0B1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 89C0B1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 89C0B1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 89C0B1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 89C0B1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 89C0B1E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 89C0B1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_CREATE 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_CLOSE 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_POWER 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_SYSTEM_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_PNP 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_CREATE 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_CLOSE 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_INTERNAL_DEVICE_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_POWER 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_SYSTEM_CONTROL 8995A1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_PNP 8995A1E8
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_CREATE 899431E8
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_CLOSE 899431E8
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_INTERNAL_DEVICE_CONTROL 899431E8
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_POWER 899431E8
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_SYSTEM_CONTROL 899431E8
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_PNP 899431E8
Device \Driver\usbohci \Device\USBFDO-7 IRP_MJ_CREATE 898F81E8
Device \Driver\usbohci \Device\USBFDO-7 IRP_MJ_CLOSE 898F81E8
Device \Driver\usbohci \Device\USBFDO-7 IRP_MJ_DEVICE_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBFDO-7 IRP_MJ_INTERNAL_DEVICE_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBFDO-7 IRP_MJ_POWER 898F81E8
Device \Driver\usbohci \Device\USBFDO-7 IRP_MJ_SYSTEM_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBFDO-7 IRP_MJ_PNP 898F81E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1 IRP_MJ_CREATE 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1 IRP_MJ_CLOSE 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1 IRP_MJ_DEVICE_CONTROL 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1 IRP_MJ_INTERNAL_DEVICE_CONTROL 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1 IRP_MJ_POWER 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1 IRP_MJ_SYSTEM_CONTROL 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1 IRP_MJ_PNP 898B01E8
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 IRP_MJ_CREATE 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 IRP_MJ_CLOSE 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 IRP_MJ_POWER 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 IRP_MJ_PNP 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1 IRP_MJ_CREATE 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1 IRP_MJ_CLOSE 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1 IRP_MJ_DEVICE_CONTROL 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1 IRP_MJ_POWER 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1 IRP_MJ_SYSTEM_CONTROL 89B981E8
Device \Driver\JRAID \Device\Scsi\JRAID1 IRP_MJ_PNP 89B981E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1Port5Path0Target0Lun0 IRP_MJ_CREATE 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1Port5Path0Target0Lun0 IRP_MJ_CLOSE 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1Port5Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1Port5Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1Port5Path0Target0Lun0 IRP_MJ_POWER 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1Port5Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 898B01E8
Device \Driver\aox0pxsk \Device\Scsi\aox0pxsk1Port5Path0Target0Lun0 IRP_MJ_PNP 898B01E8
Device \Driver\usbohci \Device\USBFDO-8 IRP_MJ_CREATE 898F81E8
Device \Driver\usbohci \Device\USBFDO-8 IRP_MJ_CLOSE 898F81E8
Device \Driver\usbohci \Device\USBFDO-8 IRP_MJ_DEVICE_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBFDO-8 IRP_MJ_INTERNAL_DEVICE_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBFDO-8 IRP_MJ_POWER 898F81E8
Device \Driver\usbohci \Device\USBFDO-8 IRP_MJ_SYSTEM_CONTROL 898F81E8
Device \Driver\usbohci \Device\USBFDO-8 IRP_MJ_PNP 898F81E8
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_READ 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 87717790
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 87717790

AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [B5157FE2] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [B5157BEC] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [B51583D4] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [B515867A] amon.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [B515867A] amon.sys

Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 896823A8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 896823A8
---- Processes - GMER 1.0.13 ----

Library C:\Programmi\Eset\pr_upd.dll (*** hidden *** ) @ C:\Programmi\Eset\nod32krn.exe [556] 0x20300000

---- Registry - GMER 1.0.13 ----

Reg \Registry\USER\S-1-5-21-299502267-162531612-725345543-1003\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY@?? 0xCC 0xD0 0xC5 0xB2 ...
Reg \Registry\USER\S-1-5-21-299502267-162531612-725345543-1003\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY@?? 0x06 0x62 0xE2 0x5B ...

---- EOF - GMER 1.0.13 ----

Sajiuuk Kaar
06-11-2007, 23:14
sempre più perfetto:
Win Worms Door Cleaner mi dice che SVCHOST.exe è infetto da qualche virus inquanto occupa 24Mb in memoria... Do un'occhio con procexp

Sajiuuk Kaar
06-11-2007, 23:50
sempre più perfetto:
Win Worms Door Cleaner mi dice che SVCHOST.exe è infetto da qualche virus inquanto occupa 24Mb in memoria... Do un'occhio con procexp

edit: procexp non mi fa vedere niente di strano; cmq ho disattivato i servizi che "bacavano" e riavviato, all'avvio mi è apparso un'errore di sistema il quale cercava un file: "C:\windows\config\lsass.exe" e che non lo trovava (non c'è).
ho cercato nel registro per chiavi correlate, l'ho trovata la chiave che avviava questo presunto file e l'ho cancellata.

xcdegasp
07-11-2007, 00:01
edit: procexp non mi fa vedere niente di strano; cmq ho disattivato i servizi che "bacavano" e riavviato, all'avvio mi è apparso un'errore di sistema il quale cercava un file: "C:\windows\config\lsass.exe" e che non lo trovava (non c'è).
ho cercato nel registro per chiavi correlate, l'ho trovata la chiave che avviava questo presunto file e l'ho cancellata.

mi puzza molto la cosa.. scarica e installa prevx 2.0 e fai una scansione dell'intero sistema ovviamente in modalità normale e collegato a internet ;)

Sajiuuk Kaar
07-11-2007, 01:22
mi puzza molto la cosa.. scarica e installa prevx 2.0 e fai una scansione dell'intero sistema ovviamente in modalità normale e collegato a internet ;)

quoto... puzza pure a me...
Mi sembra assurdo, ho traccie del passaggio almeno 4 virus diversi nel pc...

EDIT: non ha trovato niente. Mi dice che non ci osno minaccie. Ora: o il computer stesso è diventato un virus mutante oppure erano residui di virus...

P.S: fino a domani sera non ci sono, ogni messaggio scritto lo leggerò domani sera :S

Sajiuuk Kaar
08-11-2007, 11:24
aggiornamento: wwdc non riesce a chiudere le porte di netbios. ad ogni riavvio mi dice che lo farà al riavvio del sistema...

juninho85
08-11-2007, 11:26
aggiornamento: wwdc non riesce a chiudere le porte di netbios. ad ogni riavvio mi dice che lo farà al riavvio del sistema...

devi disabilitare il servizio helper

Sajiuuk Kaar
08-11-2007, 12:34
devi disabilitare il servizio helper

Ma... è disabilitato... l'ho disabilitato dopo la prima volta che ho preso sto virus...
se intendi Helper NetBIOS di TCP/IP ovviamente

juninho85
08-11-2007, 14:28
Ma... è disabilitato... l'ho disabilitato dopo la prima volta che ho preso sto virus...
se intendi Helper NetBIOS di TCP/IP ovviamente

si quello.
prova anche a disabilitarlo manualmente dalle impostazioni avanzate della tua connessione di rete

Sajiuuk Kaar
08-11-2007, 18:04
si quello.
prova anche a disabilitarlo manualmente dalle impostazioni avanzate della tua connessione di rete

Niente da fare >.< li è già disabilitato... o ho una connessione attiva con QUALCOSA di esterno e non lo so ne lo posso vedere o non so perchè non riesco a disattivarlo...