PDA

View Full Version : Logfile Hijack


rig1
21-07-2005, 16:25
Ho un piccolo problema con uno spyware che non ne vuole sapere di andare via... ho già provato un paio di AV (il panda online rileva adware ma non riesce ad eliminarlo) con ad-aware ma niente! ecco il log di hijack. Qualche suggerimento?

Logfile of HijackThis v1.99.1
Scan saved at 16.17.34, on 21/07/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\FMCTRL.EXE
C:\PROGRAMMI\PANDA SOFTWARE\PANDA ANTIVIRUS TITANIUM\APVXDWIN.EXE
C:\PROGRAMMI\FILE COMUNI\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAMMI\ENERGYPLUGIN\ENERGYPLUGIN.EXE
C:\WINDOWS\SYSTEM\INTEL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\ITDDD.EXE
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\MSOFFICE.EXE
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAMMI\PANDA SOFTWARE\PANDA ANTIVIRUS TITANIUM\PAVPROXY.EXE
C:\PROGRAMMI\INTERNET EXPLORER\IEXPLORE.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.1:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMI\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {490A7312-39CB-96B3-6C4E-910E37471D0F} - C:\WINDOWS\SYSTEM\JALAKEL.DLL
O2 - BHO: (no name) - {6DA975EA-CBB4-411B-97C0-DB0A892BF2C1} - C:\WINDOWS\SYSTEM\TEPIB.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [Q3dctlTray] Fmctrl.EXE
O4 - HKLM\..\Run: [APVXDWIN] "C:\Programmi\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [HPLJ Config] C:\Programmi\Hewlett-Packard\hp LaserJet 1150_1300\SetConfig.exe -c Direct -p \\ENNIO2\hpLaserJ1150 -pn "hp LaserJet 1150 PCL5e" -n 0 -l 1040 -sl 120000
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EnergyPlugIn] C:\Programmi\EnergyPlugIn\EnergyPlugin.exe
O4 - HKLM\..\Run: [RegSvr32] C:\WINDOWS\SYSTEM\msmsgs.exe
O4 - HKLM\..\Run: [intel32.exe] C:\WINDOWS\SYSTEM\intel32.exe
O4 - HKLM\..\Run: [Systems] C:\WINDOWS\SYSTEM\itDDD.exe
O4 - Startup: Avvio Office.lnk = C:\Programmi\Microsoft Office\Office\OSA.EXE
O4 - Startup: Barra degli strumenti Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\MSOFFICE.EXE
O4 - Startup: Ricerca rapida.lnk = C:\Programmi\Microsoft Office\Office\FINDFAST.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.skymasters.biz
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.linkautomatici.com
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/234516791cd6c4e1cd14/netzip/RdxIE601_it.cab
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://deposito.hostance.net/dialer/1014021.exe
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/1056307.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://download.energyfactor.com/dialer/it/activex_261_it.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 192.168.1.1

andorra24
21-07-2005, 16:42
Fixa:
C:\PROGRAMMI\ENERGYPLUGIN\ENERGYPLUGIN.EXE
C:\WINDOWS\SYSTEM\INTEL32.EXE
C:\WINDOWS\SYSTEM\ITDDD.EXE
O2 - BHO: (no name) - {490A7312-39CB-96B3-6C4E-910E37471D0F} - C:\WINDOWS\SYSTEM\JALAKEL.DLL
O2 - BHO: (no name) - {6DA975EA-CBB4-411B-97C0-DB0A892BF2C1} - C:\WINDOWS\SYSTEM\TEPIB.DLL (file missing)
O4 - HKLM\..\Run: [EnergyPlugIn] C:\Programmi\EnergyPlugIn\EnergyPlugin.exe
O4 - HKLM\..\Run: [intel32.exe] C:\WINDOWS\SYSTEM\intel32.exe
O4 - HKLM\..\Run: [Systems] C:\WINDOWS\SYSTEM\itDDD.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.skymasters.biz
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.linkautomatici.com
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://deposito.hostance.net/dialer/1014021.exe
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/1056307.exe
O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://download.energyfactor.com/di...ivex_261_it.exe

matteo1
21-07-2005, 16:44
cavolo è ben più di uno spyware,i problemi mi sembrano:
ENERGYPLUGIN.EXE
about:blank
O2 - BHO: (no name) - {490A7312-39CB-96B3-6C4E-910E37471D0F} - C:\WINDOWS\SYSTEM\JALAKEL.DLL
O2 - BHO: (no name) - {6DA975EA-CBB4-411B-97C0-DB0A892BF2C1} - C:\WINDOWS\SYSTEM\TEPIB.DLL (file missing)
O4 - HKLM\..\Run: [EnergyPlugIn] C:\Programmi\EnergyPlugIn\EnergyPlugin.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O15 - Trusted Zone: www.redfunny.comx
O15 - Trusted Zone: www.skymasters.bizx
O15 - Trusted Zone: www.archiviosex.netx
O15 - Trusted Zone: www.linkautomatici.comx
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://deposito.hostance.net/dialer/1014021.exex
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/1056307.exex
O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://download.energyfactor.com/di...ivex_261_it.exex

Prova a scaricarti:
http://www.softpedia.com/get/Antivirus/BhoScanner.shtml
http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/Spy-Sweeper.shtml
aggiornali e usali in modalità provvisoria.
ps ho messo la x sui siti che rimandano agli spyware,per evitare che qualcuno inavvertitamente ci clicchi.

Quando hai finito il lavoro scaricati questo:
http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/SpywareBlaster.shtml
che blocca le chiavi di registro usate dagli spyware.
E ricorda di non navigare in"certi"siti.

bluepix
21-07-2005, 16:46
Fixerei le seguenti linee:

O2 - BHO: (no name) - {490A7312-39CB-96B3-6C4E-910E37471D0F} - C:\WINDOWS\SYSTEM\JALAKEL.DLL
O2 - BHO: (no name) - {6DA975EA-CBB4-411B-97C0-DB0A892BF2C1} - C:\WINDOWS\SYSTEM\TEPIB.DLL


O4 - HKLM\..\Run: [RegSvr32] C:\WINDOWS\SYSTEM\msmsgs.exe
O4 - HKLM\..\Run: [intel32.exe] C:\WINDOWS\SYSTEM\intel32.exe
O4 - HKLM\..\Run: [Systems] C:\WINDOWS\SYSTEM\itDDD.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.skymasters.biz
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.linkautomatici.com
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://deposito.hostance.net/dialer/1014021.exe
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/1056307.exe

cancella i file in modalità provvisoria:

C:\WINDOWS\SYSTEM\msmsgs.exe
C:\WINDOWS\SYSTEM\intel32.exe

fai una passata con:

ad-aware http://www.download.com/3001-8022_4-10399602.html
mwav: http://www.spywareinfo.dk/download/mwav.exe

pulisci i files temporanei:

http://www.ccleaner.com/ccdownload.asp

bluepix
21-07-2005, 16:47
ops. scusate.. sono arrivato ultimo :(

matteo1
21-07-2005, 16:52
non è mica una gara;e poi io avevo dimenticato qualcosa. :cool:

BravoGT83
21-07-2005, 16:53
il buon vecchio 98

penso che gli altri hanno già detto tutto

rig1
21-07-2005, 18:42
Siete dei grandi! Tutto a posto grazie ai vostri suggerimenti. :ave: In effetti il mio collega si diverte a fare qualche visitina a siti non troppo ortodossi, io l'avevo avvertito ma è più forte di lui... :rolleyes:
Grazie ancora!

matteo1
21-07-2005, 18:51
se vuole visitare siti porno,digli:
di non visitare quelli multilanguage(perchè creano dialer appositi)
di usare firefox e disabilitare javascript con NoScript

rig1
22-07-2005, 11:16
se vuole visitare siti porno,digli:
di non visitare quelli multilanguage(perchè creano dialer appositi)
di usare firefox e disabilitare javascript con NoScript

Sarebbe meglio se lavorasse... :D

rig1
22-07-2005, 11:44
Questa mattina, preso da una strana ansia, ho fatto una scansione totale al MIO pc con panda platinum 7 (sempre attivo anche con firewall) e non mi ha rilevato nullla. Poi per sicurezza ho utilizzato anche activescan on line e mi ha rilevato degli spyware che purtroppo non riesce ad eliminare... :muro: Ecco il log di activescan:

Incidente ------------ Stato ------------ Percorso

Spyware:spyware/altnet Non Disinfettato C:\PROGRAM FILES\Altnet
Adware:adware/myway Non Disinfettato HKEY_LOCAL_MACHINE\SOFTWARE\MYWAY
Virus:Application/Restart Non Disinfettato C:\WINDOWS\system32\Tools\Restart.exe
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\adm.exe
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\adm25.dll
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\adm4.dll
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\admdloader.dll
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\admfdi.dll
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\admprog.dll
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\dmfiles.cab
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\dmfiles.cab[AltnetUninstall.exe]
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\dmfiles.cab[asmend.exe]
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\pmexe.cab
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\pmexe.cab[Points Manager.exe]
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\pmfiles.cab
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\pmfiles.cab[sysdetect.dll]
Spyware:Spyware/Altnet Non Disinfettato C:\WINDOWS\Temp\Altnet\Setup.exe



Sinceramente non riesco a capire come ho fatto a prendermi questa robaccia, io so cosa si rischia andando in giro per la rete su siti non proprio ortodossi e quindi evito sempre di farlo! L'unica cosa che mi può venire in mente è quando digiti male un indirizzo web e subito ti compaiono tette a destra e sinistra hehehe. Comunque vi posto il log anche del mio pc:

Logfile of HijackThis v1.99.1
Scan saved at 11.12.37, on 22/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Iomega\AutoDisk\ADUserMon.exe
C:\Programmi\Iomega\DriveIcons\ImgIcon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe
C:\Programmi\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
C:\Programmi\Java\jre1.5.0_02\bin\jusched.exe
C:\Programmi\File comuni\Nokia\Services\ServiceLayer.exe
C:\Programmi\File comuni\Nokia\NCLTools\NclTray.exe
C:\Programmi\Microsoft Office\Office\OSA.EXE
C:\Programmi\Microsoft Office\Office\MSOFFICE.EXE
C:\Programmi\Nokia\PC Suite Nokia 3650\connmngmntbox.exe
C:\Programmi\Nokia\PC Suite Nokia 3650\ectaskscheduler.exe
C:\PROGRA~1\Nokia\PCSUIT~1\Elogerr.exe
C:\Programmi\Intuwave\Shared\mRouterRunTime\mRouterRuntime.exe
C:\PROGRA~1\Nokia\PCSUIT~1\BROADC~1.EXE
C:\PROGRA~1\Nokia\PCSUIT~1\SCRFS.exe
C:\PROGRA~1\TUN\COMMON\ESLCBCST.EXE
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Programmi\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
C:\Programmi\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\Programmi\Iomega\AutoDisk\ADService.exe
C:\Programmi\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Documents and Settings\luca\Desktop\hijackthis\HijackThis.exe
C:\Programmi\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bancaintesa.it/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emmecomputer.it/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.1:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ADUserMon] C:\Programmi\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Programmi\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Programmi\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKLM\..\Run: [SCANINICIO] "C:\Programmi\Panda Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Programmi\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ServiceLayer] C:\Programmi\File comuni\Nokia\Services\ServiceLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Programmi\File comuni\Nokia\NCLTools\NclTray.exe
O4 - Global Startup: Avvio Office.lnk = C:\Programmi\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Barra degli strumenti Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\MSOFFICE.EXE
O4 - Global Startup: PCSuiteperNokia3650 Detect.lnk = ?
O4 - Global Startup: PCSuiteperNokia3650 TS.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.emmecomputer.it/
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/IT/install.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {83B67220-025C-416C-8049-398E12764B36} (Flo2_L2 Control) - http://www.nokiagame.com/games/2K1E4R5Vem5ui1Sw1Wyas/flo2_l2.cab
O16 - DPF: {8BC4B4C3-2CA2-44B0-9A36-495EF3946E22} (Flo2_L1 Control) - http://www.nokiagame.com/games/1fpO934H6RyteU8j62jfl/flo2_l1.cab
O16 - DPF: {970D1F38-542B-471C-9574-72E1AE852EA1} (Flo2_L4 Control) - http://www.nokiagame.com/games/4eQo0tyh3Gldg2En371h3/flo2_l4.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B47CD421-1AA8-4FE6-A25A-5824BDADC307} (Flo2_L3 Control) - http://www.nokiagame.com/games/3Uyti4JKfpumjn246j8HI/flo2_l3.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpbasicdetection3.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = Host-4
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = Host-4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = Host-4
O23 - Service: Esker License Control (EskerLicenseControl) - Esker - C:\PROGRA~1\TUN\COMMON\ESLCBCST.EXE
O23 - Service: Esker FTPD (ftpds) - Esker - C:\PROGRA~1\TUN\TCPW\WFTPDSNT.EXE
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Iomega Security (IomegaSecurity) - Unknown owner - C:\Iomg_NT\IoSecur.exe (file missing)
O23 - Service: Esker LPD (lpds) - Esker - C:\PROGRA~1\TUN\TCPW\WLPDSNT.EXE
O23 - Service: Esker NFSD (nfsds) - Esker - C:\PROGRA~1\TUN\TCPW\WNFSDSNT.EXE
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Programmi\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Programmi\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Programmi\Iomega\AutoDisk\ADService.exe

Che ne pensate? :help: E' grave? Voglio precisare che emmecomputer è la ditta dove ho comprato il pc...
Grazie ancora per il vostro aiuto.

juninho85
23-07-2005, 01:26
cosa sarebbe esker?

rig1
25-07-2005, 09:20
cosa sarebbe esker?

E' un emulatore unix... Mi serve per la contabilità :D