|
|||||||
|
|
|
![]() |
|
|
Strumenti |
|
|
#1 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
Virus Blocca VirIT CCleaner e HWupgrade forum
Ciao ragazzi ci risiamo .....
vi spiego che succede : - sistema con XP nod32 aggiornato e a-squared aggiornato - da due giorni CCleaner non mi và più , clicco , si apre e ritorna sul desktop anche se provo a reinstallarlo . Mi insospettisco e provo a cercare sul forum le possibili cause , clicco il link e track si chiude il browser , comincio a sentire puzza di bruciato ... - da un'altro pc vado sul forum di HWupgrade , e seguo le istruzioni per cercare di capire cosa ho ..... provo gli antivirus online consigliati ( in modalità provvisoria con rete dopo aver disabilitato ripristino config. etc .) ma niente ... poi provo anche VirIT ( sempre in modalità provvisoria con rete ) e fine scansione mi trova due bei virus .... Trojan.Win32.Agent.BMY e Trojan.Win32.Dialer.IH .... io esulto e non riesco neanche a cercarlo su internet ..... ho già formattato un anno fa , questa volta vorrei provare a batterlo , aiutatemi ... non possono sempre vincere loro ora proverò ad inserire dei log , è la prima volta quindi non sò se uscirà qualcosa ..... log di HijackThis Codice:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18.13.09, on 10/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\Programmi\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmi\Eset\nod32kui.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Programmi\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\a-squared Free\a2service.exe
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Eset\nod32krn.exe
C:\Programs\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\PrevxCSI\prevxcsi.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\VEXPLITE\viritsvc.exe
C:\WINDOWS\System32\alg.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://google.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Programmi\Corel\Corel Graphics 12\Languages\IT\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=062408 serial=DR12WRS-8796594-FHE lang=IT
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [H2O] C:\Programmi\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\VEXPLITE\MONLITE.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe
O23 - Service: CSIScanner - Prevx - C:\Programmi\PrevxCSI\prevxcsi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\mssrv32.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programs\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
O24 - Desktop Component 1: Aqua Real - 7db39a0d-580f-4be9-9195-8bfcd226f6c2
--
End of file - 5510 bytes
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#2 |
|
Senior Member
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
|
disattiva il ripristino di configurazione e segui la semplice procedura descritta in Guida alla Disinfezione per Infetti e pubblica tutti i log richiesti facendo attenzione alle Regole di Sezione, così potremmo aiutarti
nella guida è ben descritto come disabilitare il ripristino di sistema
__________________
"Visti da vicino siamo tutti strani..." ~|~ What Defines a Community? ~|~ Thread eMule Ufficiale ~|~ Online Armor in Italiano ~|~ Regole di Sezione ~|► Guida a PrivateFirewall
|
|
|
|
|
|
#3 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
Scusate forse non mi sono spiegato bene ma , il ripristino di configurazione di sistema è stato disattivato , prima di tutte le operazioni
se può aiutare , quando entro in modalità provvisoria appaiono due user : ADMIN e ADMINISTRATOR ... è normale ? per quanto riguarda la guida ecco cosa ho fatto : 1) ADS Scanner 2.0 - niente 2) A-Squared Free v3.x deep - niente 3) F-Secure OnLine - niente 4) Dr.Web CureIT - lasciato log in ufficio 5) ESET SysInspector - log in formato XML da 1,52 mb ( come lo posto ? ) 6) HiJackThis - vedi sopra 7) Gmer Codice:
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-06-10 12:07:21
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT spjw.sys ZwCreateKey [0xF74B90E0]
SSDT spjw.sys ZwEnumerateKey [0xF74D6CA2]
SSDT spjw.sys ZwEnumerateValueKey [0xF74D7030]
SSDT spjw.sys ZwOpenKey [0xF74B90C0]
SSDT spjw.sys ZwQueryKey [0xF74D7108]
SSDT spjw.sys ZwQueryValueKey [0xF74D6F88]
SSDT spjw.sys ZwSetValueKey [0xF74D719A]
INT 0x62 ? 863D7BF8
INT 0x63 ? 863D7BF8
INT 0x73 ? 86244F00
INT 0x82 ? 863D7BF8
INT 0x94 ? 86244F00
INT 0xA4 ? 86244F00
---- Kernel code sections - GMER 1.0.14 ----
? spjw.sys Impossibile trovare il file specificato. !
.text USBPORT.SYS!DllUnload F725262C 5 Bytes JMP 862444E0
.text agmy20m1.SYS F71B1384 1 Byte [ 20 ]
.text agmy20m1.SYS F71B1386 35 Bytes [ 00, 68, 00, 00, 00, 00, 00, ... ]
.text agmy20m1.SYS F71B13AA 24 Bytes [ 00, 00, 20, 00, 00, E0, 00, ... ]
.text agmy20m1.SYS F71B13C4 3 Bytes [ 00, 00, 00 ]
.text agmy20m1.SYS F71B13C9 1 Byte [ 00 ]
.text ...
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 863695E0
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74DF6D0] spjw.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F74E3708] spjw.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74BA046] spjw.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74BA142] spjw.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74BA0C4] spjw.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74BA7CE] spjw.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74BA6A4] spjw.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 862445E0
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74C5D7A] spjw.sys
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlInitUnicodeString] DD000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!swprintf] 74000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeSetEvent] 1F000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 4B000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoGetConfigurationInformation] BD000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 8B000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmFreeMappingAddress] 8A000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 70000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 3E000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmUnmapIoSpace] B5000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 66000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IofCompleteRequest] 48000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 03000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IofCallDriver] F6000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 0E000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 61000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoConnectInterrupt] 35000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoDetachDevice] 57000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeWaitForSingleObject] B9000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInitializeEvent] 86000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] C1000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlInitAnsiString] 1D000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 9E000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoQueueWorkItem] E1000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmMapIoSpace] F8000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 98000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoReportDetectedDevice] 11000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoReportResourceForDetection] 69000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] D9000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!NlsMbCodePageTag] 8E000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!PoRequestPowerIrp] 94000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 9B000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 1E000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!sprintf] 87000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] E9000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ObfDereferenceObject] CE000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 55000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 28000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ZwClose] DF000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 8C000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] A1000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 89000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 0D000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!PoCallDriver] [BF000000] \SystemRoot\System32\drivers\dxg.sys (DirectX Graphics Driver/Microsoft Corporation)
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoCreateDevice] E6000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 42000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 68000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ZwOpenKey] 41000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 99000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoStartTimer] 2D000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInitializeTimer] 0F000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoInitializeTimer] B0000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInitializeDpc] 54000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInitializeSpinLock] BB000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoInitializeIrp] 16000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ZwCreateKey] 00000052
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 00000009
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 0000006A
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ZwSetValueKey] 000000D5
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeInsertQueueDpc] 00000030
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 00000036
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoStartPacket] 000000A5
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 00000038
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000BF
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoFreeMdl] 00000040
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmUnlockPages] 000000A3
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 0000009E
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 00000081
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 000000F3
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000D7
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeSynchronizeExecution] 000000FB
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoStartNextPacket] 0000007C
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeBugCheckEx] 000000E3
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 00000039
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeSetTimer] 00000082
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeCancelTimer] 0000009B
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!_allmul] 0000002F
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmProbeAndLockPages] 000000FF
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!_except_handler3] 00000087
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!PoSetPowerState] 00000034
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 0000008E
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 00000043
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!_aulldiv] 00000044
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!strstr] 000000C4
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!_strupr] 000000DE
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeQuerySystemTime] 000000E9
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000CB
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!KeTickCount] 00000054
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 0000007B
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoDeleteDevice] 00000094
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 00000032
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAllocateWorkItem] 000000A6
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAllocateIrp] 000000C2
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoAllocateMdl] 00000023
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 0000003D
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000EE
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 0000004C
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 00000095
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!ExFreePoolWithTag] 0000000B
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoFreeIrp] 00000042
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!IoFreeWorkItem] 000000FA
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!InitSafeBootMode] 000000C3
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlCompareMemory] 0000004E
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 00000008
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!memmove] 0000002E
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[ntoskrnl.exe!MmHighestUserAddress] 000000A1
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KfAcquireSpinLock] 6C000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!READ_PORT_UCHAR] 56000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KeGetCurrentIrql] F4000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KfRaiseIrql] EA000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KfLowerIrql] 65000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!HalGetInterruptVector] 7A000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!HalTranslateBusAddress] AE000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KeStallExecutionProcessor] 08000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!KfReleaseSpinLock] BA000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 78000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!READ_PORT_USHORT] 25000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 2E000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[HAL.dll!WRITE_PORT_UCHAR] 1C000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[WMILIB.SYS!WmiSystemControl] B4000000
IAT \SystemRoot\System32\Drivers\agmy20m1.SYS[WMILIB.SYS!WmiCompleteRequest] C6000000
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 863D61F8
Device \FileSystem\Fastfat \FatCdrom 860BB1F8
Device \Driver\sptd \Device\189952900 spjw.sys
Device \Driver\usbuhci \Device\USBPDO-0 8622F1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 863671F8
Device \Driver\dmio \Device\DmControl\DmConfig 863671F8
Device \Driver\dmio \Device\DmControl\DmPnP 863671F8
Device \Driver\dmio \Device\DmControl\DmInfo 863671F8
Device \Driver\usbuhci \Device\USBPDO-1 8622F1F8
Device \Driver\usbuhci \Device\USBPDO-2 8622F1F8
Device \Driver\usbuhci \Device\USBPDO-3 8622F1F8
Device \Driver\usbehci \Device\USBPDO-4 8623A1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 863D81F8
Device \Driver\Cdrom \Device\CdRom0 8621F1F8
Device \Driver\Cdrom \Device\CdRom1 8621F1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 863D71F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 863D71F8
Device \Driver\atapi \Device\Ide\IdePort0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 863D71F8
Device \Driver\atapi \Device\Ide\IdePort1 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort2 863D71F8
Device \Driver\atapi \Device\Ide\IdePort2 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort3 863D71F8
Device \Driver\atapi \Device\Ide\IdePort3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e 863D71F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\Cdrom \Device\CdRom2 8621F1F8
Device \Driver\prohlp02 \Device\ProHlp02 E100F6C8
Device \Driver\PCI_PNP9150 \Device\0000004a spjw.sys
Device \Driver\usbuhci \Device\USBFDO-0 8622F1F8
Device \Driver\usbuhci \Device\USBFDO-1 8622F1F8
Device \Driver\usbuhci \Device\USBFDO-2 8622F1F8
Device \Driver\usbuhci \Device\USBFDO-3 8622F1F8
Device \Driver\usbehci \Device\USBFDO-4 8623A1F8
Device \Driver\Ftdisk \Device\FtControl 863D81F8
Device \Driver\agmy20m1 \Device\Scsi\agmy20m11Port4Path0Target0Lun0 8621E1F8
Device \Driver\agmy20m1 \Device\Scsi\agmy20m11 8621E1F8
Device \Driver\agmy20m1 \Device\Scsi\agmy20m11Port4Path0Target1Lun0 8621E1F8
Device \FileSystem\Fastfat \Fat 860BB1F8
Device \FileSystem\Cdfs \Cdfs 860E81F8
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -1880953118
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 881923701
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Programs\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xDC 0xC6 0xCC 0xA6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x30 0xF1 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x8E 0xF8 0xFB 0x7A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0xD4 0xDD 0xB6 0xE1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x5F 0x35 0x90 0x82 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x80 0x16 0x2B 0xF3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Programs\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xDC 0xC6 0xCC 0xA6 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x30 0xF1 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x8E 0xF8 0xFB 0x7A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0xD4 0xDD 0xB6 0xE1 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x5F 0x35 0x90 0x82 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 2
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x80 0x16 0x2B 0xF3 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@oagfmgeeemdfpmaobedmicgmkpjemp 0x64 0x61 0x64 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@oakeemcdpeoooaonjjlanibkplalac 0x6A 0x61 0x64 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@naaikgijmnleglpjhhfobgigbpmn 0x6A 0x61 0x66 0x70 ...
---- EOF - GMER 1.0.14 ----
spero di aver messo le cose giuste , non sono protico di Gmer o HJ etc. etc. a metto anche i log trovati nella cartella di VirIT prima che non mi funzionasse più Codice:
[SCANSIONE DEL REGISTRO] OK [A:] BOOT SECTOR: OK [C:] MASTER BOOT RECORD: OK BOOT SECTOR: OK C:\WINDOWS\system32\updedvih.exe Infetto da Trojan.Win32.Agent.BMY * * * RIMOSSO * * * C:\WINDOWS\Temp\pzxwlk.exe Infetto da Trojan.Win32.Dialer.IH * * * RIMOSSO * * * [D:] [I:] [J:] Chiavi Registro infette: 0. Files Infetti: 2. Files Sospetti: 0. Files Analizzati: 44429. Files Totali: 44429. Chiavi Registro rimosse: 0. Virus Rimossi: 2. Codice:
VirIT Lite Monitor: Lista ultimi file creati o modificati C:\WINDOWS 10/06/2008 13:26 0.log (0) 10/06/2008 14:01 bootstat.dat (2048) 10/06/2008 09:36 gmer.dll (884736) 10/06/2008 13:45 gmer.ini (250) 10/06/2008 09:36 gmer_uninstall.cmd (80) 10/06/2008 07:41 ModemLog_Modem standard.txt (1904) 31/05/2008 09:20 NeroDigital.ini (69) 10/06/2008 13:57 ntbtlog.txt (273134) 10/06/2008 13:20 SchedLgU.Txt (890) 10/06/2008 13:12 Sti_Trace.log (0) 09/06/2008 16:45 system.ini (253) 10/06/2008 13:26 wiadebug.log (159) 10/06/2008 13:26 wiaservc.log (50) 09/06/2008 16:45 win.ini (564) 10/06/2008 13:59 WindowsUpdate.log (6069) C:\WINDOWS\system32 09/06/2008 14:07 wpa.dbl (2206) C:\WINDOWS\system32\drivers 10/06/2008 09:36 gmer.sys (85969) 10/06/2008 10:32 pxark.sys (17408) C:\DOCUME~1\Admin\IMPOST~1\Temp\ 29/05/2008 17:14 control.xml (12818) 04/06/2008 17:04 femdom-005.mpg (1298436) 09/06/2008 17:02 IH110.tmp (9601) 10/06/2008 13:19 IH2B.tmp (2592) 04/06/2008 08:28 IH2DA.tmp (9744) 09/06/2008 16:52 IH41.tmp (3869) 26/05/2008 17:14 IH60DC.tmp (507991) 09/06/2008 15:46 IH719C.tmp (3869) 09/06/2008 15:51 IH7242.tmp (1161) 09/06/2008 15:52 IH726B.tmp (690) 09/06/2008 17:18 java_install_reg.log (4244) 10/06/2008 13:17 jusched.log (9570) 10/06/2008 13:53 LastScan.txt (904) 10/06/2008 13:53 restart.a2s (483) C:\ 09/06/2008 16:45 boot.ini (211) 10/06/2008 14:01 pagefile.sys (1598029824) C:\WINDOWS\system32\dllcache C:\WINDOWS\Temp 10/06/2008 10:36 exp103.tmp (0) 02/06/2008 10:32 exp1DDF.tmp (0) 05/06/2008 10:35 exp23C2.tmp (0) 03/06/2008 10:32 exp2CB6.tmp (0) 06/06/2008 10:35 exp4B2B.tmp (0) 07/06/2008 10:35 exp75C2.tmp (0) 08/06/2008 10:35 exp7744.tmp (0) 09/06/2008 10:35 exp7BB9.tmp (0) 01/06/2008 10:32 exp849.tmp (0) 29/05/2008 09:20 expB656.tmp (0) 04/06/2008 10:35 expD47.tmp (0) 30/05/2008 09:22 expE683.tmp (0) 31/05/2008 09:32 expFC7C.tmp (0) C:\VEXPLITE\ 10/06/2008 10:42 CLEAN.DAT (370570) 10/06/2008 10:42 DISLITE.EXE (45056) 10/06/2008 10:42 GOTGSOFT.BAT (42) 10/06/2008 10:42 GOVIRITEXPSVC.BAT (17) 10/06/2008 10:42 GOVIRSMD.BAT (17) 10/06/2008 14:02 lastfile.txt (0) 10/06/2008 10:56 listathread.txt (14492) 10/06/2008 10:42 MONLITE.EXE (245760) 10/06/2008 10:42 NAME-LT.DAT (302413) 10/06/2008 10:42 ORDINA.WRI (12496) 10/06/2008 10:42 PROCDLL.DLL (57344) 10/06/2008 13:12 reg_ecc.dat (0) 10/06/2008 10:56 REPORT.RPT (72) 10/06/2008 10:42 SCAN.DLL (290816) 10/06/2008 10:42 SCANFILE.TXT (0) 10/06/2008 14:02 Syskrn.txt (32886) 10/06/2008 10:42 TGSVCSTP.EXE (40960) 10/06/2008 10:42 VIRAGTLT.SYS (39808) 10/06/2008 10:42 VIRIT-LT.DAT (765200) 10/06/2008 10:42 VIRITEXP.CSM (4) 10/06/2008 10:42 VIRITEXP.EXE (688128) 10/06/2008 10:56 VIRITEXP.LOG (636) 10/06/2008 13:12 VIRITMON.LOG (30) 10/06/2008 10:42 VIRITSVC.EXE (57344) 10/06/2008 10:42 VIRITUPG.DLL (102400)
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#4 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
ecco il link al log di SysInspector-PC
http://wikisend.com/download/497536/...PC-lucap78.xml chissà se funzia ?
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#5 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
ragan aggiungo una informazione che forse è utile
nella schermata di gmer su registry, alla voce HKEY-LOCAL-MACHINE ho trovato una cartella di nome SAM contenente sotto cartelle tutte di colore rosso ? è una cosa normale ? in attesa di utili consigli distinti saluti
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#6 |
|
Senior Member
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
|
tu carica il log secondo le modalità e copia nella discussione le voci in rosso (che di norma andrebbero eliminate)
__________________
fattoebloggato.com • Trattamento post disinfezione • Recupero dati, RAID e Partizioni • Guida UBCD4Win • Test RAM • Controllo Disco • TestDisk • Operazioni di emergenza • Live cd Linux • UBCD • Backup • Gestione ISO & immagini virtuali • Partizionare un disco • Sardu • ScreenRecording • |
|
|
|
|
|
#7 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
Le voci in rosso non sono nella schermata iniziale
ma dentro il registry, alla voce HKEY-LOCAL-MACHINE comunque oggi se ce la faccio posto un log di gmer anche se penso di aver trovato un file gif sospetto in System32 che non si cancella e non si invia per lo scan online
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#8 | |
|
Senior Member
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
|
Quote:
__________________
fattoebloggato.com • Trattamento post disinfezione • Recupero dati, RAID e Partizioni • Guida UBCD4Win • Test RAM • Controllo Disco • TestDisk • Operazioni di emergenza • Live cd Linux • UBCD • Backup • Gestione ISO & immagini virtuali • Partizionare un disco • Sardu • ScreenRecording • |
|
|
|
|
|
|
#9 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
allora ... ecco i log di Gmer prima posto quello dei Rootkit
Codice:
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-06-12 16:39:28
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT spni.sys ZwCreateKey [0xF74B90E0]
SSDT spni.sys ZwEnumerateKey [0xF74D6CA2]
SSDT spni.sys ZwEnumerateValueKey [0xF74D7030]
SSDT spni.sys ZwOpenKey [0xF74B90C0]
SSDT spni.sys ZwQueryKey [0xF74D7108]
SSDT spni.sys ZwQueryValueKey [0xF74D6F88]
SSDT spni.sys ZwSetValueKey [0xF74D719A]
INT 0x62 ? 86368BF8
INT 0x63 ? 86368BF8
INT 0x82 ? 86368BF8
INT 0x94 ? 86239BF8
INT 0xA4 ? 86239BF8
---- Kernel code sections - GMER 1.0.14 ----
? spni.sys Impossibile trovare il file specificato. !
.text USBPORT.SYS!DllUnload F712F62C 5 Bytes JMP 862391D8
.text afy2zzfx.SYS F7069384 1 Byte [ 20 ]
.text afy2zzfx.SYS F7069386 35 Bytes [ 00, 68, 00, 00, 00, 00, 00, ... ]
.text afy2zzfx.SYS F70693AA 24 Bytes [ 00, 00, 20, 00, 00, E0, 00, ... ]
.text afy2zzfx.SYS F70693C4 3 Bytes [ 00, 00, 00 ]
.text afy2zzfx.SYS F70693C9 1 Byte [ 00 ]
.text ...
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 863D92D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74DF6D0] spni.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F74E3708] spni.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74BA046] spni.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74BA142] spni.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74BA0C4] spni.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74BA7CE] spni.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74BA6A4] spni.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 862392D8
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74C5D7A] spni.sys
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlInitUnicodeString] DD000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!swprintf] 74000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeSetEvent] 1F000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 4B000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoGetConfigurationInformation] BD000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 8B000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmFreeMappingAddress] 8A000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 70000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 3E000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmUnmapIoSpace] B5000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 66000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IofCompleteRequest] 48000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 03000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IofCallDriver] F6000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 0E000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 61000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoConnectInterrupt] 35000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoDetachDevice] 57000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeWaitForSingleObject] B9000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInitializeEvent] 86000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] C1000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlInitAnsiString] 1D000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 9E000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoQueueWorkItem] E1000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmMapIoSpace] F8000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 98000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoReportDetectedDevice] 11000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoReportResourceForDetection] 69000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] D9000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!NlsMbCodePageTag] 8E000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!PoRequestPowerIrp] 94000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 9B000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 1E000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!sprintf] 87000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] E9000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ObfDereferenceObject] CE000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 55000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 28000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ZwClose] DF000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 8C000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] A1000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 89000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 0D000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!PoCallDriver] [BF000000] \SystemRoot\System32\drivers\dxg.sys (DirectX Graphics Driver/Microsoft Corporation)
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoCreateDevice] E6000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 42000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 68000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ZwOpenKey] 41000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 99000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoStartTimer] 2D000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInitializeTimer] 0F000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoInitializeTimer] B0000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInitializeDpc] 54000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInitializeSpinLock] BB000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoInitializeIrp] 16000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ZwCreateKey] 00000052
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 00000009
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 0000006A
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ZwSetValueKey] 000000D5
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeInsertQueueDpc] 00000030
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 00000036
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoStartPacket] 000000A5
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 00000038
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000BF
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoFreeMdl] 00000040
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmUnlockPages] 000000A3
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 0000009E
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 00000081
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 000000F3
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000D7
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeSynchronizeExecution] 000000FB
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoStartNextPacket] 0000007C
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeBugCheckEx] 000000E3
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 00000039
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeSetTimer] 00000082
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeCancelTimer] 0000009B
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!_allmul] 0000002F
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmProbeAndLockPages] 000000FF
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!_except_handler3] 00000087
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!PoSetPowerState] 00000034
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 0000008E
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 00000043
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!_aulldiv] 00000044
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!strstr] 000000C4
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!_strupr] 000000DE
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeQuerySystemTime] 000000E9
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000CB
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!KeTickCount] 00000054
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 0000007B
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoDeleteDevice] 00000094
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 00000032
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAllocateWorkItem] 000000A6
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAllocateIrp] 000000C2
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoAllocateMdl] 00000023
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 0000003D
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000EE
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 0000004C
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 00000095
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!ExFreePoolWithTag] 0000000B
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoFreeIrp] 00000042
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!IoFreeWorkItem] 000000FA
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!InitSafeBootMode] 000000C3
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlCompareMemory] 0000004E
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 00000008
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!memmove] 0000002E
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[ntoskrnl.exe!MmHighestUserAddress] 000000A1
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KfAcquireSpinLock] 6C000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!READ_PORT_UCHAR] 56000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KeGetCurrentIrql] F4000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KfRaiseIrql] EA000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KfLowerIrql] 65000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!HalGetInterruptVector] 7A000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!HalTranslateBusAddress] AE000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KeStallExecutionProcessor] 08000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!KfReleaseSpinLock] BA000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 78000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!READ_PORT_USHORT] 25000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 2E000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[HAL.dll!WRITE_PORT_UCHAR] 1C000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[WMILIB.SYS!WmiSystemControl] B4000000
IAT \SystemRoot\System32\Drivers\afy2zzfx.SYS[WMILIB.SYS!WmiCompleteRequest] C6000000
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 863671F8
AttachedDevice \FileSystem\Ntfs \Ntfs amon.sys (Amon monitor/Eset )
Device \Driver\sptd \Device\1625828836 spni.sys
Device \Driver\usbuhci \Device\USBPDO-0 862371F8
Device \Driver\usbuhci \Device\USBPDO-1 862371F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 863D71F8
Device \Driver\dmio \Device\DmControl\DmConfig 863D71F8
Device \Driver\dmio \Device\DmControl\DmPnP 863D71F8
Device \Driver\dmio \Device\DmControl\DmInfo 863D71F8
Device \Driver\usbuhci \Device\USBPDO-2 862371F8
Device \Driver\usbuhci \Device\USBPDO-3 862371F8
Device \Driver\usbehci \Device\USBPDO-4 862361F8
Device \Driver\prodrv06 \Device\ProDrv06 E15F2550
Device \Driver\Ftdisk \Device\HarddiskVolume1 863691F8
Device \Driver\Cdrom \Device\CdRom0 861F6498
Device \Driver\Cdrom \Device\CdRom1 861F6498
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 863681F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 863681F8
Device \Driver\atapi \Device\Ide\IdePort0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 863681F8
Device \Driver\atapi \Device\Ide\IdePort1 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort2 863681F8
Device \Driver\atapi \Device\Ide\IdePort2 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort3 863681F8
Device \Driver\atapi \Device\Ide\IdePort3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e 863681F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\Cdrom \Device\CdRom2 861F6498
Device \Driver\prohlp02 \Device\ProHlp02 E13F1548
Device \Driver\PCI_PNP5086 \Device\0000004a spni.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export 85D661F8
Device \Driver\NetBT \Device\NetbiosSmb 85D661F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{BE148E8A-8250-4E6C-B1EF-DF79FE2B59B8} 85D661F8
Device \Driver\usbuhci \Device\USBFDO-0 862371F8
Device \Driver\usbuhci \Device\USBFDO-1 862371F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 85D061F8
Device \Driver\usbuhci \Device\USBFDO-2 862371F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 85D061F8
Device \Driver\usbuhci \Device\USBFDO-3 862371F8
Device \Driver\Ftdisk \Device\FtControl 863691F8
Device \Driver\usbehci \Device\USBFDO-4 862361F8
Device \Driver\afy2zzfx \Device\Scsi\afy2zzfx1Port4Path0Target0Lun0 861F21F8
Device \Driver\afy2zzfx \Device\Scsi\afy2zzfx1 861F21F8
Device \Driver\afy2zzfx \Device\Scsi\afy2zzfx1Port4Path0Target1Lun0 861F21F8
Device \FileSystem\Cdfs \Cdfs 85D041F8
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -1880953118
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 881923701
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Programs\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xDC 0xC6 0xCC 0xA6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x30 0xF1 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x8E 0xF8 0xFB 0x7A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0xD4 0xDD 0xB6 0xE1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x5F 0x35 0x90 0x82 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x80 0x16 0x2B 0xF3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Programs\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xDC 0xC6 0xCC 0xA6 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x30 0xF1 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x8E 0xF8 0xFB 0x7A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg41@ujdew 0xD4 0xDD 0xB6 0xE1 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x5F 0x35 0x90 0x82 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 2
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x80 0x16 0x2B 0xF3 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@oagfmgeeemdfpmaobedmicgmkpjemp 0x64 0x61 0x64 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@oakeemcdpeoooaonjjlanibkplalac 0x6A 0x61 0x64 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBBF57DC-398E-F203-A2AC-98121E55F689}@naaikgijmnleglpjhhfobgigbpmn 0x6A 0x61 0x66 0x70 ...
---- EOF - GMER 1.0.14 ----
Codice:
GMER 1.0.14.14536 - http://www.gmer.net
Autostart scan 2008-06-12 16:41:08
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui@DLLName = igfxdev.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
MDM@ = "C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE"
NOD32krn@ = "C:\Programmi\Eset\nod32krn.exe"
StarWindServiceAE@ = C:\Programs\Alcohol 120\StarWind\StarWindServiceAE.exe
UMWdf@ = C:\WINDOWS\system32\wdfmgr.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@CorelDRAW Graphics Suite 11bC:\Programmi\Corel\Corel Graphics 12\Languages\IT\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=062408 serial=DR12WRS-8796594-FHE lang=IT /*file not found*/ = C:\Programmi\Corel\Corel Graphics 12\Languages\IT\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=062408 serial=DR12WRS-8796594-FHE lang=IT /*file not found*/
@SunJavaUpdateSched"C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe" = "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
@SoundMAXPnPC:\Programmi\Analog Devices\Core\smax4pnp.exe = C:\Programmi\Analog Devices\Core\smax4pnp.exe
@SoundMAX"C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray = "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
@PersistenceC:\WINDOWS\system32\igfxpers.exe = C:\WINDOWS\system32\igfxpers.exe
@nod32kui"C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE = "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
@IgfxTrayC:\WINDOWS\system32\igfxtray.exe = C:\WINDOWS\system32\igfxtray.exe
@HotKeysCmdsC:\WINDOWS\system32\hkcmd.exe = C:\WINDOWS\system32\hkcmd.exe
@High Definition Audio Property Page ShortcutHDAShCut.exe = HDAShCut.exe
@H2OC:\Programmi\SyncroSoft\Pos\H2O\cledx.exe = C:\Programmi\SyncroSoft\Pos\H2O\cledx.exe
RunOnce@SpybotSnD = "C:\Programmi\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@SpybotSD TeaTimerC:\Programmi\Spybot - Search & Destroy\TeaTimer.exe = C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe@Debugger = "c:\windows\system32\ejvcveef.gif"
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Pagina proprietà versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRar\rarext.dll = C:\Programmi\WinRar\rarext.dll
@{B089FE88-FB52-11D3-BDF1-0050DA34150D} /*NOD32 Context Menu Shell Extension*/C:\Programmi\Eset\nodshex.dll = C:\Programmi\Eset\nodshex.dll
@{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2} /*NeroCoverEd Live Icons*/C:\Programmi\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll = C:\Programmi\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\OFFICE11\msohev.dll = C:\Programmi\Microsoft Office\OFFICE11\msohev.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{45670FA8-ED97-4F44-BC93-305082590BFB} /*Microsoft.XPS.Shell.Metadata.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{44121072-A222-48f2-A58A-6D9AD51EBBE9} /*Microsoft.XPS.Shell.Thumbnail.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@CorelDRAW Shell Extension Component /*CorelDRAW Shell Extension Component*/(null) =
@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} /*Shell Extension for Malware scanning*/(null) =
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Cover Designer@{73FCA462-9BD5-4065-A73F-A8E5F6904EF7} = C:\Programmi\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll
DaemonShellExtImage@{40966797-8FFE-46C8-9EF8-7003F33CCF0F} =
NOD32 Context Menu Shell Extension@{B089FE88-FB52-11D3-BDF1-0050DA34150D} = C:\Programmi\Eset\nodshex.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRar\rarext.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRar\rarext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
NOD32 Context Menu Shell Extension@{B089FE88-FB52-11D3-BDF1-0050DA34150D} = C:\Programmi\Eset\nodshex.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRar\rarext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll = C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
@{53707962-6F74-2D53-2644-206D7942484F}C:\PROGRA~1\SPYBOT~1\SDHelper.dll = C:\PROGRA~1\SPYBOT~1\SDHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll = C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
HKCU\Control Panel\[email protected] = C:\WINDOWS\system32\logon.scr
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.google.it/ = http://www.google.it/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
ms-itss@CLSID = C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL
mso-offdap@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\system32\wiascr.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000002@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000003@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000004@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
000000000005@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011@PackedCatalogItem = C:\WINDOWS\system32\imon.dll
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica = Avvio veloce di Adobe Reader.lnk
---- EOF - GMER 1.0.14 ----
se riesco a rimpicciolire il file
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#10 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
ecco le cartelle in rosso in allegato
scusate la qualità ma per infilarla ho dovuto ridurla all'osso attendo info sul da farsi grazie in anticipo
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#11 |
|
Senior Member
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
|
Riedita cortesemente secondo le modalità di pubblicazione dei log
Se i log o le immagini (.JPG) non superano i 24Kb allegali tramite il comodo comando Gestisci allegati nelle Opzioni aggiuntive. Clicca su Gestisci allegati → si aprirà una finestra → Click su Sfoglia → seleziona il file da caricare → Click su Carica → sotto allegati correnti vedrai il tuo log caricato → Chiudi la finestra Altrimenti caricali su [wikisend.com] o su [mediafire.com]. Una volta sul sito → clicca su sfoglia → seleziona il file da caricare → poi invia o upload → aspetta che venga caricato → copia tutto il contenuto a fianco della della riga "Forum link nel primo caso oppure sotto "Sharing URL" nel secondo e lo incolli nella risposta della discussione. Le immagini più grosse salvale in JPG, essendo più leggere, e caricale su fileqube.com che permette di visualizzarle direttamente online.
__________________
fattoebloggato.com • Trattamento post disinfezione • Recupero dati, RAID e Partizioni • Guida UBCD4Win • Test RAM • Controllo Disco • TestDisk • Operazioni di emergenza • Live cd Linux • UBCD • Backup • Gestione ISO & immagini virtuali • Partizionare un disco • Sardu • ScreenRecording • |
|
|
|
|
|
#12 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
scusa ma l'ignoranza abbonda
link al download del log di Gmer inerente i Rootkit http://wikisend.com/download/908710/...alwareGMER.txt e allego il log di Gmer Autostart
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#13 |
|
Senior Member
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
|
rieseguiun log con sysinspectator e hijackthis pubblicandoli sempre tramite link per il download è così più comodo visionarli
__________________
"Visti da vicino siamo tutti strani..." ~|~ What Defines a Community? ~|~ Thread eMule Ufficiale ~|~ Online Armor in Italiano ~|~ Regole di Sezione ~|► Guida a PrivateFirewall
|
|
|
|
|
|
#14 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
allora eccoci qua ora vi mettèro i link come dice xcdegasp
premetto che vi stò scrivendo da un thinClient collegato a uno schermo CRT di 10 anni fà penso sia un 13" , al massimo 14" ![]() 1) sysinspectator http://wikisend.com/download/522264/...80613-0948.xml 2) hijackthis http://wikisend.com/download/225048/hijackthis.log sono pronto per la battaglia
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#15 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
l'ho TERMINATO !!!![]() ma tra i vari programmi quello che mi ha " aperto gli occhi " è stato Spybot - Search & Destroy ed ora vi allego che cosa si era infiltrato http://wikisend.com/download/542228/trojan.jpg http://wikisend.com/download/618958/voce registro non eliminabile.jpg spero di esservi stato utile come cavia grazie a tutti per l'interessamento
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#16 |
|
Senior Member
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
|
ottimo ti ha rimosso
Codice:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe@Debugger = "c:\windows\system32\ejvcveef.gif" ad ogni modo vai al link http://secunia.com/software_inspector/ e scansiona online il tuo, al termine ti notificherà tutti i programmi critici che sono obsoleti. nel caso della java ricordati poi di disinstallare quella attuale, per quanto riguarda acrobat reader valuta la possibilità di sostituirlo con il più veloce, leggero e performante FoxitReader
__________________
"Visti da vicino siamo tutti strani..." ~|~ What Defines a Community? ~|~ Thread eMule Ufficiale ~|~ Online Armor in Italiano ~|~ Regole di Sezione ~|► Guida a PrivateFirewall
Ultima modifica di xcdegasp : 13-06-2008 alle 22:05. |
|
|
|
|
|
#17 |
|
Senior Member
Iscritto dal: Jun 2001
Città: RiCcIoNe
Messaggi: 105
|
Grazie xcdegasp
![]() avevo tutto un pò vecchiotto certo che se non ci fosse sto forum .... grazie mille ancora , non si finisce mai di imparare ora il PC che ho in ufficio dimostra 5 anni in meno
__________________
" La PIADINA s'e PARSOT la PIS un po' MA TOT " |
|
|
|
|
|
#18 |
|
Senior Member
Iscritto dal: Dec 2007
Città: Brianza
Messaggi: 14704
|
Dai un'occhiata al trattamento di prevenzione / post disinfezione, ti aiuta a verificare la configurazione di sicurezza del tuo pc, aggiornare programmi vulnerabili obsoleti ed eliminare eventuali residui inutili dei programmi utilizzati nelle guide.
In particolare IE va aggiornato quanto prima alla 7
__________________
fattoebloggato.com • Trattamento post disinfezione • Recupero dati, RAID e Partizioni • Guida UBCD4Win • Test RAM • Controllo Disco • TestDisk • Operazioni di emergenza • Live cd Linux • UBCD • Backup • Gestione ISO & immagini virtuali • Partizionare un disco • Sardu • ScreenRecording • |
|
|
|
|
|
#19 |
|
Senior Member
Iscritto dal: Nov 2001
Città: Fidenza(pr) da Trento
Messaggi: 27479
|
benissimo
__________________
"Visti da vicino siamo tutti strani..." ~|~ What Defines a Community? ~|~ Thread eMule Ufficiale ~|~ Online Armor in Italiano ~|~ Regole di Sezione ~|► Guida a PrivateFirewall
|
|
|
|
|
| Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 00:24.














l'ho TERMINATO !!!









