Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

aiuto virusssss

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

aiuto virusssss

Messaggioda milos » mer feb 09, 2005 8:31 am

salve.Sono preoccupatissima, ieri mattina all'apertura di internet mi si presentava un'altra pagina,forse un motore di ricerca.Con stopgozzilla sono stati rilevati: vv6.s13.tempx.cc e newdotnet6.38.dll. Leggendo un altro post di questo forum,ho provato a scaricare Antivir,ho fatto la scansione (circa 20 minuti)e mi ha trovato 3 file infetti che ha cancellati. Ho riavviato e rifatto la scansione, questa volta dopo 70 min non era ancora terminata. Ora la home page è esatta, ma tutto è diventato lentissimo, ogni icona che clikko sul desktop ci impiega una vita ad aprirsi, per non parlare di internet. Cosa può essere successo? Ho xp professional. per cortesia aiutatemi passo a passo perché io non sono esperta. Allego anche il logfile di Hijackthis. Grazie, aspetto con ansia.
Logfile of HijackThis v1.98.2
Scan saved at 18.22.59, on 08/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\AVPersonal\AVGUARD.EXE
C:\Programmi\AVPersonal\AVWUPSRV.EXE
C:\Programmi\CA\eTrust Antivirus\InoRpc.exe
C:\Programmi\CA\eTrust Antivirus\InoRT.exe
C:\Programmi\CA\eTrust Antivirus\InoTask.exe
C:\Programmi\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Programmi\Microsoft Works\WksSb.exe
C:\Programmi\AVPersonal\AVGNT.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Programmi\File comuni\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmi\TTERMPRO\ttermpro.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\utente\Desktop\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.it/default.asp?Ath=f
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.210:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {24BC9B2D-03BC-4473-853F-E690F5A39CBC} - C:\WINDOWS\System32\jnpc.dll (file missing)
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Programmi\NewDotNet\newdotnet6_38.dll (file missing)
O2 - BHO: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Programmi\QuickSearch\QuickSearchBar3_28.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Programmi\QuickSearch\QuickSearchBar3_28.dll (file missing)
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [WorksFUD] C:\Programmi\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmi\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmi\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programmi\AVPersonal\AVGNT.EXE" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Promemoria del Calendario di Microsoft Works.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 7882900160
O16 - DPF: {D5649FCD-D683-11D4-8C85-0020AFE1F8EC} (NIFtpDLLs.clsObject) - https://213.26.67.124/ce_milano/denunce ... tpDLLs.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{274E0FAA-2869-4A14-AF17-B2FB6059AB4B}: NameServer = 193.76.202.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{6CB7D100-0394-49BB-8AEE-C9146F6C512C}: NameServer = 193.76.202.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{274E0FAA-2869-4A14-AF17-B2FB6059AB4B}: NameServer = 193.76.202.5
Avatar utente
milos
Neo Iscritto
Neo Iscritto
 
Messaggi: 15
Iscritto il: mar feb 08, 2005 5:46 pm

Messaggioda Mr.TFM » mer feb 09, 2005 9:57 am

Per il new.net comuncia a cercare sul forum abbiamo già risolto PIÙ volte questo tipo di problema........
MegaLab è una potentissima droga virtuale.
"Nella setta del Codice Macintosh si può entrare, ma non se ne può uscire." V. ZUCCONI
Avatar utente
Mr.TFM
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 23387
Iscritto il: gio mar 18, 2004 11:46 am
Località: Livorno Ferraris (Vercelli)

Messaggioda crazy.cat » mer feb 09, 2005 1:14 pm

Oltre alle pulizie con i vari spybot e adware, togli queste righe qui sotto

O2 - BHO: (no name) - {24BC9B2D-03BC-4473-853F-E690F5A39CBC} - C:\WINDOWS\System32\jnpc.dll (file missing)
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Programmi\NewDotNet\newdotnet6_38.dll (file missing)
O2 - BHO: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Programmi\QuickSearch\QuickSearchBar3_28.dll (file missing) C:\Programmi\QuickSearch\QuickSearchBar3_28.dll (file missing)

Hai due antivirus installati e attivi?
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programmi\AVPersonal\AVGNT.EXE" /min
Per forza il pc è lento, togliene uno e vedi come và.

Per ulteriore sicurezza fai una scansione con questo programma
http://www.MegaLab.it/2333
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre


Messaggioda milos » mer feb 09, 2005 3:15 pm

grazie1000 ad entrambi. Ho tolto un antivirus ed effettivamente ora va come il vento (quando si è ignoranti si è ignoranti!). Ho fatto pulizia con spybot e adware e mi è rimasto ciò che segue, che devo fare ora. Abbiate pazienza!

DSO Exploit: Data source object exploit (Modifica al registro, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Modifica al registro, nothing done)
HKEY_USERS\S-1-5-21-3364005892-2716406928-3452464051-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Modifica al registro, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Modifica al registro, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Modifica al registro, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3


--- Spybot - Search && Destroy version: 1.3 ---
2004-11-29 Includes\Cookies.sbi
2005-01-27 Includes\Dialer.sbi
2005-01-27 Includes\Hijackers.sbi
2005-01-11 Includes\Keyloggers.sbi
2004-05-12 Includes\LSP.sbi
2005-01-27 Includes\Malware.sbi
2004-11-29 Includes\Revision.sbi
2004-11-29 Includes\Security.sbi
2005-01-27 Includes\Spybots.sbi
2004-11-29 Includes\Tracks.uti
2005-01-27 Includes\Trojans.sbi



Ad-Aware SE Build 1.05
Logfile Created on:mercoledì 9 febbraio 2005 14.58.09
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R27 05.02.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch(TAC index:10):9 total references
MRU List(TAC index:0):19 total references
Tracking Cookie(TAC index:3):2 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0

Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment : "HOMEOldSP"
Rootkey : HKEY_USERS
Object : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\internet explorer\main
Value : HOMEOldSP

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment : "HOMEOldSP"
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\main
Value : HOMEOldSP

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 2
Objects found so far: 2

Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 2

Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : utente@cgi-bin[2].txt
Category : Data Miner
Comment : Hits:17
Value : Cookie:utente@imrworldwide.com/cgi-bin
Expires : 07-02-2015 14.39.36
LastSync : Hits:17
UseCount : 0
Hits : 17

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : utente@tradedoubler[1].txt
Category : Data Miner
Comment : Hits:5
Value : Cookie:utente@tradedoubler.com/
Expires : 10-02-2005 2.38.40
LastSync : Hits:5
UseCount : 0
Hits : 5

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 2
Objects found so far: 4

Deep scanning and examining files...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 4

Disk Scan Result for C:\WINDOWS\System32
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 4

Disk Scan Result for C:\DOCUME~1\utente\IMPOST~1\Temp\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 4

Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 4

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\windows\currentversion\applets\wordpad\recent file list
Description : list of recent files opened using wordpad

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\windows\currentversion\applets\paint\recent file list
Description : list of files recently opened using microsoft paint

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\internet explorer\main
Description : last save directory used in microsoft internet explorer

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer

MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles
Description : list of recently used files in adobe reader

MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player

MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X

MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
Description : windows media sdk

MRU List Object Recognized!
Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
Description : windows media sdk

MRU List Object Recognized!
Location: : S-1-5-21-3364005892-2716406928-3452464051-1004\software\microsoft\windows media\wmsdk\general
Description : windows media sdk

MRU List Object Recognized!
Location: : C:\Documents and Settings\utente\recent
Description : list of recently opened documents


Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment : CWS.About:Blank
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\searchassistant uninstall

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment : CWS.About:Blank
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\searchassistant uninstall
Value : DisplayName

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment : CWS.About:Blank
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\searchassistant uninstall
Value : UninstallString

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\search
Value : SearchAssistant

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Enable Browser Extensions

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Use Custom Search URL

CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\main
Value : Use Search Asst

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 7
Objects found so far: 30

14.58.49 Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00.00.39.798
Objects scanned:58505
Objects identified:11
Objects ignored:0
New critical objects:11
Avatar utente
milos
Neo Iscritto
Neo Iscritto
 
Messaggi: 15
Iscritto il: mar feb 08, 2005 5:46 pm

Messaggioda crazy.cat » mer feb 09, 2005 5:13 pm

Per spybot prova ad installare questo aggiornamento e poi rifai la scansione.
http://www.pctuning.cz/ilustrace2/vlkou ... d131tx.exe

Cancella tutti i files temporanei di internet e fai la scansione con questo programma
http://www.intermute.com/spysubtract/cw ... nload.html

I cookies li puoi cancellare e gli Mru sono solo i documenti recenti e quindi puoi pulire anche quelli senza problemi.

Ho tolto alcune cose dal tuo log perché non pericolose e per abbreviarlo, altrimenti era troppo lungo da leggere.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda milos » mer feb 09, 2005 6:37 pm

ho aggiornato spybot come mi hai consigliato, fo rifatto la scan ed ho ottenuto "non sono state riscontrate minacce immediate"!
Poi ho canc i files temp di internet ed ho rifatto la scan con spysubtract, ecco il log:
--------------------------------- SpySubtract session started ---------------------------------
Machine=POSTO4
Time=Wed Feb 09 17:58:46 2005
Product Version=1, 0, 1, 49
OS Version=Microsoft Windows XP Professional Service Pack 1 (Build 2600)

--------------------------------- SpySubtract session ended ---------------------------------

--------------------------------- SpySubtract session started ---------------------------------
Machine=POSTO4
Time=Wed Feb 09 17:59:44 2005
Product Version=1, 0, 1, 49
OS Version=Microsoft Windows XP Professional Service Pack 1 (Build 2600)

Started Scanning
Programs in Memory
Finished Scanning
Started Scanning
Internet Cookies
Programs in Memory
Windows Registry
Found '' in 'SOFTWARE\New.net'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Uninstall\New.net'
Found '' in 'SOFTWARE\Classes\Tldctl2.URLLink'
Found '' in 'SOFTWARE\Classes\Tldctl2.URLLink.1'
Found '' in 'SOFTWARE\Classes\Tldctl2.URLLink.1\CLSID'
Found '' in 'SOFTWARE\Classes\Tldctl2.URLLink\CLSID'
Found '' in 'SOFTWARE\Classes\Tldctl2.URLLink\CurVer'
Found '' in 'SOFTWARE\New.net'
Found '' in 'SOFTWARE\Classes\TypeLib\{BAF13496-8F72-47A1-9CEE-09238EFC75F0}\1.0\0\win32'
Found '' in 'SOFTWARE\Classes\TypeLib\{BAF13496-8F72-47A1-9CEE-09238EFC75F0}\1.0\FLAGS'
Found '' in 'SOFTWARE\Classes\TypeLib\{BAF13496-8F72-47A1-9CEE-09238EFC75F0}\1.0\HELPDIR'
Internet URL Shortcuts
Files and Directories
Finished Scanning
--------------------------------- SpySubtract session started ---------------------------------
Machine=POSTO4
Time=Wed Feb 09 18:19:02 2005
Product Version=1, 0, 1, 49
OS Version=Microsoft Windows XP Professional Service Pack 1 (Build 2600)

--------------------------------- SpySubtract session started ---------------------------------
Machine=POSTO4
Time=Wed Feb 09 18:19:50 2005
Product Version=1, 0, 1, 49
OS Version=Microsoft Windows XP Professional Service Pack 1 (Build 2600)

--------------------------------- SpySubtract session ended ---------------------------------

--------------------------------- SpySubtract session started ---------------------------------
Machine=POSTO4
Time=Wed Feb 09 18:21:22 2005
Product Version=1, 0, 1, 49
OS Version=Microsoft Windows XP Professional Service Pack 1 (Build 2600)

--------------------------------- SpySubtract session ended ---------------------------------

--------------------------------- SpySubtract session started ---------------------------------
Machine=POSTO4
Time=Wed Feb 09 18:22:32 2005
Product Version=1, 0, 1, 49
OS Version=Microsoft Windows XP Professional Service Pack 1 (Build 2600)

Started Scanning
Programs in Memory
Finished Scanning
--------------------------------- SpySubtract session started ---------------------------------
Machine=POSTO4
Time=Wed Feb 09 18:23:11 2005
Product Version=1, 0, 1, 49
OS Version=Microsoft Windows XP Professional Service Pack 1 (Build 2600)

Started Scanning
Internet Cookies
Programs in Memory
Windows Registry
Found '' in 'SOFTWARE\New.net'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Uninstall\New.net'
Found '' in 'SOFTWARE\Classes\Tldctl2.URLLink'
Found '' in 'SOFTWARE\Classes\Tldctl2.URLLink.1'
Found '' in 'SOFTWARE\Classes\Tldctl2.URLLink.1\CLSID'
Found '' in 'SOFTWARE\Classes\Tldctl2.URLLink\CLSID'
Found '' in 'SOFTWARE\Classes\Tldctl2.URLLink\CurVer'
Found '' in 'SOFTWARE\New.net'
Found '' in 'SOFTWARE\Classes\TypeLib\{BAF13496-8F72-47A1-9CEE-09238EFC75F0}\1.0\0\win32'
Found '' in 'SOFTWARE\Classes\TypeLib\{BAF13496-8F72-47A1-9CEE-09238EFC75F0}\1.0\FLAGS'
Found '' in 'SOFTWARE\Classes\TypeLib\{BAF13496-8F72-47A1-9CEE-09238EFC75F0}\1.0\HELPDIR'
Internet URL Shortcuts
Files and Directories
Finished Scanning
--------------------------------- SpySubtract session started ---------------------------------
Machine=POSTO4
Time=Wed Feb 09 18:35:05 2005
Product Version=1, 0, 1, 49
OS Version=Microsoft Windows XP Professional Service Pack 1 (Build 2600)
Avatar utente
milos
Neo Iscritto
Neo Iscritto
 
Messaggi: 15
Iscritto il: mar feb 08, 2005 5:46 pm


Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 0 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising