Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

trojan da win Live messenger

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

trojan da win Live messenger

Messaggioda jack_the _best » gio gen 31, 2008 7:29 pm

ciao, un mio amico si è preso un virus via Windows Live messenger, il report di avg da queste info:

trojan horse backdoor.generic5.hsm

ha infettato il file nella cartella system32 mga.exe di 260 kb

il file non viene riparato da avg il quale propone di eliminare il file

per ora il file è in quarantena

si puo fare qualcosa per debellare il virus o basta eliminare il file?

grazie
Ci sono 10 tipi di persone al mondo. Quelli che capiscono il codice binario e quelli che non lo capiscono.
Avatar utente
jack_the _best
Senior Member
Senior Member
 
Messaggi: 172
Iscritto il: mer lug 12, 2006 1:58 pm

Messaggioda ste_95 » gio gen 31, 2008 7:30 pm

Posta un log di hijackthis:

Scarica HijackThis
Salvalo in una cartella (non aprirlo direttamente, sennò non farà i backup!)
Apri l'eseguibile
Clicca quindi su "Do a System Scan and Save a Logfile"
Attendi che finisca la scansione
Quindi copia il contenuto del blocco note qui sul forum.
«A volte è meglio tacere e sembrare stupidi che aprir bocca e togliere ogni dubbio.» Oscar Wilde
Avatar utente
ste_95
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 17271
Iscritto il: lun ago 06, 2007 11:19 am

Messaggioda jack_the _best » gio gen 31, 2008 7:59 pm

si eccolo:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19.36.27, on 31/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\Winamp\winampa.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Windows Live\Messenger\usnsvc.exe
C:\Programmi\Winamp\Winamp.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgvv.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Programmi\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programmi\File comuni\LightScribe\LSSrvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

--
End of file - 7215 bytes
Ci sono 10 tipi di persone al mondo. Quelli che capiscono il codice binario e quelli che non lo capiscono.
Avatar utente
jack_the _best
Senior Member
Senior Member
 
Messaggi: 172
Iscritto il: mer lug 12, 2006 1:58 pm


Messaggioda ste_95 » ven feb 01, 2008 7:56 am

Mi sembra che AVG abbia lavorato bene, non c'è traccia del trojan.
«A volte è meglio tacere e sembrare stupidi che aprir bocca e togliere ogni dubbio.» Oscar Wilde
Avatar utente
ste_95
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 17271
Iscritto il: lun ago 06, 2007 11:19 am

Messaggioda jack_the _best » ven feb 01, 2008 3:40 pm

Grazie

ma questo file si puo eliminarte senza rischi per il sistema?

grazie ancora
Ci sono 10 tipi di persone al mondo. Quelli che capiscono il codice binario e quelli che non lo capiscono.
Avatar utente
jack_the _best
Senior Member
Senior Member
 
Messaggi: 172
Iscritto il: mer lug 12, 2006 1:58 pm

Messaggioda ste_95 » ven feb 01, 2008 3:57 pm

Naturalmente [^]
«A volte è meglio tacere e sembrare stupidi che aprir bocca e togliere ogni dubbio.» Oscar Wilde
Avatar utente
ste_95
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 17271
Iscritto il: lun ago 06, 2007 11:19 am

Re: trojan da win Live messenger

Messaggioda naploli » sab mag 01, 2010 5:06 pm

lo stesso e succeso purea me comedv fare ??
Avatar utente
naploli
Neo Iscritto
Neo Iscritto
 
Messaggi: 12
Iscritto il: sab mag 01, 2010 4:37 pm

Re: trojan da win Live messenger

Messaggioda ste_95 » sab mag 01, 2010 5:14 pm

Scarica ComboFix , salvandolo sul desktop con un nome di fantasia, ed esegui la scansione seguendo queste istruzioni (giù in fondo). Al termine della scansione verrà creato il file di report C:\combofix.txt, copia qui il suo contenuto inserendolo tra i tag LOG, in questo modo:
Codice: Seleziona tutto
[LOG]qui va inserito il log[/LOG]
«A volte è meglio tacere e sembrare stupidi che aprir bocca e togliere ogni dubbio.» Oscar Wilde
Avatar utente
ste_95
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 17271
Iscritto il: lun ago 06, 2007 11:19 am

Re: trojan da win Live messenger

Messaggioda naploli » sab mag 01, 2010 5:25 pm

ma il collegamento che mi hai dato nn parte
Avatar utente
naploli
Neo Iscritto
Neo Iscritto
 
Messaggi: 12
Iscritto il: sab mag 01, 2010 4:37 pm

Re: trojan da win Live messenger

Messaggioda ste_95 » sab mag 01, 2010 5:36 pm

naploli ha scritto:ma il collegamento che mi hai dato non parte

Cosa significa?
«A volte è meglio tacere e sembrare stupidi che aprir bocca e togliere ogni dubbio.» Oscar Wilde
Avatar utente
ste_95
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 17271
Iscritto il: lun ago 06, 2007 11:19 am

Re: trojan da win Live messenger

Messaggioda naploli » sab mag 01, 2010 6:05 pm

niente scusa si era disconnesso internet xo nn so perché quando o avviato il programma avg mi a trovato 3 virus : tool-nircmd
come devo fare ?
Avatar utente
naploli
Neo Iscritto
Neo Iscritto
 
Messaggi: 12
Iscritto il: sab mag 01, 2010 4:37 pm

Re: trojan da win Live messenger

Messaggioda ste_95 » sab mag 01, 2010 6:08 pm

Disattiva AVG mentre esegui ComboFix.
«A volte è meglio tacere e sembrare stupidi che aprir bocca e togliere ogni dubbio.» Oscar Wilde
Avatar utente
ste_95
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 17271
Iscritto il: lun ago 06, 2007 11:19 am

Re: trojan da win Live messenger

Messaggioda naploli » sab mag 01, 2010 6:17 pm

come si fa?? e poi siamo sicuri che nn sia un qualche virus ?
Avatar utente
naploli
Neo Iscritto
Neo Iscritto
 
Messaggi: 12
Iscritto il: sab mag 01, 2010 4:37 pm

Re: trojan da win Live messenger

Messaggioda ste_95 » sab mag 01, 2010 6:21 pm

naploli ha scritto:come si fa?? e poi siamo sicuri che non sia un qualche virus ?

Ma dai, sarebbe il colmo se venissi su un forum a chiedere aiuto e ti dessimo un virus, non trovi? [rolleyes]

Per installare?
http://forums.avg.com/it-it/avg-free-fo ... how&id=319
«A volte è meglio tacere e sembrare stupidi che aprir bocca e togliere ogni dubbio.» Oscar Wilde
Avatar utente
ste_95
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 17271
Iscritto il: lun ago 06, 2007 11:19 am

Re: trojan da win Live messenger

Messaggioda naploli » dom mag 02, 2010 12:17 pm

ComboFix 10-04-30.03 - Tommy 02/05/2010 13.08.32.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.510.217 [GMT 2:00]
Eseguito da: c:\documents and settings\Tommy\Desktop\ComboFix.exe
AV: AVG Internet Security 3-pack *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programmi\WindowsUpdate
c:\windows\system32\Ijl11.dll

.
((((((((((((((((((((((((( Files Creati Da 2010-04-02 al 2010-05-02 )))))))))))))))))))))))))))))))))))
.

2010-05-01 16:55 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-05-01 16:55 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-05-01 14:44 . 2010-05-01 14:44 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\WMTools Downloaded Files
2010-05-01 14:22 . 2010-05-01 15:38 -------- d-----w- c:\documents and settings\Tommy\Tracing
2010-05-01 14:21 . 2010-05-01 14:21 -------- d-----w- c:\programmi\Microsoft
2010-05-01 14:21 . 2010-05-01 14:21 -------- d-----w- c:\programmi\Windows Live SkyDrive
2010-05-01 14:20 . 2010-05-01 14:21 -------- d-----w- c:\programmi\Windows Live
2010-05-01 14:11 . 2010-05-01 14:11 -------- d-----w- c:\programmi\File comuni\Windows Live
2010-05-01 14:11 . 2010-05-01 14:22 14248 ----a-w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-04-29 21:57 . 2010-05-01 23:32 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\vlc
2010-04-29 21:55 . 2010-04-29 21:55 -------- d-----w- c:\programmi\VideoLAN
2010-04-25 20:18 . 2010-04-25 20:18 -------- d-----w- c:\windows\Sun
2010-04-25 20:17 . 2010-04-25 20:17 -------- d-----w- c:\programmi\File comuni\Java
2010-04-25 20:17 . 2010-04-25 20:17 503808 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5afadc01-n\msvcp71.dll
2010-04-25 20:17 . 2010-04-25 20:17 499712 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5afadc01-n\jmc.dll
2010-04-25 20:17 . 2010-04-25 20:17 348160 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5afadc01-n\msvcr71.dll
2010-04-25 20:17 . 2010-04-25 20:17 61440 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6238d18e-n\decora-sse.dll
2010-04-25 20:17 . 2010-04-25 20:17 12800 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6238d18e-n\decora-d3d.dll
2010-04-25 20:16 . 2010-04-25 20:16 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-25 20:16 . 2010-04-25 20:16 -------- d-----w- c:\programmi\Java
2010-04-22 19:26 . 2010-04-22 19:26 -------- d-sh--w- c:\documents and settings\Tommy\PrivacIE
2010-04-22 19:21 . 2010-04-22 19:21 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-04-22 19:21 . 2010-04-22 19:21 -------- d-sh--w- c:\documents and settings\Tommy\IETldCache
2010-04-22 19:18 . 2010-02-25 06:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-04-22 19:18 . 2010-02-25 06:16 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-04-22 19:18 . 2010-02-25 06:16 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-04-22 19:18 . 2010-02-25 06:16 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-04-22 19:18 . 2010-02-25 06:16 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-22 19:18 . 2010-02-25 09:46 11070976 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-04-22 19:18 . 2010-04-24 16:17 -------- d-----w- c:\windows\ie8updates
2010-04-22 19:17 . 2010-02-16 04:50 64000 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-04-22 19:13 . 2010-04-22 19:16 -------- dc-h--w- c:\windows\ie8
2010-04-22 18:39 . 2010-04-22 18:39 360584 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgtdix.sys
2010-04-22 18:39 . 2010-04-22 18:39 28424 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgmfx86.sys
2010-04-22 18:39 . 2010-04-22 18:39 74760 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\UniversalDD.sys
2010-04-22 18:39 . 2010-04-22 18:39 30216 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSFilter.sys
2010-04-22 18:39 . 2010-04-22 18:39 25736 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSShim.sys
2010-04-22 18:39 . 2010-04-22 18:39 25608 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSxx.sys
2010-04-22 18:39 . 2010-04-22 18:39 122376 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSDriver.sys
2010-04-22 18:39 . 2010-04-22 18:39 333192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgldx86.sys
2010-04-22 18:39 . 2010-04-22 18:39 161800 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgrkx86.sys
2010-04-22 18:38 . 2010-04-22 18:38 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-04-22 18:25 . 2010-04-22 18:14 1007896 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.exe
2010-04-22 18:25 . 2010-04-22 18:14 1658136 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.dll
2010-04-22 18:25 . 2010-04-22 18:14 613656 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgiproxy.exe
2010-04-22 18:25 . 2010-04-22 18:14 800536 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avginet.dll
2010-04-22 18:15 . 2010-04-22 18:42 -------- d-----w- C:\$AVG
2010-04-22 18:14 . 2010-04-22 18:38 25096 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-04-22 18:14 . 2010-04-22 18:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-04-22 18:13 . 2010-04-22 18:13 -------- d-----w- c:\windows\SxsCaPendDel
2010-04-22 18:07 . 2010-01-25 13:28 3777816 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Temp\AVG\setup.exe
2010-04-22 18:07 . 2010-04-22 18:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Temp
2010-04-22 10:10 . 2008-03-28 08:07 20992 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\languages\compare.exe
2010-04-22 10:10 . 2010-04-22 10:10 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\Convivea
2010-04-22 10:10 . 2009-04-10 16:40 118784 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\x.exe
2010-04-22 10:10 . 2008-03-28 08:02 60928 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\update.exe
2010-04-22 10:10 . 2007-07-11 17:43 24557 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\special.exe
2010-04-22 10:10 . 2003-08-19 03:06 80896 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\x.dll
2010-04-22 10:10 . 2010-04-22 10:10 -------- d-----w- c:\programmi\Bit Che
2010-04-22 09:54 . 2010-05-01 21:36 -------- d-----w- c:\programmi\uTorrent
2010-04-22 09:54 . 2010-04-22 09:54 -------- d-----w- c:\programmi\Conduit
2010-04-22 09:54 . 2010-04-22 09:54 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Conduit
2010-04-22 09:54 . 2010-04-26 18:49 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Softonic-IT
2010-04-22 09:54 . 2010-04-22 10:02 -------- d-----w- c:\programmi\Softonic-IT
2010-04-22 09:53 . 2010-05-02 11:10 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\uTorrent
2010-04-22 09:50 . 2010-04-22 09:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DivX
2010-04-22 08:03 . 2010-04-28 18:14 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Temp
2010-04-22 08:03 . 2010-04-22 08:05 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google
2010-04-22 08:00 . 2010-02-17 12:05 2193664 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-04-22 08:00 . 2010-02-16 19:05 2149888 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-04-22 08:00 . 2010-02-16 19:05 2028032 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-04-22 07:57 . 2008-06-14 17:32 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-04-22 07:57 . 2008-06-14 17:32 272768 ------w- c:\windows\system32\drivers\bthport.sys
2010-04-21 17:57 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-21 15:20 . 2010-04-21 15:20 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Ahead
2010-04-21 15:18 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-04-21 15:17 . 2010-04-21 15:17 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\Ahead
2010-04-21 15:15 . 2010-04-21 15:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2010-04-21 15:15 . 2010-04-21 15:17 -------- d-----w- c:\programmi\File comuni\Ahead
2010-04-21 15:15 . 2010-04-21 15:15 -------- d-----w- c:\programmi\Nero
2010-04-21 15:06 . 2010-04-22 18:38 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-04-21 14:56 . 2010-04-22 18:38 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-21 14:55 . 2010-04-22 18:38 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-21 14:55 . 2010-04-22 18:38 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-21 14:55 . 2010-05-02 10:49 -------- d-----w- c:\windows\system32\drivers\Avg
2010-04-21 14:55 . 2010-04-22 18:14 -------- d-----w- c:\programmi\AVG
2010-04-21 07:55 . 2009-01-07 16:21 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2010-04-21 07:55 . 2010-05-01 17:02 -------- d--h--w- c:\windows\$hf_mig$
2010-04-20 18:22 . 2010-04-20 18:22 -------- d-sh--w- c:\documents and settings\Tommy\UserData
2010-04-20 18:08 . 2008-10-21 03:16 465152 ----a-r- c:\windows\system32\drivers\rt73.sys
2010-04-20 18:06 . 2006-05-24 11:36 110592 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\U3\temp\cleanup.exe
2010-04-20 18:05 . 2010-04-20 18:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2010-04-20 17:58 . 2010-04-20 17:58 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Help
2010-04-20 17:52 . 2002-09-12 15:29 6016 ----a-w- c:\windows\system32\ntsim.sys
2010-04-20 17:52 . 2008-04-13 09:45 6272 -c--a-w- c:\windows\system32\dllcache\splitter.sys
2010-04-20 17:52 . 2008-04-13 09:45 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-04-20 17:52 . 2008-04-13 10:17 83072 -c--a-w- c:\windows\system32\dllcache\wdmaud.sys
2010-04-20 17:52 . 2008-04-13 10:17 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2010-04-20 17:49 . 2010-04-20 17:49 -------- d-----w- c:\windows\Drivers
2010-04-20 17:49 . 2010-04-20 17:49 -------- d-----w- c:\programmi\WLAN a+b+g mini-PCI module
2010-04-20 17:47 . 2003-03-26 05:27 59392 ------w- c:\windows\system32\agrsmdel.exe
2010-04-20 17:46 . 2010-04-20 17:46 -------- d-----w- c:\windows\Options
2010-04-20 17:45 . 2010-04-20 17:46 -------- d-----w- c:\programmi\ATI Technologies
2010-04-20 17:45 . 2010-04-20 17:55 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-04-20 17:45 . 2010-04-20 17:49 -------- d-----w- c:\programmi\File comuni\InstallShield
2010-04-20 17:44 . 2010-04-20 17:44 -------- d-----w- c:\documents and settings\Tommy\Bluetooth Software
2010-04-20 17:40 . 2010-04-20 17:40 -------- d-----w- c:\programmi\VIA
2010-04-20 17:40 . 2002-12-27 02:41 26880 ----a-w- c:\windows\system32\drivers\VIAAGP1.SYS
2010-04-20 17:40 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-04-20 17:23 . 2001-08-30 18:41 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-04-20 17:23 . 2001-08-30 18:41 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-04-20 17:23 . 2008-04-13 09:45 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-04-20 17:23 . 2008-04-13 09:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-04-20 17:21 . 2010-04-21 15:09 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\U3
2010-04-20 17:21 . 2008-04-13 09:45 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-24 17:40 . 2004-08-30 20:00 48012 ----a-w- c:\windows\system32\perfc010.dat
2010-04-24 17:40 . 2004-08-30 20:00 345620 ----a-w- c:\windows\system32\perfh010.dat
2010-04-21 19:25 . 2010-04-19 17:35 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-04-20 17:51 . 2010-04-20 17:51 -------- d-----w- c:\programmi\Realtek Sound Manager
2010-04-20 17:51 . 2010-04-20 17:51 -------- d-----w- c:\programmi\AvRack
2010-04-19 17:36 . 2010-04-19 17:36 -------- d-----w- c:\programmi\microsoft frontpage
2010-04-19 17:34 . 2010-04-19 17:34 -------- d-----w- c:\programmi\Servizi in linea
2010-04-19 17:31 . 2010-04-19 17:31 21840 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-10 06:15 . 2008-04-13 17:13 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:16 . 2008-04-13 17:13 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2008-04-13 10:17 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 12:05 . 2008-04-13 16:55 2193664 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:05 . 2008-04-13 18:55 2070528 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2008-04-13 17:13 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2008-04-13 10:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.

------- Sigcheck -------

[-] 2008-06-20 . 3316C8A8EC07A9D4C0BE10310809A9E5 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e3393495-8103-46a0-8181-270273eddd60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-03-17 2355224]

[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e3393495-8103-46a0-8181-270273eddd60}]
2010-03-17 13:45 2355224 ----a-w- c:\programmi\Softonic-IT\tbSoft.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e3393495-8103-46a0-8181-270273eddd60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-03-17 2355224]

[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E3393495-8103-46A0-8181-270273EDDD60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-03-17 2355224]

[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
"Google Update"="c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2010-04-22 136176]
"uTorrent"="c:\programmi\uTorrent\uTorrent.exe" [2010-05-01 321328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"AGRSMMSG"="AGRSMMSG.exe" [2003-04-01 88267]
"SoundMan"="SOUNDMAN.EXE" [2003-05-14 55296]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-22 18:38 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [22/04/2010 20.14.47 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [21/04/2010 17.06.43 52872]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [21/04/2010 16.55.59 216200]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [21/04/2010 16.56.04 242896]
R2 avg9emc;AVG E-mail Scanner;c:\programmi\AVG\AVG9\avgemc.exe [22/04/2010 20.38.25 916760]
R2 avg9wd;AVG WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [22/04/2010 20.38.43 308064]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [22/04/2010 20.14.28 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [22/04/2010 20.14.27 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [22/04/2010 20.14.26 26120]
S3 AVGIDSAgent;AVG9IDSAgent;c:\programmi\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [22/04/2010 20.38.30 5888008]
.
Contenuto della cartella 'Scheduled Tasks'

2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-789336058-1202660629-1003Core.job
- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-22 08:03]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-789336058-1202660629-1003UA.job
- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-22 08:03]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://search.conduit.com?SearchSource= ... =CT2530241
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKCU-Run-WGA Agent - c:\windows\system32\mga.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-02 13:11
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2010-05-02 13:13:23
ComboFix-quarantined-files.txt 2010-05-02 11:13

Pre-Run: 72.687.509.504 byte disponibili
Post-Run: 73.504.567.296 byte disponibili

WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 87989AB626458C3BC4F565449B79B2E9
Avatar utente
naploli
Neo Iscritto
Neo Iscritto
 
Messaggi: 12
Iscritto il: sab mag 01, 2010 4:37 pm

Re: trojan da win Live messenger

Messaggioda naploli » dom mag 02, 2010 12:18 pm

questo è quello che è uscito dopo la scansione ora che devo fare ??
Avatar utente
naploli
Neo Iscritto
Neo Iscritto
 
Messaggi: 12
Iscritto il: sab mag 01, 2010 4:37 pm

Re: trojan da win Live messenger

Messaggioda ste_95 » dom mag 02, 2010 1:14 pm

Intanto correggere il post aggiungendo il tag LOG.

Poi, hai ancora problemi?
«A volte è meglio tacere e sembrare stupidi che aprir bocca e togliere ogni dubbio.» Oscar Wilde
Avatar utente
ste_95
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 17271
Iscritto il: lun ago 06, 2007 11:19 am

Re: trojan da win Live messenger

Messaggioda naploli » dom mag 02, 2010 1:27 pm

no ma il tag lo copiato nella risposta rapida nn è la stessa kosa??
Avatar utente
naploli
Neo Iscritto
Neo Iscritto
 
Messaggi: 12
Iscritto il: sab mag 01, 2010 4:37 pm

C:\combofix.txt

Messaggioda naploli » dom mag 02, 2010 1:56 pm

ComboFix 10-04-30.03 - Tommy 02/05/2010 13.08.32.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.510.217 [GMT 2:00]
Eseguito da: c:\documents and settings\Tommy\Desktop\ComboFix.exe
AV: AVG Internet Security 3-pack *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programmi\WindowsUpdate
c:\windows\system32\Ijl11.dll

.
((((((((((((((((((((((((( Files Creati Da 2010-04-02 al 2010-05-02 )))))))))))))))))))))))))))))))))))
.

2010-05-01 16:55 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-05-01 16:55 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-05-01 14:44 . 2010-05-01 14:44 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\WMTools Downloaded Files
2010-05-01 14:22 . 2010-05-01 15:38 -------- d-----w- c:\documents and settings\Tommy\Tracing
2010-05-01 14:21 . 2010-05-01 14:21 -------- d-----w- c:\programmi\Microsoft
2010-05-01 14:21 . 2010-05-01 14:21 -------- d-----w- c:\programmi\Windows Live SkyDrive
2010-05-01 14:20 . 2010-05-01 14:21 -------- d-----w- c:\programmi\Windows Live
2010-05-01 14:11 . 2010-05-01 14:11 -------- d-----w- c:\programmi\File comuni\Windows Live
2010-05-01 14:11 . 2010-05-01 14:22 14248 ----a-w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-04-29 21:57 . 2010-05-01 23:32 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\vlc
2010-04-29 21:55 . 2010-04-29 21:55 -------- d-----w- c:\programmi\VideoLAN
2010-04-25 20:18 . 2010-04-25 20:18 -------- d-----w- c:\windows\Sun
2010-04-25 20:17 . 2010-04-25 20:17 -------- d-----w- c:\programmi\File comuni\Java
2010-04-25 20:17 . 2010-04-25 20:17 503808 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5afadc01-n\msvcp71.dll
2010-04-25 20:17 . 2010-04-25 20:17 499712 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5afadc01-n\jmc.dll
2010-04-25 20:17 . 2010-04-25 20:17 348160 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5afadc01-n\msvcr71.dll
2010-04-25 20:17 . 2010-04-25 20:17 61440 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6238d18e-n\decora-sse.dll
2010-04-25 20:17 . 2010-04-25 20:17 12800 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6238d18e-n\decora-d3d.dll
2010-04-25 20:16 . 2010-04-25 20:16 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-25 20:16 . 2010-04-25 20:16 -------- d-----w- c:\programmi\Java
2010-04-22 19:26 . 2010-04-22 19:26 -------- d-sh--w- c:\documents and settings\Tommy\PrivacIE
2010-04-22 19:21 . 2010-04-22 19:21 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-04-22 19:21 . 2010-04-22 19:21 -------- d-sh--w- c:\documents and settings\Tommy\IETldCache
2010-04-22 19:18 . 2010-02-25 06:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-04-22 19:18 . 2010-02-25 06:16 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-04-22 19:18 . 2010-02-25 06:16 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-04-22 19:18 . 2010-02-25 06:16 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-04-22 19:18 . 2010-02-25 06:16 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-22 19:18 . 2010-02-25 09:46 11070976 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-04-22 19:18 . 2010-04-24 16:17 -------- d-----w- c:\windows\ie8updates
2010-04-22 19:17 . 2010-02-16 04:50 64000 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-04-22 19:13 . 2010-04-22 19:16 -------- dc-h--w- c:\windows\ie8
2010-04-22 18:39 . 2010-04-22 18:39 360584 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgtdix.sys
2010-04-22 18:39 . 2010-04-22 18:39 28424 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgmfx86.sys
2010-04-22 18:39 . 2010-04-22 18:39 74760 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\UniversalDD.sys
2010-04-22 18:39 . 2010-04-22 18:39 30216 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSFilter.sys
2010-04-22 18:39 . 2010-04-22 18:39 25736 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSShim.sys
2010-04-22 18:39 . 2010-04-22 18:39 25608 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSxx.sys
2010-04-22 18:39 . 2010-04-22 18:39 122376 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\AVGIDSDriver.sys
2010-04-22 18:39 . 2010-04-22 18:39 333192 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgldx86.sys
2010-04-22 18:39 . 2010-04-22 18:39 161800 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgrkx86.sys
2010-04-22 18:38 . 2010-04-22 18:38 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-04-22 18:25 . 2010-04-22 18:14 1007896 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.exe
2010-04-22 18:25 . 2010-04-22 18:14 1658136 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgupd.dll
2010-04-22 18:25 . 2010-04-22 18:14 613656 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avgiproxy.exe
2010-04-22 18:25 . 2010-04-22 18:14 800536 ----a-w- c:\documents and settings\All Users\Dati applicazioni\avg9\update\backup\avginet.dll
2010-04-22 18:15 . 2010-04-22 18:42 -------- d-----w- C:\$AVG
2010-04-22 18:14 . 2010-04-22 18:38 25096 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-04-22 18:14 . 2010-04-22 18:14 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg9
2010-04-22 18:13 . 2010-04-22 18:13 -------- d-----w- c:\windows\SxsCaPendDel
2010-04-22 18:07 . 2010-01-25 13:28 3777816 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Temp\AVG\setup.exe
2010-04-22 18:07 . 2010-04-22 18:07 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Temp
2010-04-22 10:10 . 2008-03-28 08:07 20992 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\languages\compare.exe
2010-04-22 10:10 . 2010-04-22 10:10 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\Convivea
2010-04-22 10:10 . 2009-04-10 16:40 118784 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\x.exe
2010-04-22 10:10 . 2008-03-28 08:02 60928 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\update.exe
2010-04-22 10:10 . 2007-07-11 17:43 24557 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\special.exe
2010-04-22 10:10 . 2003-08-19 03:06 80896 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\Convivea\Bit_Che\scripts\x.dll
2010-04-22 10:10 . 2010-04-22 10:10 -------- d-----w- c:\programmi\Bit Che
2010-04-22 09:54 . 2010-05-01 21:36 -------- d-----w- c:\programmi\uTorrent
2010-04-22 09:54 . 2010-04-22 09:54 -------- d-----w- c:\programmi\Conduit
2010-04-22 09:54 . 2010-04-22 09:54 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Conduit
2010-04-22 09:54 . 2010-04-26 18:49 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Softonic-IT
2010-04-22 09:54 . 2010-04-22 10:02 -------- d-----w- c:\programmi\Softonic-IT
2010-04-22 09:53 . 2010-05-02 11:10 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\uTorrent
2010-04-22 09:50 . 2010-04-22 09:51 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\DivX
2010-04-22 08:03 . 2010-04-28 18:14 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Temp
2010-04-22 08:03 . 2010-04-22 08:05 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google
2010-04-22 08:00 . 2010-02-17 12:05 2193664 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-04-22 08:00 . 2010-02-16 19:05 2149888 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-04-22 08:00 . 2010-02-16 19:05 2028032 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-04-22 07:57 . 2008-06-14 17:32 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-04-22 07:57 . 2008-06-14 17:32 272768 ------w- c:\windows\system32\drivers\bthport.sys
2010-04-21 17:57 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-21 15:20 . 2010-04-21 15:20 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Ahead
2010-04-21 15:18 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-04-21 15:17 . 2010-04-21 15:17 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\Ahead
2010-04-21 15:15 . 2010-04-21 15:15 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Nero
2010-04-21 15:15 . 2010-04-21 15:17 -------- d-----w- c:\programmi\File comuni\Ahead
2010-04-21 15:15 . 2010-04-21 15:15 -------- d-----w- c:\programmi\Nero
2010-04-21 15:06 . 2010-04-22 18:38 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-04-21 14:56 . 2010-04-22 18:38 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-21 14:55 . 2010-04-22 18:38 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-21 14:55 . 2010-04-22 18:38 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-21 14:55 . 2010-05-02 10:49 -------- d-----w- c:\windows\system32\drivers\Avg
2010-04-21 14:55 . 2010-04-22 18:14 -------- d-----w- c:\programmi\AVG
2010-04-21 07:55 . 2009-01-07 16:21 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2010-04-21 07:55 . 2010-05-01 17:02 -------- d--h--w- c:\windows\$hf_mig$
2010-04-20 18:22 . 2010-04-20 18:22 -------- d-sh--w- c:\documents and settings\Tommy\UserData
2010-04-20 18:08 . 2008-10-21 03:16 465152 ----a-r- c:\windows\system32\drivers\rt73.sys
2010-04-20 18:06 . 2006-05-24 11:36 110592 ----a-w- c:\documents and settings\Tommy\Dati applicazioni\U3\temp\cleanup.exe
2010-04-20 18:05 . 2010-04-20 18:05 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Office Genuine Advantage
2010-04-20 17:58 . 2010-04-20 17:58 -------- d-----w- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Help
2010-04-20 17:52 . 2002-09-12 15:29 6016 ----a-w- c:\windows\system32\ntsim.sys
2010-04-20 17:52 . 2008-04-13 09:45 6272 -c--a-w- c:\windows\system32\dllcache\splitter.sys
2010-04-20 17:52 . 2008-04-13 09:45 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-04-20 17:52 . 2008-04-13 10:17 83072 -c--a-w- c:\windows\system32\dllcache\wdmaud.sys
2010-04-20 17:52 . 2008-04-13 10:17 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2010-04-20 17:49 . 2010-04-20 17:49 -------- d-----w- c:\windows\Drivers
2010-04-20 17:49 . 2010-04-20 17:49 -------- d-----w- c:\programmi\WLAN a+b+g mini-PCI module
2010-04-20 17:47 . 2003-03-26 05:27 59392 ------w- c:\windows\system32\agrsmdel.exe
2010-04-20 17:46 . 2010-04-20 17:46 -------- d-----w- c:\windows\Options
2010-04-20 17:45 . 2010-04-20 17:46 -------- d-----w- c:\programmi\ATI Technologies
2010-04-20 17:45 . 2010-04-20 17:55 -------- d--h--w- c:\programmi\InstallShield Installation Information
2010-04-20 17:45 . 2010-04-20 17:49 -------- d-----w- c:\programmi\File comuni\InstallShield
2010-04-20 17:44 . 2010-04-20 17:44 -------- d-----w- c:\documents and settings\Tommy\Bluetooth Software
2010-04-20 17:40 . 2010-04-20 17:40 -------- d-----w- c:\programmi\VIA
2010-04-20 17:40 . 2002-12-27 02:41 26880 ----a-w- c:\windows\system32\drivers\VIAAGP1.SYS
2010-04-20 17:40 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-04-20 17:23 . 2001-08-30 18:41 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-04-20 17:23 . 2001-08-30 18:41 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-04-20 17:23 . 2008-04-13 09:45 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-04-20 17:23 . 2008-04-13 09:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-04-20 17:21 . 2010-04-21 15:09 -------- d-----w- c:\documents and settings\Tommy\Dati applicazioni\U3
2010-04-20 17:21 . 2008-04-13 09:45 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-24 17:40 . 2004-08-30 20:00 48012 ----a-w- c:\windows\system32\perfc010.dat
2010-04-24 17:40 . 2004-08-30 20:00 345620 ----a-w- c:\windows\system32\perfh010.dat
2010-04-21 19:25 . 2010-04-19 17:35 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-04-20 17:51 . 2010-04-20 17:51 -------- d-----w- c:\programmi\Realtek Sound Manager
2010-04-20 17:51 . 2010-04-20 17:51 -------- d-----w- c:\programmi\AvRack
2010-04-19 17:36 . 2010-04-19 17:36 -------- d-----w- c:\programmi\microsoft frontpage
2010-04-19 17:34 . 2010-04-19 17:34 -------- d-----w- c:\programmi\Servizi in linea
2010-04-19 17:31 . 2010-04-19 17:31 21840 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-10 06:15 . 2008-04-13 17:13 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:16 . 2008-04-13 17:13 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2008-04-13 10:17 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 12:05 . 2008-04-13 16:55 2193664 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:05 . 2008-04-13 18:55 2070528 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2008-04-13 17:13 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2008-04-13 10:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.

------- Sigcheck -------

[-] 2008-06-20 . 3316C8A8EC07A9D4C0BE10310809A9E5 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e3393495-8103-46a0-8181-270273eddd60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-03-17 2355224]

[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e3393495-8103-46a0-8181-270273eddd60}]
2010-03-17 13:45 2355224 ----a-w- c:\programmi\Softonic-IT\tbSoft.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e3393495-8103-46a0-8181-270273eddd60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-03-17 2355224]

[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E3393495-8103-46A0-8181-270273EDDD60}"= "c:\programmi\Softonic-IT\tbSoft.dll" [2010-03-17 2355224]

[HKEY_CLASSES_ROOT\clsid\{e3393495-8103-46a0-8181-270273eddd60}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmi\File comuni\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
"Google Update"="c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2010-04-22 136176]
"uTorrent"="c:\programmi\uTorrent\uTorrent.exe" [2010-05-01 321328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"AGRSMMSG"="AGRSMMSG.exe" [2003-04-01 88267]
"SoundMan"="SOUNDMAN.EXE" [2003-05-14 55296]
"NeroFilterCheck"="c:\programmi\File comuni\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-22 18:38 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\uTorrent\\uTorrent.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgemc.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [22/04/2010 20.14.47 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [21/04/2010 17.06.43 52872]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [21/04/2010 16.55.59 216200]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [21/04/2010 16.56.04 242896]
R2 avg9emc;AVG E-mail Scanner;c:\programmi\AVG\AVG9\avgemc.exe [22/04/2010 20.38.25 916760]
R2 avg9wd;AVG WatchDog;c:\programmi\AVG\AVG9\avgwdsvc.exe [22/04/2010 20.38.43 308064]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [22/04/2010 20.14.28 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [22/04/2010 20.14.27 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\programmi\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [22/04/2010 20.14.26 26120]
S3 AVGIDSAgent;AVG9IDSAgent;c:\programmi\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [22/04/2010 20.38.30 5888008]
.
Contenuto della cartella 'Scheduled Tasks'

2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-789336058-1202660629-1003Core.job
- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-22 08:03]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-789336058-1202660629-1003UA.job
- c:\documents and settings\Tommy\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2010-04-22 08:03]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://search.conduit.com?SearchSource= ... =CT2530241
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKCU-Run-WGA Agent - c:\windows\system32\mga.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-02 13:11
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2010-05-02 13:13:23
ComboFix-quarantined-files.txt 2010-05-02 11:13

Pre-Run: 72.687.509.504 byte disponibili
Post-Run: 73.504.567.296 byte disponibili

WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 87989AB626458C3BC4F565449B79B2E9
Avatar utente
naploli
Neo Iscritto
Neo Iscritto
 
Messaggi: 12
Iscritto il: sab mag 01, 2010 4:37 pm


Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 0 ospiti

cron
Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising