Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

Dopo averle provate (quasi) tutte xp continua a crashare

Problemi con i sistemi operativi di casa Microsoft? Questa è la sezione che fa per te!

Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » ven nov 06, 2009 6:35 pm

Ciao a tutti,

in questi giorni mi è successa una cosa spiacevole, proprio collegandomi sul sito della mia facoltà (www.econoca.it). Inizialmente c'è stata una restrizione da parte di google, con il messaggio che il sito potrebbe avere malaware, ma entrando lo stesso il kaspersky ha rilevato dei virus che ha prontamente eliminato. Tutto sembra risolto, ma a seguito di questo si sono creati degli errori che portano inesorabilmente a dei crash di sistema.

Posto il log del crashdump

Microsoft (R) Windows Debugger Version 6.10.0003.233 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [E:\Trasferimenti\Mini110609-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: C:\Debugging Tools for Windows (x86)\Symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055ab20
Debug session time: Fri Nov 6 14:41:59.687 2009 (GMT+1)
System Uptime: 0 days 0:15:39.357
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
................................................................
.................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 100000C5, {7010d, 2, 0, 8054b88f}

*** WARNING: Unable to verify timestamp for mssmbios.sys
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: mssmbios!_SMBIOS_DATA_OBJECT ***
*** ***
*************************************************************************
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+ac )

Followup: Pool_corruption
---------

kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is
caused by drivers that have corrupted the system pool. Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: 0007010d, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 8054b88f, address which referenced memory

Debugging Details:
------------------

*************************************************************************
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: mssmbios!_SMBIOS_DATA_OBJECT ***
*** ***
*************************************************************************

BUGCHECK_STR: 0xC5_2

CURRENT_IRQL: 2

FAULTING_IP:
nt!ExDeferredFreePool+ac
8054b88f 8b08 mov ecx,dword ptr [eax]

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: DRIVER_FAULT

PROCESS_NAME: System

LAST_CONTROL_TRANSFER: from 8054ba1e to 8054b88f

STACK_TEXT:
f78cabcc 8054ba1e 851579f0 862cd8f8 85d197b8 nt!ExDeferredFreePool+0xac
f78cac0c 804efd1e 85d197b8 00000000 85d197b8 nt!ExFreePoolWithTag+0x489
f78cac1c 804f04b9 0231f000 86317228 85d197b8 nt!CcDeallocateBcb+0x1d
f78cac40 804f044d 00000000 00001000 f78cad40 nt!CcUnpinFileData+0x143
f78cac60 804efe61 862cd8f8 f78cacb0 00001000 nt!CcReleaseByteRangeFromWrite+0x72
f78cace8 804ee228 00001000 00000000 00000001 nt!CcFlushCache+0x49d
f78cad2c 804e54ad 863c52f8 80561b40 863c98b8 nt!CcWriteBehind+0xdc
f78cad74 804e47fe 863c52f8 00000000 863c98b8 nt!CcWorkerThread+0x126
f78cadac 8057dfed 863c52f8 00000000 00000000 nt!ExpWorkerThread+0x100
f78caddc 804fa477 804e4729 00000000 00000000 nt!PspSystemThreadStartup+0x34
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!ExDeferredFreePool+ac
8054b88f 8b08 mov ecx,dword ptr [eax]

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt!ExDeferredFreePool+ac

FOLLOWUP_NAME: Pool_corruption

IMAGE_NAME: Pool_Corruption

DEBUG_FLR_IMAGE_TIMESTAMP: 0

MODULE_NAME: Pool_Corruption

FAILURE_BUCKET_ID: 0xC5_2_nt!ExDeferredFreePool+ac

BUCKET_ID: 0xC5_2_nt!ExDeferredFreePool+ac

Followup: Pool_corruption
---------


In linea del tutto preventiva ho fatto una scansione con il kaspersky rescue disk, che ha dato esito negativo, e nonostante ciò, i crash si sono ripetuti. Approfittando del poco tempo a disposizione tra un crash e l'altro, ho avviato Ccleaner e ho fatto correggere eventuali errori di sistema, ma senza risolvere nulla. Come ultima cosa ho lanciato la scansione con Hijackthis di cui posto il log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17.40.47, on 06/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\PROGRA~1\CachemanXP\CachemanXP.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmi\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Programmi\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Programmi\Netropa\Onscreen Display\OSD.exe
C:\Programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\No-IP\DUC20.exe
C:\Programmi\Yzshadow\YzShadow.exe
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
O1 - Hosts: 205.238.40.1 winmx.com
O1 - Hosts: 205.238.40.51 http://www.winmx.com err.winmx.com
O1 - Hosts: 205.238.40.2 test3201.winmx.com test3205.winmx.com
O1 - Hosts: 205.238.40.2 test3202.winmx.com test3206.winmx.com
O1 - Hosts: 205.238.40.1 test3203.winmx.com test3207.winmx.com
O1 - Hosts: 82.43.224.20 test3204.winmx.com test3208.winmx.com
O1 - Hosts: 205.238.40.2 c3310.z1301.winmx.com c3310.z1302.winmx.com c3310.z1303.winmx.com c3310.z1304.winmx.com c3310.z1305.winmx.com c3310.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3313.z1301.winmx.com c3313.z1302.winmx.com c3313.z1303.winmx.com c3313.z1304.winmx.com c3313.z1305.winmx.com c3313.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3316.z1301.winmx.com c3316.z1302.winmx.com c3316.z1303.winmx.com c3316.z1304.winmx.com c3316.z1305.winmx.com c3316.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3311.z1301.winmx.com c3311.z1302.winmx.com c3311.z1303.winmx.com c3311.z1304.winmx.com c3311.z1305.winmx.com c3311.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3314.z1301.winmx.com c3314.z1302.winmx.com c3314.z1303.winmx.com c3314.z1304.winmx.com c3314.z1305.winmx.com c3314.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3317.z1301.winmx.com c3317.z1302.winmx.com c3317.z1303.winmx.com c3317.z1304.winmx.com c3317.z1305.winmx.com c3317.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3312.z1301.winmx.com c3312.z1302.winmx.com c3312.z1303.winmx.com c3312.z1304.winmx.com c3312.z1305.winmx.com c3312.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3315.z1301.winmx.com c3315.z1302.winmx.com c3315.z1303.winmx.com c3315.z1304.winmx.com c3315.z1305.winmx.com c3315.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3318.z1301.winmx.com c3318.z1302.winmx.com c3318.z1303.winmx.com c3318.z1304.winmx.com c3318.z1305.winmx.com c3318.z1306.winmx.com
O1 - Hosts: 82.43.224.20 c3319.z1301.winmx.com c3319.z1302.winmx.com c3319.z1303.winmx.com c3319.z1304.winmx.com c3319.z1305.winmx.com c3319.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3520.z1301.winmx.com c3520.z1302.winmx.com c3520.z1303.winmx.com c3520.z1304.winmx.com c3520.z1305.winmx.com c3520.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3523.z1301.winmx.com c3523.z1302.winmx.com c3523.z1303.winmx.com c3523.z1304.winmx.com c3523.z1305.winmx.com c3523.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3526.z1301.winmx.com c3526.z1302.winmx.com c3526.z1303.winmx.com c3526.z1304.winmx.com c3526.z1305.winmx.com c3526.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3521.z1301.winmx.com c3521.z1302.winmx.com c3521.z1303.winmx.com c3521.z1304.winmx.com c3521.z1305.winmx.com c3521.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3524.z1301.winmx.com c3524.z1302.winmx.com c3524.z1303.winmx.com c3524.z1304.winmx.com c3524.z1305.winmx.com c3524.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3527.z1301.winmx.com c3527.z1302.winmx.com c3527.z1303.winmx.com c3527.z1304.winmx.com c3527.z1305.winmx.com c3527.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3522.z1301.winmx.com c3522.z1302.winmx.com c3522.z1303.winmx.com c3522.z1304.winmx.com c3522.z1305.winmx.com c3522.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3525.z1301.winmx.com c3525.z1302.winmx.com c3525.z1303.winmx.com c3525.z1304.winmx.com c3525.z1305.winmx.com c3525.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3528.z1301.winmx.com c3528.z1302.winmx.com c3528.z1303.winmx.com c3528.z1304.winmx.com c3528.z1305.winmx.com c3528.z1306.winmx.com
O1 - Hosts: 82.43.224.20 c3529.z1301.winmx.com c3529.z1302.winmx.com c3529.z1303.winmx.com c3529.z1304.winmx.com c3529.z1305.winmx.com c3529.z1306.winmx.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Programmi\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NielsenOnline] C:\Programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Programmi\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: No-IP DUC.lnk = C:\Programmi\No-IP\DUC20.exe
O4 - Startup: YzShadow.lnk = C:\Programmi\Yzshadow\YzShadow.exe
O8 - Extra context menu item: Add to AMV Converter... - C:\Programmi\MP3 Player Utilities 4.17\AMVConverter\grab.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Statistiche sulla protezione del traffico Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programmi\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programmi\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{0943D617-20FE-49AD-AAD7-1F91A4639DF2}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CCS\Services\Tcpip\..\{1EFF52E2-9131-40FF-AD37-A3DEDC115554}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CCS\Services\Tcpip\..\{25797286-FEBD-4D00-A550-13DF87C9D2A4}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CS1\Services\Tcpip\..\{0943D617-20FE-49AD-AAD7-1F91A4639DF2}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CS2\Services\Tcpip\..\{0943D617-20FE-49AD-AAD7-1F91A4639DF2}: NameServer = 213.205.32.70,213.205.36.70
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\Skype4COM.dll
O18 - Filter hijack: text/html - {03974811-C15F-462c-B6B0-2D2336AA57D0} - (no file)
O20 - AppInit_DLLs: C:\PROGRA~1\Kaspersky Lab\Kaspersky Anti-Virus 2009\mzvkbd.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: AntiVir Update (AVWUpSrv) - Unknown owner - C:\Programmi\AVPersonal\AVWUPSRV.EXE (file missing)
O23 - Service: CachemanXP (CachemanXPService) - OuterTechnologies - C:\PROGRA~1\CachemanXP\CachemanXP.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Programmi\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Programmi\File comuni\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Programmi\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe
O23 - Service: StyleXPService - Unknown owner - C:\Programmi\TGTSoft\StyleXP\StyleXPService.exe

--
End of file - 12012 bytes


Come ultima cosa ho deselezionato dal pannello di avvio selettivo di windows i programmi in esecuzione automatica che riportavano errori, e per il momento sembra resistere...
Cosa mi consigliate di fare ancora prima di istituire una nuova disciplina olimpica, ovvero il lancio del pc?
Vi ringrazio tutti quanti in anticipo per il vostro aiuto [grazie]
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Guya » sab nov 07, 2009 8:33 pm

Aprire il case e controllare che non ci sia della lana di polvere sulla ram e sulla scheda madre.
Nei periodi di sbalzo di temperatura (caldo-freddo e freddo-caldo) si crea una leggera condensa
sulle parti metalliche dei componenti elettronici del PC che sommata alla polvere crea un corpo
conduttivo/capacitivo che danneggia la paginazione della ram.
Munirsi di pennello morbido e spazzolare mentre un aspirapolvere si succhia tutto.

Questa operazione andrebbe fatta almeno 2 volte l'anno in un pc che sta acceso 40ore a settimana.

Poi, sempre dopo un crash è consigliabile un CHKDSK /P /R con avvio da cd di istallazione in modalità ripristino.
Vedimai che qualche file è danneggiato, e così rimetti a posto i files.

Cancellazione immediata di tutti i temporanei : Internet explorer - Temp utente - Temp windows

Poi una controllatina al' MBR.
L'uso di Combofix ha anche questo controllo nei suoi processi.
Disabilitare l'antivirus se si usa combofix, tanto te lo chiede lui.

Noto che in questo periodo c'è di nuovo una pandemia di virus che si insidiano nell' MBR
creano un root-kit e si beccano in ftp e in http
Avatar utente
Guya
Aficionado
Aficionado
 
Messaggi: 140
Iscritto il: mar ott 07, 2003 1:50 pm
Località: Lombardia

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Berga95 » sab nov 07, 2009 9:35 pm

Guya ha scritto:Poi una controllatina al' MBR.
L'uso di Combofix ha anche questo controllo nei suoi processi.


Posta anche il log,naturalmente (c:\combofix) e aspetta il parere di esperti... xD
Non è morto ciò che in eterno può attendere - e col passare di strani eoni - anche la morte può morire.
~ H.P. Lovecraft
Avatar utente
Berga95
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3342
Iscritto il: sab set 12, 2009 12:56 pm
Località: C:\Python27 | C:\Dev-Cpp | Treviso


Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » lun nov 09, 2009 4:58 pm

Grazie per i consigli, in effetti mi ero dimenticato di questa possibilità offerta da combofix. Inoltre, faccio un test con il comando verifier così vedo qual è veramente il conflitto che genera il crash. E dal momento che il pc rimane acceso perennemente, cioè 7 giorni su 7 e 24h/24, un po' di pulizia non sarebbe male!! [^]
Appena possibile faccio un aggiornamento della situazione nella speranza di risolvere tutto quanto. [grazie]
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » ven nov 13, 2009 4:58 pm

Piccolo aggiornamento... aprendo il case ho scoperto che il sistema di raffreddamento della scheda video si è sciolto (letteralmente [acc2]) e quindi ho sostituito direttamente la scheda video. Pensando che questo fosse il fulcro del problema, ho riattivato tutto quanto ma ovviamente il crash di sistema si è ripresentato.. con un messaggio di errore differente e ora passo sia alla verifica con driver verifier e poi eventualmente posto nuovamente tutti i log necessari per venirne a capo.
Appena posso invio tutto quanto, a più tardi

[grazie]
Ultima modifica di Uomo_Senza_Sonno il mar nov 24, 2009 8:46 pm, modificato 1 volta in totale.
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Fred » ven nov 13, 2009 9:20 pm

Uomo_Senza_Sonno ha scritto:aprendo il case ho scoperto che il sistema della scheda video si è sciolto
In che senso?
Uomo_Senza_Sonno ha scritto:con un messaggio di errore differente

Quale?
Asus M3N78SE;AMD Athlon 64X2 5200+@5400;2 GB DDR2;NVIDIA GeForce 9500GT;Windows 7 Pro 64bit;
AcerASPIRE5230;Windows 7 Pro 64bit
Skype: nellopc90
Avatar utente
Fred
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3623
Iscritto il: mer apr 27, 2005 4:13 pm
Località: Urbe

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » sab nov 14, 2009 12:14 am

Per il post precedente.. volevo dire che aprendo il case ho trovato il sistema di raffreddamento della scheda video completamente sciolto, con tanto di ventola del dissipatore in pezzi... e dal momento che non vengono costruiti dissipatori di ricambio o adattabili, si è preferito comprare una nuova scheda video.
Allora... giusto per riportare la storia dei crash, ecco in ordine temporale i report del debugger

1° crash

Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\Master\Desktop\dump\Mini111309-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: C:\Windows\Symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055ab20
Debug session time: Fri Nov 13 16:43:17.984 2009 (GMT+1)
System Uptime: 0 days 0:13:31.696
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
................................................................
.................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000000A, {5c, 2, 0, 804dc6a8}

*** WARNING: Unable to verify timestamp for mssmbios.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Probably caused by : ntoskrnl.exe ( nt+56a8 )

Followup: MachineOwner
---------

kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000005c, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 804dc6a8, address which referenced memory

Debugging Details:
------------------

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************

ADDITIONAL_DEBUG_TEXT:
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

MODULE_NAME: nt

FAULTING_MODULE: 804d7000 nt

DEBUG_FLR_IMAGE_TIMESTAMP: 41108004

READ_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
0000005c

CURRENT_IRQL: 2

FAULTING_IP:
nt+56a8
804dc6a8 8a4f58 mov cl,byte ptr [edi+58h]

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0xA

LAST_CONTROL_TRANSFER: from 804dc6f2 to 804dc6a8

STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
b6b6ab0c 804dc6f2 00000200 e336a180 00001000 nt+0x56a8
b6b6ab10 00000000 e336a180 00001000 e631604b nt+0x56f2


STACK_COMMAND: kb

FOLLOWUP_IP:
nt+56a8
804dc6a8 8a4f58 mov cl,byte ptr [edi+58h]

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt+56a8

FOLLOWUP_NAME: MachineOwner

IMAGE_NAME: ntoskrnl.exe

BUCKET_ID: WRONG_SYMBOLS

Followup: MachineOwner
---------

2°...

Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\Master\Desktop\dump\Mini111309-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: C:\Windows\Symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055ab20
Debug session time: Fri Nov 13 17:52:55.125 2009 (GMT+1)
System Uptime: 0 days 0:58:53.828
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
................................................................
................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000000A, {fffffff0, 2, 0, 80672f19}

*** WARNING: Unable to verify timestamp for mssmbios.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Probably caused by : ntoskrnl.exe ( nt+19bf19 )

Followup: MachineOwner
---------

kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffffff0, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 80672f19, address which referenced memory

Debugging Details:
------------------

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************


ADDITIONAL_DEBUG_TEXT:
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

MODULE_NAME: nt

FAULTING_MODULE: 804d7000 nt

DEBUG_FLR_IMAGE_TIMESTAMP: 41108004

READ_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
fffffff0

CURRENT_IRQL: 2

FAULTING_IP:
nt+19bf19
80672f19 8b4808 mov ecx,dword ptr [eax+8]

CUSTOMER_CRASH_COUNT: 2

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0xA

LAST_CONTROL_TRANSFER: from 8054bca2 to 80672f19

STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
b534cc4c 8054bca2 98e2af68 98e2af68 b534ccd3 nt+0x19bf19
b534cc90 80671661 98e2af68 00000000 80671808 nt+0x74ca2
b534ccb8 8066a208 0019586c 00000000 b534cd48 nt+0x19a661
b534ccc8 80566bdc 98e2af68 b534cd64 01bafe94 nt+0x193208
b534cd48 804df06b 00000a98 01bafedc 01bafebc nt+0x8fbdc
b534cd64 7c91eb94 badb0d00 01bafe80 55555555 nt+0x806b
b534cd68 badb0d00 01bafe80 55555555 55555555 0x7c91eb94
b534cd6c 01bafe80 55555555 55555555 00000000 0xbadb0d00
b534cd70 55555555 55555555 00000000 00000000 0x1bafe80
b534cd74 55555555 00000000 00000000 00000000 0x55555555
b534cd78 00000000 00000000 00000000 00000000 0x55555555


STACK_COMMAND: kb

FOLLOWUP_IP:
nt+19bf19
80672f19 8b4808 mov ecx,dword ptr [eax+8]

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt+19bf19

FOLLOWUP_NAME: MachineOwner

IMAGE_NAME: ntoskrnl.exe

BUCKET_ID: WRONG_SYMBOLS

Followup: MachineOwner
---------

3°...

Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\Master\Desktop\dump\Mini111309-03.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: C:\Windows\Symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055ab20
Debug session time: Fri Nov 13 22:33:31.421 2009 (GMT+1)
System Uptime: 0 days 0:59:16.968
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
................................................................
..................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 100000C5, {6dedc, 2, 0, 8054b88f}

*** WARNING: Unable to verify timestamp for mssmbios.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*** WARNING: Unable to verify timestamp for USBPORT.SYS
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Probably caused by : USBPORT.SYS ( USBPORT!USBPORT_Core_UsbIocDpc_Worker+69 )

Followup: MachineOwner
---------

kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is
caused by drivers that have corrupted the system pool. Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: 0006dedc, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 8054b88f, address which referenced memory

Debugging Details:
------------------

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************

ADDITIONAL_DEBUG_TEXT:
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

MODULE_NAME: USBPORT

FAULTING_MODULE: 804d7000 nt

DEBUG_FLR_IMAGE_TIMESTAMP: 41107d62

BUGCHECK_STR: 0xC5_2

CURRENT_IRQL: 2

FAULTING_IP:
nt+7488f
8054b88f 8b08 mov ecx,dword ptr [eax]

CUSTOMER_CRASH_COUNT: 3

DEFAULT_BUCKET_ID: DRIVER_FAULT

LAST_CONTROL_TRANSFER: from 8054ba1e to 8054b88f

STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
80550704 8054ba1e 88447160 898510ec 885858c8 nt+0x7488f
80550744 8054b7b9 885858c8 00000000 805507c0 nt+0x74a1e
80550754 ba4b4fb1 885858c8 884889a8 885858c8 nt+0x747b9
805507c0 ba4b5b57 88444450 00000000 898517d8 USBPORT!USBPORT_Core_UsbIocDpc_Worker+0x69
805507f0 ba4b6754 026e6f44 898510e0 898510e0 USBPORT!MPf_GetEndpointStatus+0xa1
80550828 ba4b7f6a 89851028 804e3579 89851230 USBPORT!USBPORT_TxCsqInsertIrpEx+0x40
80550854 ba4c5fb0 89851028 804e3579 89851028 USBPORT!USBPORT_iEndpointRemoveStateList+0x1a
80550890 ba4c6128 89851028 00000001 80559580 USBPORT!USBPORT_StartDevice+0x100
805508ac 804dc179 8985164c 6b755044 00000000 USBPORT!USBPORT_StartDevice+0x278
805508b8 00000000 898510ec 80559320 ffdffc50 nt+0x5179


STACK_COMMAND: kb

FOLLOWUP_IP:
USBPORT!USBPORT_Core_UsbIocDpc_Worker+69
ba4b4fb1 ?? ???

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: USBPORT!USBPORT_Core_UsbIocDpc_Worker+69

FOLLOWUP_NAME: MachineOwner

IMAGE_NAME: USBPORT.SYS

BUCKET_ID: WRONG_SYMBOLS

Followup: MachineOwner
---------

Dopo questo ennesimo crash ho avviato combofix (mi domandavo perché non l'ho avviato prima) e al termine del suo lavoro ha rimosso alcune cosette che sono riportate nel suo log

ComboFix 09-11-13.06 - PC 13/11/2009 23.23.20.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1535.1138 [GMT 1:00]
Eseguito da: c:\documents and settings\PC\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Esecuzione precedente -------
.
c:\windows\g32.txt
c:\windows\gs32.txt
c:\windows\s32.txt
c:\windows\system32\kernel1.exe
c:\windows\system32\REGLOAD.EXE
c:\windows\ws386.ini

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ASPIMGR
-------\Legacy_R_SERVER
-------\Service_aspimgr
-------\Service_r_server


((((((((((((((((((((((((( Files Creati Da 2009-10-13 al 2009-11-13 )))))))))))))))))))))))))))))))))))
.

2009-11-13 15:04 . 2009-11-13 15:04 -------- d-----w- c:\windows\system32\AGEIA
2009-11-13 15:04 . 2009-11-13 15:04 -------- d-----w- c:\programmi\AGEIA Technologies
2009-11-13 15:03 . 2009-11-13 15:04 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-11-13 14:52 . 2004-08-03 22:08 20480 -c--a-w- c:\windows\system32\dllcache\usbuhci.sys
2009-11-13 14:52 . 2004-08-03 22:08 20480 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2009-11-07 14:00 . 2009-11-13 22:04 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\TeraCopy
2009-11-07 14:00 . 2009-11-07 14:00 -------- d-----w- c:\programmi\TeraCopy
2009-11-06 16:40 . 2009-11-06 16:40 -------- d-----w- c:\programmi\Trend Micro
2009-11-02 16:40 . 2009-06-03 15:32 14336 ----a-w- c:\windows\system32\drivers\nnrnstdi.sys
2009-11-02 16:39 . 2009-06-03 15:27 8832 ----a-w- c:\windows\system32\drivers\km_filter.sys
2009-11-02 16:38 . 2008-03-21 12:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-11-02 16:37 . 2008-12-16 12:44 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2009-11-02 16:34 . 2009-02-25 14:21 58688 ----a-w- c:\windows\nswatchdog.exe
2009-10-17 08:09 . 2009-10-17 08:10 -------- d-----w- c:\programmi\File comuni\DivX Shared

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-13 22:19 . 2009-02-26 22:06 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2009-11-13 22:14 . 2009-02-26 22:06 696352 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-11-13 22:14 . 2009-02-26 22:06 5556 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-11-13 22:14 . 2009-02-26 22:06 5064224 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-11-13 22:14 . 2009-02-26 22:06 42740 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-11-13 14:57 . 2006-01-24 11:01 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\ATI
2009-11-10 23:09 . 2006-01-25 18:20 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\Skype
2009-11-10 17:58 . 2008-03-25 21:12 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\skypePM
2009-11-09 14:07 . 2006-02-21 10:58 -------- d-----w- c:\programmi\eMule
2009-11-07 17:19 . 2007-05-28 10:22 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\MysteryStudio
2009-11-04 12:29 . 2001-08-31 12:00 85046 ----a-w- c:\windows\system32\perfc010.dat
2009-11-04 12:29 . 2001-08-31 12:00 490848 ----a-w- c:\windows\system32\perfh010.dat
2009-11-04 09:27 . 2006-01-25 10:52 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\AdobeUM
2009-11-02 16:38 . 2009-11-02 16:38 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf
2009-11-02 16:38 . 2009-11-02 16:38 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-11-01 17:56 . 2009-09-15 22:19 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\vlc
2009-10-17 08:11 . 2005-12-20 18:01 -------- d-----w- c:\programmi\DivX
2009-10-15 21:53 . 2009-02-26 22:06 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-15 21:53 . 2009-02-26 22:06 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-15 21:49 . 2009-05-15 17:31 58 ----a-w- c:\windows\msi.bat
2009-10-13 21:19 . 2009-10-13 21:17 20299296 ----a-w- c:\documents and settings\PC\Dati applicazioni\TomTom\HOME\Profiles\flz39tn3.default\Updates\v2_7_2_1825_win.exe
2009-10-04 09:05 . 2009-10-04 08:58 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\Notepad++
2009-10-04 08:58 . 2009-10-04 08:58 -------- d-----w- c:\programmi\Notepad++
2009-09-25 16:41 . 2009-09-25 16:41 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-09-25 16:41 . 2009-09-25 16:41 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-09-25 16:41 . 2009-09-25 16:41 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-09-25 16:41 . 2009-09-25 16:41 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-09-25 16:41 . 2009-09-25 16:41 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-09-25 16:41 . 2009-09-25 16:41 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-09-25 16:41 . 2009-09-25 16:41 696320 ----a-w- c:\windows\system32\DivX.dll
2009-09-24 19:03 . 2005-12-20 11:49 300960 -c--a-w- c:\documents and settings\PC\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-09-24 19:01 . 2009-09-24 19:01 -------- d-----w- c:\programmi\Microsoft
2009-09-24 19:01 . 2009-09-24 19:01 -------- d-----w- c:\programmi\Windows Live
2009-09-24 19:01 . 2009-09-24 19:01 -------- d-----w- c:\programmi\Windows Live SkyDrive
2009-09-24 17:21 . 2009-09-24 17:21 -------- d-----w- c:\programmi\File comuni\Windows Live
2009-09-24 09:03 . 2006-02-21 19:35 -------- d-----w- c:\programmi\OESpamBully
2009-09-18 23:51 . 2009-03-03 22:27 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\DivX
2009-09-17 00:31 . 2009-01-06 12:19 -------- d-----w- c:\programmi\Microsoft Money
2009-09-15 22:15 . 2009-09-15 22:15 -------- d-----w- c:\programmi\VideoLAN
2006-02-19 13:57 . 2006-02-19 13:57 21 -c--a-w- c:\programmi\AVPersonalAVWIN.INI
2003-12-23 00:20 . 2006-09-08 15:02 777 -c--a-w- c:\programmi\trial_setup.ini
2003-12-23 00:20 . 2006-09-08 15:02 4297728 -c--a-w- c:\programmi\trial_setup.msi
2003-12-23 00:20 . 2006-09-08 15:02 40448 -c--a-w- c:\programmi\trial_setup.exe
2009-06-03 15:34 . 2009-11-04 16:33 180224 ----a-w- c:\programmi\mozilla firefox\components\nsgkff31_meter3.dll
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\programmi\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\programmi\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\programmi\TGTSoft\StyleXP\StyleXP.exe" [2005-01-25 1159168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MULTIMEDIA KEYBOARD"="c:\programmi\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-07-25 167936]
"NielsenOnline"="c:\programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2009-02-25 45056]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-03-24 77824]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\programmi\TGTSoft\StyleXP\CurrentLogon.EXE"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^PC^Menu Avvio^Programmi^Esecuzione automatica^YzShadow.lnk]
path=c:\documents and settings\PC\Menu Avvio\Programmi\Esecuzione automatica\YzShadow.lnk
backup=c:\windows\pss\YzShadow.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\ICQLite\\ICQLite.exe"=
"c:\\Programmi\\WinMX\\WinMX.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Italian\\setup.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:tcp emule
"4672:UDP"= 4672:UDP:udp emule

R0 ElbyVCD;ElbyVCD;c:\windows\system32\drivers\ElbyVCD.sys [28/11/2002 11.43.49 22016]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 18.29.38 33808]
R1 msikbd2k;Multimedia Keyboard Filter Driver;c:\windows\system32\drivers\Msikbd2k.sys [25/01/2006 13.30.17 6656]
R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [02/11/2009 17.40.17 14336]
R2 CachemanXPService;CachemanXP;c:\progra~1\CachemanXP\CachemanXP.exe [25/01/2006 19.50.29 204800]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [25/03/2008 20.07.10 24592]
R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [02/11/2009 17.39.49 8832]
R3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [26/01/2006 23.48.03 91830]
S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys --> c:\windows\system32\DRIVERS\nielprt.sys [?]
S0 xmasscsi;xmasscsi;c:\windows\system32\Drivers\xmasscsi.sys --> c:\windows\system32\Drivers\xmasscsi.sys [?]
S1 c2scsi;c2scsi; [x]
S2 AVWUpSrv;AntiVir Update;c:\programmi\AVPersonal\AVWUPSRV.EXE --> c:\programmi\AVPersonal\AVWUPSRV.EXE [?]
S2 nhksrv;Netropa NHK Server;c:\programmi\Netropa\Multimedia Keyboard\nhksrv.exe [25/01/2006 13.30.18 28672]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [26/07/2005 14.32.14 348352]
S3 ATHFMWDL;D-Link predator Bootloader driver;c:\windows\system32\drivers\Athfmwdl.sys [26/07/2005 14.35.36 43392]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?]

--- Altri Servizi/Drivers In Memoria ---

*NewlyCreated* - MBR
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
mStart Page = hxxp://search.myheritage.com
uInternet Connection Wizard,ShellNext = iexplore
IE: Add to AMV Converter... - c:\programmi\MP3 Player Utilities 4.17\AMVConverter\grab.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {0943D617-20FE-49AD-AAD7-1F91A4639DF2} = 213.205.32.70,213.205.36.70
TCP: {1EFF52E2-9131-40FF-AD37-A3DEDC115554} = 213.205.32.70,213.205.36.70
TCP: {25797286-FEBD-4D00-A550-13DF87C9D2A4} = 213.205.32.70,213.205.36.70
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\PC\Dati applicazioni\Mozilla\Firefox\Profiles\1wx1xwxp.default\
FF - prefs.js: browser.search.selectedEngine - MyHeritage Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - component: c:\programmi\Mozilla Firefox\components\nsgkff31_meter3.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJava11.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJava12.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJava13.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJava14.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJava32.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPOJI610.dll
FF - plugin: c:\programmi\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\programmi\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\programmi\Real\RealOne Player\Netscape6\nprpjplug.dll

---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

Notify-AtiExtEvent - (no file)
AddRemove-Themexp.org File - c:\progra~1\themexp\Themexp.org



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-13 23:28
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys >>UNKNOWN [0x89888EB0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x89888eb0
\Driver\ACPI -> 0x88dadb00
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x017BD1417
malicious code @ sector 0x017BD141A !
PE file found in sector at 0x017BD1430 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(1144)
c:\windows\system32\klogon.dll

- - - - - - - > 'explorer.exe'(2868)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2009-11-13 23:29
ComboFix-quarantined-files.txt 2009-11-13 22:29

Pre-Run: 8.036.114.432 byte disponibili
Post-Run: 7.994.585.088 byte disponibili

- - End Of File - - C330447FC24FD86904B83196E37937DE
ma nonostante questo si è presentato impietoso un nuovo crash!!!
Ovviamente ho fatto una scansione anche con hijackthis ed ecco il nuovo log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0.31.48, on 14/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\PROGRA~1\CachemanXP\CachemanXP.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmi\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Programmi\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Programmi\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Programmi\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [NielsenOnline] C:\Programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [STYLEXP] C:\Programmi\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to AMV Converter... - C:\Programmi\MP3 Player Utilities 4.17\AMVConverter\grab.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Statistiche sulla protezione del traffico Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programmi\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programmi\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{0943D617-20FE-49AD-AAD7-1F91A4639DF2}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CCS\Services\Tcpip\..\{1EFF52E2-9131-40FF-AD37-A3DEDC115554}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CCS\Services\Tcpip\..\{25797286-FEBD-4D00-A550-13DF87C9D2A4}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CS1\Services\Tcpip\..\{0943D617-20FE-49AD-AAD7-1F91A4639DF2}: NameServer = 213.205.32.70,213.205.36.70
O17 - HKLM\System\CS2\Services\Tcpip\..\{0943D617-20FE-49AD-AAD7-1F91A4639DF2}: NameServer = 213.205.32.70,213.205.36.70
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\Skype4COM.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: AntiVir Update (AVWUpSrv) - Unknown owner - C:\Programmi\AVPersonal\AVWUPSRV.EXE (file missing)
O23 - Service: CachemanXP (CachemanXPService) - OuterTechnologies - C:\PROGRA~1\CachemanXP\CachemanXP.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Programmi\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Programmi\File comuni\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Programmi\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: StyleXPService - Unknown owner - C:\Programmi\TGTSoft\StyleXP\StyleXPService.exe

--
End of file - 7826 bytes

4° crash

Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\Master\Desktop\dump\Mini111309-05.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055ab20
Debug session time: Fri Nov 13 23:31:01.578 2009 (GMT+1)
System Uptime: 0 days 0:12:17.187
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
................................................................
.....................
Loading User Symbols
Loading unloaded module list
............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 100000C5, {60705, 2, 0, 8054b88f}

*** WARNING: Unable to verify timestamp for mssmbios.sys
*** ERROR: Module load completed but symbols could not be loaded for mssmbios.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*** WARNING: Unable to verify timestamp for USBPORT.SYS
*** ERROR: Module load completed but symbols could not be loaded for USBPORT.SYS
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Probably caused by : USBPORT.SYS ( USBPORT+9fb1 )

Followup: MachineOwner
---------

kd> .reload
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
................................................................
.....................
Loading User Symbols
Loading unloaded module list
............
kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is
caused by drivers that have corrupted the system pool. Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: 00060705, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 8054b88f, address which referenced memory

Debugging Details:
------------------

*** WARNING: Unable to verify timestamp for mssmbios.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.

*** WARNING: Unable to verify timestamp for USBPORT.SYS
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
ADDITIONAL_DEBUG_TEXT:
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

MODULE_NAME: USBPORT

FAULTING_MODULE: 804d7000 nt

DEBUG_FLR_IMAGE_TIMESTAMP: 41107d62

BUGCHECK_STR: 0xC5_2

CURRENT_IRQL: 2

FAULTING_IP:
nt+7488f
8054b88f 8b08 mov ecx,dword ptr [eax]

CUSTOMER_CRASH_COUNT: 4

DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT

LAST_CONTROL_TRANSFER: from 8054ba1e to 8054b88f

STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
80550704 8054ba1e 87f59008 897340ec 88022b38 nt+0x7488f
80550744 8054b7b9 88022b38 00000000 805507c0 nt+0x74a1e
80550754 ba4b4fb1 88022b38 87f708a8 88022b38 nt+0x747b9
805507c0 ba4b5b57 87f67b4c 00000000 897347d8 USBPORT!USBPORT_Core_UsbIocDpc_Worker+0x69
805507f0 ba4b6754 026e6f44 897340e0 897340e0 USBPORT!MPf_GetEndpointStatus+0xa1
80550828 ba4b7f6a 89734028 804e3579 89734230 USBPORT!USBPORT_TxCsqInsertIrpEx+0x40
80550854 ba4c5fb0 89734028 804e3579 89734028 USBPORT!USBPORT_iEndpointRemoveStateList+0x1a
80550890 ba4c6128 89734028 00000001 80559580 USBPORT!USBPORT_StartDevice+0x100
805508ac 804dc179 8973464c 6b755044 00000000 USBPORT!USBPORT_StartDevice+0x278
805508b8 00000000 897340ec 80559320 ffdffc50 nt+0x5179


STACK_COMMAND: kb

FOLLOWUP_IP:
USBPORT!USBPORT_Core_UsbIocDpc_Worker+69
ba4b4fb1 ?? ???

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: USBPORT!USBPORT_Core_UsbIocDpc_Worker+69

FOLLOWUP_NAME: MachineOwner

IMAGE_NAME: USBPORT.SYS

BUCKET_ID: WRONG_SYMBOLS

Followup: MachineOwner
---------

a questo punto mi resta solo da fare un test intensivo alle ram ma in queste condizioni non posso proprio farlo, perché il pc rimane acceso esattamente 10 minuti prima di presentare il BSOD [acc2]

Suggerimenti? 1000 [grazie] per l'interessamento
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Guya » sab nov 14, 2009 8:07 am

Aggiorna immediatamente alla versione 2010 del kaspersky, è gratuita e in automatico recupera la chiave di licenza.
Mi sebra leggendo tra i logs, che avviene un ripristino di sistema ad ogni avvio.

quando lo hai usato Combofix ha fatto un riavvio automatico ?
Avatar utente
Guya
Aficionado
Aficionado
 
Messaggi: 140
Iscritto il: mar ott 07, 2003 1:50 pm
Località: Lombardia

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » sab nov 14, 2009 3:06 pm

ovviamente combofix ha terminato tutto il suo processo e ha riavviato in automatico.. e successivamente, quando tutto sembrava andare per il meglio, si è ripresentata impietosa la schermata blu.
Ora riprovo a smontare le componenti e verificare se ce n'è qualcuna che crea problemi, ed infine verifico le ram, sempre se il pc non si pianta prima. Nel caso posto nuovi log.

Grazie ancora per l'interessamento
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » sab nov 14, 2009 5:55 pm

nuovo aggiornamento... ho fatto un controllo all'mbr e ho trovato un'infezione proprio del rootkit che si insinua nell'mbr. Ho usato il tool mbr.exe e seguito la guida ma l'infezione non si elimina... infine sono andato nella console di ripristino ma sinceramente vorrei sapere se devo dare oltre al comando fixmbr altri consensi o se parte tutto in automatico e devo solo aspettare.
In altre parole, mi potete scrivere una guida passo passo su come usare questo comando?

[grazie]
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Fred » sab nov 14, 2009 7:22 pm

Dai fixmbr e poi fai fare al comando il suo corso. Poi chiudi la console e riavvii il sistema.
[ciao]
Asus M3N78SE;AMD Athlon 64X2 5200+@5400;2 GB DDR2;NVIDIA GeForce 9500GT;Windows 7 Pro 64bit;
AcerASPIRE5230;Windows 7 Pro 64bit
Skype: nellopc90
Avatar utente
Fred
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3623
Iscritto il: mer apr 27, 2005 4:13 pm
Località: Urbe

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » sab nov 14, 2009 8:27 pm

ho appena eseguito il comando dalla console di ripristino, ma riavviando nuovamente ho rieseguito nuovamente mbr.exe per una verifica ma il responso è stato il seguente

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x017BD1417
malicious code @ sector 0x017BD141A !
PE file found in sector at 0x017BD1430 !


ed eseguendo il comando mbr.exe -f il log rimane identico... però ho eseguito un altro tool di rimozione e mi da il pc ripulito.. a cosa devo credere? Posto il log di questo tool

Norman SinowalMBR Cleaner
Copyright © 1990 - 2008, Norman ASA. Built 2008/05/13 16:21:18

Norman Scanner Engine Version: 5.92.04
Nvcbin.def Version: 5.92.00, Date: 2008/05/13 16:21:18, Variants: 0

Running pre-scan cleanup routine:
Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 2
Logged on user: LISA\PC

Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = "48 BB 92 01 78 01 A3 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 EE B8 00 A0 02 00 00 40 10 09 91 00 00 00 01 00 1D 00 5C 53 79 73 74 65 6D 52 6F 6F 74 5C 73 79 73 74 65 6D 33 32 5C 64 72 69 76 65 72 73 5C 6B 6D 69 78 65 72 2E 73 79 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 " -> ""
Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00000000

Scan started: 14/11/2009 18:22:29

Scanning bootsectors...

Found and removed SinowalMBR hooks (reboot required)

Number of sectors found: 0
Number of sectors scanned: 0
Number of sectors not scanned: 0
Number of infections found: 0
Number of infections removed: 0
Total scanning time: 1s 406ms


Scanning running processes and process memory...

Number of processes/threads found: 1634
Number of processes/threads scanned: 1632
Number of processes/threads not scanned: 2
Number of infected processes/threads terminated: 0
Total scanning time: 17s


Scanning file system...

Scanning: C:\*.*

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown185 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown186 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown187 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown188 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown189 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown190 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown191 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown192 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown193 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown194 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown195 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown196 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown197 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown198 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown199 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown200 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown201 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown202 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown203 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown204 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown205 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown206 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown207 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown208 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown209 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown210 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown211 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown212 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown213 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown214 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown215 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown216 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown217 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown218 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown219 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown220 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown221 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown222 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown223 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown224 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown225 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown226 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown227 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown228 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown229 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown230 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown231 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown232 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown233 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown234 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown235 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown236 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown237 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown238 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown239 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown240 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown241 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown242 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown243 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown244 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown245 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown246 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown247 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown248 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown249 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown250 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown251 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown252 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown253 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown254 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown255 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown256 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown257 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown258 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown259 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown260 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown261 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown262 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown263 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown264 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown265 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown266 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown267 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown268 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown269 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown270 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown271 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown272 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown273 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown274 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown275 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown276 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown277 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown278 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown279 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown280 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown281 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown282 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown283 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown284 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown285 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown286 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown287 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown288 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown289 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown290 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown291 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown292 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown293 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown294 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown295 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown296 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown297 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown298 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown299 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown300 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown301 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown302 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown303 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown304 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown305 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown306 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown307 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown308 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown309 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown310 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown311 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown312 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown313 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown314 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown315 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown316 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown317 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown318 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown319 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown320 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown321 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown322 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown323 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown324 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown325 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown326 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown327 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown328 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown329 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown330 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown331 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown332 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown333 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown334 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown335 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown336 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown337 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown338 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown339 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown340 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown341 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown342 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown343 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown344 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown345 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown346 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown347 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown348 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown349 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown350 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown351 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown352 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown353 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown354 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown355 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown356 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown357 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown358 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown359 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown360 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown361 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown362 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown363 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown364 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown365 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown366 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown367 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown368 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown369 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown370 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown371 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown372 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown373 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown374 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown375 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown376 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown377 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown378 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown379 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown380 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown381 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown382 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown383 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown384 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown385 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown386 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown387 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown388 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown389 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown390 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown391 (Error whilst scanning file: I/O Error)

C:\Documents and Settings\PC\Documenti\TomTom\HOME\Downloads\program\TomTomGO720TomTomGO920TomTomGO520\8.351.gox20.CAB-navcore-GO.cab/unknown393 (Error whilst scanning file: I/O Error)

Scanning: D:\*.*

D:\giochi\mame\roms\SVOLLEY.ZIP/sps_16.bin (Error whilst scanning file: I/O Error)


Running post-scan cleanup routine:

Number of files found: 191566
Number of archives unpacked: 1813
Number of files scanned: 191183
Number of files not scanned: 383
Number of files skipped due to exclude list: 0
Number of infected files found: 0
Number of infected files repaired/deleted: 0
Number of infections removed: 0
Total scanning time: 46m 51s


[grazie]
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » dom nov 15, 2009 4:12 pm

=============================================================================
Dr.Web Scanner per Windows v5.00.8 (5.00.8.11100)
© Doctor Web, Ltd., 1992-2009
Log generati su: 2009-11-14, 20:57:15 [LISA][PC]
Linea di Comando: "C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\9nrtqXP.exe" /lng:it-scan /ini:setup_XP.ini /fast
Sistema operativo: Windows XP Professional x86 (Build 2600), Service Pack 2
=============================================================================
DwShield avviato
Versione Engine: 5.00 (5.00.0.12182)
Versione API dell'Engine: 2.02
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\d79d63b0 - 25921 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\97e7a3a9 - 26893 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\cdd325dd - 25927 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\f3dae03e - 27494 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\89e3d1c3 - 12425 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\6598c9b6 - 4903 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\04f4daf9 - 3476 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\eba6ab14 - 8537 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\9a75aa85 - 5741 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\cbcdb441 - 4308 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\3c933b32 - 5456 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\8c95c8a1 - 6848 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\e56cb343 - 5479 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\b8f388ef - 8526 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\adf8a811 - 7640 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\d46bc55b - 6071 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\05aa7ca5 - 4983 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\f0c06527 - 2139 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\3ef4993d - 3732 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\c1d1a6ca - 6424 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\61682d7a - 5242 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\c71d18ce - 2770 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\1a6828f4 - 2685 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\2fdb5fd6 - 3327 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\bd2dc93b - 4697 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\7633fbd4 - 2792 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\f30f0503 - 5841 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\29c46c8c - 2260 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\801f1f37 - 4796 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\62e54992 - 5098 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\b2e8ec29 - 4891 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\2911a5d0 - 5033 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\a31f6000 - 3254 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\1a544de4 - 5206 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\ae2d0c38 - 7585 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\95af5935 - 5298 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\a573fe8c - 5947 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\8af61a6a - 6039 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\de9e53f6 - 5309 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\d879fdbb - 3511 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\fd2a0393 - 2495 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\116146c2 - 4565 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\0cde274e - 4467 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\ae180fdd - 5196 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\9ecdcfcc - 2359 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\dd478d62 - 1938 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\cabfb3c3 - 3335 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\e0c015c3 - 3185 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\21ffa52e - 1468 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\7be00a64 - 280 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\e0b90897 - 567 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\1ec7cfeb - 1194 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\ac509ba4 - 423328 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\a873f544 - 660 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\e5c2bbce - 575 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\bff2c517 - 508 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\d18b485d - 665 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\da2a11c1 - 626 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\37bea8e4 - 907 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\74638163 - 864 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\dcc8f6da - 1459 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\0cb22ff3 - 753 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\1278009b - 597 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\b6fabd58 - 554 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\ed9ce2b4 - 680 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\bf3b7035 - 712 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\0b15d654 - 925 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\85142639 - 840 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\52d4cf93 - 3316 virus records
[Virus base] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\19903618 - 19303 virus records
Totale virus records: 782825
[Self-checking] C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\9nrtqXP.exe
File Chiave: C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\setup.key
Numero della chiave della licenza: 0011097003
Registrato a nome di: An unauthorized User
Chiave della Licenza attiva: 2009-09-14
Scadenza della chiave della Licenza: 2010-03-17
Processi in memoria: System:4 - OK
Processi in memoria: C:\WINDOWS\system32\spoolsv.exe:352 - OK
Processi in memoria: C:\WINDOWS\system32\svchost.exe:488 - OK
Processi in memoria: C:\WINDOWS\SOUNDMAN.EXE:512 - OK
Processi in memoria: C:\Programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe:524 - OK
Processi in memoria: C:\Programmi\Netropa\Multimedia Keyboard\nhksrv.exe:664 - OK
Processi in memoria: \SystemRoot\System32\smss.exe:716 - OK
Processi in memoria: C:\Programmi\Netropa\Multimedia Keyboard\MMKeybd.exe:744 - OK
Processi in memoria: C:\WINDOWS\Explorer.EXE:768 - OK
Processi in memoria: C:\PROGRA~1\CachemanXP\CachemanXP.exe:852 - OK
Processi in memoria: C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE:904 - OK
Processi in memoria: C:\WINDOWS\system32\nvsvc32.exe:924 - OK
Processi in memoria: C:\Programmi\Netropa\Multimedia Keyboard\TrayMon.exe:1028 - OK
Processi in memoria: C:\Programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe:1048 - OK
Processi in memoria: \??\C:\WINDOWS\system32\csrss.exe:1104 - OK
Processi in memoria: \??\C:\WINDOWS\system32\winlogon.exe:1128 - OK
Processi in memoria: C:\WINDOWS\system32\services.exe:1176 - OK
Processi in memoria: C:\WINDOWS\system32\lsass.exe:1188 - OK
Processi in memoria: C:\Programmi\Netropa\Onscreen Display\OSD.exe:1372 - OK
Processi in memoria: C:\WINDOWS\system32\svchost.exe:1380 - OK
Processi in memoria: C:\WINDOWS\system32\svchost.exe:1428 - OK
Processi in memoria: C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\yhu5s3.exe:1500 - OK
Processi in memoria: C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxMediaDB.exe:1508 - OK
Processi in memoria: C:\WINDOWS\System32\svchost.exe:1560 - OK
Processi in memoria: C:\WINDOWS\system32\svchost.exe:1652 - OK
Processi in memoria: C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxWatch.exe:1744 - OK
Processi in memoria: C:\WINDOWS\system32\svchost.exe:1760 - OK
Processi in memoria: C:\WINDOWS\System32\alg.exe:2572 - OK
Processi in memoria: C:\WINDOWS\system32\RUNDLL32.EXE:2648 - OK
Processi in memoria: C:\DOCUME~1\PC\IMPOST~1\Temp\dc93888633\9nrtqXP.exe:2720 - OK
Processi in memoria: C:\Programmi\Mozilla Firefox\firefox.exe:3892 - OK
[Memory test] Nessun virus trovato
Master Boot Record HDD1 - OK
Active OS/2 or WinNT Boot Sector HDD1 - OK

Il log riportato sopra è il risultato della scansione effettuata con Dr.web cureit, appena possibile posto anche altri log di verifica con combofix, hijackthis, gmer e mbr.exe
a questo punto è importante capire dove devo andare a riparare

1000 [grazie] per l'aiuto
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » dom nov 15, 2009 4:57 pm

Come avevo detto prima, posto i vari log a seguito delle operazioni di pulizia che mi avete consigliato, compreso utilizzare il fixmbr dalla console di ripristino di windows.

Tuttavia, il log di mbr.exe rimane sempre lo stesso, ma ho effettuato altri esami per verificare questo messaggio, e il risultato è il seguente:

log mbr.exe

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x017BD1417
malicious code @ sector 0x017BD141A !
PE file found in sector at 0x017BD1430 !


log combofix

ComboFix 09-11-15.02 - PC 15/11/2009 16.48.37.3.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.511.205 [GMT 1:00]
Eseguito da: c:\documents and settings\PC\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((( Files Creati Da 2009-10-15 al 2009-11-15 )))))))))))))))))))))))))))))))))))
.

2009-11-14 19:57 . 2009-11-15 11:00 -------- d-----w- c:\documents and settings\PC\DoctorWeb
2009-11-14 16:14 . 2009-11-14 16:14 77312 ----a-w- C:\mbr.exe
2009-11-13 15:04 . 2009-11-13 15:04 -------- d-----w- c:\windows\system32\AGEIA
2009-11-13 15:04 . 2009-11-13 15:04 -------- d-----w- c:\programmi\AGEIA Technologies
2009-11-13 15:03 . 2009-11-13 15:04 -------- d-----w- c:\programmi\File comuni\Wise Installation Wizard
2009-11-13 14:52 . 2004-08-03 22:08 20480 -c--a-w- c:\windows\system32\dllcache\usbuhci.sys
2009-11-13 14:52 . 2004-08-03 22:08 20480 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2009-11-07 14:00 . 2009-11-15 15:45 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\TeraCopy
2009-11-07 14:00 . 2009-11-07 14:00 -------- d-----w- c:\programmi\TeraCopy
2009-11-06 16:40 . 2009-11-06 16:40 -------- d-----w- c:\programmi\Trend Micro
2009-11-02 16:40 . 2009-06-03 15:32 14336 ----a-w- c:\windows\system32\drivers\nnrnstdi.sys
2009-11-02 16:39 . 2009-06-03 15:27 8832 ----a-w- c:\windows\system32\drivers\km_filter.sys
2009-11-02 16:38 . 2008-03-21 12:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-11-02 16:37 . 2008-12-16 12:44 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2009-11-02 16:34 . 2009-02-25 14:21 58688 ----a-w- c:\windows\nswatchdog.exe
2009-10-17 08:09 . 2009-10-17 08:10 -------- d-----w- c:\programmi\File comuni\DivX Shared

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-15 15:01 . 2006-12-28 15:10 -------- d-----w- c:\programmi\Radmin
2009-11-15 14:25 . 2009-02-26 22:06 5153824 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-11-15 14:23 . 2009-02-26 22:06 43440 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-11-15 11:00 . 2007-10-21 10:26 -------- d-----w- c:\programmi\Cake Mania Back to the Bakery
2009-11-15 08:35 . 2009-02-26 22:06 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2009-11-14 19:25 . 2009-02-26 22:06 712736 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-11-14 19:25 . 2009-02-26 22:06 5612 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-11-14 19:19 . 2006-09-08 15:20 96256 ----a-w- c:\windows\system32\drivers\sptd8045.sys
2009-11-13 14:57 . 2006-01-24 11:01 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\ATI
2009-11-10 23:09 . 2006-01-25 18:20 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\Skype
2009-11-10 17:58 . 2008-03-25 21:12 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\skypePM
2009-11-09 14:07 . 2006-02-21 10:58 -------- d-----w- c:\programmi\eMule
2009-11-07 17:19 . 2007-05-28 10:22 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\MysteryStudio
2009-11-04 12:29 . 2001-08-31 12:00 85046 ----a-w- c:\windows\system32\perfc010.dat
2009-11-04 12:29 . 2001-08-31 12:00 490848 ----a-w- c:\windows\system32\perfh010.dat
2009-11-04 09:27 . 2006-01-25 10:52 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\AdobeUM
2009-11-02 16:38 . 2009-11-02 16:38 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf
2009-11-02 16:38 . 2009-11-02 16:38 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-11-01 17:56 . 2009-09-15 22:19 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\vlc
2009-10-17 08:11 . 2005-12-20 18:01 -------- d-----w- c:\programmi\DivX
2009-10-15 21:53 . 2009-02-26 22:06 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-15 21:53 . 2009-02-26 22:06 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-15 21:49 . 2009-05-15 17:31 58 ----a-w- c:\windows\msi.bat
2009-10-13 21:19 . 2009-10-13 21:17 20299296 ----a-w- c:\documents and settings\PC\Dati applicazioni\TomTom\HOME\Profiles\flz39tn3.default\Updates\v2_7_2_1825_win.exe
2009-10-04 09:05 . 2009-10-04 08:58 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\Notepad++
2009-10-04 08:58 . 2009-10-04 08:58 -------- d-----w- c:\programmi\Notepad++
2009-09-25 16:41 . 2009-09-25 16:41 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-09-25 16:41 . 2009-09-25 16:41 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-09-25 16:41 . 2009-09-25 16:41 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-09-25 16:41 . 2009-09-25 16:41 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-09-25 16:41 . 2009-09-25 16:41 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-09-25 16:41 . 2009-09-25 16:41 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-09-25 16:41 . 2009-09-25 16:41 696320 ----a-w- c:\windows\system32\DivX.dll
2009-09-24 19:03 . 2005-12-20 11:49 300960 -c--a-w- c:\documents and settings\PC\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-09-24 19:01 . 2009-09-24 19:01 -------- d-----w- c:\programmi\Microsoft
2009-09-24 19:01 . 2009-09-24 19:01 -------- d-----w- c:\programmi\Windows Live
2009-09-24 19:01 . 2009-09-24 19:01 -------- d-----w- c:\programmi\Windows Live SkyDrive
2009-09-24 17:21 . 2009-09-24 17:21 -------- d-----w- c:\programmi\File comuni\Windows Live
2009-09-24 09:03 . 2006-02-21 19:35 -------- d-----w- c:\programmi\OESpamBully
2009-09-18 23:51 . 2009-03-03 22:27 -------- d-----w- c:\documents and settings\PC\Dati applicazioni\DivX
2009-09-17 00:31 . 2009-01-06 12:19 -------- d-----w- c:\programmi\Microsoft Money
2006-02-19 13:57 . 2006-02-19 13:57 21 -c--a-w- c:\programmi\AVPersonalAVWIN.INI
2003-12-23 00:20 . 2006-09-08 15:02 777 -c--a-w- c:\programmi\trial_setup.ini
2003-12-23 00:20 . 2006-09-08 15:02 4297728 -c--a-w- c:\programmi\trial_setup.msi
2003-12-23 00:20 . 2006-09-08 15:02 40448 -c--a-w- c:\programmi\trial_setup.exe
2009-06-03 15:34 . 2009-11-04 16:33 180224 ----a-w- c:\programmi\mozilla firefox\components\nsgkff31_meter3.dll
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\programmi\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\programmi\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\programmi\TGTSoft\StyleXP\StyleXP.exe" [2005-01-25 1159168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MULTIMEDIA KEYBOARD"="c:\programmi\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-07-25 167936]
"NielsenOnline"="c:\programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2009-02-25 45056]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-03-24 77824]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\programmi\TGTSoft\StyleXP\CurrentLogon.EXE"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^PC^Menu Avvio^Programmi^Esecuzione automatica^YzShadow.lnk]
path=c:\documents and settings\PC\Menu Avvio\Programmi\Esecuzione automatica\YzShadow.lnk
backup=c:\windows\pss\YzShadow.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\ICQLite\\ICQLite.exe"=
"c:\\Programmi\\WinMX\\WinMX.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"c:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Italian\\setup.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:tcp emule
"4672:UDP"= 4672:UDP:udp emule

R0 ElbyVCD;ElbyVCD;c:\windows\system32\drivers\ElbyVCD.sys [28/11/2002 11.43.49 22016]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 18.29.38 33808]
R1 msikbd2k;Multimedia Keyboard Filter Driver;c:\windows\system32\drivers\Msikbd2k.sys [25/01/2006 13.30.17 6656]
R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [02/11/2009 17.40.17 14336]
R2 CachemanXPService;CachemanXP;c:\progra~1\CachemanXP\CachemanXP.exe [25/01/2006 19.50.29 204800]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [25/03/2008 20.07.10 24592]
R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [02/11/2009 17.39.49 8832]
R3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [26/01/2006 23.48.03 91830]
S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys --> c:\windows\system32\DRIVERS\nielprt.sys [?]
S0 xmasscsi;xmasscsi;c:\windows\system32\Drivers\xmasscsi.sys --> c:\windows\system32\Drivers\xmasscsi.sys [?]
S1 c2scsi;c2scsi; [x]
S2 AVWUpSrv;AntiVir Update;c:\programmi\AVPersonal\AVWUPSRV.EXE --> c:\programmi\AVPersonal\AVWUPSRV.EXE [?]
S2 nhksrv;Netropa NHK Server;c:\programmi\Netropa\Multimedia Keyboard\nhksrv.exe [25/01/2006 13.30.18 28672]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [26/07/2005 14.32.14 348352]
S3 ATHFMWDL;D-Link predator Bootloader driver;c:\windows\system32\drivers\Athfmwdl.sys [26/07/2005 14.35.36 43392]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?]

--- Altri Servizi/Drivers In Memoria ---

*Deregistered* - DwShield000076D1
*Deregistered* - mbr
*Deregistered* - PROCEXP113
*Deregistered* - pxtdapow
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
mStart Page = hxxp://search.myheritage.com
uInternet Connection Wizard,ShellNext = iexplore
IE: Add to AMV Converter... - c:\programmi\MP3 Player Utilities 4.17\AMVConverter\grab.html
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {0943D617-20FE-49AD-AAD7-1F91A4639DF2} = 213.205.32.70,213.205.36.70
TCP: {1EFF52E2-9131-40FF-AD37-A3DEDC115554} = 213.205.32.70,213.205.36.70
TCP: {25797286-FEBD-4D00-A550-13DF87C9D2A4} = 213.205.32.70,213.205.36.70
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\PC\Dati applicazioni\Mozilla\Firefox\Profiles\1wx1xwxp.default\
FF - prefs.js: browser.search.selectedEngine - MyHeritage Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - component: c:\programmi\Mozilla Firefox\components\nsgkff31_meter3.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJava11.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJava12.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJava13.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJava14.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJava32.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF - plugin: c:\programmi\Java\jre1.5.0_05\bin\NPOJI610.dll
FF - plugin: c:\programmi\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\programmi\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\programmi\Real\RealOne Player\Netscape6\nprpjplug.dll

---- FIREFOX POLICIES ----
c:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-15 16:54
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'winlogon.exe'(1128)
c:\windows\system32\klogon.dll

- - - - - - - > 'explorer.exe'(1572)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Ora fine scansione: 2009-11-15 16:56
ComboFix-quarantined-files.txt 2009-11-15 15:56
ComboFix2.txt 2009-11-13 22:29

Pre-Run: 9.136.680.960 byte disponibili
Post-Run: 9.096.585.216 byte disponibili

- - End Of File - - 80CD8C958E7CD653F41AA502A2E0554C


[il post continua perché è troppo grande...]
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » dom nov 15, 2009 4:59 pm

log gmer/sezione autostart

GMER 1.0.15.15227 - http://www.gmer.net
Autostart scan 2009-11-15 16:27:52
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@BootExecute = autocheck autochk * /*file not found*/

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\SYSTEM\CurrentControlSet\Control\WOW@cmdline = %SystemRoot%\system32\ntvdm.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon >>>
@UserinitC:\WINDOWS\system32\userinit.exe, = C:\WINDOWS\system32\userinit.exe,
@ShellExplorer.exe = Explorer.exe
@System =
@UIHostC:\Programmi\TGTSoft\StyleXP\CurrentLogon.EXE = C:\Programmi\TGTSoft\StyleXP\CurrentLogon.EXE

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
crypt32chain@DLLName = crypt32.dll
cryptnet@DLLName = cryptnet.dll
cscdll@DLLName = cscdll.dll
klogon@DLLName = C:\WINDOWS\system32\klogon.dll
ScCertProp@DLLName = wlnotify.dll
Schedule@DLLName = wlnotify.dll
sclgntfy@DLLName = sclgntfy.dll
SensLogn@DLLName = WlNotify.dll
termsrv@DLLName = wlnotify.dll
wlballoon@DLLName = wlnotify.dll

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs =

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
AudioSrv@ = %SystemRoot%\System32\svchost.exe -k netsvcs
AVP@ = "C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r
AVWUpSrv@ = C:\Programmi\AVPersonal\AVWUPSRV.EXE /*file not found*/
Browser@ = %SystemRoot%\system32\svchost.exe -k netsvcs
CachemanXPService@ = C:\PROGRA~1\CachemanXP\CachemanXP.exe
CryptSvc@ = %SystemRoot%\system32\svchost.exe -k netsvcs
DcomLaunch@ = %SystemRoot%\system32\svchost -k DcomLaunch
Dhcp@ = %SystemRoot%\system32\svchost.exe -k netsvcs
dmserver@ = %SystemRoot%\System32\svchost.exe -k netsvcs
ERSvc@ = %SystemRoot%\System32\svchost.exe -k netsvcs
Eventlog@ = %SystemRoot%\system32\services.exe
Fax@ = %systemroot%\system32\fxssvc.exe
helpsvc@ = %SystemRoot%\System32\svchost.exe -k netsvcs
Irmon@ = %SystemRoot%\system32\svchost.exe -k netsvcs
lanmanserver@ = %SystemRoot%\system32\svchost.exe -k netsvcs
lanmanworkstation@ = %SystemRoot%\system32\svchost.exe -k netsvcs
LmHosts@ = %SystemRoot%\system32\svchost.exe -k LocalService
MDM@ = "C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE"
nhksrv@ = C:\Programmi\Netropa\Multimedia Keyboard\nhksrv.exe
NVSvc@ = %SystemRoot%\system32\nvsvc32.exe
PlugPlay@ = %SystemRoot%\system32\services.exe
PolicyAgent@ = %SystemRoot%\system32\lsass.exe
ProtectedStorage@ = %SystemRoot%\system32\lsass.exe
RemoteRegistry@ = %SystemRoot%\system32\svchost.exe -k LocalService
RoxLiveShare@ = "C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxLiveShare.exe"
RoxUpnpServer@ = "C:\Programmi\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe"
RoxWatch@ = "C:\Programmi\File comuni\Roxio Shared\SharedCOM8\RoxWatch.exe"
RpcSs@ = %SystemRoot%\system32\svchost -k rpcss
SamSs@ = %SystemRoot%\system32\lsass.exe
Schedule@ = %SystemRoot%\System32\svchost.exe -k netsvcs
seclogon@ = %SystemRoot%\System32\svchost.exe -k netsvcs
SENS@ = %SystemRoot%\system32\svchost.exe -k netsvcs
SharedAccess@ = %SystemRoot%\System32\svchost.exe -k netsvcs
ShellHWDetection@ = %SystemRoot%\System32\svchost.exe -k netsvcs
Spooler@ = %SystemRoot%\system32\spoolsv.exe
srservice@ = %SystemRoot%\system32\svchost.exe -k netsvcs
stisvc@ = %SystemRoot%\system32\svchost.exe -k imgsvc
StyleXPService@ = "C:\Programmi\TGTSoft\StyleXP\StyleXPService.exe"
Themes@ = %SystemRoot%\System32\svchost.exe -k netsvcs
TrkWks@ = %SystemRoot%\system32\svchost.exe -k netsvcs
W32Time@ = %SystemRoot%\System32\svchost.exe -k netsvcs
WebClient@ = %SystemRoot%\system32\svchost.exe -k LocalService
winmgmt@ = %systemroot%\system32\svchost.exe -k netsvcs
wscsvc@ = %SystemRoot%\System32\svchost.exe -k netsvcs
wuauserv@ = %systemroot%\system32\svchost.exe -k netsvcs
WudfSvc@ = %SystemRoot%\system32\svchost.exe -k WudfServiceGroup
WZCSVC@ = %SystemRoot%\System32\svchost.exe -k netsvcs

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@SoundManSOUNDMAN.EXE = SOUNDMAN.EXE
@MULTIMEDIA KEYBOARDC:\Programmi\Netropa\Multimedia Keyboard\MMKeybd.exe = C:\Programmi\Netropa\Multimedia Keyboard\MMKeybd.exe
@NielsenOnlineC:\Programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe = C:\Programmi\NetRatingsNetSight\NetSight\NielsenOnline.exe
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
@nwiznwiz.exe /install = nwiz.exe /install
@NvMediaCenterRUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
@AVP"C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" = "C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run@STYLEXP = C:\Programmi\TGTSoft\StyleXP\StyleXP.exe -Hide

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad >>>
@PostBootReminder%SystemRoot%\system32\SHELL32.dll = %SystemRoot%\system32\SHELL32.dll
@CDBurn%SystemRoot%\system32\SHELL32.dll = %SystemRoot%\system32\SHELL32.dll
@WebCheck%Systemroot%\system32\webcheck.dll = %Systemroot%\system32\webcheck.dll
@SysTray%systemroot%\system32\stobject.dll = %systemroot%\system32\stobject.dll
@WPDShServiceObjC:\WINDOWS\system32\WPDShServiceObj.dll = C:\WINDOWS\system32\WPDShServiceObj.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler >>>
@{438755C2-A8BA-11D1-B96B-00A0C90312E1}%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{8C7461EF-2B13-11d2-BE35-3078302C2030}%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll

HKLM\Software\Classes\Folder\shell\open\command@ = %SystemRoot%\Explorer.exe /idlist,%I,%L

HKLM\Software\Classes\Folder\shell\explore\command@ = %SystemRoot%\Explorer.exe /e,/idlist,%I,%L

HKLM\Software\Classes\ >>>
.exe@ = "%1" %*
.com@ = "%1" %*
.cmd@ = "%1" %*
.bat@ = "%1" %*
.pif@ = "%1" %*
.scr@ = "%1" /S
.hta@ = C:\WINDOWS\system32\mshta.exe "%1" %*

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{AEB6717E-7E19-11d0-97EE-00C04FD91972} = shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{00022613-0000-0000-C000-000000000046} /*Proprietà dei file Multimedia*/mmsys.cpl = mmsys.cpl
@{176d6597-26d3-11d1-b350-080036a75b03} /*Gestore scanner ICM*/icmui.dll = icmui.dll
@{1F2E5C40-9550-11CE-99D2-00AA006E086C} /*Pagina di protezione NTFS*/rshx32.dll = rshx32.dll
@{3EA48300-8CF6-101B-84FB-666CCB9BCD32} /*Pagina di proprietà di Docfile OLE*/docprop.dll = docprop.dll
@{40dd6e20-7c17-11ce-a804-00aa003ca9f6} /*Estensioni shell per la condivisione*/ntshrui.dll = ntshrui.dll
@{41E300E0-78B6-11ce-849B-444553540000} /*PlusPack CPL Extension*/%SystemRoot%\system32\themeui.dll = %SystemRoot%\system32\themeui.dll
@{42071712-76d4-11d1-8b24-00a0c9068ff3} /*Estensione scheda video del Pannello di controllo*/deskadp.dll = deskadp.dll
@{42071713-76d4-11d1-8b24-00a0c9068ff3} /*Estensione monitor del Pannello di controllo*/deskmon.dll = deskmon.dll
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{4E40F770-369C-11d0-8922-00A024AB2DBB} /*Pagina di protezione DS*/dssec.dll = dssec.dll
@{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} /*Pagina compatibilità*/SlayerXP.dll = SlayerXP.dll
@{56117100-C0CD-101B-81E2-00AA004AE837} /*Gestore dati dei ritagli di shell*/shscrap.dll = shscrap.dll
@{59099400-57FF-11CE-BD94-0020AF85B590} /*Estensione copia dischi*/diskcopy.dll = diskcopy.dll
@{59be4990-f85c-11ce-aff7-00aa003ca9f6} /*Estensioni shell per oggetti Rete Microsoft Windows*/ntlanui2.dll = ntlanui2.dll
@{5DB2625A-54DF-11D0-B6C4-0800091AA605} /*Gestore monitor ICM*/%SystemRoot%\System32\icmui.dll = %SystemRoot%\System32\icmui.dll
@{675F097E-4C4D-11D0-B6C1-0800091AA605} /*Gestore stampante ICM*/%SystemRoot%\system32\icmui.dll = %SystemRoot%\system32\icmui.dll
@{764BF0E1-F219-11ce-972D-00AA00A14F56} /*Estensioni shell per la compressione dei file*/(null) =
@{77597368-7b15-11d0-a0c2-080036af3f03} /*Estensione shell per la stampante Web*/printui.dll = printui.dll
@{7988B573-EC89-11cf-9C00-00AA00A14F56} /*Disk Quota UI*/dskquoui.dll = dskquoui.dll
@{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} /*Menu di scelta rapida di crittografia*/(null) =
@{85BBD920-42A0-1069-A2E4-08002B30309D} /*Sincronia file*/syncui.dll = syncui.dll
@{88895560-9AA2-1069-930E-00AA0030EBC8} /*Estensione di icona di HyperTerminal*/C:\WINDOWS\system32\hticons.dll = C:\WINDOWS\system32\hticons.dll
@{BD84B380-8CA2-1069-AB1D-08000948F534} /*Tipi di carattere*/fontext.dll = fontext.dll
@{DBCE2480-C732-101B-BE72-BA78E9AD5B27} /*Profilo ICC*/%SystemRoot%\system32\icmui.dll = %SystemRoot%\system32\icmui.dll
@{F37C5810-4D3F-11d0-B4BF-00AA00BBB723} /*Pagina di protezione della stampante*/rshx32.dll = rshx32.dll
@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} /*Estensioni shell per la condivisione*/ntshrui.dll = ntshrui.dll
@{f92e8c40-3d33-11d2-b1aa-080036a75b03} /*Display TroubleShoot CPL Extension*/deskperf.dll = deskperf.dll
@{7444C717-39BF-11D1-8CD9-00C04FC29D45} /*Estensione Crypto PKO*/C:\WINDOWS\system32\cryptext.dll = C:\WINDOWS\system32\cryptext.dll
@{7444C719-39BF-11D1-8CD9-00C04FC29D45} /*Estensione firma crittografata*/C:\WINDOWS\system32\cryptext.dll = C:\WINDOWS\system32\cryptext.dll
@{7007ACC7-3202-11D1-AAD2-00805FC1270E} /*Connessioni di rete*/C:\WINDOWS\system32\NETSHELL.dll = C:\WINDOWS\system32\NETSHELL.dll
@{992CFFA0-F557-101A-88EC-00DD010CCC48} /*Connessioni di rete*/C:\WINDOWS\system32\NETSHELL.dll = C:\WINDOWS\system32\NETSHELL.dll
@{E211B736-43FD-11D1-9EFB-0000F8757FCD} /*Scanner e fotocamere digitali*/wiashext.dll = wiashext.dll
@{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD} /*Scanner e fotocamere digitali*/wiashext.dll = wiashext.dll
@{905667aa-acd6-11d2-8080-00805f6596d2} /*Scanner e fotocamere digitali*/wiashext.dll = wiashext.dll
@{3F953603-1008-4f6e-A73A-04AAC7A992F1} /*Scanner e fotocamere digitali*/wiashext.dll = wiashext.dll
@{83bbcbf3-b28a-4919-a5aa-73027445d672} /*Scanner e fotocamere digitali*/wiashext.dll = wiashext.dll
@{F0152790-D56E-4445-850E-4F3117DB740C} /*Remote Sessions CPL Extension*/C:\WINDOWS\system32\remotepg.dll = C:\WINDOWS\system32\remotepg.dll
@{60254CA5-953B-11CF-8C96-00AA00B8708C} /*Estensione shell per Windows Script Host*/C:\WINDOWS\system32\wshext.dll = C:\WINDOWS\system32\wshext.dll
@{2206CDB2-19C1-11D1-89E0-00C04FD7A829} /*Microsoft Data Link*/C:\Programmi\File comuni\System\Ole DB\oledb32.dll = C:\Programmi\File comuni\System\Ole DB\oledb32.dll
@{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF} /*Tasks Folder Icon Handler*/C:\WINDOWS\system32\mstask.dll = C:\WINDOWS\system32\mstask.dll
@{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF} /*Tasks Folder Shell Extension*/C:\WINDOWS\system32\mstask.dll = C:\WINDOWS\system32\mstask.dll
@{D6277990-4C6A-11CF-8D87-00AA0060F5BF} /*Operazioni pianificate*/C:\WINDOWS\system32\mstask.dll = C:\WINDOWS\system32\mstask.dll
@{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0} /*Set Program Access and Defaults*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{5F327514-6C5E-4d60-8F16-D07FA08A78ED} /*Auto Update Property Sheet Extension*/C:\WINDOWS\system32\wuaucpl.cpl = C:\WINDOWS\system32\wuaucpl.cpl
@{0DF44EAA-FF21-4412-828E-260A8728E7F1} /*Barra delle applicazioni e menu di avvio*/(null) =
@{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0} /*Cerca*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0} /*Guida in linea e supporto tecnico*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} /*Guida in linea e supporto tecnico*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} /*Esegui...*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0} /*Internet*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0} /*Posta elettronica*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{D20EA4E1-3957-11d2-A40B-0C5020524152} /*Tipi di carattere*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{D20EA4E1-3957-11d2-A40B-0C5020524153} /*Strumenti di amministrazione*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Pagina proprietà versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{875CB1A1-0F29-45de-A1AE-CFB4950D0B78} /*Audio Media Properties Handler*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{40C3D757-D6E4-4b49-BB41-0E5BBEA28817} /*Video Media Properties Handler*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{E4B29F9D-D390-480b-92FD-7DDB47101D71} /*Wav Properties Handler*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{87D62D94-71B3-4b9a-9489-5FE6850DC73E} /*Avi Properties Handler*/%SystemRoot%\System32\shmedia.dll = %SystemRoot%\System32\shmedia.dll
@{A6FD9E45-6E44-43f9-8644-08598F5A74D9} /*Midi Properties Handler*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{c5a40261-cd64-4ccf-84cb-c394da41d590} /*Video Thumbnail Extractor*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{5E6AB780-7743-11CF-A12B-00AA004AE837} /*Barra degli strumenti Microsoft Internet*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{22BF0C20-6DA7-11D0-B373-00A0C9034938} /*Stato del download*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{91EA3F8B-C99B-11d0-9815-00C04FD91972} /*Shell Folder accresciuto*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6413BA2C-B461-11d1-A18A-080036B11A03} /*Shell Folder 2 accresciuto*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{F61FFEC1-754F-11d0-80CA-00AA005B4383} /*BandProxy*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{7BA4C742-9E81-11CF-99D3-00AA004AE837} /*Microsoft BrowserBand*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*SearchBand*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{169A0691-8DF9-11d1-A1C4-00C04FD75D13} /*Ricerca all'interno*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{07798131-AF23-11d1-9111-00A0C98BA67D} /*Ricerca Web*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{AF4F6510-F982-11d0-8595-00AA004CD6D8} /*Utilità opzioni della struttura del Registro di sistema*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{01E04581-4EEE-11d0-BFE9-00AA005B4383} /*&Indirizzo*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{A08C11D2-A228-11d0-825B-00AA005B4383} /*Address EditBox*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2763-6A77-11D0-A535-00C04FD7D062} /*Completamento automatico Microsoft*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{7376D660-C583-11d0-A3A5-00C04FD706EC} /*TridentImageExtractor*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6756A641-DE71-11d0-831B-00AA005B4383} /*Elenco di Completamento automatico MRU*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} /*Elenco di Completamento automatico MRU personalizzato*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{7e653215-fa25-46bd-a339-34a2790f3cb7} /*Accessibile*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{acf35015-526e-4230-9596-becbe19f0ac9} /*Indicatore di avanzamento popup*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2764-6A77-11D0-A535-00C04FD7D062} /*Elenco di Completamento automatico della Cronologia di Microsoft*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{03C036F1-A186-11D0-824A-00AA005B4383} /*Elenco di Completamento automatico di Shell Folder di Microsoft*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2765-6A77-11D0-A535-00C04FD7D062} /*Contenitore dell'elenco di Completamento automatico multiplo Microsoft*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{ECD4FC4E-521C-11D0-B792-00A0C90312E1} /*Shell Band Site Menu*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{3CCF8A41-5C85-11d0-9796-00AA00B90ADF} /*Shell DeskBarApp*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{ECD4FC4C-521C-11D0-B792-00A0C90312E1} /*Shell DeskBar*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{ECD4FC4D-521C-11D0-B792-00A0C90312E1} /*Shell Rebar BandSite*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{DD313E04-FEFF-11d1-8ECD-0000F87A470C} /*Assistenza utente*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} /*Impostazioni cartella globale*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{EFA24E61-B078-11d0-89E4-00C04FC9E26E} /*Favorites Band*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{0A89A860-D7B1-11CE-8350-444553540000} /*Shell Automation Inproc Service*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{A5E46E3A-8849-11D1-9D8C-00C04FC99D61} /*Microsoft Browser Architecture*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/shdocvw.dll = shdocvw.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Servizio Cronologia Url Microsoft*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*Cronologia*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*File temporanei Internet*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*File temporanei Internet*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Hook per la ricerca di URL Microsoft*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC} /*Schermata iniziale applicazioni Internet Explorer 4*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{67EA19A0-CCEF-11d0-8024-00C04FD75D13} /*CDF Extension Copy Hook*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{131A6951-7F78-11D0-A979-00C04FD705A2} /*ISFBand OC*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{9461b922-3c5a-11d2-bf8b-00c04fb93661} /*Search Assistant OC*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*Internet*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{EFA24E64-B078-11d0-89E4-00C04FC9E26E} /*Explorer Band*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} /*Sendmail service*/C:\WINDOWS\system32\sendmail.dll = C:\WINDOWS\system32\sendmail.dll
@{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} /*Sendmail service*/C:\WINDOWS\system32\sendmail.dll = C:\WINDOWS\system32\sendmail.dll
@{88C6C381-2E85-11D0-94DE-444553540000} /*Cartella cache ActiveX*/%SystemRoot%\system32\occache.dll = %SystemRoot%\system32\occache.dll
@{E6FB5E20-DE35-11CF-9C87-00AA005127ED} /*WebCheck*/%Systemroot%\system32\webcheck.dll = %Systemroot%\system32\webcheck.dll
@{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} /*Subscription Mgr*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{F5175861-2688-11d0-9C5E-00AA00A45957} /*Cartella Subscription*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{08165EA0-E946-11CF-9C87-00AA005127ED} /*WebCheckWebCrawler*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB} /*WebCheckChannelAgent*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7} /*TrayAgent*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{7D559C10-9FE9-11d0-93F7-00AA0059CE02} /*Code Download Agent*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{E6CC6978-6B6E-11D0-BECA-00C04FD940BE} /*ConnectionAgent*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{D8BD2030-6FC9-11D0-864F-00AA006809D9} /*PostAgent*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} /*WebCheck SyncMgr Handler*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{352EC2B7-8B9A-11D1-B8AE-006008059382} /*Gestione applicazioni shell*/%SystemRoot%\system32\appwiz.cpl = %SystemRoot%\system32\appwiz.cpl
@{0B124F8F-91F0-11D1-B8B5-006008059382} /*Enumeratore applicazioni installate*/%SystemRoot%\system32\appwiz.cpl = %SystemRoot%\system32\appwiz.cpl
@{CFCCC7A0-A282-11D1-9082-006008059382} /*Darwin App Publisher*/%SystemRoot%\system32\appwiz.cpl = %SystemRoot%\system32\appwiz.cpl
@{e84fda7c-1d6a-45f6-b725-cb260c236066} /*Shell Image Verbs*/%SystemRoot%\system32\shimgvw.dll = %SystemRoot%\system32\shimgvw.dll
@{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178} /*Shell Image Data Factory*/%SystemRoot%\system32\shimgvw.dll = %SystemRoot%\system32\shimgvw.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{3F30C968-480A-4C6C-862D-EFC0897BB84B} /*GDI + programma di estrazione file in anteprima*/C:\WINDOWS\system32\shimgvw.dll = C:\WINDOWS\system32\shimgvw.dll
@{9DBD2C50-62AD-11d0-B806-00C04FD706EC} /*Summary Info Thumbnail handler (DOCFILES)*/C:\WINDOWS\system32\shimgvw.dll = C:\WINDOWS\system32\shimgvw.dll
@{EAB841A0-9550-11cf-8C16-00805F1408F3} /*Programma di estrazione pagine HTML in anteprima*/C:\WINDOWS\system32\shimgvw.dll = C:\WINDOWS\system32\shimgvw.dll
@{eb9b1153-3b57-4e68-959a-a3266bc3d7fe} /*Shell Image Property Handler*/%SystemRoot%\system32\shimgvw.dll = %SystemRoot%\system32\shimgvw.dll
@{CC6EEFFB-43F6-46c5-9619-51D571967F7D} /*Pubblicazione guidata sul Web*/%SystemRoot%\system32\netplwiz.dll = %SystemRoot%\system32\netplwiz.dll
@{add36aa8-751a-4579-a266-d66f5202ccbb} /*Ordinazione di stampe tramite Web*/%SystemRoot%\system32\netplwiz.dll = %SystemRoot%\system32\netplwiz.dll
@{6b33163c-76a5-4b6c-bf21-45de9cd503a1} /*Oggetto Pubblicazione guidata sul Web*/%SystemRoot%\system32\netplwiz.dll = %SystemRoot%\system32\netplwiz.dll
@{58f1f272-9240-4f51-b6d4-fd63d1618591} /*Creazione guidata profilo Passport*/%SystemRoot%\system32\netplwiz.dll = %SystemRoot%\system32\netplwiz.dll
@{7A9D77BD-5403-11d2-8785-2E0420524153} /*Account utente*/(null) =
@{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} /*Cartella compressa*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{BD472F60-27FA-11cf-B8B4-444553540000} /*Compressed (zipped) Folder Right Drag Handler*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{888DCA60-FC0A-11CF-8F0F-00C04FD7D062} /*Compressed (zipped) Folder SendTo Target*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{f39a0dc0-9cc8-11d0-a599-00c04fd64433} /*File del canale*/%SystemRoot%\system32\cdfview.dll = %SystemRoot%\system32\cdfview.dll
@{f3aa0dc0-9cc8-11d0-a599-00c04fd64434} /*Collegamento al canale*/%SystemRoot%\system32\cdfview.dll = %SystemRoot%\system32\cdfview.dll
@{f3ba0dc0-9cc8-11d0-a599-00c04fd64435} /*Channel Handler Object*/%SystemRoot%\system32\cdfview.dll = %SystemRoot%\system32\cdfview.dll
@{f3da0dc0-9cc8-11d0-a599-00c04fd64437} /*Channel Menu*/%SystemRoot%\system32\cdfview.dll = %SystemRoot%\system32\cdfview.dll
@{f3ea0dc0-9cc8-11d0-a599-00c04fd64438} /*Channel Properties*/%SystemRoot%\system32\cdfview.dll = %SystemRoot%\system32\cdfview.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{63da6ec0-2e98-11cf-8d82-444553540000} /*FTP Folders Webview*/C:\WINDOWS\system32\msieftp.dll = C:\WINDOWS\system32\msieftp.dll
@{883373C3-BF89-11D1-BE35-080036B11A03} /*Microsoft DocProp Shell Ext*/C:\WINDOWS\system32\docprop2.dll = C:\WINDOWS\system32\docprop2.dll
@{A9CF0EAE-901A-4739-A481-E35B73E47F6D} /*Microsoft DocProp Inplace Edit Box Control*/C:\WINDOWS\system32\docprop2.dll = C:\WINDOWS\system32\docprop2.dll
@{8EE97210-FD1F-4B19-91DA-67914005F020} /*Microsoft DocProp Inplace ML Edit Box Control*/C:\WINDOWS\system32\docprop2.dll = C:\WINDOWS\system32\docprop2.dll
@{0EEA25CC-4362-4A12-850B-86EE61B0D3EB} /*Microsoft DocProp Inplace Droplist Combo Control*/C:\WINDOWS\system32\docprop2.dll = C:\WINDOWS\system32\docprop2.dll
@{6A205B57-2567-4A2C-B881-F787FAB579A3} /*Microsoft DocProp Inplace Calendar Control*/C:\WINDOWS\system32\docprop2.dll = C:\WINDOWS\system32\docprop2.dll
@{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33} /*Microsoft DocProp Inplace Time Control*/C:\WINDOWS\system32\docprop2.dll = C:\WINDOWS\system32\docprop2.dll
@{8A23E65E-31C2-11d0-891C-00A024AB2DBB} /*Directory Query UI*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{9E51E0D0-6E0F-11d2-9601-00C04FA31A86} /*Shell properties for a DS object*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{163FDC20-2ABC-11d0-88F0-00A024AB2DBB} /*Directory Object Find*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{F020E586-5264-11d1-A532-0000F8757D7E} /*Directory Start/Search Find*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{0D45D530-764B-11d0-A1CA-00AA00C16E65} /*Directory Property UI*/%SystemRoot%\system32\dsuiext.dll = %SystemRoot%\system32\dsuiext.dll
@{62AE1F9A-126A-11D0-A14B-0800361B1103} /*Directory Context Menu Verbs*/%SystemRoot%\system32\dsuiext.dll = %SystemRoot%\system32\dsuiext.dll
@{ECF03A33-103D-11d2-854D-006008059367} /*MyDocs Copy Hook*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{ECF03A32-103D-11d2-854D-006008059367} /*MyDocs Drop Target*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{4a7ded0a-ad25-11d0-98a8-0800361b1103} /*MyDocs Properties*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{750fdf0e-2a26-11d1-a3ea-080036587f03} /*Offline Files Menu*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{10CFC467-4392-11d2-8DB4-00C04FA31A66} /*Offline Files Folder Options*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E} /*Cartella file non in linea*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{143A62C8-C33B-11D1-84FE-00C04FA34A14} /*Microsoft Agent Character Property Sheet Handler*/C:\WINDOWS\msagent\agentpsh.dll = C:\WINDOWS\msagent\agentpsh.dll
@{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} /*DfsShell*/C:\WINDOWS\system32\dfsshlex.dll = C:\WINDOWS\system32\dfsshlex.dll
@{60fd46de-f830-4894-a628-6fa81bc0190d} /*%DESC_PublishDropTarget%*/%SystemRoot%\system32\photowiz.dll = %SystemRoot%\system32\photowiz.dll
@{7A80E4A8-8005-11D2-BCF8-00C04F72C717} /*MMC Icon Handler*/%SystemRoot%\System32\mmcshext.dll = %SystemRoot%\System32\mmcshext.dll
@{0CD7A5C0-9F37-11CE-AE65-08002B2E1262} /*.CAB file viewer*/cabview.dll = cabview.dll
@{32714800-2E5F-11d0-8B85-00AA0044F941} /*&Contatti...*/C:\Programmi\Outlook Express\wabfind.dll = C:\Programmi\Outlook Express\wabfind.dll
@{8DD448E6-C188-4aed-AF92-44956194EB1F} /*Windows Media Player Play as Playlist Context Menu Handler*/C:\WINDOWS\system32\wmpshell.dll = C:\WINDOWS\system32\wmpshell.dll
@{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} /*Windows Media Player Burn Audio CD Context Menu Handler*/C:\WINDOWS\system32\wmpshell.dll = C:\WINDOWS\system32\wmpshell.dll
@{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD} /*Windows Media Player Add to Playlist Context Menu Handler*/C:\WINDOWS\system32\wmpshell.dll = C:\WINDOWS\system32\wmpshell.dll
@{1D2680C9-0E2A-469d-B787-065558BC7D43} /*Fusion Cache*/C:\WINDOWS\system32\mscoree.dll = C:\WINDOWS\system32\mscoree.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Programmi\Real\RealOne Player\rpshellext.dll = C:\Programmi\Real\RealOne Player\rpshellext.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRAR\rarext.dll = C:\Programmi\WinRAR\rarext.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\OFFICE11\msohev.dll = C:\Programmi\Microsoft Office\OFFICE11\msohev.dll
@{AC1DB655-4F9A-4c39-8AD2-A65324A4C446} /*Autodesk Drawing Preview*/C:\Programmi\File comuni\Autodesk Shared\Thumbnail\AcThumbnail16.dll = C:\Programmi\File comuni\Autodesk Shared\Thumbnail\AcThumbnail16.dll
@{36A21736-36C2-4C11-8ACB-D4136F2B57BD} /*Gestore icona firma digitale di AutoCAD*/C:\WINDOWS\system32\AcSignIcon.dll = C:\WINDOWS\system32\AcSignIcon.dll
@{6DEA92E9-8682-4b6a-97DE-354772FE5727} /*Autodesk DWF Preview*/C:\Programmi\File comuni\Autodesk Shared\Thumbnail\AcDwfThmbPrxy16.dll = C:\Programmi\File comuni\Autodesk Shared\Thumbnail\AcDwfThmbPrxy16.dll
@{73B24247-042E-4EF5-ADC2-42F62E6FD654} /*ICQ Lite Shell Extension*/C:\Programmi\ICQLite\ICQLiteShell.dll = C:\Programmi\ICQLite\ICQLiteShell.dll
@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} /*Adobe.Acrobat.ContextMenu*/C:\Programmi\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll = C:\Programmi\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
@{0E6C58A9-F592-4862-B35F-CA45E24003B3} /*CloneCD*/C:\Programmi\Elaborate Bytes\CloneCD\ElbyVCDShell.dll = C:\Programmi\Elaborate Bytes\CloneCD\ElbyVCDShell.dll
@{FED7043D-346A-414D-ACD7-550D052499A7} /*dBpowerAMP Music Converter 1*/C:\Programmi\Illustrate\dBpowerAMP\dBShell.dll = C:\Programmi\Illustrate\dBpowerAMP\dBShell.dll
@{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5} /*dBpowerAMP Music Converter*/C:\Programmi\Illustrate\dBpowerAMP\dMCShell.dll = C:\Programmi\Illustrate\dBpowerAMP\dMCShell.dll
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/(null) =
@{8FF88D21-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.6 Context Menu Shell Extension*/C:\Programmi\WinAce\arcext.dll = C:\Programmi\WinAce\arcext.dll
@{8FF88D25-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.6 DragDrop Shell Extension*/C:\Programmi\WinAce\arcext.dll = C:\Programmi\WinAce\arcext.dll
@{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.6 Context Menu Shell Extension*/C:\Programmi\WinAce\arcext.dll = C:\Programmi\WinAce\arcext.dll
@{8FF88D23-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.6 Property Sheet Shell Extension*/C:\Programmi\WinAce\arcext.dll = C:\Programmi\WinAce\arcext.dll
@{5E44E225-A408-11CF-B581-008029601108} /*Roxio DragToDisc Shell Extension*/C:\Programmi\Roxio\Easy Media Creator 8\Drag to Disc\Shellex.dll = C:\Programmi\Roxio\Easy Media Creator 8\Drag to Disc\Shellex.dll
@{0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} /*RXDCExtShlExt extension*/C:\Programmi\Roxio\Easy Media Creator 8\Virtual Drive\DC_ShellExt.dll = C:\Programmi\Roxio\Easy Media Creator 8\Virtual Drive\DC_ShellExt.dll
@{D9872D13-7651-4471-9EEE-F0A00218BEBB} /*Multiscan*/(null) =
@{0561EC90-CE54-4f0c-9C55-E226110A740C} /*Haali Column Provider*/(null) =
@{E4D8441D-F89C-4b5c-90AC-A857E1768F1F} /*Haali Matroska Thumbnail Exctractor*/(null) =
@{7C5E74A0-D5E0-11D0-A9BF-E886A83B9BE5} /*Context Menu Shell Extension*/C:\Programmi\TagRename\TRshell.dll = C:\Programmi\TagRename\TRshell.dll
@{640167b4-59b0-47a6-b335-a6b3c0695aea} /*Portable Media Devices*/%SystemRoot%\system32\Audiodev.dll = %SystemRoot%\system32\Audiodev.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{85E0B171-04FA-11D1-B7DA-00A0C90348D6} /*Statistiche sulla protezione del traffico Web*/C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll = C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{45670FA8-ED97-4F44-BC93-305082590BFB} /*Microsoft.XPS.Shell.Metadata.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{44121072-A222-48f2-A58A-6D9AD51EBBE9} /*Microsoft.XPS.Shell.Thumbnail.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{A7005AF0-D6E8-48AF-8DFA-023B1CF660A7} /*TeraCopy*/C:\Programmi\TeraCopy\TeraCopy.dll = C:\Programmi\TeraCopy\TeraCopy.dll
@{A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} /*TeraCopy*/C:\Programmi\TeraCopy\TeraCopyExt.dll = C:\Programmi\TeraCopy\TeraCopyExt.dll
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Adobe.Acrobat.ContextMenu@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Programmi\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
ICQLiteMenu@{73B24247-042E-4EF5-ADC2-42F62E6FD654} = C:\Programmi\ICQLite\ICQLiteShell.dll
Kaspersky Anti-Virus@{dd230880-495a-11d1-b064-008048ec2fc5} = C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\ShellEx.dll
Notepad++@{120B94B5-2E6A-4F13-94D0-414BCB64FA0F} = C:\Programmi\Notepad++\nppcm.dll
Offline Files@{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
Open With@{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
Open With EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
RXDCExtSvr@{0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} = C:\Programmi\Roxio\Easy Media Creator 8\Virtual Drive\DC_ShellExt.dll
TagRename_ContextMenu@{7C5E74A0-D5E0-11D0-A9BF-E886A83B9BE5} = C:\Programmi\TagRename\TRshell.dll
TeraCopy@{A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} = C:\Programmi\TeraCopy\TeraCopyExt.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
ZFAdd@{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} = C:\Programmi\WinAce\arcext.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} = %SystemRoot%\system32\SHELL32.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
ICQLiteMenu@{73B24247-042E-4EF5-ADC2-42F62E6FD654} = C:\Programmi\ICQLite\ICQLiteShell.dll
Offline Files@{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
Sharing@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
TeraCopy@{A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} = C:\Programmi\TeraCopy\TeraCopyExt.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
ZFAdd@{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} = C:\Programmi\WinAce\arcext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
Kaspersky Anti-Virus@{dd230880-495a-11d1-b064-008048ec2fc5} = C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\ShellEx.dll
RXDCExtSvr@{0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} = C:\Programmi\Roxio\Easy Media Creator 8\Virtual Drive\DC_ShellExt.dll
TagRename_ContextMenu@{7C5E74A0-D5E0-11D0-A9BF-E886A83B9BE5} = C:\Programmi\TagRename\TRshell.dll
TeraCopy@{A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} = C:\Programmi\TeraCopy\TeraCopyExt.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{18DF081C-E8AD-4283-A596-FA578C2EBDC3}C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll = C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
@{1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A}C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll = C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.dll
@{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll = C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
@{9030D464-4C02-4ABF-8ECC-5164760863C6}C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll = C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
@{AE7CD045-E861-484f-8273-0445EE161910}C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll = C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft.com/fwlink/?LinkId=69157
@Start Pagehttp://search.myheritage.com = http://search.myheritage.com
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.google.it/ = http://www.google.it/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Filter\ >>>
application/octet-stream@CLSID = mscoree.dll
application/x-complus@CLSID = mscoree.dll
application/x-msdownload@CLSID = mscoree.dll
Class Install Handler@CLSID = C:\WINDOWS\system32\urlmon.dll
deflate@CLSID = C:\WINDOWS\system32\urlmon.dll
gzip@CLSID = C:\WINDOWS\system32\urlmon.dll
lzdhtml@CLSID = C:\WINDOWS\system32\urlmon.dll
text/webviewhtml@CLSID = %SystemRoot%\system32\SHELL32.dll
text/xml@CLSID = C:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
about@CLSID = %SystemRoot%\system32\mshtml.dll
cdl@CLSID = C:\WINDOWS\system32\urlmon.dll
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
file@CLSID = C:\WINDOWS\system32\urlmon.dll
ftp@CLSID = C:\WINDOWS\system32\urlmon.dll
gopher@CLSID = C:\WINDOWS\system32\urlmon.dll
http@CLSID = C:\WINDOWS\system32\urlmon.dll
https@CLSID = C:\WINDOWS\system32\urlmon.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
javascript@CLSID = %SystemRoot%\system32\mshtml.dll
livecall@CLSID = C:\PROGRA~1\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll
local@CLSID = C:\WINDOWS\system32\urlmon.dll
mailto@CLSID = %SystemRoot%\system32\mshtml.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
mk@CLSID = C:\WINDOWS\system32\urlmon.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
ms-itss@CLSID = C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL
msnim@CLSID = C:\PROGRA~1\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll
mso-offdap@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
res@CLSID = %SystemRoot%\system32\mshtml.dll
skype4com@CLSID = C:\PROGRA~1\FILECO~1\Skype\Skype4COM.dll
sysimage@CLSID = %SystemRoot%\system32\mshtml.dll
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
vbscript@CLSID = %SystemRoot%\system32\mshtml.dll
wia@CLSID = C:\WINDOWS\system32\wiascr.dll

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters@Domain =

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ >>>
000000000001@LibraryPath = %SystemRoot%\System32\mswsock.dll
000000000002@LibraryPath = %SystemRoot%\System32\winrnr.dll
000000000003@LibraryPath = %SystemRoot%\System32\mswsock.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000002@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000003@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000004@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000005@PackedCatalogItem = %SystemRoot%\system32\rsvpsp.dll
000000000006@PackedCatalogItem = %SystemRoot%\system32\rsvpsp.dll
000000000007@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000008@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000009@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000010@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000011@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000012@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000013@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000014@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000015@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000016@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000017@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000018@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000019@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000020@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000021@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000022@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000023@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000024@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll

---- EOF - GMER 1.0.15 ----
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » dom nov 15, 2009 4:59 pm

log gmer/sezione rootkit

GMER 1.0.15.15227 - http://www.gmer.net
Rootkit scan 2009-11-15 16:42:21
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\PC\IMPOST~1\Temp\pxtdapow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwAdjustPrivilegesToken [0xF345BA72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwClose [0xF345C01E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwConnectPort [0xF345DA82]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateFile [0xF345D438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateKey [0xF345B1E8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xF345F3E4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateThread [0xF345BE1A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeleteKey [0xF345B62A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeleteValueKey [0xF345B82A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeviceIoControlFile [0xF345D744]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDuplicateObject [0xF345F8F0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwEnumerateKey [0xF345B940]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwEnumerateValueKey [0xF345B9A8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwFsControlFile [0xF345D5FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwLoadDriver [0xF345EEA8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenFile [0xF345D294]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenKey [0xF345B34A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenProcess [0xF345BC40]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenSection [0xF345F40E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenThread [0xF345BB96]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryKey [0xF345BA10]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryMultipleValueKey [0xF345B714]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryValueKey [0xF345B4F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueueApcThread [0xF345F110]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwReplaceKey [0xF345AE6A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwRequestWaitReplyPort [0xF345E30C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwRestoreKey [0xF345AFCC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwResumeThread [0xF345F7C0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSaveKey [0xF345AC68]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSecureConnectPort [0xF345D924]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetContextThread [0xF345BF18]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetSecurityObject [0xF345EFA2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetSystemInformation [0xF345F438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetValueKey [0xF345B3A0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSuspendProcess [0xF345F51C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSuspendThread [0xF345F648]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSystemDebugControl [0xF345EDD4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwTerminateProcess [0xF345BCEA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwWriteVirtualMemory [0xF345BD5C]

Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) IoIsOperationSynchronous

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!_abnormal_termination + F3 804E2DC4 4 Bytes CALL 9341737A
.text ntoskrnl.exe!_abnormal_termination + 443 804E3114 12 Bytes [1C, F5, 45, F3, 48, F6, 45, ...]
.text ntoskrnl.exe!_abnormal_termination + 453 804E3124 4 Bytes JMP 7CF345BC
? C:\WINDOWS\system32\drivers\sptd.sys Impossibile accedere al file. Il file è utilizzato da un altro processo.
? C:\WINDOWS\System32\Drivers\SPTD8045.SYS Impossibile accedere al file. Il file è utilizzato da un altro processo.
? C:\DOCUME~1\PC\IMPOST~1\Temp\mbr.sys Impossibile trovare il file specificato. !

---- User code sections - GMER 1.0.15 ----

? C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[492] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[492] USER32.dll!VRipOutput + FFFA5010 77D12A78 4 Bytes [70, 11, 41, 35]
? C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[4076] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[4076] USER32.dll!VRipOutput + FFFA5010 77D12A78 4 Bytes [70, 11, 41, 35]

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F83B989E] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F83CFD86] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F83B9E24] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F83B9D28] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IofCallDriver] [F83B9EF4] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IofCallDriver] [F83B9EF4] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F83B9E24] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F83B9D28] sptd.sys
IAT PartMgr.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F83CF1AE] sptd.sys
IAT PartMgr.sys[ntoskrnl.exe!IoDetachDevice] [F83B9A5A] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IofCompleteRequest] [F83CF04A] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F83B98F2] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F83ACAD2] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F83ACC0E] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F83ACB96] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F83AD76C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F83AD642] sptd.sys
IAT disk.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F83CFE4A] sptd.sys
IAT \WINDOWS\system32\DRIVERS\CLASSPNP.SYS[ntoskrnl.exe!IoDetachDevice] [F83BE8C6] sptd.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!IofCompleteRequest] [F83CF04A] sptd.sys
IAT \SystemRoot\system32\DRIVERS\cdrom.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F83CFE4A] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F83CF056] sptd.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] 817F9820
IAT \SystemRoot\system32\DRIVERS\netbt.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] 817F9820
IAT \SystemRoot\system32\DRIVERS\ipnat.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\netbios.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\rdbss.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\rdbss.sys[ntoskrnl.exe!IofCallDriver] [F83B9CC6] sptd.sys
IAT \SystemRoot\system32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IofCallDriver] [F83B9CC6] sptd.sys
IAT \SystemRoot\system32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\System32\Drivers\Fips.SYS[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\STREAM.SYS[NTOSKRNL.EXE!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\HIDCLASS.SYS[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\System32\Drivers\Cdfs.SYS[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\mouhid.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\irda.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\mrxdav.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\System32\Drivers\ParVdm.SYS[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\drivers\wdmaud.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\drivers\sysaudio.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\System32\Drivers\HTTP.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\System32\Drivers\Fastfat.SYS[ntoskrnl.exe!IoCreateDevice] 817F96D0
IAT \SystemRoot\system32\drivers\kmixer.sys[ntoskrnl.exe!IoCreateDevice] 817F96D0

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 822AAC78
Device \FileSystem\Fastfat \FatCdrom 81BF38A0

AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

Device \Driver\dmio \Device\DmControl\DmIoDaemon 822F8910
Device \Driver\dmio \Device\DmControl\DmConfig 822F8910
Device \Driver\dmio \Device\DmControl\DmPnP 822F8910
Device \Driver\dmio \Device\DmControl\DmInfo 822F8910

AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

Device \Driver\Ftdisk \Device\HarddiskVolume1 822F8BC8
Device \Driver\Ftdisk \Device\HarddiskVolume2 822F8BC8
Device \Driver\Cdrom \Device\CdRom0 821023E8
Device \FileSystem\Rdbss \Device\FsWrap 8212A0E8
Device \Driver\Cdrom \Device\CdRom1 821023E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F826E2F0] atapi.sys[unknown section] {MOV EAX, 0x822f82c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c0e12; RET }
Device \Driver\atapi \Device\Ide\IdePort0 [F826E2F0] atapi.sys[unknown section] {MOV EAX, 0x822f82c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c0e12; RET }
Device \Driver\atapi \Device\Ide\IdePort1 [F826E2F0] atapi.sys[unknown section] {MOV EAX, 0x822f82c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c0e12; RET }
Device \Driver\atapi \Device\Ide\IdePort2 [F826E2F0] atapi.sys[unknown section] {MOV EAX, 0x822f82c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c0e12; RET }
Device \Driver\atapi \Device\Ide\IdePort3 [F826E2F0] atapi.sys[unknown section] {MOV EAX, 0x822f82c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c0e12; RET }
Device \Driver\atapi \Device\Ide\IdePort4 [F826E2F0] atapi.sys[unknown section] {MOV EAX, 0x822f82c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c0e12; RET }
Device \Driver\atapi \Device\Ide\IdePort5 [F826E2F0] atapi.sys[unknown section] {MOV EAX, 0x822f82c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c0e12; RET }
Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-10 [F826E2F0] atapi.sys[unknown section] {MOV EAX, 0x822f82c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf83c0e12; RET }
Device ACPI.sys (Driver ACPI per NT/Microsoft Corporation)
Device \Driver\NetBT \Device\NetBt_Wins_Export 8203D250
Device \Driver\NetBT \Device\NetbiosSmb 8203D250
Device \Driver\NetBT \Device\NetBT_Tcpip_{0943D617-20FE-49AD-AAD7-1F91A4639DF2} 8203D250

AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp nnrnstdi.SYS (NNRNSTDI helper driver/The Nielsen Company)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 81B54708
Device \FileSystem\MRxSmb \Device\LanmanRedirector 81B54708
Device \FileSystem\Npfs \Device\NamedPipe 8202F1E8
Device \Driver\Ftdisk \Device\FtControl 822F8BC8
Device \FileSystem\cdudf_xp \Device\CdUdf_XP 8204B640
Device \FileSystem\Msfs \Device\Mailslot 820261D8
Device \Driver\ElbyVCD \Device\Scsi\ElbyVCD1 822F8658
Device \Driver\ElbyVCD \Device\Scsi\ElbyVCD1Port0Path0Target0Lun0 822F8658
Device \FileSystem\Fastfat \Fat 81BF38A0

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 81B41708

---- Threads - GMER 1.0.15 ----

Thread System [4:608] 8183A000
Thread System [4:612] 8183A000
Thread System [4:616] 818077E0
Thread System [4:620] 818077E0
Thread System [4:628] 818097D0
Thread System [4:632] 818097D0
Thread System [4:636] 818077E0

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s0 489619570
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 200404727
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -1524873901
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD4 0x69 0x66 0x55 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD4 0x69 0x66 0x55 ...

---- EOF - GMER 1.0.15 ----


A questo punto il pc è pulito o devo preoccuparmi ancora e provare qualcos'altro?
[grazie]
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » sab nov 21, 2009 6:53 pm

scusate se insisto, ma il pc continua a presentare problemi...

dal log di mbr, come evidenziato nel post precedente, l'infezione rimane presente, anche se i problemi di crash continui non si sono più verificati [^]

dal log di combofix non risulta più nulla, ma il pc presenta problemi di lentezza eccessiva nel lavorare.

in sintesi, non è possibile lavorare con due applicativi contemporaneamente.

L'unica cosa che devo verificare, come fase preliminare, è la ram che ho montato in più e che forse presenta problemi di scrittura e lettura, ma a parte questo vorrei capire se eventualmente ci sono strette connessioni tra la lentezza eccessiva nel pc e la probabile presenza di questo rootkit che secondo mbr.exe non ne vuole sapere di andarsene via.

[grazie] per l'interessamento
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » dom nov 22, 2009 3:33 pm

Scusate di nuovo l'insistenza, ma visti i problemi che il pc manifesta, ho rifatto eseguire una scansione con gmer, e il risultato è stato il seguente:

GMER 1.0.15.15227 - http://www.gmer.net
Rootkit scan 2009-11-22 15:14:02
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\PC\IMPOST~1\Temp\pxtdapow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwAdjustPrivilegesToken [0xB7708A72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwClose [0xB770901E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwConnectPort [0xB770AA82]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateFile [0xB770A438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateKey [0xB77081E8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xB770C3E4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateThread [0xB7708E1A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeleteKey [0xB770862A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeleteValueKey [0xB770882A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeviceIoControlFile [0xB770A744]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDuplicateObject [0xB770C8F0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwEnumerateKey [0xB7708940]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwEnumerateValueKey [0xB77089A8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwFsControlFile [0xB770A5FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwLoadDriver [0xB770BEA8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenFile [0xB770A294]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenKey [0xB770834A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenProcess [0xB7708C40]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenSection [0xB770C40E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenThread [0xB7708B96]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryKey [0xB7708A10]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryMultipleValueKey [0xB7708714]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryValueKey [0xB77084F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueueApcThread [0xB770C110]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwReplaceKey [0xB7707E6A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwRequestWaitReplyPort [0xB770B30C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwRestoreKey [0xB7707FCC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwResumeThread [0xB770C7C0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSaveKey [0xB7707C68]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSecureConnectPort [0xB770A924]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetContextThread [0xB7708F18]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetSecurityObject [0xB770BFA2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetSystemInformation [0xB770C438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetValueKey [0xB77083A0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSuspendProcess [0xB770C51C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSuspendThread [0xB770C648]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSystemDebugControl [0xB770BDD4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwTerminateProcess [0xB7708CEA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwWriteVirtualMemory [0xB7708D5C]

Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) IoIsOperationSynchronous

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!_abnormal_termination + F3 804E2DC4 4 Bytes CALL 93059E4A
.text ntoskrnl.exe!_abnormal_termination + 443 804E3114 5 Bytes [1C, C5, 70, B7, 48] {SBB AL, 0xc5; JO 0xffffffffffffffbb; DEC EAX}
.text ntoskrnl.exe!_abnormal_termination + 449 804E311A 6 Bytes [70, B7, D4, BD, 70, B7] {JO 0xffffffffffffffb9; AAM 0xbd; JO 0xffffffffffffffbd}
.text ntoskrnl.exe!_abnormal_termination + 453 804E3124 4 Bytes JMP 7CB7708C
.text ntoskrnl.exe!IoIsOperationSynchronous 804E8EBA 5 Bytes JMP B771F5A2 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab)
.text ntoskrnl.exe!FsRtlCheckLockForReadAccess 804FDAF1 5 Bytes JMP B771F1E8 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab)
? C:\WINDOWS\system32\drivers\sptd.sys Impossibile accedere al file. Il file è utilizzato da un altro processo.
? C:\WINDOWS\System32\Drivers\SPTD8045.SYS Impossibile accedere al file. Il file è utilizzato da un altro processo.

---- User code sections - GMER 1.0.15 ----

? C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[984] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[984] USER32.dll!VRipOutput + FFFA5010 77D12A78 4 Bytes [70, 11, 41, 35]
? C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[1008] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[1008] USER32.dll!VRipOutput + FFFA5010 77D12A78 4 Bytes [70, 11, 41, 35]
.text C:\Programmi\Outlook Express\msimn.exe[1400] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 000A4FC0
.text C:\Programmi\Outlook Express\msimn.exe[1400] kernel32.dll!FreeLibrary 7C80AA66 6 Bytes JMP 000A51F0
.text C:\Programmi\Outlook Express\msimn.exe[1400] USER32.dll!TranslateMessage 77D18BCE 6 Bytes JMP 000A5B10
.text C:\Programmi\Outlook Express\msimn.exe[1400] USER32.dll!DefWindowProcW 77D1B1E5 6 Bytes JMP 000A58E0
.text C:\Programmi\Outlook Express\msimn.exe[1400] USER32.dll!DefWindowProcA 77D1DF6B 6 Bytes JMP 000A4F08
.text C:\Programmi\Outlook Express\msimn.exe[1400] USER32.dll!GetSubMenu 77D2355A 6 Bytes JMP 000A5D40
.text C:\Programmi\Outlook Express\msimn.exe[1400] USER32.dll!DialogBoxParamW 77D26702 6 Bytes JMP 000A6600
.text C:\Programmi\Outlook Express\msimn.exe[1400] USER32.dll!DialogBoxParamA 77D288E1 6 Bytes JMP 000A63D0
.text C:\Programmi\Outlook Express\msimn.exe[1400] USER32.dll!SetMenuItemInfoW 77D3C137 6 Bytes JMP 000A61A0
.text C:\Programmi\Outlook Express\msimn.exe[1400] USER32.dll!SetMenuItemInfoA 77D6AA06 6 Bytes JMP 000A5F70

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F751189E] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7527D86] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F7511E24] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F7511D28] sptd.sys
IAT ftdisk.sys[ntoskrnl.exe!IofCallDriver] [F7511EF4] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IofCallDriver] [F7511EF4] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IoGetAttachedDeviceReference] [F7511E24] sptd.sys
IAT dmio.sys[ntoskrnl.exe!IoGetDeviceObjectPointer] [F7511D28] sptd.sys
IAT PartMgr.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F75271AE] sptd.sys
IAT PartMgr.sys[ntoskrnl.exe!IoDetachDevice] [F7511A5A] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IofCompleteRequest] [F752704A] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F75118F2] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7504AD2] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F7504C0E] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F7504B96] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F750576C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F7505642] sptd.sys
IAT disk.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7527E4A] sptd.sys
IAT \WINDOWS\system32\DRIVERS\CLASSPNP.SYS[ntoskrnl.exe!IoDetachDevice] [F75168C6] sptd.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!IofCompleteRequest] [F752704A] sptd.sys
IAT \SystemRoot\system32\DRIVERS\cdrom.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7527E4A] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F7527056] sptd.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] 88EA1820
IAT \SystemRoot\system32\DRIVERS\netbt.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] 88EA1820
IAT \SystemRoot\system32\DRIVERS\ipnat.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\netbios.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\rdbss.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\rdbss.sys[ntoskrnl.exe!IofCallDriver] [F7511CC6] sptd.sys
IAT \SystemRoot\system32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IofCallDriver] [F7511CC6] sptd.sys
IAT \SystemRoot\system32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\System32\Drivers\Fips.SYS[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\STREAM.SYS[NTOSKRNL.EXE!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\HIDCLASS.SYS[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\System32\Drivers\Cdfs.SYS[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\mouhid.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\irda.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\mrxdav.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\drivers\wdmaud.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\drivers\sysaudio.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\System32\Drivers\ParVdm.SYS[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\System32\Drivers\HTTP.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\System32\Drivers\Fastfat.SYS[ntoskrnl.exe!IoCreateDevice] 88EA16D0
IAT \SystemRoot\system32\drivers\kmixer.sys[ntoskrnl.exe!IoCreateDevice] 88EA16D0

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 89888C78
Device \FileSystem\Fastfat \FatCdrom 884EF3B8

AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

Device \Driver\dmio \Device\DmControl\DmIoDaemon 898D6910
Device \Driver\dmio \Device\DmControl\DmConfig 898D6910
Device \Driver\dmio \Device\DmControl\DmPnP 898D6910
Device \Driver\dmio \Device\DmControl\DmInfo 898D6910

AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

Device \Driver\Ftdisk \Device\HarddiskVolume1 898D6BC8
Device \Driver\Ftdisk \Device\HarddiskVolume2 898D6BC8
Device \Driver\Cdrom \Device\CdRom0 897BAAF0
Device \FileSystem\Rdbss \Device\FsWrap 892468A0
Device \Driver\Cdrom \Device\CdRom1 897BAAF0
Device \Driver\Ftdisk \Device\HarddiskVolume3 898D6BC8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F797A2F0] atapi.sys[unknown section] {MOV EAX, 0x898d62c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
Device \Driver\atapi \Device\Ide\IdePort0 [F797A2F0] atapi.sys[unknown section] {MOV EAX, 0x898d62c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
Device \Driver\atapi \Device\Ide\IdePort1 [F797A2F0] atapi.sys[unknown section] {MOV EAX, 0x898d62c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
Device \Driver\atapi \Device\Ide\IdePort2 [F797A2F0] atapi.sys[unknown section] {MOV EAX, 0x898d62c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
Device \Driver\atapi \Device\Ide\IdePort3 [F797A2F0] atapi.sys[unknown section] {MOV EAX, 0x898d62c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
Device \Driver\atapi \Device\Ide\IdePort4 [F797A2F0] atapi.sys[unknown section] {MOV EAX, 0x898d62c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
Device \Driver\atapi \Device\Ide\IdePort5 [F797A2F0] atapi.sys[unknown section] {MOV EAX, 0x898d62c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1f [F797A2F0] atapi.sys[unknown section] {MOV EAX, 0x898d62c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-10 [F797A2F0] atapi.sys[unknown section] {MOV EAX, 0x898d62c0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7518e12; RET }
Device ACPI.sys (Driver ACPI per NT/Microsoft Corporation)
Device \Driver\NetBT \Device\NetBt_Wins_Export 892618A0
Device \Driver\NetBT \Device\NetbiosSmb 892618A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{0943D617-20FE-49AD-AAD7-1F91A4639DF2} 892618A0

AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

Device \Driver\Disk \Device\Harddisk0\DR0 89888EB0

AttachedDevice \Driver\Tcpip \Device\RawIp nnrnstdi.SYS (NNRNSTDI helper driver/The Nielsen Company)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

Device \Driver\Disk \Device\Harddisk1\DR1 89888EB0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 892408A0
Device \FileSystem\MRxSmb \Device\LanmanRedirector 892408A0
Device \FileSystem\Npfs \Device\NamedPipe 892B08A0
Device \Driver\Ftdisk \Device\FtControl 898D6BC8
Device \FileSystem\Msfs \Device\Mailslot 892BC8A0
Device \FileSystem\cdudf_xp \Device\CdUdf_XP 8928A8A0
Device \Driver\ElbyVCD \Device\Scsi\ElbyVCD1 898D6658
Device \Driver\ElbyVCD \Device\Scsi\ElbyVCD1Port0Path0Target0Lun0 898D6658
Device \FileSystem\Fastfat \Fat 884EF3B8

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 891C68A0

---- Threads - GMER 1.0.15 ----

Thread System [4:604] 88EE5000
Thread System [4:608] 88EE5000
Thread System [4:612] 88EAF7E0
Thread System [4:616] 88EAF7E0
Thread System [4:624] 88EB17D0
Thread System [4:628] 88EB17D0
Thread System [4:632] 88EAF7E0
---- Processes - GMER 1.0.15 ----

Library C:\Documents (*** hidden *** ) @ C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [984] 0x08B40000

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s0 489619570
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 200404727
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -1524873901
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD4 0x69 0x66 0x55 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD4 0x69 0x66 0x55 ...

---- EOF - GMER 1.0.15 ----


la scansione è stata fatta con il kaspersky attivo, mi devo preoccupare ed eventualemente ricorrere ai ripari?

[grazie]
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Fred » mer nov 25, 2009 2:37 pm

Scusa il ritardo della risposta ma in questo periodo sono tremendamente impegnato ed ho pochissimo tempo per stare al PC, figuriamoci su MLI. In ogni caso potresti fare una prova, ovvero utilizzare il MegaLabCD. Scaricalo, crealo (c'è una guida fatta benissimo sul portale) ed avvialo. Fai girare tutti i tools antivirus e vedi cosa succede. Inoltre controlla se si presentano problemi di sorta come BSOD, riavii involontari e simili.
[ciao]
Asus M3N78SE;AMD Athlon 64X2 5200+@5400;2 GB DDR2;NVIDIA GeForce 9500GT;Windows 7 Pro 64bit;
AcerASPIRE5230;Windows 7 Pro 64bit
Skype: nellopc90
Avatar utente
Fred
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3623
Iscritto il: mer apr 27, 2005 4:13 pm
Località: Urbe

Re: Dopo averle provate (quasi) tutte xp continua a crashare

Messaggioda Uomo_Senza_Sonno » mer nov 25, 2009 3:42 pm

Va bene, provo a sottoporlo a tutte le scansioni presenti nel cd, una volta creato.. ma per il momento, BSOD non se ne presentano, l'unica pecca è che rimane molto lento. Appena posso faccio un nuovo aggiornamento.

[grazie]
Grazie per tutto Zane

conosciamo l'1% delle leggi che governano l'universo, le altre non le abbiamo ancora comprese a fondo o addirittura nemmeno intuite
Avatar utente
Uomo_Senza_Sonno
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 3255
Iscritto il: gio feb 07, 2008 9:00 am
Località: http://turbolab.it

Prossimo

Torna a Sistema Operativo

Chi c’è in linea

Visitano il forum: Nessuno e 1 ospite

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising