Pagina 1 di 4 1 2 3 ... ultimoultimo
Visualizzazione dei risultati da 1 a 10 su 40

Discussione: Win32:small-BTH (trj)

  1. #1
    Utente di HTML.it
    Registrato dal
    Sep 2006
    Messaggi
    32

    Win32:small-BTH (trj)

    Ragazzi per favore voi competenti datemi una mano sono ormai giorni che il mio antivirus avast mi segnala la presenza di un troiano Win32:small-BTH in Temp\adfc1.exe
    ho provato tutte le vostre istruzioni ma niente da fare il troiano bastardo e sempre lì...
    ecco l'ordine dei programmi (tutti aggiornati alle ultime versioni) che ho utilizzato anche in modalità provvisoria:
    - Atf cleaner
    - Spybot search e destroy
    - Lavasoft Ad-aware
    - Xoftspy
    - Spyware doctor
    - Registry mechanic
    - Avast antivirus
    - Kaspersky online

    beh dopo averli usati tutti ad uno alla volta il computer risulta pulito o sembrerebbe dato che il giorno dopo mi ritrovo di nuovo col solito allarme

    a qst punto ho utilizzato il programma da voi consigliato HijackThis per intenderci ma mi sono limitato solo a fare una scansione con log senza procedere col fix checked ho paura di fare qualche guaio sinceramente non essendo abbastanza competente in questo genere di cose. lo scan l'ho effettuato disattivando firewall internet avast e insumma tutte quei programmini che si avviano con il windows e hanno le loro icone sulla destra della barra delle applicazioni
    comunque riporto di seguito il log del programma vi prego ragazzi aiutatemi io credo che forse c'è ne è anche qulacun altro di troiano non lo so ho questo presentimento....

    LOG:
    Logfile of HijackThis v1.99.1
    Scan saved at 1.20.10, on 11/09/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\Antivirus Alwil Software\Avast4\aswUpdSv.exe
    C:\Programmi\Antivirus Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\ANTIVI~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\oodag.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
    C:\Programmi\QuickTime\qttask.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Spyware Doctor\sdhelp.exe
    C:\Programmi\Messenger\msmsgs.exe
    C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.libero.it/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.libero.it/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: Class - {7A0E1A3C-189F-64ED-48F6-8F7A37A3F011} - blank (file missing)
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmi\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - blank (file missing)
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\StarModem\StarModem USB Network\CnxTrApp.dll",AppEntry -REG "Conexant\Conexant USB Network"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ANTIVI~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programmi\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [OM_Monitor] C:\Programmi\OLYMPUS\OLYMPUS Master\FirstStart.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [OM_Monitor] C:\Programmi\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
    O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Anteprima Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Stampa ad alta velocità Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://cirorep.spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ms...downloader.cab
    O16 - DPF: {EC52F7A4-27A7-4319-9BA1-E7FE5C90D3AC} - http://td8eau9td.com/8f30667b/50310/1/xp/FreeAccess.ocx
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Antivirus Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Antivirus Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Antivirus Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Antivirus Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Programmi\Spyware Doctor\sdhelp.exe
    O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe
    aspetto vostre delucidazioni grazie in anticipo ragazzi siete grandiosi

  2. #2
    Moderatore di Sicurezza informatica e virus L'avatar di amvinfe
    Registrato dal
    May 2002
    Messaggi
    6,739
    scarica sul desktop GMER
    scopatta, sempre sul desktop il file gmer.zip.
    Esegui gmer.exe
    Clicca sul Tab "Rootkit"
    Clicca su "Scan"
    finita la scansione clicca su "Copy"
    Apri il Blocco Note incolla il risultato (CTRL+V)

    Esegui gmer.exe
    Clicca sul Tab "Autostart"
    Clicca su "Scan"
    finita la scansione clicca su "Copy"
    Apri il Blocco Note incolla il risultato (CTRL+V)

    Copia in questa discussione entrambi i log
    ==
    Visita il mio blog SuspectFile.com
    ==

  3. #3
    Utente di HTML.it
    Registrato dal
    Sep 2006
    Messaggi
    32
    grazie per essermi venuto in soccorso amvinfe
    eccoti riportati di seguito i log delle due scansioni:
    GMER 1.0.10.10122 - http://www.gmer.net
    Rootkit 2006-09-11 12:30:31
    Windows 5.1.2600 Service Pack 2


    ---- System - GMER 1.0.10 ----

    SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwAllocateVirtualMemory
    SSDT a347bus.sys ZwClose
    SSDT a347bus.sys ZwCreateKey
    SSDT a347bus.sys ZwCreatePagingFile
    SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwCreateThread
    SSDT a347bus.sys ZwEnumerateKey
    SSDT a347bus.sys ZwEnumerateValueKey
    SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwMapViewOfSection
    SSDT a347bus.sys ZwOpenFile
    SSDT a347bus.sys ZwOpenKey
    SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwProtectVirtualMemory
    SSDT a347bus.sys ZwQueryKey
    SSDT a347bus.sys ZwQueryValueKey
    SSDT a347bus.sys ZwSetSystemPowerState
    SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwShutdownSystem
    SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwTerminateProcess
    SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwWriteVirtualMemory

  4. #4
    Utente di HTML.it
    Registrato dal
    Sep 2006
    Messaggi
    32
    ZwWriteVirtualMemory

    ---- Devices - GMER 1.0.10 ----

    Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F8738220] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSEIRP_MJ_READ [F8738480] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F87385A0] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN [F87385D0] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F8738220] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSEIRP_MJ_READ [F8738480] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F87385A0] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN [F87385D0] wpsdrvnt.sys
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSEIRP_MJ_READ 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 820B15D0
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP_POWER 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSEIRP_MJ_READ 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP

  5. #5
    Utente di HTML.it
    Registrato dal
    Sep 2006
    Messaggi
    32
    820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 820B15D0
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP_POWER 820B15D0
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSEIRP_MJ_READ 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 820BA538
    Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP_POWER 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_NAMED_PIPE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLOSEIRP_MJ_READ 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_WRITE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_EA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_EA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_FLUSH_BUFFERS 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_VOLUME_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_VOLUME_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DIRECTORY_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_FILE_SYSTEM_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SHUTDOWN 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_LOCK_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLEANUP 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_MAILSLOT 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_SECURITY

  6. #6
    Utente di HTML.it L'avatar di holifay
    Registrato dal
    May 2005
    Messaggi
    1,330
    Ciao, sicuro di aver copiato tutto dal log di Rootkit? Mi sembra incompleto.

    Devi postare anche quello fatto nel tab Autostart di GMER.
    Pensi di avere un file infetto? Invialo a SuspectFile

  7. #7
    Utente di HTML.it
    Registrato dal
    Sep 2006
    Messaggi
    32
    820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_SECURITY 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_POWER 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SYSTEM_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CHANGE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_QUOTA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_QUOTA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_PNP 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_PNP_POWER 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSEIRP_MJ_READ 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 820BA538
    Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP_POWER 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE_NAMED_PIPE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLOSEIRP_MJ_READ 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_WRITE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_INFORMATION

  8. #8
    Utente di HTML.it
    Registrato dal
    Sep 2006
    Messaggi
    32
    820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_EA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_EA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_FLUSH_BUFFERS 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_VOLUME_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_VOLUME_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DIRECTORY_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_FILE_SYSTEM_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DEVICE_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_INTERNAL_DEVICE_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SHUTDOWN 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_LOCK_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLEANUP 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE_MAILSLOT 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_SECURITY 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_SECURITY 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_POWER 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SYSTEM_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DEVICE_CHANGE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_QUOTA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_QUOTA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_PNP 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_PNP_POWER 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_CREATE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_CREATE_NAMED_PIPE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_CLOSEIRP_MJ_READ 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_WRITE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_QUERY_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_SET_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_QUERY_EA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_SET_EA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_FLUSH_BUFFERS 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_QUERY_VOLUME_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_SET_VOLUME_INFORMATION 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_DIRECTORY_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_FILE_SYSTEM_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_DEVICE_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_INTERNAL_DEVICE_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_SHUTDOWN 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_LOCK_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_CLEANUP 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_CREATE_MAILSLOT 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_QUERY_SECURITY 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_SET_SECURITY 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_POWER 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_SYSTEM_CONTROL 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_DEVICE_CHANGE 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_QUERY_QUOTA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_SET_QUOTA 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_PNP 820BA538
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_PNP_POWER 820BA538
    Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F8738220] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSEIRP_MJ_READ [F8738480] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL

  9. #9
    Utente di HTML.it
    Registrato dal
    Sep 2006
    Messaggi
    32
    [F87385A0] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN [F87385D0] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F8738220] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSEIRP_MJ_READ [F8738480] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F87385A0] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN [F87385D0] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F8738220] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSEIRP_MJ_READ [F8738480] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F87385A0] wpsdrvnt.sys
    Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SHUTDOWN [F87385D0] wpsdrvnt.sys

  10. #10
    Utente di HTML.it
    Registrato dal
    Sep 2006
    Messaggi
    32
    ---- Modules - GMER 1.0.10 ----

    Module _________ F8452000

    ---- Registry - GMER 1.0.10 ----

    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af164764 4e76e06692b 0xC8 0x28 0x51 0xAF ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2e cedcc62c59b 0x71 0x3B 0x04 0x66 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023 a60d06dd016 0x7A 0x45 0x05 0xFD ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be0 6337561aa48 0x86 0x8C 0x21 0x01 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d96 86d4b818472 0xE9 0x02 0x6C 0xFA ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b7 4b2b4522f5d 0xDF 0x20 0x58 0x62 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e 232fed27b7b 0x31 0x77 0xE1 0xBA ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb 204b76f993d 0xAA 0x52 0xC6 0x00 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a 51804d844a3 0x51 0xFA 0x6E 0x91 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe 080bb27835b 0x3D 0xCE 0xEA 0x26 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a 6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616 fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
    Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\Curre ntVersion\System@OODEFRAG08.00.00.01WORKSTATION 8B7C4A49767CE979FCF026E29317B6D99A88E47D7DE757ED66 5CF42D63A666AA2AF28296552F170A41F8E4FEBC9E127BECC7 4CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C FEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E6679D B7CE019D40AA5CC038D530D6EB3452A6A0AC4980AC79330911 E428E96A283A471A2404A2A00239FADDE7FC0623307176C6E2 303236F451C68D2A9BEEB6AA11F6172162ECD37517CA1E76D6 132A88B49A322C62DEA8F22DBA8333B0CEBF0A8E6EFE15B1E6 EA5458F33AAFEC3A0390F514B27E1B0B624507CC5776A0F75C E6F58863EEC2C0FA0865E2121CC28A1D1AE07D931DB5C6D145 ED6BDD10BA1D15445D234743796DC95C7706F26A72D89B5CF5 7990ED1EE89732C78863BE633327092D21A249CD2352819FD2 A4E9A8BDD56E882B5D78590906ACCD9AA6E410758480A469E1 DDCCDCC28C3E3FDE10289458CF41BC9EED7B8528BD0C1A5B89 CEE053DAD466E380955B7DF40CC8CFF5C4FCE1DF9AD8701F30 7EB94D630527D73C386CAA23867FD45D21981892ED1758685C E5E5E4B1DE0135D92AAB895C271E0D81DDE84A3D79236B74DF B5B1324A9810DA8C0AC3FB6C2E5D411F8A0627E7CF8887E7EE D68110D61EE1D0739B1EF13ACD63315A2F700F648D207080B5 EEED8489D781FCAC4C720063371ED7D53C8CE646A762C77349 B185C0A82C87CA40B075FEC
    Reg \Registry\USER\S-1-5-21-606747145-220523388-682003330-1003\Software\Zepter Software\RegLib

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved.