Moderatori: m.paolo, kadosh, Luke57
:otl
PRC - C:\Program Files (x86)\Norton Security\Engine\22.5.2.15\NS.exe (Symantec Corporation)
SRV - (NS) -- C:\Program Files (x86)\Norton Security\Engine\22.5.2.15\NS.exe (Symantec Corporation)
DRV:[b]64bit:[/b] - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:[b]64bit:[/b] - (SymNetS) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\symnets.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (SymIRON) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\ironx64.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (SymEFASI) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\symefasi64.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (SRTSP) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\srtsp64.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (SRTSPX) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\srtspx64.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (ccSet_NS) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\ccsetx64.sys (Symantec Corporation)
DRV - (NAVEX15) -- C:\Program Files (x86)\Norton Security\NortonData\22.5.0.124\Definitions\VirusDefs\20151114.006\EX64.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\Program Files (x86)\Norton Security\NortonData\22.5.0.124\Definitions\VirusDefs\20151114.006\ENG64.SYS (Symantec Corporation)
DRV - (IDSVia64) -- C:\Program Files (x86)\Norton Security\NortonData\22.5.0.124\Definitions\IPSDefs\20151113.001\IDSvia64.sys (Symantec Corporation)
DRV - (BHDrvx64) -- C:\Program Files (x86)\Norton Security\NortonData\22.5.0.124\Definitions\BASHDefs\20151102.001\BHDrvx64.sys (Symantec Corporation)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
IE - HKLM\..\SearchScopes,DefaultScope = {E9410C70-B6AE-41FF-AB71-32F4B279EA5F}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}: "URL" = https://www.google.com/search?trackid=sp-006&q={searchTerms}
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/it-it/?ocid=iehp
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = it
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9B 10 CB CB 54 50 D0 01 [binary data]
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NS&chn=retail&geo=IT&ver=22&locale=it_IT&gct=sb&qsrc=2869
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\..\SearchScopes\OldSearch: "URL" = http://www.google.it/#hl=it&source=hp&q={searchTerms}&aq=f&aqi=g10&aql=&oq=&gs_rfai=&fp=9fca69c98b5d77d7
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.5.0.124\coFFPlgn\ [2015/11/15 20:58:43 | 000,000,000 | ---D | M]
CHR - Extension: No name found = C:\Users\portatile\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
CHR - Extension: No name found = C:\Users\portatile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijoffpmfcdnncgblkdnobhomnjnkofdm\2015.11.15.44622_0\
CHR - Extension: No name found = C:\Users\portatile\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfpjmkngecpnnajkmdhplmeoelenkpgk\2015.11.15.44622_0\
O2:[b]64bit:[/b] - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security\Engine64\22.5.2.15\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security\Engine\22.5.2.15\coIEPlg.dll (Symantec Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine64\22.5.2.15\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine\22.5.2.15\coIEPlg.dll (Symantec Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2276094326-4152468845-1038248676-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C322DBA-1876-4CB3-97A6-72A70DD792E1}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O33 - MountPoints2\{d459b040-241c-11e5-89d8-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{d459b040-241c-11e5-89d8-806e6f6e6963}\Shell\AutoRun\command - "" = G:\SETUP.EXE
O33 - MountPoints2\{d459b040-241c-11e5-89d8-806e6f6e6963}\Shell\configure\command - "" = G:\SETUP.EXE
O33 - MountPoints2\{d459b040-241c-11e5-89d8-806e6f6e6963}\Shell\install\command - "" = G:\SETUP.EXE
O33 - MountPoints2\{f05b6a0e-c655-11e4-bed9-0017c47a1264}\Shell - "" = AutoRun
O33 - MountPoints2\{f05b6a0e-c655-11e4-bed9-0017c47a1264}\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true
[2015/11/15 19:33:47 | 000,576,248 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\symnets.sys
[2015/11/15 19:33:47 | 000,050,936 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\srtspx64.sys
[2015/11/15 19:33:47 | 000,024,192 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\symelam.sys
[2015/11/15 19:33:46 | 000,926,448 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\srtsp64.sys
[2015/11/15 19:33:46 | 000,297,720 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\ironx64.sys
[2015/11/15 19:33:46 | 000,173,808 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\ccsetx64.sys
[2015/11/15 19:33:44 | 001,620,720 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NSx64\1605020.00F\symefasi64.sys
[2015/11/15 18:35:07 | 003,237,248 | ---- | C] (Enigma Software Group USA, LLC.) -- C:\Users\portatile\Desktop\SpyHunter-Installer.exe
[2015/11/15 19:34:06 | 000,111,344 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2015/11/15 19:34:06 | 000,008,214 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2015/11/15 19:34:06 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2015/11/15 18:35:15 | 003,237,248 | ---- | M] (Enigma Software Group USA, LLC.) -- C:\Users\portatile\Desktop\SpyHunter-Installer.exe
:Commands
[emptytemp]
[reboot]
Chrome: due profili uguali aperti contemporaneamente Autore: franco11 |
Forum: Software Windows Risposte: 1 |
Visitano il forum: Nessuno e 19 ospiti