Condividi:        

log di hijack

Come rimuovere virus e spyware? Le carte di credito sono davvero sicure in rete? È possibile navigare anonimi? Con quali programmi tutelare la propria privacy? Come proteggere i file importanti? Se volete una risposta a queste e altre domande questo è il luogo giusto!

Moderatori: m.paolo, kadosh, Luke57

log di hijack

Postdi dupasquet » 08/08/08 09:53

ciao grazie in anticipo potete controllarmi il log che ho postato


Log created by WinPatrol version 12.0.2007.1:12.0.2007.1
Scan saved at 10:52:42 AM, on 8/08/2008
Platform: Windows XP SP3 Home Edition Service Pack 3 (Build 2600)
MSIE: Internet Explorer (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRAMMI\AVG\AVG8\avgtray.exe
C:\Programmi\AVG\AVG8\avgwdsvc.exe
C:\Programmi\AVG\AVG8\avgfws8.exe
C:\APPS\POWERCINEMA\Kernel\TV\CLCapSvc.exe
C:\APPS\POWERCINEMA\Kernel\TV\CLSched.exe
C:\PROGRAMMI\CYBERLINK\SHARED FILES\CLML_NTSERVICE\CLMLSERVER.EXE
C:\APPS\HIDSERVICE\HIDSERVICE.EXE
C:\PROGRAMMI\CYBERLINK\SHARED FILES\CLML_NTSERVICE\CLMLSERVICE.EXE
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Programmi\AVG\AVG8\avgam.exe
C:\Programmi\AVG\AVG8\avgrsx.exe
C:\Programmi\AVG\AVG8\avgnsx.exe
C:\Programmi\AVG\AVG8\avgemc.exe
C:\PROGRAMMI\Xfire\xfire.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\PROGRAMMI\eMule\emule.exe
C:\PROGRAMMI\SpeedFan\speedfan.exe
C:\PROGRAMMI\INTERNET EXPLORER\iexplore.exe
C:\PROGRAMMI\Adobe\ACROBAT 7.0\Reader\AcroRd32.exe
C:\PROGRAMMI\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
C:\PROGRAMMI\BILLP STUDIOS\WINPATROL\WINPATROLEX.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 127.0.0.
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG8\avgssie.dll
O2 - BHO: - {7E853D72-626A-48EC-A868-BA8D5E23E045} -
O2 - BHO: - {b69a9db4-d0a1-4722-b56b-f20757a29cdf} -
O3 - Toolbar: - {b69a9db4-d0a1-4722-b56b-f20757a29cdf} -
O4 - HKLM\..\Run: [AVG8_TRAY]C:\Programmi\AVG\AVG8\avgtray.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O11 - Options group: [Java (Sun)] Java (Sun) - C:\Programmi\Java\j2re1.4.2_05\bin
O11 - Options group: [] -
O14 - IERESET.INF: START_PAGE_URL = file://C:\APPS\IE\offline\it.htm
O14 - IERESET.INF: SEARCH_PAGE_URL = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
O14 - IERESET.INF:HKCU, Start Page = %START_PAGE_URL%
O14 - IERESET.INF:HKLM, Default_Page_URL = %START_PAGE_URL%
O14 - IERESET.INF:HKLM, Default_Search_URL = %SEARCH_PAGE_URL%
O14 - IERESET.INF:HKLM, Search Page = %SEARCH_PAGE_URL%
O14 - IERESET.INF:HKCU, Search Page = %SEARCH_PAGE_URL%
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/sh ... tor/sw.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 1362101563
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.4.2_05) - http://java.sun.com/products/plugin/aut ... s-i586.cab
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} (Java Plug-in 1.4.2_05) - http://java.sun.com/products/plugin/aut ... s-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O20 - AppInit_DLLs: avgrsstx.dll

O21 - WPDShServiceObj - WPDShServiceObj Class - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: a-squared Anti-Malware Service - Emsi Software GmbH - I:\antivirus\a-squared\installazione a-squared\a-squared Anti-Malware\a2service.exe
O23 - Service: Avvisi - Microsoft Corporation - C:\WINDOWS\system32\alrsvc.dll
O23 - Service: Servizio Gateway di livello applicazione - Microsoft Corporation - C:\WINDOWS\system32\alg.exe
O23 - Service: Gestione applicazione - - C:\WINDOWS\System32\appmgmts.dll
O23 - Service: ASP.NET State Service - Microsoft Corporation - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: ATI Smart - - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Audio Windows - Microsoft Corporation - C:\WINDOWS\system32\audiosrv.dll
O23 - Service: AVG8 E-mail Scanner - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG8\avgfws8.exe
O23 - Service: Servizio trasferimento intelligente in background - Microsoft Corporation - C:\WINDOWS\system32\qmgr.dll
O23 - Service: Browser di computer - Microsoft Corporation - C:\WINDOWS\system32\browser.dll
O23 - Service: Indexing Service - Microsoft Corporation - C:\WINDOWS\system32\cisvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) - - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: ClipBook - Microsoft Corporation - C:\WINDOWS\system32\clipsrv.exe
O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 - Microsoft Corporation - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
O23 - Service: CyberLink Task Scheduler (CTS) - - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: Applicazione di sistema COM+ - - C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
O23 - Service: Servizi di crittografia - Microsoft Corporation - C:\WINDOWS\system32\cryptsvc.dll
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programmi\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Utilità di avvio processo server DCOM - Microsoft Corporation - C:\WINDOWS\system32\rpcss.dll
O23 - Service: Client DHCP - Microsoft Corporation - C:\WINDOWS\system32\dhcpcsvc.dll
O23 - Service: Servizio amministrativo di Gestione disco logico - - C:\WINDOWS\System32\dmadmin.exe /com
O23 - Service: Gestione dischi logici - Microsoft Corp. - C:\WINDOWS\system32\dmserver.dll
O23 - Service: Client DNS - Microsoft Corporation - C:\WINDOWS\system32\dnsrslvr.dll
O23 - Service: Configurazione automatica reti cablate - Microsoft Corporation - C:\WINDOWS\system32\dot3svc.dll
O23 - Service: Servizio Extensible Authentication Protocol - Microsoft Corporation - C:\WINDOWS\system32\eapsvc.dll
O23 - Service: Error Reporting Service - Microsoft Corporation - C:\WINDOWS\system32\ersvc.dll
O23 - Service: Registro eventi - Microsoft Corporation - C:\WINDOWS\system32\services.exe
O23 - Service: Sistema di eventi COM+ - Microsoft Corporation - C:\WINDOWS\system32\es.dll
O23 - Service: Compatibilità di Cambio rapido utente - Microsoft Corporation - C:\WINDOWS\system32\shsvcs.dll
O23 - Service: Generic Service for HID Keyboard Input Collections - - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Guida in linea e supporto tecnico - Microsoft Corporation - C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll
O23 - Service: HID Input Service - Microsoft Corporation - C:\WINDOWS\system32\hidserv.dll
O23 - Service: Servizio gestione chiavi e certificati di integrità - Microsoft Corporation - C:\WINDOWS\system32\kmsvc.dll
O23 - Service: SSL HTTP - Microsoft Corporation - C:\WINDOWS\system32\w3ssl.dll
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Servizio COM di masterizzazione CD IMAPI - Microsoft Corporation - C:\WINDOWS\system32\imapi.exe
O23 - Service: Server - Microsoft Corporation - C:\WINDOWS\system32\srvsvc.dll
O23 - Service: Workstation - Microsoft Corporation - C:\WINDOWS\system32\wkssvc.dll
O23 - Service: Helper NetBIOS di TCP/IP - Microsoft Corporation - C:\WINDOWS\system32\lmhsvc.dll
O23 - Service: Messenger - Microsoft Corporation - C:\WINDOWS\system32\msgsvc.dll
O23 - Service: Condivisione desktop remoto di NetMeeting - Microsoft Corporation - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Distributed Transaction Coordinator - Microsoft Corporation - C:\WINDOWS\system32\msdtc.exe
O23 - Service: Windows Installer - - C:\WINDOWS\system32\msiexec.exe /V
O23 - Service: Agente protezione accesso alla rete - Microsoft Corporation - C:\WINDOWS\system32\qagentrt.dll
O23 - Service: DDE di rete - Microsoft Corporation - C:\WINDOWS\system32\netdde.exe
O23 - Service: DDE DSDM di rete - Microsoft Corporation - C:\WINDOWS\system32\netdde.exe
O23 - Service: Accesso rete - Microsoft Corporation - C:\WINDOWS\system32\lsass.exe
O23 - Service: Connessioni di rete - Microsoft Corporation - C:\WINDOWS\system32\netman.dll
O23 - Service: NLA (Network Location Awareness) - Microsoft Corporation - C:\WINDOWS\system32\mswsock.dll
O23 - Service: Provider supporto protezione LM NT - Microsoft Corporation - C:\WINDOWS\system32\lsass.exe
O23 - Service: Archivi rimovibili - Microsoft Corporation - C:\WINDOWS\system32\ntmssvc.dll
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Plug and Play - Microsoft Corporation - C:\WINDOWS\system32\services.exe
O23 - Service: PnkBstrA - - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Servizi IPSEC - Microsoft Corporation - C:\WINDOWS\system32\lsass.exe
O23 - Service: Archiviazione protetta - Microsoft Corporation - C:\WINDOWS\system32\lsass.exe
O23 - Service: Auto Connection Manager di Accesso remoto - Microsoft Corporation - C:\WINDOWS\system32\rasauto.dll
O23 - Service: Connection Manager di Accesso remoto - Microsoft Corporation - C:\WINDOWS\system32\rasmans.dll
O23 - Service: Gestione sessione di assistenza mediante desktop remoto - Microsoft Corporation - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Routing e Accesso remoto - Microsoft Corporation - C:\WINDOWS\system32\mprdim.dll
O23 - Service: RPC Locator - Microsoft Corporation - C:\WINDOWS\system32\locator.exe
O23 - Service: RPC (Remote Procedure Call) - Microsoft Corporation - C:\WINDOWS\system32\rpcss.dll
O23 - Service: QoS RSVP - Microsoft Corporation - C:\WINDOWS\system32\rsvp.exe
O23 - Service: Gestione account di protezione (SAM) - Microsoft Corporation - C:\WINDOWS\system32\lsass.exe
O23 - Service: smart card - Microsoft Corporation - C:\WINDOWS\system32\scardsvr.exe
O23 - Service: Utilità di pianificazione - Microsoft Corporation - C:\WINDOWS\system32\schedsvc.dll
O23 - Service: Accesso secondario - Microsoft Corporation - C:\WINDOWS\system32\seclogon.dll
O23 - Service: Notifica eventi di sistema - Microsoft Corporation - C:\WINDOWS\system32\sens.dll
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Windows Firewall / Condivisione connessione Internet (ICS) - Microsoft Corporation - C:\WINDOWS\system32\ipnathlp.dll
O23 - Service: Rilevamento hardware shell - Microsoft Corporation - C:\WINDOWS\system32\shsvcs.dll
O23 - Service: Spooler di stampa - Microsoft Corporation - C:\WINDOWS\system32\spoolsv.exe
O23 - Service: Servizio Ripristino configurazione di sistema - Microsoft Corporation - C:\WINDOWS\system32\srsvc.dll
O23 - Service: Servizio di rilevamento SSDP - Microsoft Corporation - C:\WINDOWS\system32\ssdpsrv.dll
O23 - Service: Acquisizione di immagini di Windows (WIA) - Microsoft Corporation - C:\WINDOWS\system32\wiaservc.dll
O23 - Service: MS Software Shadow Copy Provider - - C:\WINDOWS\system32\dllhost.exe /Processid:{86F27356-A5B9-4C90-8CB5-4607757A8095}
O23 - Service: Avvisi e registri di prestazioni - Microsoft Corporation - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Telefonia - Microsoft Corporation - C:\WINDOWS\system32\tapisrv.dll
O23 - Service: Servizi terminal - Microsoft Corporation - C:\WINDOWS\system32\termsrv.dll
O23 - Service: Temi - Microsoft Corporation - C:\WINDOWS\system32\shsvcs.dll
O23 - Service: Manutenzione collegamenti distribuiti client - Microsoft Corporation - C:\WINDOWS\system32\trkwks.dll
O23 - Service: Host di periferiche Plug and Play universali - Microsoft Corporation - C:\WINDOWS\system32\upnphost.dll
O23 - Service: Uninterruptible Power Supply - Microsoft Corporation - C:\WINDOWS\system32\ups.exe
O23 - Service: Servizio Messenger Sharing Folders USN Journal Reader - Microsoft Corporation - C:\Programmi\MSN Messenger\usnsvc.exe
O23 - Service: Copia replicata del volume - Microsoft Corporation - C:\WINDOWS\system32\vssvc.exe
O23 - Service: Ora di Windows - Microsoft Corporation - C:\WINDOWS\system32\w32time.dll
O23 - Service: WebClient - Microsoft Corporation - C:\WINDOWS\system32\webclnt.dll
O23 - Service: Strumentazione gestione Windows - Microsoft Corporation - C:\WINDOWS\system32\wbem\wmisvc.dll
O23 - Service: Windows Live Setup Service - Microsoft Corporation - C:\Programmi\Windows Live\installer\WLSetupSvc.exe
O23 - Service: Servizio Numero di serie per dispositivi multimediali portatili - Microsoft Corporation - C:\WINDOWS\system32\mspmsnsv.dll
O23 - Service: Scheda WMI Performance - Microsoft Corporation - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Servizio di condivisione in rete Windows Media Player - Microsoft Corporation - C:\Programmi\Windows Media Player\wmpnetwk.exe
O23 - Service: Centro sicurezza PC - Microsoft Corporation - C:\WINDOWS\system32\wscsvc.dll
O23 - Service: Aggiornamenti automatici - Microsoft Corporation - C:\WINDOWS\system32\wuauserv.dll
O23 - Service: Windows Driver Foundation - User-mode Driver Framework - Microsoft Corporation - C:\WINDOWS\system32\WudfSvc.dll
O23 - Service: Zero Configuration reti senza fili - Microsoft Corporation - C:\WINDOWS\system32\wzcsvc.dll
O23 - Service: Servizio Provisioning di rete - Microsoft Corporation - C:\WINDOWS\system32\xmlprov.dll
O24 - Desktop Component 0: Pagina iniziale corrente - About:Home

--- Additional WinPatrol Info ---
Default Browser: Windows® Internet Explorer - Internet Explorer version 7.00.6000.16674
MSIE: Internet Explorer (7.00.6000.16674)
5 IE Cookies in Folder: C:\Documents and Settings\pasquale\Cookies\

WP00 - HKLM\CS1: BootExecute = autocheck autochk *
WP00 - HKLM\CCS: BootExecute = autocheck autochk *
WP00 - HKLM\CS2: BootExecute = autocheck autochk *
WP02 - HKLM\CCS: Command = C:\WINDOWS\system32\cmd.exe


WP31 - Scheduled Tasks: [Symantec NetDetect.job]C:\Programmi\Symantec\LiveUpdate\NDETECT.EXE Mai
WP31 - Scheduled Tasks: [AppleSoftwareUpdate.job]C:\Programmi\Apple Software Update\SoftwareUpdate.exe 08/04/2008 10:48 AM

WP32 - Hidden File: C:\BOOT.BAK
WP32 - Hidden File: C:\BOOT.INI
WP32 - Hidden File: C:\Bootfont.bin
WP32 - Hidden File: C:\cmldr
WP32 - Hidden File: C:\hiberfil.sys
WP32 - Hidden File: C:\IO.SYS
WP32 - Hidden File: C:\MSDOS.SYS
WP32 - Hidden File: C:\pagefile.sys
WP32 - Hidden File: C:\WINDOWS\QTFont.qfn
WP32 - Hidden File: C:\WINDOWS\S52C2EDD9.tmp
WP32 - Hidden File: C:\WINDOWS\WindowsShell.Manifest
WP32 - Hidden File: C:\WINDOWS\winnt.bmp
WP32 - Hidden File: C:\WINDOWS\winnt256.bmp
WP32 - Hidden File: C:\WINDOWS\system32\cdplayer.exe.manifest
WP32 - Hidden File: C:\WINDOWS\system32\config\default.LOG
WP32 - Hidden File: C:\WINDOWS\system32\config\SAM.LOG
WP32 - Hidden File: C:\WINDOWS\system32\config\SECURITY.LOG
WP32 - Hidden File: C:\WINDOWS\system32\config\software.LOG
WP32 - Hidden File: C:\WINDOWS\system32\config\system.LOG
WP32 - Hidden File: C:\WINDOWS\system32\config\TempKey.LOG
WP32 - Hidden File: C:\WINDOWS\system32\config\userdiff.LOG
WP32 - Hidden File: C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
WP32 - Hidden File: C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
WP32 - Hidden File: C:\WINDOWS\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
WP32 - Hidden File: C:\WINDOWS\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
WP32 - Hidden File: C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
WP32 - Hidden File: C:\WINDOWS\system32\logonui.exe.manifest
WP32 - Hidden File: C:\WINDOWS\system32\ncpa.cpl.manifest
WP32 - Hidden File: C:\WINDOWS\system32\nwc.cpl.manifest
WP32 - Hidden File: C:\WINDOWS\system32\Restore\filelist.xml
WP32 - Hidden File: C:\WINDOWS\system32\sapi.cpl.manifest
WP32 - Hidden File: C:\WINDOWS\system32\WindowsLogon.manifest
WP32 - Hidden File: C:\WINDOWS\system32\wuaucpl.cpl.manifest

WP33 - File Type .AVI: [Video clip]C:\Programmi\Windows Media Player\wmplayer.exe /prefetch:8 /Open %L
WP33 - File Type .AVI: [GOM Media file(.avi)]C:\Programmi\GRETECH\GomPlayer\GOM.exe /open %1
WP33 - File Type .BAT: [File batch MS-DOS]%1 %*
WP33 - File Type .CAB: [Archivio WinRAR]C:\Programmi\WinRAR\WinRAR.exe %1
WP33 - File Type .CAT: [Catalogo protezione]rundll32.exe cryptext.dll,CryptExtOpenCAT %1
WP33 - File Type .CHM: [File di HTML Help compilato]C:\WINDOWS\hh.exe %1
WP33 - File Type .COM: [Applicazione per MS-DOS]%1 %*
WP33 - File Type .CMD: [Script di comandi Windows NT]%1 %*
WP33 - File Type .DOC: [WordPad Document]C:\Programmi\Windows NT\Accessori\WORDPAD.EXE %1
WP33 - File Type .EML: [Messaggio di Outlook Express Mail]C:\Programmi\Outlook Express\msimn.exe /eml:%1
WP33 - File Type .EXE: [Applicazione]%1 %*
WP33 - File Type .INF: [Informazioni di installazione]C:\WINDOWS\System32\NOTEPAD.EXE %1
WP33 - File Type .JS: [File di script JScript]C:\WINDOWS\System32\WScript.exe %1 %*
WP33 - File Type .LOG: [Documento di testo]C:\WINDOWS\system32\NOTEPAD.EXE %1
WP33 - File Type .MSI: [Windows Installer Package]C:\WINDOWS\System32\msiexec.exe /i %1 %*
WP33 - File Type .MID: [Sequenza MIDI]C:\Programmi\Windows Media Player\wmplayer.exe /Open %L
WP33 - File Type .MP3: [Audio formato MP3]C:\Programmi\Windows Media Player\wmplayer.exe /prefetch:6 /Open %L
WP33 - File Type .PIF: [Collegamento ad un programma per MS-DOS]%1 %*
WP33 - File Type .RAM: [Presentazione di RealPlayer]C:\Programmi\Real\RealPlayer\RealPlay.exe %1
WP33 - File Type .REG: [Voci di registrazione]regedit.exe %1
WP33 - File Type .RTF: [Documento RTF]C:\Programmi\Windows NT\Accessori\WORDPAD.EXE %1
WP33 - File Type .SCR: [Screen saver]%1 /S
WP33 - File Type .TXT: [Documento di testo]C:\WINDOWS\system32\NOTEPAD.EXE %1
WP33 - File Type .URL: [Collegamento Internet]rundll32.exe ieframe.dll,OpenURL %l
WP33 - File Type .VBS: [File di script VBScript]C:\WINDOWS\System32\WScript.exe %1 %*
WP33 - File Type .VBE: [File di script codificato in VBScript]C:\WINDOWS\System32\WScript.exe %1 %*
WP33 - File Type .WSF: [File di script Windows]C:\WINDOWS\System32\WScript.exe %1 %*
WP33 - File Type .WSH: [File di impostazioni di Windows Script Host]C:\WINDOWS\System32\WScript.exe %1 %*

Memory currently in use: 68%
Physical Memory Free: 333,212 KB
Paging File Free: 2,382,788 KB
Virtual Memory Free: 2,049,240 KB


--
End of file
dupasquet
Utente Junior
 
Post: 22
Iscritto il: 27/08/06 16:10

Sponsor
 

Torna a Sicurezza e Privacy


Topic correlati a "log di hijack":

controllo Hijack
Autore: dayfreeman
Forum: Sicurezza e Privacy
Risposte: 1

Chi c’è in linea

Visitano il forum: Nessuno e 46 ospiti