Nikon ha scritto:Verissimo,ma sono puliti.non c'è niente di strano.
Adesso quarda.
Scarica questo programma:
http://www.downloads.subratam.org/l2mfix.exeEstrai in una sua cartela in Documenti (come che hai fato con Hijackhits)
dai nome che vuoi (consiglio 12mfix)
Dopo apri la cartella e clicca sul (leggi bene)
cosi si vede : 12mfix
File batch MS-DOS
8kb
Fai doppio click sul questo,si apre una finestra
premi Invio
poi premmi 1
INVIO
quando finisce mi mandi REPORT qua.(come con Hijackhits)
eccolo, speriamo che esce il problema
L2MFIX find log 010406
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
**********************************************************************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{5a61f7a0-cde1-11cf-9113-00aa00425c62}"="IIS Shell Extension"
**********************************************************************************
HKEY ROOT CLASSIDS:
**********************************************************************************
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
bassmod.dll Tue 31 Jan 2006 13.10.36 A.... 15.360 15,00 K
browseui.dll Thu 24 Nov 2005 1.14.46 A.... 1.022.464 998,50 K
danim.dll Sat 5 Nov 2005 4.16.58 A.... 1.056.256 1,00 M
gdi32.dll Thu 29 Dec 2005 3.55.46 A.... 280.064 273,50 K
imon.dll Sat 28 Jan 2006 18.22.04 A.... 270.336 264,00 K
mshtml.dll Thu 24 Nov 2005 1.14.46 A.... 3.013.632 2,87 M
shdocvw.dll Thu 1 Dec 2005 4.31.04 A.... 1.492.992 1,42 M
sirenacm.dll Wed 14 Dec 2005 9.24.42 A.... 118.784 116,00 K
urlmon.dll Sat 5 Nov 2005 4.17.02 A.... 605.184 591,00 K
vsdata.dll Tue 15 Nov 2005 0.50.30 A.... 83.720 81,76 K
vsinit.dll Tue 15 Nov 2005 0.50.42 A.... 141.064 137,76 K
vsmonapi.dll Tue 15 Nov 2005 0.50.52 A.... 104.208 101,77 K
vspubapi.dll Tue 15 Nov 2005 0.50.56 A.... 227.088 221,77 K
vsregexp.dll Tue 15 Nov 2005 0.51.00 A.... 71.440 69,77 K
vsutil.dll Tue 15 Nov 2005 0.51.12 A.... 382.728 373,76 K
vsxml.dll Tue 15 Nov 2005 0.51.20 A.... 100.104 97,76 K
zlcomm.dll Tue 15 Nov 2005 0.51.40 A.... 79.624 77,76 K
zlcommdb.dll Tue 15 Nov 2005 0.51.44 A.... 71.440 69,77 K
18 items found: 18 files, 0 directories.
Total of file sizes: 9.136.488 bytes 8,71 M
Locate .tmp files:
No matches found.
**********************************************************************************
Directory Listing of system files:
Il volume nell'unit… C non ha etichetta.
Numero di serie del volume: 48F9-B1FE
Directory di C:\WINDOWS\System32
02/02/2006 11.28 <DIR> dllcache
12/12/2005 12.46 <DIR> Microsoft
0 File 0 byte
2 Directory 95.884.120.064 byte disponibili