Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

My Hijackthis Opzioni
shapiro
Inviato: Monday, October 04, 2010 3:53:02 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
la scansione e' pulita

leggi qui
7slevin
Inviato: Saturday, October 09, 2010 12:45:09 PM
Rank: AiutAmico

Iscritto dal : 9/29/2010
Posts: 78
qualche giorno fa ho scaricato Spyware Terminator e nelle sue scansioni giornaliere mi trova sempre le stesse 2 minacce anche se le rimuovo il giorno prima. Ora non so se tu utilizzi questo antispyware e puoi consigliarmi. Le 2 minacce sono:

Affiliate tracking cookie e Tracking Flash Shared Objects

Cosa dovrei fare secondo te? Ti allego anche il log della scansione di oggi:

Logfile of Spyware Terminator v2.8.0.18 (db:4.010.008.000)
Scan Time: 09/10/2010 12.27.06 length: 281 s
Platform: WXP (5.1.0.2600)
User: Admin
Boot Mode: Normal
Scan type: Fast_Spyware_Scan
Scanned Objects: 79945 (Critical:0)
Filter: No System items, No Safe items, No Invalid items

Running Processes
AppleMobileDeviceService.exe [Apple Inc.] : C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
SeaPort.exe [Microsoft Corporation] : C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
StarWindServiceAE.exe [Rocket Division Software] : C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
FxSvr2.exe [Logitech Inc.] : C:\Programmi\Logitech\Video\FxSvr2.exe
iPodService.exe [Apple Inc.] : C:\Programmi\iPod\bin\iPodService.exe
chrome.exe [Google Inc.] : C:\Documents and Settings\Nunzio\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
chrome.exe [Google Inc.] : C:\Documents and Settings\Nunzio\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
msnmsgr.exe [Microsoft Corporation] : C:\Programmi\Windows Live\Messenger\msnmsgr.exe
wlcomm.exe [Microsoft Corporation] : C:\Programmi\Windows Live\Contacts\wlcomm.exe
chrome.exe [Google Inc.] : C:\Documents and Settings\Nunzio\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe

Internet Settings
R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, ProxyOverride = local
R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =

BHO
02 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - [Microsoft Corporation] : C:\Programmi\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
02 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - [Microsoft Corporation] : C:\Programmi\Windows Live\Toolbar\wltcore.dll

Toolbars
03 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - [Microsoft Corporation] : C:\Programmi\Windows Live\Toolbar\wltcore.dll

StartUps
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Google Update : [Google Inc.] : C:\Documents and Settings\Nunzio\IMPOSTAZIONI LOCALI\DATI APPLICAZIONI\GOOGLE\UPDATE\GOOGLEUPDATE.EXE
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, DAEMON Tools Lite : [DT Soft Ltd] : C:\Programmi\DAEMON TOOLS LITE\DTLITE.EXE
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, AlcoholAutomount : [Alcohol Soft Development Team] : C:\Programmi\ALCOHOL SOFT\ALCOHOL 120\AXCMD.EXE
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, OutpostMonitor : [Agnitum Ltd.] : C:\Programmi\Agnitum\Outpost Firewall\op_mon.exe
04 - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs : [Agnitum Ltd.] : C:\Programmi\Agnitum\Outpost Firewall\wl_hook.dll

Shell Extensions
CLSID_WLMCMimeFilter - {0563DB41-F538-4B37-A92D-4659049B7766} - [Microsoft Corporation] : C:\Programmi\Windows Live\Mail\mailcomm.dll
- {06A2568A-CED6-4187-BB20-400B8C02BE5A} - [Microsoft Corporation] : C:\Programmi\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
Windows Live Photo Gallery Viewer Autoplay Shim - {00F33137-EE26-412F-8D71-F84E4C2C6625} - [Microsoft Corporation] : C:\Programmi\Windows Live\Photo Gallery\PhotoViewerShim.dll
Windows Live Photo Gallery Autoplay Drop Target - {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} - [Microsoft Corporation] : C:\Programmi\WINDOWS LIVE\PHOTO GALLERY\WLXPHOTOGALLERY.EXE
Windows Live Photo Gallery Editor Drop Target - {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} - [Microsoft Corporation] : C:\Programmi\WINDOWS LIVE\PHOTO GALLERY\WLXPHOTOGALLERY.EXE
Windows Live Photo Gallery Viewer Drop Target - {00F374B7-B390-4884-B372-2FC349F2172B} - [Microsoft Corporation] : C:\Programmi\WINDOWS LIVE\PHOTO GALLERY\WLXPHOTOGALLERY.EXE
Windows Live Photo Gallery Viewer Shim - {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} - [Microsoft Corporation] : C:\Programmi\Windows Live\Photo Gallery\PhotoViewerShim.dll
Windows Live Photo Gallery Editor Shim - {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} - [Microsoft Corporation] : C:\Programmi\Windows Live\Photo Gallery\PhotoViewerShim.dll
Windows Live Photo Gallery Viewer Autoplay Shim - {00F30F90-3E96-453B-AFCD-D71989ECC2C7} - [Microsoft Corporation] : C:\Programmi\Windows Live\Photo Gallery\PhotoViewerShim.dll
Immagini Logitech - {400CFEE2-39D0-46DC-96DF-E0BB5A4324B3} - [Logitech Inc.] : C:\Programmi\Logitech\Video\Namespc2.dll
AcColumnHandler - {8A0BC933-7552-42E2-A228-3BE055777227} - [Autodesk] : C:\Programmi\File comuni\Autodesk Shared\AcShellEx\AcShellExtension.dll
AcInfoTipHandler - {5800AD5B-72C1-477B-9A08-CA112DF06D97} - [Autodesk] : C:\Programmi\File comuni\Autodesk Shared\AcShellEx\AcShellExtension.dll
ACTHUMBNAIL - {AC1DB655-4F9A-4c39-8AD2-A65324A4C446} - [Autodesk, Inc.] : C:\Programmi\File comuni\Autodesk Shared\Thumbnail\AcThumbnail16.dll
AcDgnImageExtractor - {ADC46291-D8A1-4486-A24C-86FFB392AEFA} - [Autodesk] : C:\Programmi\File comuni\Autodesk Shared\AcDgnCOM17.dll
WIBU-SYSTEMS Shell Extension - {00020000-0000-1011-8004-0000C06B5161} - [WIBU-SYSTEMS AG] : C:\Programmi\WIBU-SYSTEMS\System\WibuShellExt.dll

Protocol Handler
- {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Programmi\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll
- {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Programmi\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll
Windows Live Mail HTML Asynchronous Pluggable Protocol Handler - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - [Microsoft Corporation] : C:\Programmi\Windows Live\Mail\mailcomm.dll

Services
23 - [Agnitum Ltd.] : C:\Programmi\Agnitum\Outpost Firewall\acs.exe
23 - [Apple Inc.] : C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
23 - [GEAR Software Inc.] : C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
23 - [Apple Inc.] : C:\Programmi\iPod\bin\iPodService.exe
23 - [Logitech Inc.] : C:\WINDOWS\system32\drivers\lvusbsta.sys
23 - [Creative Technology Ltd.] : C:\WINDOWS\system32\drivers\monfilt.sys
23 - : C:\WINDOWS\system32\DRIVERS\ASACPI.sys
23 - [Logitech Inc.] : C:\WINDOWS\system32\DRIVERS\LV561AV.SYS
23 - [Realtek Semiconductor Corporation] : C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
23 - [Microsoft Corporation] : C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
23 - [Crawler.com] : C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
23 - [Rocket Division Software] : C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
23 - [VIA Technologies, Inc.] : C:\WINDOWS\system32\drivers\viahduaa.sys
23 - [WIBU-SYSTEMS AG] : C:\WINDOWS\system32\DRIVERS\WibuKey.sys

Threat Files
<Tracking Flash Shared Objects> : C:\Documents and Settings\Nunzio\Dati applicazioni\Macromedia\Flash Player\#SharedObjects\RJFMRS67\core.videoegg.com\#com\videoegg\Demo.sol
<Tracking Flash Shared Objects> : C:\Documents and Settings\Nunzio\Dati applicazioni\Macromedia\Flash Player\#SharedObjects\RJFMRS67\core.videoegg.com\#com\videoegg\OptOut.sol
<Tracking Flash Shared Objects> : C:\Documents and Settings\Nunzio\Dati applicazioni\Macromedia\Flash Player\#SharedObjects\RJFMRS67\core.videoegg.com\#com\videoegg\Retargeting.sol
<Tracking Flash Shared Objects> : C:\Documents and Settings\Nunzio\Dati applicazioni\Macromedia\Flash Player\#SharedObjects\RJFMRS67\core.videoegg.com\#com\videoegg\Tearsheet.sol
<Tracking Flash Shared Objects> : C:\Documents and Settings\Nunzio\Dati applicazioni\Macromedia\Flash Player\#SharedObjects\RJFMRS67\core.videoegg.com\#com\videoegg\Twig.sol
<Tracking Flash Shared Objects> : C:\Documents and Settings\Nunzio\Dati applicazioni\Macromedia\Flash Player\#SharedObjects\RJFMRS67\core.videoegg.com\#ve\admanager.sol

Advanced Files Report
%SYSDIR%\CNMLM66.DLL [CANON INC.] [Canon BJ Raster Printer Driver for Microsoft Windows XP / Windows 2000] MD5=CC5FD591AE1E467595DD47E60933B143 SIZE=116736
%SYSDIR%\pdf995mon.dll MD5=AF238673651EFC0226EA74239B502A6F SIZE=51716
%SYSDIR%\pdfcmnnt.dll MD5=1574DD9D409F2DC45CF82C22B99164A4 SIZE=116224
%SYSDIR%\spool\PRTPROCS\W32X86\CNMPD66.DLL [CANON INC.] [Canon BJ Raster Printer Driver for Microsoft Windows XP / Windows 2000] MD5=644BC7F5356A080D83ECE9B992EB401D SIZE=17920
%COMMONFILES%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [Apple Inc.] [Apple Mobile Device Service] MD5=4B5AE15E5C73EB4DC8DBEC2788230D41 SIZE=144672
%PROGRAMFILES%\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [Microsoft Corporation] [Microsoft Search Enhancement Pack] MD5=4A5809A1D796E2675AC0332BF7B0CB11 SIZE=249136
%SYSDIR%\lvmaenum.dll [Logitech Inc.] [Logitech QuickCam] MD5=F703C8018ABAEEFD6129C374CC2969D0 SIZE=258048
%SYSDIR%\lvcomcx.dll [Logitech Inc.] [Logitech QuickCam] MD5=FB8081383C5360FBA8829E717FE6AC44 SIZE=77824
%PROGRAMFILES%\Logitech\Video\QCUI2.dll [Logitech Inc.] [Logitech QuickCam] MD5=647642EB3EE0C4D819DB57AE8DFD8009 SIZE=466944
%PROGRAMFILES%\Logitech\Video\LTWVC12n.dll [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=3C7B1E2C0E0C54FE99852F18B3DC8445 SIZE=856064
%PROGRAMFILES%\Logitech\Video\LTFIL12n.DLL [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=2D50FD2FC9B7BD4360229B5A5DB1E572 SIZE=131072
%PROGRAMFILES%\Logitech\Video\LTKRN12n.dll [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=E09877BA179E67F465DD6EAB44684A19 SIZE=406016
%PROGRAMFILES%\Logitech\Video\LQCUI2.dll [Logitech Inc.] [Logitech QuickCam] MD5=9728AA37DE26828D9A14004AA4BF4D68 SIZE=90112
%PROGRAMFILES%\Logitech\Video\LLogTray.dll [Logitech Inc.] [Logitech QuickCam] MD5=AC11ED289836EFE5440F72562DFB1BE1 SIZE=90112
%PROGRAMFILES%\Logitech\Video\LTDIS12N.DLL [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=70319E2275E78D7D91FA9A8EF34F48FA SIZE=259072
%PROGRAMFILES%\Logitech\Video\LTIMG12N.DLL [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=54240AFF9562BB1BC88BD1BBED29C865 SIZE=164864
%PROGRAMFILES%\Logitech\Video\LTEFX12N.DLL [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=C6DC5023661EE122A296E9D0931AB163 SIZE=207872
%PROGRAMFILES%\Logitech\Video\LFFAX12N.DLL [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=9981617DC7BD61AFC8A01E0C2429559D SIZE=78336
%PROGRAMFILES%\Logitech\Video\LFCMP12N.DLL [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=F61EC05FB1B10F088A8BC33C09987C67 SIZE=328704
%PROGRAMFILES%\Logitech\Video\LFTIF12N.DLL [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=9181BF08AE5C2B0A2094944B753A6004 SIZE=141312
%PROGRAMFILES%\Logitech\Video\LFBMP12N.DLL [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=747B156D7ADAFA031B3BF816D87E1A6D SIZE=30720
%PROGRAMFILES%\Logitech\Video\FXSvrps.dll [Logitech Inc.] [Logitech QuickCam] MD5=38ED18ED5E80514EDBD6E231B05AF7B6 SIZE=8192
%COMMONFILES%\Apple\Apple Application Support\CoreFoundation.dll [Apple Inc.] [CoreFoundation] MD5=F71F3C014C37AD294585728130756B98 SIZE=824608
%COMMONFILES%\Apple\Apple Application Support\pthreadVC2.dll [Open Source Software community project] MD5=4AA0527547BE16653D5ADF96F41E1E24 SIZE=53024
%COMMONFILES%\Apple\Apple Application Support\objc.dll MD5=F7E5225F9655594FB62048D29D83E6D1 SIZE=120096
%COMMONFILES%\Apple\Apple Application Support\icuin40.dll [IBM Corporation and others] [International Components for Unicode] MD5=FFE3D7E9E4C4CE8199F0E2B4DE4E7FEA SIZE=1041696
%COMMONFILES%\Apple\Apple Application Support\icuuc40.dll [IBM Corporation and others] [International Components for Unicode] MD5=70CAF7B4FDD77B6807BEAC3D85417972 SIZE=922912
%COMMONFILES%\Apple\Apple Application Support\icudt40.dll [IBM Corporation and others] [International Components for Unicode] MD5=28456A077F575ADCDBDEBD8ABD01A033 SIZE=14009632
%COMMONFILES%\Apple\Apple Application Support\ASL.dll MD5=985195828E487517A0B56E21E03D687C SIZE=39712
%COMMONFILES%\Apple\Apple Application Support\CFNetwork.dll [Apple, Inc.] [CFNetwork] MD5=74AA945B76964995552C63A37BA285E6 SIZE=603424
%COMMONFILES%\Apple\Apple Application Support\SQLite3.dll [Apple Inc.] [SQLite3] MD5=9C3A0CEA433D79DAE7985022A60B8DC3 SIZE=406816
%COMMONFILES%\Apple\Apple Application Support\zlib1.dll [zlib] MD5=E5B1D6DA7F1E3D7E930A1D5531F37933 SIZE=67872
%COMMONFILES%\Apple\Mobile Device Support\bin\iTunesMobileDevice.dll [Apple Inc.] [iTunesMobileDevice] MD5=B63A750AB385A44D4F888751DA6703AE SIZE=1352992
%PROGRAMFILES%\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [Rocket Division Software] [StarWind Alcohol Edition] MD5=B1691AF4A072CB674D600DB16DD7308E SIZE=275968
%PROGRAMFILES%\Logitech\Video\FxSvr2.exe [Logitech Inc.] [Logitech QuickCam] MD5=1B11C113DC4383C6C07A45BFFBDC7D63 SIZE=192512
%PROGRAMFILES%\iPod\bin\iPodService.exe [Apple Inc.] [iTunes] MD5=31116E352808019E69ECA58D1A6C66B0 SIZE=545568
%PROGRAMFILES%\iPod\bin\iPodService.Resources\it.lproj\iPodServiceLocalized.DLL [Apple Inc.] [iTunes] MD5=7800B5663C0E60F657102F74E55F6BBE SIZE=48928
%PROGRAMFILES%\iPod\bin\iPodService.Resources\iPodService.DLL [Apple Inc.] [iTunes] MD5=5CDA4C1A3E50ACAB6250CC1DF9FA6364 SIZE=47904
%USERPROFILE%\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe [Google Inc.] [Google Chrome] MD5=14B2758984AC9C8E7777D17AFD6D5819 SIZE=977976
%USERPROFILE%\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\6.0.472.63\chrome.dll [Google Inc.] [Google Chrome] MD5=87C118B3AE0A25C46BB1F7D24FBE45E9 SIZE=20082232
%USERPROFILE%\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\6.0.472.63\icudt42.dll [IBM Corporation and others] [International Components for Unicode] MD5=74FAA2493087575B82D8E655190A889D SIZE=10911800
%USERPROFILE%\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\6.0.472.63\locales\it.dll MD5=1DA09A162B8A504DD4F2291F66A85444 SIZE=200760
%USERPROFILE%\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\6.0.472.63\gears.dll [Google Inc.] [Google Gears 0.5.33.0] MD5=2D5A948FE6F81F5306BBEF6BE9884AE8 SIZE=3184184
%USERPROFILE%\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\6.0.472.63\gcswf32.dll [Adobe Systems, Inc.] [Shockwave Flash] MD5=F752D010567D66101D41298D2A3E4C00 SIZE=5964752
%PROGRAMFILES%\Windows Live\Messenger\msnmsgr.exe [Microsoft Corporation] [Windows Live Messenger] MD5=AED01B89DD4A0E14B80FCA2CF2850595 SIZE=3883856
%PROGRAMFILES%\Windows Live\Messenger\MSIMG32.dll [Yuna Software] [Messenger Plus! Live] MD5=CAAA913193EA83F60C42CE25A3181F35 SIZE=59800
%PROGRAMFILES%\Messenger Plus! Live\MsgPlusLive.dll [Yuna Software] [Messenger Plus! Live] MD5=0ED65D84CEA118EAECF8E8FB7803C40D SIZE=3624344
%PROGRAMFILES%\Messenger Plus! Live\Detoured.dll MD5=6256684495C499B22DCDBA266E4F2494 SIZE=4096
%PROGRAMFILES%\Messenger Plus! Live\MsgPlusLiveRes.dll [Yuna Software] [Messenger Plus! Live] MD5=8580372AEF2F41C45F3C0293A4EEDD31 SIZE=1867160
%PROGRAMFILES%\Messenger Plus! Live\libsndfile.dll MD5=00742B11F1492D15A0A8FF25E36AB9BE SIZE=370688
%PROGRAMFILES%\Messenger Plus! Live\lame_enc.dll MD5=75430D2F8B2E204814247D62D9445CE4 SIZE=390656
%PROGRAMFILES%\Windows Live\Contacts\wlcomm.exe [Microsoft Corporation] [Windows Live Communications Platform] MD5=654480EA67078C7B4C6C8BA871B07D5D SIZE=27512
%USERPROFILE%\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\6.0.472.63\pdf.dll [Chrome PDF Viewer] MD5=89F4F845A235E210F41289B42DDAAFD9 SIZE=2613816
%USERPROFILE%\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\6.0.472.63\avcodec-52.dll MD5=14C4600CF0C285A2EE601EE860B35314 SIZE=1434680
%USERPROFILE%\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\6.0.472.63\avutil-50.dll MD5=906D6E5EF814AB5CD67EDE0AD0B89AF9 SIZE=91192
%USERPROFILE%\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\6.0.472.63\avformat-52.dll MD5=7954CA95C6D9318976129B5C7A440477 SIZE=193592
deskpan.dll
%PROGRAMFILES%\Windows Live\Mail\mailcomm.dll [Microsoft Corporation] [Windows Live Mail] MD5=021E1FA87DAB47ACE09F900B00074774 SIZE=789824
%PROGRAMFILES%\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe [Microsoft Corporation] [Windows Live® Photo Gallery] MD5=08BABBC59A813C24A4815ECD8DF881DF SIZE=230256
%PROGRAMFILES%\Windows Live\Photo Gallery\PhotoViewerShim.dll [Microsoft Corporation] [Windows Live® Photo Gallery] MD5=E6DF03D0274F72F42DCABB87821F869C SIZE=42856
%PROGRAMFILES%\WINDOWS LIVE\PHOTO GALLERY\WLXPHOTOGALLERY.EXE [Microsoft Corporation] [Raccolta foto di Windows Live®] MD5=2309F17360891BDD8BD7F40274CB7DEF SIZE=138096
%PROGRAMFILES%\Logitech\Video\Namespc2.dll [Logitech Inc.] [Logitech QuickCam] MD5=03937E74DDAB1024705CB9AF34935C19 SIZE=135168
%COMMONFILES%\Autodesk Shared\AcShellEx\AcShellExtension.dll [Autodesk] [AutoCAD] MD5=9F06182191C4D861EADAA5B9726F53D8 SIZE=103016
%COMMONFILES%\Autodesk Shared\Thumbnail\AcThumbnail16.dll [Autodesk, Inc.] [AutoCAD] MD5=8037A66AC428DF35662BF18F85859CFC SIZE=20072
%COMMONFILES%\Autodesk Shared\AcDgnCOM17.dll [Autodesk] [AcDgnCOM Module] MD5=64140741D0295ABE833D6E72A64C2274 SIZE=19560
%PROGRAMFILES%\WIBU-SYSTEMS\System\WibuShellExt.dll [WIBU-SYSTEMS AG] [WIBU-SYSTEMS AG] MD5=3CFD2C31E947E884A2E4CD9E9B228B28 SIZE=532480
%PROGRAMFILES%\Agnitum\Outpost Firewall\acs.exe [Agnitum Ltd.] [Agnitum Outpost Service] MD5=8E294ACAE2B6FB3C75F55913829B359E SIZE=1195008
%SYSDIR%\svchost.exe -k netsvcs
%SYSDIR%\svchost.exe -k bthsvcs
%SYSDIR%\svchost -k DcomLaunch
%SYSDIR%\svchost.exe -k NetworkService
%SYSDIR%\DRIVERS\GEARAspiWDM.sys [GEAR Software Inc.] [CD DVD Filter] MD5=8182FF89C65E4D38B2DE4BB0FB18564E SIZE=26600
%SYSDIR%\svchost.exe -k LocalService
%SYSDIR%\drivers\lvusbsta.sys [Logitech Inc.] [Logitech QuickCam] MD5=90259F3A20FBAEC1A08D74EF5415B9D8 SIZE=22016
%SYSDIR%\drivers\monfilt.sys [Creative Technology Ltd.] [Creative Filter Driver] MD5=9FA7207D1B1ADEAD88AE8EED9CDBBAA5 SIZE=1389056
%SYSDIR%\DRIVERS\ASACPI.sys [ATK0110 ACPI Utility] MD5=D48659BB24C48345D926ECB45C1EBDF5 SIZE=5810
%SYSDIR%\DRIVERS\LV561AV.SYS [Logitech Inc.] [Logitech QuickCam] MD5=6EEB215FABF148B8AC008F134C1F7B9F SIZE=211712
%SYSDIR%\svchost -k rpcss
%SYSDIR%\DRIVERS\Rtenicxp.sys [Realtek Semiconductor Corporation] [Realtek 10/100/1000 NIC Family all in one NDIS Driver] MD5=6E7470477D08F6E47E91016D6A1C5A5F SIZE=120064
%SYSDIR%\drivers\sp_rsdrv2.sys [Crawler.com] [Spyware Terminator] MD5=8831252BCF05FCFB5ABD116A22E552D8 SIZE=142592
%SYSDIR%\svchost.exe -k imgsvc
%SYSDIR%\drivers\viahduaa.sys [VIA Technologies, Inc.] [VIA High Definition Audio Driver] MD5=242A8309B952F7CA9E220D3439955B0E SIZE=1358720
%SYSDIR%\DRIVERS\WibuKey.sys [WIBU-SYSTEMS AG] [WIBU-KEY Software Protection System] MD5=AFCEA7939925378F867DDE6AF76F3924 SIZE=72704
%PROGRAMFILES%\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [Microsoft Corporation] [Windows Live Messenger Protocol Handler Module] MD5=61B0C981F7C10B8861809ADC1B31E8E5 SIZE=61264

End of Report


Risolto grazie!
maopapof
Inviato: Saturday, October 09, 2010 2:49:00 PM

Rank: AiutAmico

Iscritto dal : 10/31/2004
Posts: 7,179
scusa shapiro

in pagina web ..... strumenti .... opzioni internet ..... clik elimina .... escluso il primo in alto metti tutte le spunte e pulisci ..... spegni e riaccendi

start .... pannello di controllo ....opzioni cartella .... visualizzazione .... metti la spunta a visualizza file nascosti e togli la spunta a nascondi file nascosti e protetti ....applica spegni e riaccendi

con spybot .... fai una scansione completa e togli tutto quello che ti dice di togliere .... spegni e riaccendi

e guarda se esiste ancora qualcosa ..... ciao e buon lavoro :O)




7slevin
Inviato: Saturday, October 09, 2010 7:18:59 PM
Rank: AiutAmico

Iscritto dal : 9/29/2010
Posts: 78
2 cose:

1)la spunta devo toglierla anche a "Nascondi i file protetti di sistema"? Il pc mi dice che è fortemente sconsigliato..

2)la scansione devo farla per forza con spybot o posso anche farla con Malwarebytes Anti-Malware?
maopapof
Inviato: Saturday, October 09, 2010 7:51:55 PM

Rank: AiutAmico

Iscritto dal : 10/31/2004
Posts: 7,179
1 SI
2 spybot ..... http://www.aiutamici.com/software?ID=10831 lo aggirni .... poi immunizzi e poi scansiona


7slevin
Inviato: Sunday, October 10, 2010 12:42:45 PM
Rank: AiutAmico

Iscritto dal : 9/29/2010
Posts: 78
ok grazie mille, sembra che non ci sia più nulla Applause

Volevo solo chiederti se devo rimettere la spunta a Nascondi i file protetti di sistema o lo lascio senza spunta.

Infine io per navigare uso Google Chrome e ho visto che l'immunizzazione vale solo per IE e Mozilla. Dunque premettendo che con Chrome mi trovo molto bene posso fare qualcosa o lascio tutto com'è???
maopapof
Inviato: Sunday, October 10, 2010 1:12:43 PM

Rank: AiutAmico

Iscritto dal : 10/31/2004
Posts: 7,179
si rimetti spunta e metti come prima .... ripristina

...... per Infine io per navigare uso Google Chrome e ho visto che l'immunizzazione vale solo per IE e Mozilla. Dunque premettendo che con Chrome mi trovo molto bene posso fare qualcosa o lascio tutto com'è???

su questo ... non ti sòò rispondere ma credo possa essere di interesse per tutti e quindi perchè non fare un nuovo topic ? .... problemi informatici :O)

ti consiglio di prendere il tuo primo post ... ( domanda ) ...schiacciare EDIT .... ed aggiungere al titolo ,,, - RISOLTO - grazie :O)

7slevin
Inviato: Tuesday, October 12, 2010 1:23:27 PM
Rank: AiutAmico

Iscritto dal : 9/29/2010
Posts: 78
il mio pc sembra non avere pace: ieri mi collego a Messenger e mi dice che è stato effettuato l'accesso da un'altra postazione, controllo il nome ed era una postazione a me sconosciuta allora disconnetto l'accesso da quella postazione e i miei amici mi hanno detto che ho mandato dei messaggi automatici in cui dicevo di aprire dei link.
Ho fatto la scansione con Avira ma non risulta niente.

Vi posto il log fi Hijackthis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13.19.07, on 12/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Avira\AntiVir Desktop\avguard.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Programmi\Spyware Terminator\sp_rsser.exe
C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmi\Logitech\Video\LogiTray.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Logitech\Video\FxSvr2.exe
C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Programmi\OpenOffice.org 3\program\soffice.exe
C:\Programmi\OpenOffice.org 3\program\soffice.bin
C:\Programmi\iPod\bin\iPodService.exe
C:\Documents and Settings\Nunzio\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Nunzio\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nunzio\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nunzio\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\programmi antivirus\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programmi\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmi\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmi\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmi\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programmi\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programmi\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Nunzio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programmi\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Programmi\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Programmi\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Programmi\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Anteprima Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Stampa ad alta velocità Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~1\agnitum\outpos~1\wl_hook.dll
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programmi\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 10068 bytes


Anche la scansione con Malwarebytes aggiornato non ha trovato minacce.
cbbusto
Inviato: Tuesday, October 12, 2010 3:01:26 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Il log è pulito, probabile che in Messenger tu abbia cliccato da qualche parte prova a controllare le impostazioni.
Fai una pulita con Ccleaner Registro compreso, nel Registro spunta tutte le voci, poi svuota completamente la cartella Prefetch di Windows. Speak to the hand
maopapof
Inviato: Tuesday, October 12, 2010 5:59:59 PM

Rank: AiutAmico

Iscritto dal : 10/31/2004
Posts: 7,179
in MSN cerca di andare sempre senza essere amministratore .....

adesso per prima cosa cambia la pass di accesso di msn ( SPERANDO CHE TU RIESCA A FARLO :o) e poi fai una scansione online ( tutte e due ) ....

http://security.symantec.com/sscv6/default.asp?productid=globalsites&langid=it&venid=sym

elimina tutto quello che trova SEGUENDO I TRACCIATI CHE TI FORNIRA' ALLA FINE DELLA SCANSIONE E CONTROLLANDO CHE NON VI SIANO PROGRAMMI A TE UTILI .... ciao e buon lavoro :o)


PS ...quando trovi un altro problema , fai sempre un'altro post , in quanto hai più visibilità e può essere utile a tutti ....ciao e grazie :O)



a.roselli
Inviato: Tuesday, October 12, 2010 6:48:18 PM

Rank: Admin

Iscritto dal : 10/4/2000
Posts: 19,044
maopapof ha scritto:
http://security.symantec.com/sscv6/default.asp?productid=globalsites&langid=it&venid=sym

elimina tutto quello che trova ....

La scansione antivirus Symantec non elimina nulla, segnala solo se ci sono problemi.


alfonso_aiutamici@hotmail.it

Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.