Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

virus;trojan ?aiuto!!!!! Opzioni
lecoq51
Inviato: Sunday, December 14, 2008 1:01:56 AM

Rank: Member

Iscritto dal : 7/30/2007
Posts: 23
ho eliminato i due file in rosso, ma pe quanto riguarda la cartella temp, non ho capito se devo cancellare tutta la cartella in quanto dentro ci sono delle sottocartelle e numerosi documenti
r16
Inviato: Sunday, December 14, 2008 1:04:24 AM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
lecoq51 ha scritto:
ho eliminato i due file in rosso, ma pe quanto riguarda la cartella temp, non ho capito se devo cancellare tutta la cartella in quanto dentro ci sono delle sottocartelle e numerosi documenti

Intanto segui i consigli di amvinfe1 . Che sono curioso di vedere se quei file si eliminano.
Poi, devi eliminare TUTTO il contenuto della cartella TEMP (NON LA CARTELLA)
lecoq51
Inviato: Sunday, December 14, 2008 1:13:42 AM

Rank: Member

Iscritto dal : 7/30/2007
Posts: 23
all'attenzione di AMVINFE1 se non ti dispiace ricomincerei con questa operazione domani mattina a mente fresca e con meno confusione in testa.
A proposito: devo disattivare e riattivare subito o la riattivazione va fatta solo alla fine di tutte le operaziomi oppure dove? se puoi darmi qualche ulteriore
delucidazione anche sul resto "dopo il riavvio del computer" (portati in C:\.........)
Grazie per la comprensione e buona notte.
amvinfe1
Inviato: Sunday, December 14, 2008 1:16:57 AM

Rank: Newbie

Iscritto dal : 12/11/2008
Posts: 3
questo file
C:\Documents and Settings\User\Impostazioni locali\Temporary Internet Files\Content.IE5\B76NGMON\sys7132[1].exe
non è altro che SystemScan

la disabilitazione e la riabilitazione del ripristino va fatta in sequenza.

Per C:\ intendo l'hard disk
amvinfe1
Inviato: Sunday, December 14, 2008 10:02:50 AM

Rank: Newbie

Iscritto dal : 12/11/2008
Posts: 3
buon giorno,
una cortesia.
Se l'eliminazione non dovesse andare a buon fine, aspetta a procedere con eliminazioni manuali di altri valori. Ti indicherò altri passaggi per capire cosa blocca i BHO.

Grazie
lecoq51
Inviato: Sunday, December 14, 2008 1:37:07 PM

Rank: Member

Iscritto dal : 7/30/2007
Posts: 23
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\atqgmbcc

*******************

Script file located at: \??\C:\WINDOWS\system32\rsufsbta.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



Could not open file C:\WINDOWS\system32\dinput8t.dll for deletion
Deletion of file C:\WINDOWS\system32\dinput8t.dll failed!

Could not process line:
C:\WINDOWS\system32\dinput8t.dll
Status: 0xc0000022



Could not open file c:\windows\system32\ycqvimj.dll for deletion
Deletion of file c:\windows\system32\ycqvimj.dll failed!

Could not process line:
c:\windows\system32\ycqvimj.dll
Status: 0xc0000022

File C:\sqmnoopt15.sqm deleted successfully.
File C:\sqmdata15.sqm deleted successfully.
File C:\sqmnoopt14.sqm deleted successfully.
File C:\sqmdata14.sqm deleted successfully.
File C:\sqmdata13.sqm deleted successfully.
File C:\sqmnoopt13.sqm deleted successfully.
File C:\sqmnoopt12.sqm deleted successfully.
File C:\sqmdata12.sqm deleted successfully.
File C:\sqmnoopt11.sqm deleted successfully.
File C:\sqmdata11.sqm deleted successfully.
File C:\sqmdata10.sqm deleted successfully.
File C:\sqmnoopt10.sqm deleted successfully.
File C:\sqmnoopt09.sqm deleted successfully.
File C:\sqmdata09.sqm deleted successfully.
File C:\sqmdata08.sqm deleted successfully.
File C:\sqmnoopt08.sqm deleted successfully.
File C:\sqmdata19.sqm deleted successfully.
File C:\sqmnoopt07.sqm deleted successfully.
File C:\sqmdata07.sqm deleted successfully.


Could not open file C:\windows\system32\drivers\utehinhp.sys for deletion
Deletion of file C:\windows\system32\drivers\utehinhp.sys failed!

Could not process line:
C:\windows\system32\drivers\utehinhp.sys
Status: 0xc0000022



Could not open registry key HKEY_LOCAL_MACHINE\system\controlset002\services\utehinhp for deletion
Deletion of registry key HKEY_LOCAL_MACHINE\system\controlset002\services\utehinhp failed!

Could not process line:
HKEY_LOCAL_MACHINE\system\controlset002\services\utehinhp
Status: 0xc0000022



Could not open registry key HKEY_LOCAL_MACHINE\system\controlset003\services\utehinhp for deletion
Deletion of registry key HKEY_LOCAL_MACHINE\system\controlset003\services\utehinhp failed!

Could not process line:
HKEY_LOCAL_MACHINE\system\controlset003\services\utehinhp
Status: 0xc0000022



Could not open registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xzkuhibg for deletion
Deletion of registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xzkuhibg failed!
Status: 0xc0000022



Could not open registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{61B455B1-2A98-45C7-81F3-043BFAD57AFF} for deletion
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{61B455B1-2A98-45C7-81F3-043BFAD57AFF} failed!
Status: 0xc0000022



Could not open registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3984EB67-F783-46F3-885B-FB57400006F1} for deletion
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3984EB67-F783-46F3-885B-FB57400006F1} failed!
Status: 0xc0000022

Program C:\Documents and Settings\User\Impostazioni locali\Temporary Internet Files\Content.IE5\PCIBSOH9\sys5561[1].exe successfully set up to run once on reboot.

Completed script processing.

*******************

Finished! Terminate.

ora faccio la scansione con systemscan.
a piu tardi....
amvinfe1
Inviato: Sunday, December 14, 2008 2:25:37 PM

Rank: Newbie

Iscritto dal : 12/11/2008
Posts: 3
scusa il ritardo.

Apri il blocco note e incolla questo script

Commenta:
@echo off
regedit.exe /e C:\safeb.txt "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot"
regedit.exe /e C:\brow.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings"


Clicca in alto a sx su "File" poi su "Salva con nome", dalla finestra che si apre clicca in corrispondenza di "Salva come:" > seleziona "Tutti i file">nella casella "Nome file" scrivi 1.bat > salva il file sul desktop.

Ora doppio click su 1.bat, non vedari nulla. Portati in C:\ e copia/incolla il contenuto dei file safe.txt e brow.txt

grazie
lecoq51
Inviato: Sunday, December 14, 2008 2:33:55 PM

Rank: Member

Iscritto dal : 7/30/2007
Posts: 23
amvinfe1
Inviato: Sunday, December 14, 2008 2:45:58 PM

Rank: Newbie

Iscritto dal : 12/11/2008
Posts: 3
quello che mi hai postato è il link per scaricare il report di SystemScan.

Devi andare in C:\ ed aprire i due file di testo safeb.txt e brow.txt copiarne il contenuto ed incollarlo nella tua prossima risposta.
lecoq51
Inviato: Sunday, December 14, 2008 3:00:37 PM

Rank: Member

Iscritto dal : 7/30/2007
Posts: 23
salve,
ti ho postato il report poi ho incollato safeb.txt ebrow.txt su 1.bat si vedeva per un attimo una schermata nera.
tutto ok?
ti ringrazio di esserci anche di domenica.siete delle persone "fantastique"come si dice in francia.
Di questi tempi cosa molto rara.
lecoq51
Inviato: Sunday, December 14, 2008 3:09:51 PM

Rank: Member

Iscritto dal : 7/30/2007
Posts: 23
indows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell"="cmd.exe"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
@="Universal Serial Bus controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
@="CD-ROM Drive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
@="Standard floppy disk controller"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
@="PCMCIA Adapters"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
@="SCSIAdapter"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
@="Floppy disk drive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
@="Human Interface Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmadmin]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmboot.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmio.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmload.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmserver]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ip6fw.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NtLmSsp]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpcdd.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpdd.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpwd.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SRService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdpipe.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdtcp.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\termservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WZCSVC]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
@="Universal Serial Bus controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
@="CD-ROM Drive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
@="Standard floppy disk controller"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
@="Net"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
@="NetClient"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
@="NetService"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
@="NetTrans"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
@="PCMCIA Adapters"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
@="SCSIAdapter"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
@="Floppy disk drive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
@="Human Interface Devices"

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings]
"bf"=hex:9d,5d,ea,98,47,f9,a2,50,69,54,4a,1c,17,24,32,da,f3,94,44,53,aa,9e,c8,\
2f,8b,33,ee,db,00,f3,6a,93,5e
"bk"=hex:a5,54,8f,f7,3a,f2,a4,29,09,2a,50,58,56,64,6b,8b,a8,e1,45,22,f6,cf,93,\
1d,d3,01,94,9a,19,a3,36,cf,6e,d7,00,09,bf,4a,66
"iu"=dword:0000000f
"mu"=hex:7b,14,ae,47,e1,7a,84,3f
"vr"=dword:00000015
"cfp"=dword:0000001e
"cf0"=hex:85,12,c6,ab,53,ba,ec,69,4c,3a,24,5e,63,5d,22,d4,a3,93,7b,05,a7,9a,9b,\
6f,c6,77,e0,9e,1f,ba,34,c6,67,df,00,77,83,3d,14,fb,cb,ba,a7,db,e3,dd,a2,0e,\
23,4f,82,fb,3e,4d,09,f0,10,a6,22,4d,c1,65,e2,51,bd,08,db,c2,04,d3,d4,22,56,\
73,62,1f,54,78,69,d1,ff,d3,14,7d,aa,90,88,3c,91,2a,db,a5,4a,a4,3b,97,2a,93,\
46,75,a1,18,08,eb,d3,f4,f2,8d,8f,f9,a5,50,73,2a,fc,eb,7a,4a,4e,ab,0a,b7,6c,\
00,81,79,f2,12,ad,0a,d1,bd,20,d9,83,6b,33,0d,72,5a,53,3f,32,cb,ee,9d,59,20,\
a3,84,c2,3d,8b,20,f8,cc,41,fa,0b,f5,3a,d1,0b,27,fa,43,16,a5,91,a8,fb,9c,9c,\
a4,b2,11,7d,48,9b,82,44,13,11,e2,16,b3,22,5f,94,38,a9,11,aa,03,c5,ae,7e,de,\
c8,7c,51,6a,1b,65,0a,6f,7b,d7,ea,d3,06,35,e1,d8,c8,2b,97,2a,b7,c8,4b,b9,68,\
9a,2a,ea,3c,2b,b7,0a,0e,eb,ca,f7,ac,c0,c1,b9,b2,52,6d,46,86,e6,60,19,43,ab,\
73,cd,32,1e,9e,2a,ee,0b
"cf1"=hex:aa,17,8c,e0,21,d9,8a,6c,5a,6b,38,00,1c,30,4b,b5,fa,96,47,32,a6,83,d2,\
2f,c4,68,f9,96,1a,b9,31,ca,70,d5,06,7a,a0,06,57,a9,b3,8d,f2,de,dc,ea,ae,4b,\
6a,57,cc,a0,61,4e,12,f1,49,f2,78,1d,9e,22,a8,4e,ef,57,bb,c5,6a,86,d5,22,56,\
73,62,1f,54,78,69,8d,af,95,58,3e,ff,c0,88,6e,c8,76,f8,9e,1a,a2,0b,f5,3a,d6,\
02,72,e6,43,12,ef,84,a8,b9,dd,df,e4,e8,0e,29,12,d8,be,77,44,08,ee,4a,f4,5b,\
25,de,62,bb,50,ab,48,d1,e1,7e,df,96,20,4a,75,7d,52,5f,62,60,dc,f6,cc,4b,3b,\
f9,91,97,6b,cb,73,e1,9d,4b,a1,37,99,6b,83,05,77,bc,01,55,fa,87,b2,a0,8b,d6,\
e6,a7,06,7f,10,c7,a9,2c,1b,47,e2,18,ae,31,22,a4,4c,f1,10,ac,0c,eb,c2,04,d3,\
83,73,55,62,6f,52,4e,75,3d,d7,f5,c6,1a,63,b3,ab,d5,30,98,33,a1,ce,5c,f2,5a,\
92,37,84,44,20,fd,58,00,eb,e2,f0,ff,81,8a,b8,b1,4c,42,44,83,fd,3c,12,48,ab,\
08,a2,24,5c,c7,78,e8,23
"cf2"=hex:ac,12,d8,93,7d,c7,9f,7d,51,73,65,0b,4e,23,23,de,ea,ce,1b,6a,bc,d5,86,\
6e,de,7e,e3,9b,17,a3,3f,f2,54,83,53,23,e5,52,1f,a2,9e,a5,ed,87,85,b6,aa,53,\
63,7b,85,e0,28,03,51,be,0c,a2,0a,42,c7,74,f4,10,ad,08,d0,bb,52,c0,8f,71,5a,\
68,61,1c,32,34,33,cd,ec,c2,18,7b,b8,92,d4,2c,97,28,b8,f3,4b,ef,76,93,31,95,\
53,3d,d2,55,14,f0,c9,f4,f3,9d,ce,bf,a3,53,6e,42,84,af,21,15,4c,ba,1d,b3,25,\
73,d5,24,b0,1b,bc,04,87,f8,37,9a,87,2e,07,61,3b,5b,56,31,74,92,fc,96,40,6e,\
e3,c1,c7,6c,9b,76,ef,cd,1a,a5,67,c7,69,9a,6a,6d,ae,06,46,a6,8b,b3,af,db,d7,\
da,cc,5b,7b,4b,9d,ea,37,4a,06,fd,05,af,3d,4e,c2,7b,fb,23,ad,08,d0,bb,79,d6,\
94,7a,62,6a,7f,0c,1c,38,35,d0,f8,d3,2a,78,a7,99,c2,30,89,34,8a,cc,5b,e5,74,\
9a,30,93,40,2a,fc,44,0f,f0,d0,db,f3,97,9e,bb,a9,4d,7b,55,aa,ed,3c,18,51,ac,\
1b,b5,76,47,cb,7b,f6,1a
"cf3"=hex:ac,47,d9,ad,64,d2,85,6b,4d,5b,6d,5c,5c,66,75,8e,ac,94,4e,22,fb,c3,95,\
6b,d3,73,e4,9c,1a,ba,32,cd,6d,d3,1b,7b,bd,05,52,ac,8c,b3,a4,dc,da,e4,f4,42,\
42,05,d6,be,6e,4e,13,eb,47,f3,6f,22,a4,65,e3,11,b8,0e,da,aa,33,97,9d,6c,47,\
74,25,5d,13,0b,27,dc,f2,ce,13,61,ba,d9,c2,33,92,67,ad,dc,57,e4,35,cd,23,bb,\
57,2c,e2,5e,03,f1,ca,a9,ed,9d,8d,aa,e8,5b,72,4b,d6,be,6e,4e,13,eb,47,f3,6f,\
22,a4,65,e3,11,b8,0e,da,aa,33,97,9d,6c,47,74,25,5d,13,0b,2f,cf,e8,91,1b,60,\
be,8d,88,3b,92,2b,f6,d4,5d,ee,75,cc,6c,9a,6a,26,fe,41,50,f2,d1,f7,ec,c1,95,\
a5,a5,42,30,43,9a,e3,6e,46,06,e6,4b,f3,6f,1b,97,1a,8c,0d,bb,09,d0,a6,62,d2,\
db,3f,45,74,6f,1c,5d,65,3b,e3,f7,d7,00,39,a3,98,c8,2e,d0,23,ba,c3,0e,ec,75,\
86,2d,d4,04,32,d2,5e,16,e9,88,ea,f9,81,9f,f9,bd,4d,7d,5a,d8,eb,22,1b,06,ee,\
5e,fe,63,1b,97,23,bf,72
"cf4"=hex:d4,15,d3,a1,68,de,8a,7a,03,27,6d,1c,17,24,75,8d,e3,fb,1f,7f,b8,c1,cb,\
30,8a,22,f8,cb,42,fb,26,84,2d,9e,45,7c,bc,4a,3a,f6,ce,f1,a0,82,81,a3,a3,11,\
65,55,95,f2,60,13,4a,b3,5e,f6,76,16,9b,23,bf,4b,e7,6a,bc,bd,6b,d9,80,76,52,\
62,2b,4f,15,24,3f,cc,ad,95,0b,53,a7,87,d0,69,93,28,a2,df,00,f3,6a,93,7e,9c,\
45,36,fd,04,54,e2,e2,ee,e6,99,d8,ba,a9,4b,6e,09,8d,fd,2d,0a,08,bb,12,ab,76,\
1e,8e,2e,b3,4b,e7,53,8f,c2,04,c5,83,71,58,6e,7a,0a,53,77,3d,cc,e7,d4,45,3d,\
b3,ab,cf,2f,88,71,bb,c0,5e,fc,28,9b,32,8b,16,34,fd,4e,15,ac,8c,fa,ca,86,9e,\
a1,f0,52,71,57,9d,a1,35,05,45,a2,50,a3,3a,43,8e,26,a6,46,eb,53,8f,fb,37,ba,\
ec,6d,5b,69,70,06,02,32,7b,9f,e5,d4,0f,7c,fd,c5,db,03,97,37,a0,99,43,f8,76,\
8c,70,83,5a,23,ae,4c,15,e6,cd,b4,a4,92,b2,be,b6,49,28,4a,99,ff,3d,59,5d,ad,\
1d,ba,78,4b,c2,7b,a6,4e
"cf5"=hex:fe,5e,83,fb,37,83,df,12,34,75,73,01,08,3e,2a,da,a3,87,0d,7c,b7,84,95,\
6d,83,1b,bf,df,58,a1,6b,90,30,94,18,2b,e2,5b,46,e4,cd,fe,e5,dc,dc,aa,9a,56,\
6e,51,c0,e2,21,19,55,f1,05,b5,35,52,80,73,ea,13,fe,56,96,f6,3b,83,df,2b,07,\
0a,1c,1d,0b,39,20,d6,f2,c2,4b,2f,b5,84,df,2c,cd,75,ab,f3,47,e7,70,c9,33,88,\
58,23,a0,53,0a,f3,9e,fc,e5,96,9d,e4,f4,42,42,4e,86,f9,78,1a,49,b1,12,e9,2d,\
5d,cd,6a,a8,1b,b2,0b,96,fe,2e,8e,d3,2b,07,33,2f,62,64,25,23,d1,f8,ce,1a,6a,\
f3,d7,dd,2c,87,34,e5,9d,53,cb,6f,8f,28,d1,5b,20,e0,5b,48,fb,d2,eb,b6,94,9d,\
ae,b5,0c,2c,5a,aa,e6,3e,01,10,b2,11,a9,3a,01,d5,65,e5,02,f0,03,da,a3,2e,86,\
c6,26,0b,33,2f,5b,57,5a,4c,cd,fb,c9,10,66,a2,92,9b,7f,85,37,b0,d2,72,f6,6a,\
8b,3d,8a,52,13,ef,5b,12,fc,d3,e3,a5,dd,c0,b3,aa,53,3e,5c,86,e9,33,2b,47,b3,\
0a,a4,3b,4b,f2,76,ea,0b
"cf6"=hex:bd,0a,d2,fc,3c,99,9d,6d,5d,7a,38,0b,02,3b,66,8e,be,9e,43,3b,f7,c3,9f,\
52,f4,32,a4,92,46,e3,72,8f,64,c8,19,7d,bf,04,48,ae,89,b2,b8,de,d7,e4,e8,0e,\
2b,13,d9,e8,3c,46,1e,f1,0e,af,26,22,a4,70,e4,13,e3,14,93,fd,3e,ba,ec,6f,4c,\
62,70,5e,53,3f,32,cb,ee,9d,59,20,ad,8e,c4,3a,8c,34,a2,dd,41,fb,6a,d1,3d,88,\
5b,60,fc,59,15,b0,dc,aa,e5,8a,8f,a5,a5,57,31,44,db,82,44,05,44,b3,43,b4,73,\
1d,9e,1a,8c,0d,bb,1f,c2,f2,21,ba,ec,6b,4c,73,7f,1b,02,32,77,82,cd,de,05,7b,\
ab,9a,86,32,9b,34,a5,ce,49,f2,27,f2,54,93,44,3b,eb,4f,12,ae,83,d0,f7,9d,80,\
be,a8,58,3f,07,b5,e3,27,14,4d,ff,16,a2,24,4a,8e,71,e9,0d,fe,03,d3,bb,6f,de,\
8a,6c,33,0d,62,1d,1b,25,2a,8e,a3,cf,02,7b,be,cd,89,70,99,28,bb,d6,46,fe,72,\
d1,3d,88,5b,60,c3,5d,27,e5,f0,c3,f1,d2,c1,e5,e9,0d,26,15,c4,a0,2f,0f,1b,ee,\
51,a2,32,12,9f,38,e3,07
"cf7"=hex:e3,56,99,ad,6c,86,d3,30,33,0d,62,1d,1e,36,33,cc,fb,96,4b,3d,c3,fd,d2,\
2d,8e,26,a3,dc,4b,f6,65,ce,63,d2,3b,45,fa,45,12,f6,d3,e2,f9,9a,9a,e6,fb,0e,\
26,17,fb,85,3e,18,56,ee,43,af,22,5b,de,2d,a9,50,b9,08,db,b6,66,de,92,31,5d,\
68,7b,40,23,03,21,c7,d3,e3,1d,32,e1,c5,89,6d,c6,75,e4,80,4b,f3,3b,ce,71,82,\
4e,72,bf,18,0e,a2,8f,b7,b9,9f,9e,e6,f3,10,13,2d,86,e0,3e,07,47,aa,0d,a2,67,\
12,9c,27,8b,75,ae,08,c6,fd,33,df,92,6b,4e,3d,39,40,09,38,2b,c6,f6,ce,02,21,\
ad,98,cb,70,b3,13,bd,9c,63,d3,43,c2,71,d5,19,7d,b6,05,54,b0,df,ff,ab,de,c1,\
b2,a2,02,2f,08,93,f7,73,46,09,af,0e,f6,63,00,a3,1d,f6,10,ae,17,d7,ba,7d,d2,\
d4,22,0c,36,1b,65,35,24,23,d0,b0,c0,19,60,a9,9b,c3,02,f3,4d,a6,ce,49,f2,59,\
8a,2c,8e,0b,38,f9,40,48,f8,d1,e8,f1,83,8b,f9,cb,35,6e,46,91,ea,11,07,54,b2,\
43,e8,25,4a,cf,65,e5,17
"cf8"=hex:e1,6a,bc,a9,61,c5,8b,40,57,69,66,1a,1a,6a,37,b2,94,d2,04,32,ab,98,d4,\
62,99,28,b9,c8,42,f2,3d,9a,31,95,0b,2c,ef,54,0e,fa,84,bc,f3,80,9c,ea,f9,4a,\
73,1a,c7,a9,3a,16,44,e2,45,ca,5c,5a,dc,2a,ef,42,b9,08,d9,a8,62,d2,dd,76,03,\
28,63,1d,02,68,7d,b2,94,fc,05,6a,a1,d9,df,3e,96,28,b9,81,4d,f8,6b,a2,53,ed,\
46,2e,e9,52,39,ea,cc,ee,ab,9c,8b,b6,b4,5c,76,09,8f,ee,26,18,49,d2,74,b7,37,\
48,cb,48,f6,0d,b3,5a,c5,aa,6f,c5,85,77,33,0d,70,00,1c,3a,19,d6,f0,d7,03,7b,\
f3,87,ab,55,8b,35,eb,ca,41,e5,3b,8c,3b,86,44,2c,e6,19,1f,fe,d6,e8,f9,c1,8d,\
b8,ab,04,7b,48,84,b2,3d,12,47,ad,1d,af,79,4c,cf,74,ee,1a,e1,5c,bb,c5,55,c4,\
83,70,10,6a,65,01,33,5a,4c,cf,ff,c0,13,50,bb,85,cf,62,8d,22,b7,dd,4d,ff,28,\
92,2d,89,18,42,84,47,07,f8,db,d8,e6,9d,83,ea,e9,4d,7b,54,83,e3,3a,04,08,be,\
0d,b7,2e,22,a4,71,e9,0d
"cf9"=hex:b3,38,df,a1,7e,c2,92,22,4f,0a,1c,1a,1c,6a,23,d0,ec,9a,58,62,bd,99,88,\
64,9b,28,a4,92,00,fb,6f,89,3b,c9,0d,2a,e1,45,5b,fc,df,e4,fe,8a,c0,b6,b5,4f,\
66,1c,93,e0,3c,4a,08,b2,17,a4,24,40,dd,78,e0,0b,f0,5c,bb,c5,7b,c5,db,76,51,\
75,2b,41,1c,79,2b,cc,f0,89,4d,66,a1,85,9b,79,98,28,a4,c2,13,c6,44,ad,1b,dc,\
3b,45,d5,44,03,f0,90,eb,ff,99,8b,8a,cb,35,6e,46,91,ea,11,02,54,b6,43,b4,33,\
4e,dc,74,ee,51,b2,0e,c0,aa,20,ba,ec,6f,5f,60,73,30,1e,25,2b,82,b1,d5,13,7c,\
bb,9b,d2,2c,d0,26,a5,df,56,9a,0c,99,31,95,5b,10,e7,59,16,ea,ca,ba,e7,e2,e4,\
a2,b4,02,7b,48,84,b2,60,1a,55,b1,50,fc,33,40,dc,2a,a8,13,b7,11,d3,e1,35,d2,\
89,6d,03,64,77,0c,06,32,68,de,ed,d7,0e,34,ab,98,d4,62,d0,2a,bf,cc,5c,f8,75,\
90,38,93,18,74,83,3d,3d,ec,db,e8,b8,8e,81,bb,9b,32,14,57,97,e8,2b,28,53,ad,\
17,fa,37,40,c2,39,e5,10
"cf10"=hex:b3,6a,bc,bf,6f,d0,83,40,4e,75,7b,52,41,24,23,de,ec,c4,1e,30,c3,fd,\
c0,30,8c,2a,89,c6,40,e7,73,8b,63,96,43,2a,fc,4e,6b,95,d7,e9,e6,9a,9a,88,af,\
5b,23,56,83,ea,3c,0e,17,d2,74,b2,24,12,c7,2a,f4,1a,ba,0e,c4,f0,7d,c5,85,24,\
57,3a,41,0a,0c,05,23,cc,eb,cb,02,7c,f5,fa,ac,2a,8c,7a,bf,92,5c,f2,62,96,2c,\
d8,45,3d,ed,0c,0f,a2,f9,e8,f9,88,82,b2,95,73,4c,42,85,fa,22,03,55,e4,73,cd,\
0d,4d,cc,74,a8,1c,b1,49,c3,a4,53,ba,ec,6f,5f,60,73,30,1b,25,2f,82,fc,c5,15,\
21,ad,98,88,2a,95,4a,dc,df,4f,f0,63,a0,2e,95,5b,72,ed,50,0f,b2,dc,ee,f8,c0,\
9d,b2,a7,4d,7d,4f,d9,82,44,11,49,ad,13,98,3f,41,de,62,f2,42,af,6a,bc,a6,60,\
c7,93,6b,61,6e,72,52,1f,5a,4c,ca,ec,9a,13,60,bc,ca,d5,3a,9f,35,b5,c7,15,f2,\
69,8d,63,81,53,2a,ea,55,07,fc,d5,bc,f3,80,9c,ea,b2,50,71,4b,94,ee,3c,4c,2b,\
d5,25,a6,25,01,dd,63,e7,0d
"cf11"=hex:a9,06,c4,aa,53,ba,ec,6f,5f,60,73,30,1b,25,2f,82,f3,de,58,7c,ba,96,\
d4,28,9f,35,b3,81,4d,f8,6b,f2,54,97,57,28,eb,68,16,ed,d3,ba,e5,8a,8f,a5,a5,\
57,13,2d,90,e0,3c,1a,79,b6,10,b7,23,5b,93,66,f4,06,d3,6d,c3,bd,33,d2,89,6d,\
03,74,62,0e,1c,20,27,cd,fb,9c,13,60,bc,ca,d5,3a,9f,35,b5,c7,15,9a,0c,a4,3f,\
85,59,3a,fa,19,05,f0,d3,da,9b,e5,9e,b6,a1,5a,41,52,84,e6,73,04,43,be,0c,a4,\
3e,01,cf,75,e9,0a,aa,6a,bc,bf,6f,d0,83,40,4e,75,7b,52,1a,32,34,d2,ed,aa,7c,\
69,a1,85,cb,00,97,29,a6,da,5a,aa,72,9a,2c,8a,45,42,84,42,14,a2,d7,ba,e2,8a,\
9c,ba,b5,04,7b,1a,90,fa,22,1b,55,ba,1f,b5,35,47,95,1a,8c,24,b3,1e,c1,aa,6c,\
c4,83,7e,4c,64,7e,41,0d,38,2b,e2,93,ad,06,6e,a9,92,f9,2a,8c,2e,eb,81,43,ee,\
71,9a,3c,94,53,2e,fc,54,0e,b1,b3,8d,e6,8e,89,b2,99,4f,6c,4a,cb,fc,2b,16,54,\
bc,16,a1,39,5d,a3,1d,e0,10
"cf12"=hex:ac,0a,e9,a6,60,c7,93,6b,03,74,73,0e,1c,34,2e,d9,f1,d5,7b,05,bb,85,\
9b,36,c3,35,b3,cb,47,e5,63,9c,2a,dc,5f,72,ef,54,12,f6,d1,e9,ab,9f,87,b4,ad,\
04,13,2d,ad,fc,2f,07,49,f1,0e,b3,0b,22,a4,67,e7,18,bb,38,c3,bd,67,8a,c8,6c,\
5f,77,79,41,1e,23,4b,b5,ee,c6,11,6a,91,87,d4,32,c3,25,b7,dd,5c,f6,3b,f2,54,\
81,59,3d,e3,68,0f,f1,ce,f2,e2,d2,9f,da,cc,56,70,57,83,fb,11,1e,42,e2,17,a3,\
09,5e,a3,1d,f3,0d,e3,02,8b,bc,6f,c7,89,31,4e,73,2d,62,64,0c,29,c9,fb,d5,02,\
7a,bc,92,88,3c,91,2a,8b,a2,24,e7,67,98,3b,b8,43,3d,e7,0a,48,f0,c8,e2,e4,9b,\
9b,a5,a3,11,7d,48,9b,82,44,07,47,b8,1b,98,26,5d,c3,2a,cd,1a,a7,10,d9,bd,6a,\
c4,eb,15,58,68,64,02,31,3e,28,cf,eb,d3,4b,44,ab,8e,d1,30,8c,23,a5,a2,24,e2,\
74,c2,37,da,19,3c,fc,18,5d,f6,83,e6,e4,88,9d,ea,fd,32,14,7c,97,e3,3a,16,50,\
b6,0d,b3,37,01,cd,78,eb,22
"cf13"=hex:d3,6d,c6,ae,69,d2,b9,6a,4c,6e,2b,41,0f,3b,32,de,e8,ce,05,7b,af,d9,\
ab,55,8e,26,b1,ca,71,e7,74,92,63,95,53,3c,fb,5b,12,ec,b3,8d,f0,80,9c,ba,99,\
56,70,57,83,fb,73,06,2b,d5,0b,b5,6b,4a,c1,65,bb,55,f4,0f,c2,bb,7e,92,d5,5e,\
11,28,61,18,19,79,27,d3,ea,c6,00,66,bd,83,c7,71,c5,22,b9,dd,13,bd,2c,97,2a,\
93,46,6a,bd,76,49,b0,df,e9,e5,98,8b,a5,b5,11,67,46,9e,e0,21,59,1d,d2,74,b2,\
24,12,cb,78,f4,42,f4,4d,de,bb,7a,c7,dc,30,11,70,61,18,40,36,2a,cb,ff,d1,1f,\
7c,ba,96,88,64,9b,28,a4,92,04,bd,6e,8b,2a,97,0c,60,a1,56,08,ec,c9,e2,e4,9c,\
c0,ae,a7,57,71,48,d8,b4,43,7d,7d,bb,1b,e9,37,5c,c5,39,e5,10,b3,3a,bb,c5,7e,\
d6,81,7a,61,72,64,06,53,33,23,91,ff,d4,1d,21,c3,fd,d6,3e,99,22,89,df,5c,fa,\
3b,8e,63,ea,3c,29,e1,45,0b,c0,d7,e9,e6,9a,9a,ea,b7,32,14,52,84,b2,2b,4a,42,\
ba,50,a6,25,44,80,74,e9,12
"cf14"=hex:e5,6a,bc,94,6a,da,89,65,10,68,64,08,33,5a,4c,cf,ff,c0,13,50,bb,85,\
cf,62,8d,22,b7,dd,4d,ff,28,9b,33,88,4c,61,e1,45,01,92,b4,f7,f7,88,8b,88,b6,\
4d,73,1a,85,ea,2f,05,45,b7,73,cd,30,40,dc,7a,d9,16,b0,17,c3,bb,33,c4,83,7e,\
4c,64,7e,62,64,22,34,82,fb,9a,12,6a,e0,96,d5,34,d0,24,b9,c2,15,9a,0c,a4,33,\
94,58,61,e8,58,1e,ec,ce,e8,e4,9b,9d,f9,a5,50,73,7a,fb,85,3e,16,41,ba,21,b2,\
24,46,93,7a,f5,11,f0,01,d9,b7,7d,c7,89,6d,4a,74,38,0c,01,3a,4b,b5,ee,c6,11,\
6a,91,87,d4,32,c3,34,b3,ce,5c,f4,6e,f2,54,81,59,3d,e3,68,0f,f1,ce,f2,e2,d2,\
9d,a7,eb,4e,13,2d,83,fd,73,1e,1b,ac,0a,a8,24,56,95,1a,8c,24,bf,15,df,ae,60,\
d9,87,31,52,6e,74,0a,1c,38,68,d6,ea,fa,7b,05,be,96,c1,3a,a1,32,a4,c6,13,f6,\
74,96,3f,89,58,2e,a0,5b,0f,fd,db,f5,f9,c1,87,a3,cb,35,6e,46,91,ea,11,07,54,\
b2,43,b4,33,4e,dc,74,ee,72
"cf15"=hex:d4,01,d9,bd,63,e8,8f,71,4e,72,62,52,1f,22,23,cd,e7,aa,7c,7a,bc,ca,\
c3,62,9f,35,bf,ce,40,f9,67,d1,32,8e,54,2a,fc,58,5d,92,b4,dc,e5,8a,8f,a5,a5,\
57,30,46,9a,e6,2d,12,08,b6,0a,9a,5b,25,de,76,e1,1a,81,12,c4,a6,33,c4,83,7e,\
4c,64,7e,41,0f,3b,2f,dc,fb,89,1f,7b,c3,fd,d6,3e,99,22,89,df,5c,fa,3b,8c,3b,\
86,44,2c,e6,3a,6c,f9,d1,f5,fb,b0,87,b9,b6,4a,6a,1a,87,fc,43,7d,53,ad,43,a2,\
6b,4e,c2,7e,e5,1a,f0,0e,c2,f4,03,bd,bd,7a,5f,75,62,07,02,3e,28,d4,b0,c9,13,\
7b,93,fa,ac,2f,9f,20,b3,f0,5b,e5,6f,c2,3b,86,44,3b,e6,5b,0f,f1,d5,a9,f8,8a,\
9a,da,cc,4f,7f,40,93,d0,3e,05,4b,e2,0d,a2,37,5d,cd,7f,8b,75,b8,08,c4,a2,51,\
de,88,6f,4b,73,2b,1e,63,5d,33,cd,a3,c2,4b,6a,af,85,d2,37,92,2e,b8,c4,00,f9,\
63,8b,65,ea,3c,14,f9,40,11,b1,d2,e6,e5,9b,c0,b1,ab,62,13,2d,86,ee,29,12,79,\
aa,0c,ae,6b,43,cf,64,f2,51
"cf16"=hex:b8,0a,bb,c5,7e,d6,81,7a,61,77,64,02,53,26,4b,b5,f8,c8,04,62,91,9e,\
c8,2f,8b,33,eb,de,23,9d,73,8d,63,82,59,3d,b3,56,14,eb,d7,f4,e2,d4,8b,b8,b4,\
02,7f,45,99,fa,3a,4c,43,b0,0c,fa,1a,40,c9,37,ef,11,e5,02,d9,bd,33,d6,84,70,\
4b,73,2d,0a,01,25,7b,d7,fb,cb,06,34,ab,98,d4,62,9d,2f,b7,dd,5a,e4,3d,9a,31,\
95,0b,29,e1,45,13,f2,85,e2,f9,9d,d3,b3,a9,48,70,4b,99,ee,2a,4c,43,b0,0c,fa,\
25,5f,cf,79,bd,72,d4,3c,d8,aa,7a,c4,85,7e,4e,62,38,0c,01,3a,1b,b2,94,d7,17,\
68,ab,a8,d3,2d,97,7a,b8,ca,5a,e4,65,9e,2e,82,18,2c,e1,5a,6b,95,ce,e6,f1,8a,\
b1,a7,b4,52,23,54,93,ee,3c,14,4e,d2,74,a1,39,5d,c3,48,ef,11,ae,12,c2,f2,7f,\
c2,83,6d,47,0a,1c,06,00,27,33,cb,c1,ce,12,32,bf,82,c3,2d,87,76,db,a5,5b,e5,\
3b,96,63,95,53,2b,e7,45,5d,f6,83,d0,f3,8d,bc,b2,b5,4a,72,53,85,b4,43,7d,7d,\
ba,06,a4,3f,5b,cb,39,e5,10
"cf17"=hex:b3,3a,bb,c5,7e,d6,81,7a,61,72,64,06,53,32,3e,dc,f7,d3,13,21,ad,98,\
cb,52,f4,37,b7,c8,4b,c8,76,8d,33,da,45,2a,ef,45,05,f7,b3,8d,f0,80,9c,ba,99,\
56,70,57,83,fb,73,06,4d,a8,73,cd,23,5d,93,7e,bb,1c,b2,0e,d5,a4,67,c3,dd,12,\
34,5c,64,0e,03,35,2a,da,ec,89,04,7a,93,fa,ac,2f,9f,20,b3,f0,5b,e5,6f,c2,2c,\
86,5b,2d,e2,52,14,b1,cc,f2,9b,e5,9e,b6,a1,5a,41,57,84,e2,73,04,54,bc,16,ca,\
5c,49,c1,65,eb,20,b7,09,c6,ba,7a,8a,91,70,4c,63,65,62,64,22,34,82,fb,c8,04,\
32,bc,96,cb,3d,92,22,a4,94,23,9d,73,8d,63,8e,0b,20,f9,59,03,ed,e1,ee,f2,d4,\
e3,dd,9d,46,7f,09,84,fa,13,7a,2c,af,1f,a0,33,70,db,65,ef,42,a7,06,98,bd,7b,\
ba,ec,6f,5f,60,73,30,1e,25,2b,82,ed,c2,17,7d,ad,9f,ab,55,98,28,a4,c2,71,fe,\
68,8f,2b,93,0b,3b,eb,4f,12,92,b4,f2,e4,d2,8b,b8,b4,02,67,46,98,eb,2b,0f,1d,\
d2,74,b2,24,12,c7,2a,e5,10
"cf18"=hex:ab,09,c2,f4,03,bd,bd,66,5f,69,72,0a,16,79,34,ca,c3,aa,7c,7f,af,90,\
c3,00,8b,35,bf,92,57,f6,68,9b,3b,9f,18,3d,fb,3a,6c,ef,df,e0,f3,b0,9e,a5,ab,\
02,6d,42,97,fd,2d,1f,2b,d5,18,a8,24,42,f1,7e,e8,0f,ab,13,8b,bb,6b,cf,92,12,\
34,72,64,52,0b,38,34,82,e7,c6,18,6b,ab,8f,9d,52,f4,32,a4,92,47,aa,65,90,2b,\
89,42,74,83,3d,3d,f2,df,ee,fa,c1,9c,a2,9b,32,14,57,97,e8,2b,28,53,ad,17,fa,\
3b,4e,c7,7b,a8,0d,ab,6a,bc,bf,6f,d0,83,40,4e,75,7b,52,1d,32,27,cd,fd,cf,7b,\
05,a8,98,d4,32,a1,2e,b8,df,5b,e3,3b,8e,53,ed,43,3d,b3,5e,5b,fc,d2,ee,f5,84,\
d1,a2,b4,53,25,4e,cb,fb,27,03,4a,ba,73,cd,23,5d,93,7e,bb,1c,b1,12,d8,bb,35,\
ba,ec,44,53,74,78,41,0d,38,68,ca,f5,fa,7b,05,be,96,c1,3a,a1,32,a4,c6,13,fa,\
75,91,70,84,59,61,fb,5c,6b,95,ce,e6,f1,8a,b1,a7,b4,52,23,55,93,fc,3b,1b,52,\
ac,73,cd,30,40,dc,7a,d9,16
"cf19"=hex:b0,17,c3,bb,33,c6,eb,15,4b,75,2b,0a,01,25,7b,dc,ff,c4,1e,6a,f5,92,\
c9,2d,c3,35,b3,dc,5b,fb,72,8c,70,86,45,3f,f6,0c,03,f0,cc,ba,fa,86,98,b2,e8,\
5c,71,4a,d9,b4,43,7d,7d,be,0a,b3,78,41,cb,63,db,72,d4,17,d7,a8,6b,e8,93,6d,\
57,3a,77,1b,1a,79,28,da,ea,aa,7c,7f,af,90,c3,00,8e,35,bb,92,5d,f2,67,8d,3d,\
8f,3b,45,e8,58,14,f2,e1,ee,f8,9f,9b,a3,fb,4c,6a,55,9f,e1,29,7a,2c,aa,0c,fa,\
33,40,dc,2a,e7,0b,aa,49,d8,aa,7a,8c,83,70,4c,3a,75,0e,0d,3f,23,db,a5,aa,7c,\
7a,bc,ca,cf,62,8c,22,b2,c6,5c,f2,65,8b,2b,95,5a,72,b5,3a,6c,c4,cd,e2,f7,9d,\
8d,bf,e8,5c,71,4a,ab,82,44,07,47,b8,1b,98,23,5d,c7,2a,a8,0c,bb,06,c4,ac,66,\
99,85,70,53,0a,1c,1f,0f,30,23,e0,ee,d5,1b,32,bd,92,c7,2d,9d,2f,db,a5,48,f8,\
74,92,01,8e,58,3f,fb,43,5b,ee,b3,8d,e3,9d,d3,be,fb,10,7d,4b,9f,ec,25,7a,2c,\
84,1f,ab,3a,5b,c6,72,f1,1a
"cf20"=hex:bc,49,d5,a0,63,ea,eb,15,4e,66,71,0a,31,22,34,d6,a3,c6,1a,63,ba,9f,\
c3,28,9b,25,f8,cc,41,fa,0b,f5,2e,86,51,2a,d1,47,14,f2,83,f4,f3,8e,9c,b4,ae,\
32,14,41,99,fd,23,28,4f,b1,0e,b2,22,12,df,1a,8c,0a,ac,5a,d3,f2,6f,db,8a,6b,\
56,62,61,0a,0c,79,25,d0,f3,9c,7b,05,bb,85,9b,36,c3,24,b7,db,13,e0,63,9d,65,\
ea,3c,14,fa,5e,15,fc,df,eb,ff,c1,8d,b8,e8,4a,75,7a,fb,85,3e,16,41,ba,21,b2,\
24,46,93,63,ef,0c,bd,06,da,a6,20,d4,89,31,4b,6c,1b,65,1e,36,21,da,c1,d7,04,\
62,f3,85,c3,2c,8b,2b,a2,dc,23,9d,60,90,2c,8a,69,26,e0,47,13,eb,83,f6,e3,8a,\
9c,ae,cb,35,6b,55,cb,ea,73,03,4f,ac,1d,a6,3a,46,80,74,e9,44,d3,6d,ed,a9,67,\
d9,82,7e,4c,73,7f,0c,02,32,35,91,fd,c8,1b,52,c3,fd,d6,3e,99,22,89,da,5c,fe,\
3b,99,37,89,52,2e,fc,43,0f,fc,d2,e2,e5,c1,8d,b8,ab,32,14,57,97,e8,2b,28,56,\
ad,13,fa,25,4a,cf,65,e5,17
"cf21"=hex:d3,6d,d0,a0,7c,da,b9,76,50,77,63,1b,53,26,32,b2,94,d2,04,32,a7,ca,\
89,3e,97,18,b8,94,47,aa,67,8d,2a,8e,55,23,eb,44,5d,92,b4,dc,f3,81,87,a5,a9,\
11,6d,42,ab,82,44,07,47,b8,1b,98,23,5d,c7,2a,e3,11,b7,15,d9,e1,7d,d2,eb,15,\
4e,66,71,0a,31,27,34,d2,a3,d6,03,6a,bc,8e,ab,55,98,28,a4,c2,71,fe,68,8f,2b,\
93,0b,3c,eb,56,14,fc,d6,d8,e1,80,9c,b3,cb,35,6b,55,cb,ea,73,12,48,b6,0c,a8,\
78,5c,cb,2c,8b,75,85,04,da,ba,6c,9a,8f,71,4a,62,64,01,0b,23,68,d9,ec,fa,7b,\
05,be,96,c1,3a,a1,32,a4,c6,13,f9,63,8a,38,c9,50,3d,83,3d,16,fe,d9,e2,c9,9f,\
9c,ba,fb,4c,7b,46,84,ec,26,7a,2c,b9,11,b5,3b,70,c7,79,f6,0a,aa,5a,c7,ba,6b,\
c5,9f,12,34,72,64,52,0b,6a,28,da,eb,c1,58,69,bc,cc,ab,55,a5,2b,af,cc,41,e4,\
28,9c,31,c9,43,24,d3,3a,6c,ef,df,e0,f3,b0,9b,a5,af,02,6d,42,97,fd,2d,1f,08,\
b3,07,a4,39,5c,80,74,e9,51
"cf22"=hex:ab,0c,bb,c5,7e,d6,81,7a,61,77,64,02,53,26,33,da,ec,de,7b,05,a8,98,\
d4,32,a1,2e,b8,df,5b,e3,3b,8e,2b,82,44,36,83,3d,13,ed,83,e2,ab,83,97,b4,a9,\
4c,25,2a,fc,d4,2a,18,41,af,17,ab,33,01,cd,78,eb,22,d3,6d,c6,ae,69,d2,b9,6a,\
4c,6e,2b,0b,01,30,36,d6,f2,c2,58,6c,a1,9a,ab,55,8e,26,b1,ca,71,e7,74,92,63,\
95,53,3c,fb,5b,12,ec,b3,8d,f0,80,9c,ba,99,56,70,57,83,fb,73,1e,45,ba,2e,a6,\
31,4a,a3,1d,f3,0d,e3,0e,8b,ac,62,de,85,74,4d,62,64,19,0b,25,7d,b2,94,fc,05,\
67,af,80,88,3c,9f,1a,db,a5,5e,f6,61,9a,01,92,44,26,b3,44,0e,fe,c9,a9,f5,8e,\
e3,dd,b6,5e,79,42,a9,ff,3c,1a,1b,8d,1b,b4,23,43,da,64,8b,75,b8,08,c4,a2,51,\
de,88,6f,4b,73,2b,1e,63,5d,33,cd,a3,ce,19,7d,f3,85,c2,30,90,2b,af,dd,4b,e4,\
3d,96,31,95,0b,0c,fb,44,12,f0,d3,e2,e4,ac,8f,a5,a3,04,77,48,84,b2,1e,05,49,\
bb,0b,a4,22,5c,fd,72,f4,09
"cf23"=hex:b7,04,d3,bc,35,de,89,6d,13,71,79,0b,55,3e,29,cd,a3,e4,03,7c,ba,98,\
cb,3a,8c,4a,dc,f4,4c,fb,73,9a,29,8e,58,61,ed,5f,3b,92,b4,f7,f7,88,8b,88,b3,\
4d,77,1a,94,e3,3b,12,51,b6,10,e9,35,47,a3,1d,f6,1e,b9,02,e9,bf,7c,da,db,6c,\
5b,66,64,0c,06,5a,4c,d9,f1,d5,1b,50,a7,99,d6,2a,8a,7a,a7,da,4b,e5,7f,f2,54,\
92,44,72,eb,0a,04,f3,cb,e2,e1,86,80,f9,a5,57,25,2a,fc,d4,22,0e,45,b0,0d,e9,\
35,40,c3,4a,8b,75,ae,06,d1,aa,51,c2,94,76,03,74,73,0e,1c,34,2e,91,f2,de,15,\
60,bd,fa,ac,2f,9f,20,b3,f0,5e,e5,6b,c2,2f,92,53,3d,f7,3a,6c,f9,d1,f5,fb,b0,\
87,b9,b6,4a,6a,1a,87,fa,2b,05,5f,d2,74,b2,24,12,c7,2a,f2,12,ad,1e,d8,e1,79,\
d4,c8,7e,4d,6c,38,0c,01,3a,7d,b2,94,c9,1a,60,a8,91,9b,6e,f3,4d,8d,c6,59,f8,\
68,d1,3d,88,5b,6f,a1,17,07,ec,d5,a9,f5,80,83,8a,cb,35,6e,46,91,ea,11,02,54,\
b6,43,a6,25,44,80,74,e9,12
"tc"=hex:e0,04,2f,a1,b2,6d,e3,40
"im"=hex:ae,07,60,e7,f3,12,d9,07,df,3e,a0,af,32
"dk"=dword:00000004
"cf24"=hex:d3,6d,c6,ae,69,d2,b9,6f,4c,6a,2b,50,1f,6a,4b,b5,f8,c8,04,62,91,9e,\
c8,2f,8b,33,eb,de,23,9d,73,8d,63,82,0b,2e,fd,5c,48,fc,d1,ea,ad,e2,e4,a2,b4,\
02,77,1a,d0,fe,73,4c,4f,e2,51,b5,69,5b,93,2c,ef,42,bf,14,dd,e1,6d,d8,8b,24,\
33,0d,78,03,01,31,20,82,af,aa,7c,54,a3,92,cf,31,9b,34,a2,ce,4a,e3,28,9b,3b,\
ba,3b,45,fe,56,01,fa,e1,f2,e4,86,d3,ba,a3,56,70,42,85,fb,2f,13,52,f1,1a,a2,\
5b,25,de,76,e1,1a,81,17,c4,a2,33,c4,93,7c,56,62,1b,65,08,38,34,d2,c1,ce,18,\
7f,bb,83,9b,28,91,35,b2,dc,23,9d,73,8d,63,82,0b,22,eb,5e,08,fa,cd,f3,f7,8b,\
9a,f9,a2,5a,25,2a,fc,d4,2f,18,4a,f1,1d,a8,78,5a,c5,4a,8b,75,ae,06,d1,aa,51,\
c2,94,76,03,66,79,03,40,34,29,91,eb,cc,7b,05,be,96,c1,3a,a1,37,a4,c2,13,e6,\
73,9a,2c,9e,3b,45,e8,58,14,f2,e1,ee,f8,9f,9b,a3,fb,4e,6b,42,84,f6,43,7d,53,\
ad,43,ae,6b,4c,c2,7e,e5,14
"tbi1"=hex:fe,41,86,a2,b2,6d,e3,40
"ctpp1"=hex:33,9f,86,a2,b2,6d,e3,40
"tbic1"=hex:9a,99,99,99,99,99,b9,3f
"ctpp2"=hex:65,87,a9,db,b2,6d,e3,40
"rssr"=hex:8d,5d,c9,b0,7d,57,e3,40
"cst"=dword:00000002
"tstarb"=dword:000d7b4b
"cf25"=hex:bb,03,ff,bb,6b,da,b4,7e,50,0a,1c,34,03,2e,35,da,ff,d5,15,67,e0,94,\
c9,32,a3,4a,dc,df,4f,f0,63,a0,2b,95,5f,72,e3,4e,15,fa,df,f5,f5,87,c0,b4,a9,\
52,13,2d,86,ee,29,12,79,af,0c,aa,6b,5c,cb,76,f4,1c,b6,01,d9,bd,03,bd,80,70,\
4c,6a,49,06,00,27,33,cb,a3,d4,13,6e,bc,94,ce,39,91,35,db,a5,5b,e5,3b,96,63,\
86,55,3b,e7,58,08,a2,ce,ee,f5,84,e3,dd,9d,52,7f,4a,9b,ee,60,14,49,b2,23,ca,\
5c,5f,cf,70,e3,20,ab,15,df,f2,63,d6,8b,72,5f,29,75,00,03,5a,4c,cf,ff,c0,13,\
50,be,85,cb,62,8f,32,b3,dd,57,9a,0c,99,31,95,5b,10,e7,59,16,ea,ca,ba,e5,8a,\
8f,a5,a5,57,78,48,84,82,44,02,54,e2,17,fa,3f,4b,93,5a,d4,72,d4,3c,dd,ae,7a,\
d6,91,7a,5c,29,7f,1b,33,5a,4c,cf,ff,c0,13,50,bb,85,cf,62,95,26,a2,ce,59,f2,\
64,d1,37,93,3b,45,fe,56,01,fa,e1,f7,e4,82,d3,a5,a3,4c,6b,4b,82,82,44,11,49,\
ad,13,98,3f,41,de,62,f2,42
"cf26"=hex:af,6a,bc,ba,7c,8a,83,22,55,66,62,0e,19,32,24,91,f7,d3,7b,05,95,9e,\
c8,39,91,34,a6,ce,4d,f2,28,9c,31,8a,6b,42,84,47,07,f8,db,d8,e3,9d,87,ea,af,\
51,78,48,85,ff,2f,14,43,f1,1d,a8,3b,22,a4,67,e7,18,bb,38,c6,bd,63,8a,83,6c,\
4b,6b,62,1c,63,5d,20,d0,ec,ca,29,66,a0,87,d3,2b,c3,36,be,de,40,9a,0c,8a,2c,\
da,5f,72,ed,5b,0f,fc,d5,f4,9b,e5,b5,bd,b3,5d,77,4e,d8,eb,25,2a,2b,d5,0e,a6,\
31,4a,f1,62,f4,16,e3,0d,c3,ad,67,de,c8,7b,55,0a,1c,1f,0f,30,23,e0,ee,d5,1b,\
32,bf,82,c3,2d,87,4a,dc,c9,41,e5,6b,a0,37,89,46,3a,fa,0a,17,ea,db,f5,ef,e2,\
e4,a2,b4,02,77,1a,9a,e6,20,1c,2b,d5,25,ab,39,40,c5,64,eb,1e,ac,13,98,ac,61,\
da,bb,12,34,77,77,08,0b,08,33,cd,f7,9a,1a,60,a1,9c,d5,32,9f,35,a2,81,4d,f8,\
6b,f2,54,97,57,28,eb,68,16,ed,d3,ba,e4,8a,9d,a2,aa,4b,6d,2a,fc,e9,21,05,4b,\
80,17,a9,26,5a,da,2a,f7,0b
"cf27"=hex:d3,6d,c3,bd,33,de,db,6d,10,6b,79,00,05,24,2b,de,ec,d3,7b,05,95,84,\
d3,3c,96,22,b7,c0,42,b9,67,90,32,c9,52,2a,d3,3a,6c,ef,df,e0,f3,b0,9b,a5,af,\
02,7f,48,9a,fc,38,14,08,bb,1b,ca,5c,5f,cf,70,e3,20,ae,15,db,f2,7d,d2,87,6d,\
5d,6f,1b,65,08,38,34,d2,c1,ce,18,7f,bb,83,9b,2e,f3,4d,a3,dd,13,f2,3b,9e,31,\
8b,45,39,ed,19,02,fa,b3,8d,cd,83,81,b4,a7,53,30,44,99,e2,13,7a,2c,af,1f,a0,\
33,70,db,65,ef,42,b2,08,d5,ae,62,99,85,70,53,0a,1c,1f,0f,30,23,e0,ee,d5,1b,\
32,bc,92,d5,2a,92,33,a5,a2,24,f1,69,8d,33,b8,5f,21,fe,42,12,a2,d5,e2,ef,98,\
81,a5,a2,32,14,52,84,b2,27,4a,45,b3,17,a4,3d,22,a4,4c,e4,0d,b7,13,d7,a1,60,\
de,85,7e,10,64,79,02,33,5a,4c,cf,ff,c0,13,50,bb,85,cf,62,9c,35,bf,db,4f,f9,\
68,96,3d,86,18,2c,e1,5a,6b,95,ce,e6,f1,8a,b1,a7,b4,52,23,56,83,ea,3c,0e,2b,\
d5,18,a8,24,42,f1,7e,e8,0f
"cf28"=hex:ab,13,8b,be,7b,d2,94,66,33,0d,63,1d,53,3e,7b,90,ff,d5,02,66,ad,9b,\
c3,72,f3,4d,8d,dc,42,fe,28,8c,27,8a,46,2e,fa,5e,05,f0,90,e4,f7,b2,e3,dd,b6,\
5e,79,42,a9,fa,3c,1e,1b,ac,12,ae,78,5c,d7,7a,f6,1e,aa,0e,d5,a0,20,d4,87,12,\
34,77,77,08,0b,08,36,cd,f3,9a,05,6a,af,85,c5,37,f3,4d,b0,c0,5c,fa,59,96,30,\
97,43,3b,b3,46,13,fa,cc,fe,9b,e5,9b,a5,fb,5a,23,42,94,ee,37,4c,43,e2,0d,be,\
3b,5f,cf,63,ef,1c,b1,49,d5,ae,03,bd,bd,7d,52,6e,78,08,01,79,25,d0,f3,fa,7b,\
05,be,96,c1,3a,a1,32,a4,c6,13,f5,6a,96,30,80,59,61,ed,58,0b,92,b4,f7,f7,88,\
8b,88,b6,4d,73,1a,85,ea,2f,05,45,b7,73,cd,30,40,dc,7a,d9,16,b0,17,c3,bb,33,\
c6,eb,15,4b,75,2b,0a,53,35,2a,d6,f0,c0,19,21,ad,98,cb,64,f3,4d,8d,dc,4b,f6,\
74,9c,36,c9,55,27,d3,3a,6c,ef,df,e0,f3,b0,9b,a5,af,02,6d,42,97,fd,2d,1f,08,\
bc,16,ca,5c,5f,cf,70,e3,20
"cf29"=hex:ae,15,db,f2,7f,8a,eb,15,58,68,64,02,31,3e,28,cf,eb,d3,4b,7e,c3,fd,\
d3,2d,c3,22,eb,dc,4b,f6,74,9c,36,c9,55,27,83,3d,3d,ed,db,e4,fe,8a,9c,b4,ae,\
5a,30,46,99,e3,60,11,54,82,73,cd,26,4e,c9,72,d9,0a,ac,0e,8b,bd,6b,d4,8e,7a,\
4c,64,7e,0a,40,36,29,d3,b0,c1,04,02,c4,87,c7,38,9b,18,a6,dd,43,aa,77,8a,3b,\
95,4f,42,84,51,09,ed,d3,d8,ff,81,9e,a2,b2,02,6f,52,93,fd,37,7a,2c,aa,0c,fa,\
3f,40,dc,2a,f5,0f,b1,09,c5,a0,7c,d2,82,24,57,68,64,52,19,32,24,cc,fb,c6,04,\
6c,a6,cc,ab,55,a5,22,b8,cb,73,9a,0c

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\volk]
"twac"=hex:df,12,6c,94,bd,69,e3,40


amvinfe1
Inviato: Sunday, December 14, 2008 3:25:25 PM

Rank: Newbie

Iscritto dal : 12/11/2008
Posts: 3
ok, dovremmo esserci.

Apri il blocco note ed incollaci questo script:

Commenta:

KillAll::
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings]
"bf"=-
"bk"=-
"iu"=-
"mu"=-
"vr"=-
"tc"=-
"im"=-
"dk"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\volk]

[-HKEY_LOCAL_MACHINE\system\controlset002\services\utehinhp]

[-HKEY_LOCAL_MACHINE\system\controlset003\services\utehinhp]

[-HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xzkuhibg]

[-HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{61B455B1-2A98-45C7-81F3-043BFAD57AFF}]

[-HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3984EB67-F783-46F3-885B-FB57400006F1}]

Driver::
utehinhp.sys

File::
c:\windows\system32\drivers\utehinhp.sys
C:\WINDOWS\system32\dinput8t.dll
c:\windows\system32\ycqvimj.dll



salvalo sul desktop con nome CFScript.txt .

Ora dovresti già averesul desktop, come ho letto, ComboFix.

Chiudi Kaspersky e la connessione internet (è importante).

Trascina il file CFScript.txt sull'icona di ComboFix. Durante questa operazione non fare nulla.
Quando avrà finito, se non si riavvia, riavvialo tu manualmente.
Postami il log di ComboFix.

lecoq51
Inviato: Sunday, December 14, 2008 4:49:39 PM

Rank: Member

Iscritto dal : 7/30/2007
Posts: 23
ComboFix 08-12-13.03 - User 2008-12-14 16.37.58.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1040.18.2047.1606 [GMT 1:00]
Eseguito da: c:\documents and settings\User\Desktop\ComboFix123.exe
Interruttori di comando utilizzati :: c:\documents and settings\User\Desktop\CFScript.txt
* Creato nuovo punto di ripristino

ATENÇÃO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!

FILE ::
c:\windows\system32\dinput8t.dll
c:\windows\system32\drivers\utehinhp.sys
c:\windows\system32\ycqvimj.dll
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\dinput8t.dll
c:\windows\system32\drivers\utehinhp.sys
c:\windows\system32\ycqvimj.dll

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_utehinhp
-------\Service_utehinhp


((((((((((((((((((((((((( Files Creati Da 2008-11-14 al 2008-12-14 )))))))))))))))))))))))))))))))))))
.

2008-12-13 21:27 . 2008-12-14 16:33 <DIR> d-------- C:\ComboFix
2008-12-13 14:10 . 2008-12-13 14:10 <DIR> d-------- c:\programmi\Windows Installer Clean Up
2008-12-13 14:10 . 2008-12-13 14:10 <DIR> d-------- c:\programmi\MSECACHE
2008-12-11 00:15 . 2008-12-14 15:10 <DIR> d-------- c:\programmi\Unlocker
2008-12-11 00:15 . 2008-12-11 23:15 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\Desktopicon
2008-12-10 22:27 . 2008-12-10 22:28 100,054,180 --a------ C:\copia del registro.reg
2008-12-08 20:13 . 2008-12-10 18:33 <DIR> d-------- c:\programmi\SUPERAntiSpyware
2008-12-08 20:13 . 2008-12-08 20:13 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\SUPERAntiSpyware.com
2008-12-08 20:13 . 2008-12-08 20:13 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\SUPERAntiSpyware.com
2008-12-08 20:12 . 2008-12-08 20:12 <DIR> d-------- c:\programmi\File comuni\Wise Installation Wizard
2008-12-08 19:57 . 2008-12-08 19:57 <DIR> d-------- c:\programmi\Trend Micro
2008-12-07 16:46 . 2008-08-30 12:11 40,960 --a------ c:\windows\system32\drivers\VIRAGTLT.SYS
2008-12-07 16:45 . 2008-12-13 23:29 <DIR> d-------- C:\VEXPLITE
2008-12-06 13:32 . 2008-12-11 23:15 <DIR> d-------- c:\programmi\Malwarebytes' Anti-Malware
2008-12-06 13:32 . 2008-12-06 13:32 <DIR> d-------- c:\documents and settings\User\Dati applicazioni\Malwarebytes
2008-12-06 13:32 . 2008-12-06 13:32 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2008-12-06 13:32 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-06 13:32 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-05 13:39 . 2008-12-05 13:39 <DIR> d-------- c:\programmi\smartision
2008-12-05 11:39 . 2008-12-05 12:13 96,976 --a------ c:\windows\system32\drivers\klin.dat
2008-12-05 11:39 . 2008-12-05 12:13 87,855 --a------ c:\windows\system32\drivers\klick.dat
2008-12-05 11:38 . 2008-12-05 11:38 <DIR> d-------- c:\programmi\Kaspersky Lab
2008-12-05 11:38 . 2008-12-14 15:52 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\Kaspersky Lab
2008-12-05 11:38 . 2008-12-14 16:41 10,372,128 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-12-05 11:38 . 2008-12-14 16:40 143,072 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-12-05 11:38 . 2008-12-14 16:42 72,992 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2008-12-05 11:38 . 2008-12-14 16:40 8,912 --ahs---- c:\windows\system32\drivers\fidbox2.idx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-13 12:54 --------- d-----w c:\programmi\Windows Live
2008-12-13 12:46 --------- d-----w c:\programmi\Google
2008-12-13 12:45 --------- d-----w c:\programmi\Windows Live Toolbar
2008-12-10 21:01 --------- d-----w c:\programmi\CCleaner
2008-12-05 11:14 112,144 ----a-w c:\windows\system32\drivers\kl1.sys
2008-12-03 12:02 --------- d-----w c:\documents and settings\User\Dati applicazioni\Ahead
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-05-25 12:29 47,360 ----a-w c:\documents and settings\User\Dati applicazioni\pcouffin.sys
2004-03-11 12:27 40,960 ----a-w c:\programmi\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"AnyDVD"="c:\programmi\SlySoft\AnyDVD\AnyDVD.exe" [2007-04-01 344421]
"PcSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"SUPERAntiSpyware"="c:\programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-10 1809648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-03 339968]
"RemoteControl"="c:\programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"TerraTec Remote Control"="c:\programmi\TerraTec\Cinergy 400 TV\TTTVRC.exe" [2002-05-21 204800]
"NSLauncher"="c:\programmi\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 2658304]
"Adobe Photo Downloader"="c:\programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-07 57344]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"spc1000"="c:\windows\vspc1000.exe" [2007-07-12 675840]
"UnlockerAssistant"="c:\programmi\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"AVP"="c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 218376]
"Collegamento alla pagina delle proprietà di High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

c:\documents and settings\User\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma.lnk - c:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Kodak EasyShare software.lnk - c:\programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 282624]
NETGEAR WG311v3 Smart Wizard.lnk - c:\windows\Installer\{70014586-7BBA-4A92-A610-CDC896C48F8F}\NewShortcut1_1.exe [2007-09-11 1078]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmi\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-10 18:33 352256 c:\programmi\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"vidc.dvsd"= pdvcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 SASDIFSV;SASDIFSV;\??\c:\programmi\SUPERAntiSpyware\SASDIFSV.SYS [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\programmi\SUPERAntiSpyware\SASKUTIL.sys [2008-11-17 55024]
R2 PMJ151NM;Panasonic DVC Web Camera;c:\windows\system32\DRIVERS\PMJ151NM.sys [2008-07-24 14848]
R2 rvsport;RVS Virtual COM Port;c:\windows\system32\drivers\rvsport.sys [2002-07-22 39936]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2007-02-10 1258432]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-04-04 24344]
R3 SASENUM;SASENUM;\??\c:\programmi\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408]
R3 TTTvTune;Cinergy 400 TV Tuner;c:\windows\system32\DRIVERS\PhTvTune.sys [2007-02-10 16128]
R3 WDMWANMP;NDIS WAN miniport;c:\windows\system32\DRIVERS\wdmwanmp.sys [2004-02-18 29312]
S3 ISDN_u;ISDN USB CAPI;c:\windows\system32\DRIVERS\ISDN_u.sys [2004-04-01 755697]
S3 MTDVC;Panasonic DVC USB-SERIAL Driver for NT Technology;c:\windows\system32\DRIVERS\mtdv2ku1.sys [2008-07-24 12590]
S3 MTDVC_ENUM;Panasonic DVC COM Driver for NT Technology;c:\windows\system32\DRIVERS\mtdv2ks1.sys [2008-07-24 11569]
S3 phaudlwr;Philips Audio Filter;c:\windows\system32\DRIVERS\phaudlwr.sys [2007-12-09 88320]
S3 RvscomSv;RvscomSv;c:\programmi\RVS\WCOM\SYSTEM\RVSCOMSV.EXE [2002-07-22 139313]
S3 SPC1000;USB2.0 PC Camera (SPC1000);c:\windows\system32\DRIVERS\spc1000.sys [2007-12-09 3033856]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ejxcnfmp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{71e70a2e-c2af-11db-a03d-487444737531}]
\Shell\AutoRun\command - G:\setupSNK.exe

*Newly Created Service* - UTEHINHP
.
Contenuto della cartella 'Scheduled Tasks'
.
- - - - ORFÃOS REMOVIDOS - - - -

BHO-{3984EB67-F783-46F3-885B-FB57400006F1} - c:\windows\system32\dinput8t.dll
BHO-{61B455B1-2A98-45C7-81F3-043BFAD57AFF} - c:\windows\system32\ycqvimj.dll
WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
Notify-xzkuhibg - ycqvimj.dll


.
------- Supplementare di scansione -------
.
uStart Page = hxxp://www.google.it/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-14 16:41:45
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PMJ151LA]
"ImagePath"="%SystemRoot%\PMJ151LA.BIN"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

- - - - - - - > 'winlogon.exe'(984)
c:\windows\system32\MrvGINA.dll
c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\programmi\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\klogon.dll
c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll

- - - - - - - > 'lsass.exe'(1040)
c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Netgear\WG311v3\WinDomainlogon.exe
c:\windows\system32\ati2evxx.exe
c:\windows\PMJ151LA.BIN
c:\programmi\RVS\WCOM\SYSTEM\RVSINST.EXE
c:\programmi\Netgear\WG311v3\WinDomainlogon.exe
c:\windows\system32\wscntfy.exe
c:\programmi\File comuni\PCSuite\Services\ServiceLayer.exe
c:\programmi\Netgear\WG311v3\wlancfg5.exe
c:\progra~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
.
**************************************************************************
.
Ora fine scansione: 2008-12-14 16:44:35 - macchina è stato riavviato
ComboFix-quarantined-files.txt 2008-12-14 15:44:32

Pre-Run: 12.352.630.784 byte disponibili
Post-Run: 12,301,180,928 byte disponibili

184 --- E O F --- 2008-12-09 23:20:03
amvinfe1
Inviato: Sunday, December 14, 2008 4:51:34 PM

Rank: Newbie

Iscritto dal : 12/11/2008
Posts: 3
esegui, per favore, una scansione con HijackThis e posti il log?

Grazie.
lecoq51
Inviato: Sunday, December 14, 2008 5:11:01 PM

Rank: Member

Iscritto dal : 7/30/2007
Posts: 23
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17.10.16, on 14/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Programmi\NETGEAR\WG311v3\WinDomainlogon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\PMJ151LA.BIN
C:\Programmi\RVS\WCOM\SYSTEM\RVSINST.EXE
C:\WINDOWS\system32\svchost.exe
C:\Programmi\NETGEAR\WG311v3\WinDomainlogon.exe
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Programmi\TerraTec\Cinergy 400 TV\TTTVRC.exe
C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\vspc1000.exe
C:\Programmi\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
C:\Programmi\Netgear\WG311v3\wlancfg5.exe
C:\PROGRA~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Collegamento alla pagina delle proprietà di High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [TerraTec Remote Control] C:\Programmi\TerraTec\Cinergy 400 TV\TTTVRC.exe
O4 - HKLM\..\Run: [NSLauncher] C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programmi\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [spc1000] C:\WINDOWS\vspc1000.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programmi\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] "C:\Programmi\SlySoft\AnyDVD\AnyDVD.exe"
O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Programmi\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: NETGEAR WG311v3 Smart Wizard.lnk = ?
O8 - Extra context menu item: Aggiungi ad Anti-Banner - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PMJ151 AutoLaunch Service (PMJ151LA) - Matsushita Electric Industrial Co. ,Ltd, - C:\WINDOWS\PMJ151LA.BIN
O23 - Service: RvscomSv - Living Byte Software GmbH, München - C:\Programmi\RVS\WCOM\SYSTEM\RVSCOMSV.EXE
O23 - Service: RVS Installer (RVSINST) - Living Byte Software GmbH, München - C:\Programmi\RVS\WCOM\SYSTEM\RVSINST.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe

--
End of file - 6796 bytes
amvinfe1
Inviato: Sunday, December 14, 2008 5:36:02 PM

Rank: Newbie

Iscritto dal : 12/11/2008
Posts: 3
mi sembra non vi siano più problemi.
r16
Inviato: Sunday, December 14, 2008 5:38:59 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
No ,non credo.
Complimenti amvinfe1
Ciao.
amvinfe1
Inviato: Sunday, December 14, 2008 5:41:32 PM

Rank: Newbie

Iscritto dal : 12/11/2008
Posts: 3
un saluto a tutti.
lecoq51
Inviato: Sunday, December 14, 2008 6:10:07 PM

Rank: Member

Iscritto dal : 7/30/2007
Posts: 23
voglio ringraziarvi ancora per la pazienza che avete avuto nei miei confronti e complimentarmi per le vostre
abilità e profonde conoscenze in questo campo. Quest esperienza mi ha arricchito molto sia dal punto di vista
umano che tecnico. Applause
Mando un cordiale augurio di buone feste a tutto lo staff e in particolare a r16 e amvinfe1.
Buon Natale anche a tutti gli utenti del forum aiutamici.
r16
Inviato: Sunday, December 14, 2008 6:18:25 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao lecoq51
Disinstalla combofix in questo modo:
Start
Esegui
nella finestra di dialogo, digita (oppure, copia ed incolla) questo comando: Combofix /u e premi invio poi cancella le cartelle in "C" di combofix (qoobox)
Disistalla anche tutti i vari software che abbiamo installato.
Lascia installato Malwarebytes, perchè è valido.
Ricorda anche di fare una pulizia con CCleaner.
Buone feste.



Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.