Jump to content

SUBIECTE NOI
« 1 / 5 »
RSS
Melodie dance veche

RIP Shifty Shellshock

Daca nu ar conta salariul, ce mes...

Racordare la apa termosemineu
 Mi-am luat 4x4 si vreau sa-l testez

Recomandare laptop cu luminozitat...

Cautarea pe google android nu merge

Caut serviciu serios de captura v...
 Frauda magazin online

AC Woods Venezia Smart - nu races...

podea ciment denivelata

Îndepartare bule folie reflectoriz...
 Revista imobiliara cu poze... cir...

Recomandare soundbar pentru laptop

Veți renunța in 2025 la...

Coaxial pentru cablare casa
 

WillPolo cum scap de el?

- - - - -
  • Please log in to reply
36 replies to this topic

#1
ionutz11

ionutz11

    Junior Member

  • Grup: Members
  • Posts: 187
  • Înscris: 17.01.2007
Am luat virusul asta pe calculator si nu stiu cu ce sa-l maninc
Am incercat cu adawere se si il vede si zice ca-l sterge dar defapt tot acolo e
Am pus si XP-ul si apoi iar a aparut
Va rog sa ma ajutati
Multumesc mult

#2
harus_dj

harus_dj

    Member

  • Grup: Members
  • Posts: 296
  • Înscris: 25.04.2006

 ionutz11, on Jan 25 2008, 23:32, said:

Am luat virusul asta pe calculator si nu stiu cu ce sa-l maninc
Am incercat cu adawere se si il vede si zice ca-l sterge dar defapt tot acolo e
Am pus si XP-ul si apoi iar a aparut
Va rog sa ma ajutati
Multumesc mult

un antivirus bun. un firewall pe masura , fara site-uri xxx,atentie la download si te pastrezi curat.succes

#3
ionutz11

ionutz11

    Junior Member

  • Grup: Members
  • Posts: 187
  • Înscris: 17.01.2007

 harus_dj, on Jan 26 2008, 09:39, said:

un antivirus bun. un firewall pe masura , fara site-uri xxx,atentie la download si te pastrezi curat.succes



Ba nene dar raspunsul asta e coll
Scuze dar asta e
Decit sa-mi dai si tu sfaturi ca altii (adica  format :c),mai bine imi ziceai o rezolvare
Si am nod 32,adaware se 2007,crezi ca-mi mai trtebuie ceva???

#4
harus_dj

harus_dj

    Member

  • Grup: Members
  • Posts: 296
  • Înscris: 25.04.2006

 ionutz11, on Jan 25 2008, 23:46, said:

Ba nene dar raspunsul asta e coll
Scuze dar asta e
Decit sa-mi dai si tu sfaturi ca altii (adica  format :c),mai bine imi ziceai o rezolvare
Si am nod 32,adaware se 2007,crezi ca-mi mai trtebuie ceva???


da, sa fii atent ce downloadezi, ca virusii nu intra pe pc tau daca esti protejat.inseamna ca undeva este o hiba.

#5
ionutz11

ionutz11

    Junior Member

  • Grup: Members
  • Posts: 187
  • Înscris: 17.01.2007

 harus_dj, on Jan 26 2008, 10:47, said:

da, sa fii atent ce downloadezi, ca virusii nu intra pe pc tau daca esti protejat.inseamna ca undeva este o hiba.


Da multumesc
Deci rezolvare e???

#6
websitefinder

websitefinder

    pretendent

  • Grup: Senior Members
  • Posts: 5,402
  • Înscris: 15.06.2006
Pune un log HiJackThis aici daca mai ai probleme.

#7
alexandrudicu

alexandrudicu

    Active Member

  • Grup: Members
  • Posts: 1,161
  • Înscris: 06.04.2006
Tu zici ca ai instalat Xp-ul si iar a aparut problema ? Vezi sa nu fie infectat vreun executabil din kiturile ce le instalezi dupa aceea. Eu am avut infectat setupul de la Foxit Reader si mi-am dat seama dupa 3 reinstalari de windows, chiar nu banuiam ca tocmai ala sa-mi strice treaba. Asa ca dupa ce am instalat XP, primul lucru am pus nod32, si apoi pe rand, drivere, programe, si binenteles ca imi detecta nod32-ul dupa ce rulam setup-ul respectiv ca e infectat dar nu putea sa-i faca nimic ca era un vierme naspa si la primul restart cu tot disinfect si delete, era activ. Asa ca rezolvarea a fost sa reinstalez Windows si sa sterg acel setup cu probleme. Succes.

#8
enki26

enki26

    New Member

  • Grup: Members
  • Posts: 1
  • Înscris: 06.01.2007

 ionutz11, on Jan 25 2008, 23:32, said:

Am luat virusul asta pe calculator si nu stiu cu ce sa-l maninc
Am incercat cu adawere se si il vede si zice ca-l sterge dar defapt tot acolo e
Am pus si XP-ul si apoi iar a aparut
Va rog sa ma ajutati
Multumesc mult
ba dadi meseria virus .m am incaltat si eu cu el.deci am format full hardu si degeaba.asa ca hai sa ne rugam sa vada aia bazati prin PC uri postu, si poate ne lipim de o rezolvare.pana atunci pls nu mai aberati ca antivirusu ala e mai bun ca alalalt ca il am pe alta partitie sa incerc sa sterg registri de intrare ca am incercat de toate am dat restore point.PLSSS.repet faza cu full format nu mere.

Edited by enki26, 30 January 2008 - 22:11.


#9
alexcrist

alexcrist

    Watchdog

  • Grup: Moderators
  • Posts: 9,370
  • Înscris: 02.02.2006

 websitefinder, on Jan 26 2008, 15:51, said:

Pune un log HiJackThis aici daca mai ai probleme.
Subscriu. Cine are probleme, sa posteze un log HijackThis.

#10
TheCrow

TheCrow

    Junior Member

  • Grup: Members
  • Posts: 93
  • Înscris: 25.11.2006

 alexcrist, on Jan 30 2008, 10:22, said:

Subscriu. Cine are probleme, sa posteze un log HiJackThis.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:35:48 PM, on 4/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
E:\RCDMENU.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft....k/?LinkId=74005
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Piraté par WillPolo ---- Ingénieur en hacking -------- fuck u ----------
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [WillPolo] C:\WINDOWS\WillPolo.vbs
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 4592 bytes

#11
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
later edit:

fix la:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Piraté par WillPolo ---- Ingénieur en hacking -------- fuck u ----------
O4 - HKLM\..\Run: [WillPolo] C:\WINDOWS\WillPolo.vbs




+ un nou log HiJackThis.

Edited by crysty2k5, 15 April 2008 - 21:25.


#12
r4du-m4a1

r4du-m4a1

    Member

  • Grup: Members
  • Posts: 307
  • Înscris: 12.01.2008
scuzati-ma de offtopic dar sunt n00b in ale computerului ...
de ce sunt atat de multe wscript.exe

#13
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
hmmm...

daca te uiti un pic la calea fisierului, este acelasi (apare de mai multe ori in log) ;)

#14
catya-20

catya-20

    New Member

  • Grup: Members
  • Posts: 1
  • Înscris: 09.05.2008
sal...AM LUAT SI EU VIRUSUL ASTA ...INK NU AM FORMATAT DAR AS VREA SA STIU DAK VIRUSUL ASTA ATAK COMPONENTE ALE CALC....PLS RASP SI MIE K SA POT DORMI LINISTITA PANA FORMATEZ:(((

#15
pykko

pykko

    I love, therefore I am

  • Grup: Senior Members
  • Posts: 7,229
  • Înscris: 10.02.2006

 catya-20, on May 9 2008, 22:01, said:

sal...AM LUAT SI EU VIRUSUL ASTA ...INK NU AM FORMATAT DAR AS VREA SA STIU DAK VIRUSUL ASTA ATAK COMPONENTE ALE CALC....PLS RASP SI MIE K SA POT DORMI LINISTITA PANA FORMATEZ:(((
Nu este nevoie de format.
Posteaza un log HiJackThis aici si incercam sa te ajutam.

Virusul nu afecteaza si alte componente ale PC-ului.

#16
peus

peus

    Junior Member

  • Grup: Members
  • Posts: 51
  • Înscris: 18.09.2005
Buna dimineata forumisti.
   Am si eu aceeasi problema cu viermele creat de Mosieur Ingénieur en hacking aka WillPolo.vbs. Am incercat de mai multe ori  sa-l scot din sistem , folosind consecutiv NOD 32 si SpyBot search & Destroy, insa toate bune si frumoase pana a doua zi, probabil la urmatorul restart (mentionez ca eu fac doar mentenanta software ,sistemul este al unei cunostinte) cand Will e din nou prezent. Precizez ca sistenul e dual S.O. (Vista +XP Pro), are acces la retea intranet plus un NAS (Network access Storage) partajat de mai multi utilizatori. Orice parere e binevenita dat fiind faptul ca respectivul sistem (mobil, de altfel) face parte dintr-o retea de PC-uri ce asigura monitorizarea activitatii intr-o sala de operatie din cadrul unei clinici de neurochirurgie (RMN, computer tomograf, etc).

   PS: am incercat si o scanare directa de pe un stick de memorie insa fara rezultat, ba mai mult mi-au fost infectate instant ambele partitii de pe flash-ul meu , culmea - desi una era protejata cu parola, in masura in care voi ajunge astazi dimineata 9in jurul orei 11.00) la notebook-ul cu pricina , voi posta si un HiJack log file. (desi am facut fix-urile necesare de mai multe ori insa fara rezultat)....

#17
alexcrist

alexcrist

    Watchdog

  • Grup: Moderators
  • Posts: 9,370
  • Înscris: 02.02.2006
Pai tocmai acolo e problema: stick-urile USB.

La facultate avem aceeasi problema: toate calculatoarele, din toate laboratoarele (vreo 6-7 laboratoare) sunt infectate cu WillPolo + Almanahe.D. u, ca student, am curatat cateva calculatoare, dar degeaba. Daca nu se face curatenie generala (nu ma refer la format, pentru ca virusul asta se scoate destul de usor, in cateva secunde) nu se va rezolva nimic, tocmai din cauza zecilor de stickuri care umbla prin facultate si muta virusul de colo-colo.

Din cate am vazut, WillPolo si Almanahe.D (ctfmon.exe) cam umbla impreuna, insa nu este obligatoriu (in log-ul de mai sus nu apare decat WillPolo).

In fine, la subiect:
  • incerci sa strangi toate stick-urile/memory-card-urile/si alte dispozitive ce se folosesc pentru transferul datelor intre calculatoare din acea zona (orice dispozitiv de acest gen bagat in calculatorul infectat este, dupa cum ti-ai dat seama, infectat instantaneu).
  • in Explorer (sau altceva, gen TotalCommander) setezi sa apara fisierele ascunse (Hidden) si sistem (System). (How To Find Hidden Malware)
  • in TaskManager, inchizi toate procesele numite wscript.exe si ctfmon.exe
  • intrii in fiecare partitie (NU cu duclu-click, ci cu clic dreapta -> Explore) si stergi fisierele: WillPolo.vbs, autorun.inf, Recycled/ctfmon.exe (ctfmon.exe, dupa cum am spus, s-ar putea sa nu existe)
  • Apoi te duci in C:\Documents and Settings\<username>\Start Menu\Programs\Startup (pentru TOTI userii de pe sistem) si stergi, daca exista, fsierul ctfmon.exe (nu e shortcut, ci e chiar EXE-ul propriu-zis).
  • apoi rulezi HiJackThis, si dai fix la intrarea de genul
    O4 - HKLM\..\Run: [WillPolo] C:\WINDOWS\WillPolo.vbs
    
    (eventual verifici ca acel fisier, din C:\Windows, sa fie sters).
  • In final, cureti stick-urile (si alte dispozitive): le conectezi, unul cate unul, tinand tasta SHIFT apasata (pentru a preveni autorun-ul), si stergi de pe ele fisierele WillPolo.vbs, autorun.inf si directorul Recycled (care ar putea contine ctfmon.exe).
  • mai important: Repeta procedura pe celelalte calculatoare din acea zona. In plus, daca gasesti ctfmon.exe (Almanahe), ar fi bine sa verific toate calculatoarele din aceeasi retea, pentru ca el se raspandeste si prin retea. E adevarat, nu este cine stie ce worm, insa poate infecta calculatoarele neprotejate. Informatii aici: http://www.bitdefend...Almanahe.D.html
Inca ceva: daca gasesti Almanahe.D, e posibil ca acesta sa isi fi introdus si alte "module", ca sa le spunem asa. Mai exact, Almanahe.F, care se injecteaza in Explorer.exe ca DLL, si va descarca diferiti malware prin Internet Explorer. Iti sugerez sa dai o scanare cu BitDefender Online, pentru ca stie acesti virusi si te poate scapa de ei.

Atentie! Nu toate procesele ctfmon.exe sunt infectate. Cel aflat in C:\WINDOWS\system32\ctfmon.exe este legitim.


Inca un sfat: ca sa previi alte re-infectii de pe stick-uri infectate (cu orice malware care se raspandeste asa), ar fi recomandat sa dezactivezi permanent autorun-ul pentru removable disks. Nu mai stiu exact pe unde se gaseau niste instructiuni pentru asta, dar se gasesc pe forum (nu prea am timp sa le caut, dar nu ar trebui sa fie prea greu sa le gasesti pe Google ;) ).

In final, posteaza un log HijackThis, ca sa vedem daca s-a rezolvat sau nu. Succes. :)

Edited by alexcrist, 23 May 2008 - 08:39.


#18
rogal

rogal

    New Member

  • Grup: Members
  • Posts: 9
  • Înscris: 30.05.2008
salut
am si eu probleme cu willpolo si postez si eu un log HiJackThis in speranta ca ma ajuta cineva
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:35:25, on 30.05.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\drivers\spools.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\QUICKT~1\qttask.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\hasplms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ro/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Piraté par WillPolo ---- Ingénieur en hacking -------- fuck u ----------
R3 - URLSearchHook: Yahoo! ¤u¨ã&brvbar;C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: Yahoo! ¤u¨ã&brvbar;C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\Administrator\cftmon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Administrator\cftmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nLite] %systemroot%\inf\nlite.cmd (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nLite] %systemroot%\inf\nlite.cmd (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com...obat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1DF4FA34-ABBC-412F-9A52-10B33309937D}: NameServer = 193.230.240.21,193.226.47.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{C95BCD9A-E441-4EEC-83D9-290E265D90BE}: NameServer = 193.231.100.130,193.231.100.134
O17 - HKLM\System\CS1\Services\Tcpip\..\{1DF4FA34-ABBC-412F-9A52-10B33309937D}: NameServer = 193.230.240.21,193.226.47.193
O17 - HKLM\System\CS2\Services\Tcpip\..\{1DF4FA34-ABBC-412F-9A52-10B33309937D}: NameServer = 193.230.240.21,193.226.47.193
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:exe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe

--
End of file - 9945 bytes
multumesc anticipat

Anunturi

Chirurgia endoscopică a hipofizei Chirurgia endoscopică a hipofizei

"Standardul de aur" în chirurgia hipofizară îl reprezintă endoscopia transnazală transsfenoidală.

Echipa NeuroHope este antrenată în unul din cele mai mari centre de chirurgie a hipofizei din Europa, Spitalul Foch din Paris, centrul în care a fost introdus pentru prima dată endoscopul în chirurgia transnazală a hipofizei, de către neurochirurgul francez Guiot. Pe lângă tumorile cu origine hipofizară, prin tehnicile endoscopice transnazale pot fi abordate numeroase alte patologii neurochirurgicale.

www.neurohope.ro

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Forumul Softpedia foloseste "cookies" pentru a imbunatati experienta utilizatorilor Accept
Pentru detalii si optiuni legate de cookies si datele personale, consultati Politica de utilizare cookies si Politica de confidentialitate