|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
Stay one step ahead of the competition. Evaluate and give feedback
on some of the hottest web development tools on the market today.
Make your opinion heard! Click
Here
|
|
#1
|
|||
|
|||
|
I have the same problem. My home page is an about:blank Trusted Start Page|Microsoft Explorer with search links to a site: nyam-nyam.biz/search.cgi
I have removed some files with Norton Antivirus, Ad-aware, about:buster, HijackThis, spysubtract, CWShredder. But the about:blank is present the all the second time I restart iexplorer. I think that with iexplorer another program comes into memory. Please if you have ideas or if you have resolved this problem help me!! ![]() |
|
#2
|
||||
|
||||
|
Thread split - it's better to create a new thread rather than replying to someone else's.
|
|
#3
|
|||
|
|||
|
Hi antidoto,
Please download HijackThis. Make sure you install HijackThis to a permanent folder such as C:\HJT as it creates backups of what we will fix. Run the program, click the button at the top "Do a system scan and save a logfile". Save the log to a convenient place such as C:\HJT Notepad will open, copy and paste the entire log into your post. Do not fix anything yet, most of what's in the log is needed! http://www.majorgeeks.com/download3155.html Tom
__________________
HijackThis Ad-aware Spybot Search & Destroy SpywareBlaster SpywareGuard Housecall Online A/V Scan Please read the stickys at the top of the forum before posting! |
|
#4
|
|||
|
|||
|
It is the log of Hijackthis after the infection before my modifies:
Logfile of HijackThis v1.99.0 Scan saved at 14.12.36, on 29/12/04 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Programmi\File comuni\Symantec Shared\ccApp.exe D:\Programmi\ZoneAlarm\zlclient.exe C:\WINDOWS\mHotkey.exe C:\WINDOWS\System32\devldr32.exe D:\Programmi\Sonork\sonork.exe D:\Programmi\PTBSync\PTBSync.exe C:\Programmi\Norton AntiVirus2\navapsvc.exe D:\Programmi\Babylon\Babylon.exe C:\Documents and Settings\1 Massimo\Menu Avvio\Programmi\Esecuzione automatica\SANDAY32.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZONELABS\VSMON.EXE C:\WINDOWS\System32\mqsvc.exe C:\WINDOWS\System32\mqtgsvc.exe C:\Programmi\Norton AntiVirus2\SAVScan.exe D:\Documenti\about\AboutBuster.exe C:\Programmi\Internet Explorer\iexplore.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\1 Massimo\Impostazioni locali\Temp\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = file://c:\docume~1\1massi~1\impost~1\temp\sp.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 217.129.121.8:80 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Zone Labs Client] "D:\Programmi\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [CHotkey] mHotkey.exe O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Programmi\File comuni\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Sonork] "D:\Programmi\Sonork\sonork.exe" -auto O4 - HKLM\..\Run: [PTBSync] D:\Programmi\PTBSync\PTBSync.exe /Start O4 - HKCU\..\Run: [Babylon Translator] d:\Programmi\Babylon\Babylon.exe O4 - Startup: SANDAY32.EXE O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Scarica con FlashGet - D:\Programmi\FlashGet\jc_link.htm O8 - Extra context menu item: Scarica tutto con FlashGet - D:\Programmi\FlashGet\jc_all.htm O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - D:\Programmi\VisualRoute\vrie.dll O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - D:\Programmi\VisualRoute\vrie.dll O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe O9 - Extra button: Start EasyFreeWebCam - {ECC5777A-6E88-BFCE-13CE-81F134789E8B} - D:\PROGRA~1\EASYWE~1\easywebcam.exe O9 - Extra 'Tools' menuitem: &EasyFreeWebCam - {ECC5777A-6E88-BFCE-13CE-81F134789E8B} - D:\PROGRA~1\EASYWE~1\easywebcam.exe O16 - DPF: {11010101-1001-1111-1000-110112345678} - ms-its:mhtml:file://C:oo.mht!http://cellaphone.net/helps/079057/iehelp.chm::/win.exe O16 - DPF: {11111111-1111-1111-1111-111191113457} - file://c:\ied_s7.cab O16 - DPF: {11111111-1111-1111-1111-511111193457} - file://c:\x.cab O16 - DPF: {11111111-1111-1111-1111-511111193458} - file://c:\x.cab O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Recycled\Q678340.exe O16 - DPF: {23232323-2323-2323-2323-232323291122} - file://c:\x.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-17.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{7A33A462-8E12-4851-B9A3-845850D38826}: NameServer = 193.70.152.15 193.70.152.25 O20 - AppInit_DLLs: gjpownpjldy26sll.dll.dll.dll.dll.dll.dll.dll O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe O23 - Service: Servizio Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Programmi\Norton AntiVirus2\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Programmi\Norton AntiVirus2\SAVScan.exe O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: SymWMI Service - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\VSMON.EXE This is the log now (after my modifies , but the problem of about:blank startpage is unchanged )Logfile of HijackThis v1.99.0 Scan saved at 14.03.44, on 05/01/05 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Programmi\File comuni\Symantec Shared\ccApp.exe D:\Programmi\ZoneAlarm\zlclient.exe C:\WINDOWS\mHotkey.exe C:\WINDOWS\System32\devldr32.exe D:\Programmi\Sonork\sonork.exe D:\Programmi\PTBSync\PTBSync.exe C:\Programmi\Norton AntiVirus2\navapsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZONELABS\VSMON.EXE D:\Programmi\Babylon\Babylon.exe C:\Documents and Settings\1 Massimo\Menu Avvio\Programmi\Esecuzione automatica\SANDAY32.EXE C:\WINDOWS\System32\mqsvc.exe C:\WINDOWS\System32\mqtgsvc.exe C:\Programmi\Outlook Express\msimn.exe C:\Programmi\Internet Explorer\iexplore.exe D:\Documenti\about\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Zone Labs Client] "D:\Programmi\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [CHotkey] mHotkey.exe O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Programmi\File comuni\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Sonork] "D:\Programmi\Sonork\sonork.exe" -auto O4 - HKLM\..\Run: [PTBSync] D:\Programmi\PTBSync\PTBSync.exe /Start O4 - HKCU\..\Run: [Babylon Translator] d:\Programmi\Babylon\Babylon.exe O4 - Startup: SANDAY32.EXE O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Scarica con FlashGet - D:\Programmi\FlashGet\jc_link.htm O8 - Extra context menu item: Scarica tutto con FlashGet - D:\Programmi\FlashGet\jc_all.htm O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - D:\Programmi\VisualRoute\vrie.dll O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - D:\Programmi\VisualRoute\vrie.dll O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe O9 - Extra button: Start EasyFreeWebCam - {ECC5777A-6E88-BFCE-13CE-81F134789E8B} - D:\PROGRA~1\EASYWE~1\easywebcam.exe O9 - Extra 'Tools' menuitem: &EasyFreeWebCam - {ECC5777A-6E88-BFCE-13CE-81F134789E8B} - D:\PROGRA~1\EASYWE~1\easywebcam.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{7A33A462-8E12-4851-B9A3-845850D38826}: NameServer = 193.70.152.15 193.70.152.25 O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe O23 - Service: Servizio Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Programmi\Norton AntiVirus2\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Programmi\Norton AntiVirus2\SAVScan.exe O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: SymWMI Service - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\VSMON.EXE Terrible this about:blank..... ![]() |
|
#5
|
|||
|
|||
|
Interesting to see the temp\sp.html might be related to nyam-nyam.biz hijack.
Please print or copy and paste these instructions into Notepad and save them on your desktop. Ok these instructions are long and somewhat complicated. If you need help with any of the steps, please ask! These are the tools needed of the fix. Registrar Lite CWShredder Ad-Aware SE Personal Edition version 1.05 1. Download, install and run Registrar Lite. 2. Once it is installed, please double click on the icon that should now be on your desktop. If an icon is not there, then check under the programs section of your Start Menu. 3. Once registrar lite is opened, copy and paste the below line, into the address field of Registrar Lite. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs and press the enter key on your keyboard. 4. You will now be presented with new information in the bottom right and left sections and on the right section and the key called AppInit_DLLs should be highlighted. Double-click on the AppInit_DLLs key and write down the text found in the value field. This is the file that is causing the problem. It is possible that there is no file name in the AppInit_DLLs listed in the key when you double-click on it. Please continue with these steps anyways. 5. Exit Registrar Lite 6. Please make sure that you can view all hidden files. Click Start. Open My Computer. Select the Tools menu and click Folder Options. Select the View Tab. Under the Hidden Files and Folders heading select Show Hidden Files and Folders. Uncheck hide extensions for known file types. Uncheck the Hide Protected Operating System Files option. Click Yes to confirm. Click OK. 7. Create a new folder on your hard drive called c:\regbackup. 8. Run Registrar Lite again 9. Copy and paste: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows into the address field and press enter on your keyboard. On the left side of the screen the Windows key should be selected and highlighted purple. 10. With the Windows key highlighted click on the File menu, and then click on export. 11. Enter winkey.reg in the name field and change the Save as Type to Regedit4 standard .reg files (*.reg) 12. Change the Save in: dropdown menu to c:\regbackup 13. Then press the Save button 14. With the Windows key highlighted again click on the File menu, and then click on export. 15. Enter Winkey.hiv in the name field and change the Save as Type to Regedt32/WinApi hive files (*.hiv,*.dat, *.*) 16. Change the Save in: dropdown menu to c:\regbackup 17. Then press the Save button 18. When both backups are successfully saved, right-click on the highlighted Windows key and click on the rename option. Rename the Windows key to Windows1. 19. With Windows1 highlighted, look in the right section and double-click on AppInit_DLLs and clear the text in the Value field. That is the dll you have seen previously in Step 4. If a file name does not exist there, then just press the OK button. 20. Rename Windows1 back to Windows and exit the Registrar Lite. 21. Reboot your computer. 22. When you are back at your desktop, navigate to the c:\regback folder. Double-click on the winkey.reg file. When it prompt if you would like to import/merge the data press the Yes button 23. Run Registrar Lite again 24. Copy and paste: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows into the address field and press enter on your keyboard. On the left side of the screen the Windows key should be selected and highlighted purple. 25. While the Windows key is selected (highlighted purple/blue) in the left window, click on File and them Import. 26. Browse to c:\regback and select the winkey.hiv file that we created earlier and press the Open button. Then press the OK button. 27. Now double-click on the AppInit_DLLs key in the right section of the windows and clear the text in the Value field. If their is no DLL listed there, then just press OK. 28. Exit Registrar Lite 29. Now download Cwshredder from the link above. 30. After you download the program, unzip it into the directory c:\cwshredder. Make sure all browser windows are closed and double-click on the cwshredder.exe to start the program. 31. Next click on the FIX button, not the Scan Only button, let it scan your computer. When it is done, exit the program. 32. Next, using Internet Explorer, run both of these two online virus scans: http://housecall.antivirus.com/ http://www.pandasoftware.com/activescan/ 33. Please download and install the latest version of Ad-Aware from the link above. 34. When you run the program make sure you update it and then scan with it and fix any problems it finds. 35. Exit the program when you have fixed it everything it finds. 36. Finally, check to see if the file found in Step 4 still exists on your computer. If it does, delete it. Please post a fresh HijackThis log. Credit goes to Grinler for the fix! Tom |
|
#6
|
|||
|
|||
|
See my reply in http://forums.devshed.com/t215968/s.html
|
|
#7
|
|||
|
|||
|
Mhhhhh...... The file PCC.dll is suspicious. It have the same data and hour of the infection.
I think as EstericTheBum indicates it can be the simple and definitive solution for me and others as me. I will try to delete it and I will reply. ![]() |
|
#8
|
|||
|
|||
|
antidoto,
PCC.dll does not seem to be a Windows related file. EstericTheBum could be right. It's your choice. It's a new infection and not much is known about it yet. If it were me, I would try the fix posted by myself regarding the AppInit_DLLs. It is a nondestructive fix. So nothing lost trying. Tom |
|
#9
|
|||
|
|||
|
The about:blank (nyam-nyam.biz/search.cgi) create a file PCC.dll under the directory: C:\Program Files\PPC Advertor\ (I am italian and I is under C:\programmi\).
As indicated by EstericTheBum I deleted the directory PCC Advertor, I changed the start page in internet setting and now all is ok. It is not necessary to delete the directory after a start up in safe mode, but is sufficient to delete it after a normal start up but before running iexporer. The solution of this hijacker is: run Antivirus, Ad-avare, HijackThis, then delete the directory "C:\Program Files\PPC Advertor\" after a normal start up and change the start page in internet setting. Thank you to all!!!!!! ![]() |
|
#10
|
|||
|
|||
|
antidoto,
Please post a final HijackThis log. I am curious if any entries are left behind. Tom |
|
#11
|
|||
|
|||
|
This is my HiJack This log. I think nothing is changed after the elimination of PCC advertor directory. Now the start page is ok and the the log is this:
Logfile of HijackThis v1.99.0 Scan saved at 15.39.46, on 08/01/05 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Programmi\File comuni\Symantec Shared\ccApp.exe D:\Programmi\ZoneAlarm\zlclient.exe C:\WINDOWS\mHotkey.exe C:\WINDOWS\System32\devldr32.exe D:\Programmi\Sonork\sonork.exe D:\Programmi\PTBSync\PTBSync.exe C:\Programmi\Norton AntiVirus2\navapsvc.exe D:\Programmi\Babylon\Babylon.exe C:\Documents and Settings\1 Massimo\Menu Avvio\Programmi\Esecuzione automatica\SANDAY32.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZONELABS\VSMON.EXE C:\WINDOWS\System32\mqsvc.exe C:\WINDOWS\System32\mqtgsvc.exe C:\Programmi\Internet Explorer\iexplore.exe C:\Programmi\Outlook Express\msimn.exe D:\Documenti\about\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Zone Labs Client] "D:\Programmi\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [CHotkey] mHotkey.exe O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Programmi\File comuni\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Sonork] "D:\Programmi\Sonork\sonork.exe" -auto O4 - HKLM\..\Run: [PTBSync] D:\Programmi\PTBSync\PTBSync.exe /Start O4 - HKCU\..\Run: [Babylon Translator] d:\Programmi\Babylon\Babylon.exe O4 - Startup: SANDAY32.EXE O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Scarica con FlashGet - D:\Programmi\FlashGet\jc_link.htm O8 - Extra context menu item: Scarica tutto con FlashGet - D:\Programmi\FlashGet\jc_all.htm O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - D:\Programmi\VisualRoute\vrie.dll O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - D:\Programmi\VisualRoute\vrie.dll O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe O9 - Extra button: Start EasyFreeWebCam - {ECC5777A-6E88-BFCE-13CE-81F134789E8B} - D:\PROGRA~1\EASYWE~1\easywebcam.exe O9 - Extra 'Tools' menuitem: &EasyFreeWebCam - {ECC5777A-6E88-BFCE-13CE-81F134789E8B} - D:\PROGRA~1\EASYWE~1\easywebcam.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{7A33A462-8E12-4851-B9A3-845850D38826}: NameServer = 193.70.152.15 193.70.152.25 O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe O23 - Service: Servizio Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Programmi\Norton AntiVirus2\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Programmi\Norton AntiVirus2\SAVScan.exe O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: SymWMI Service - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\VSMON.EXE ![]() |
|
#12
|
|||
|
|||
|
Do you have any idea what this program is?
C:\Documents and Settings\1 Massimo\Menu Avvio\Programmi\Esecuzione automatica\SANDAY32.EXE O4 - Startup: SANDAY32.EXE Tom |
|
#13
|
|||
|
|||
|
Yes, it is ok.
It is a calendar with the saint of every day. ![]() |