Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

trojan.bubnix che non va via Opzioni
abroel
Inviato: Tuesday, March 01, 2011 7:09:41 PM
Rank: Newbie

Iscritto dal : 3/1/2011
Posts: 8
Salve, sono nuovo del forum e siccome ho visto messaggi simili al mio vi chiedo aiuto.
Da due giorni ho problemi al pc nel senso che i programmi mi rilevano la presenza di trojan ed altre schifezze.
Do subito gli indizi: Malwarebyte rileva il trojan in oggetto, dice di averlo rimosso con successo, ma al successivo avvio è sempre li:

posto solo la cosa utile che esce sia con scansione completa che veloce

File infetti:

c:\WINDOWS\SYSTEM32\DRIVERS\jksysbqod.sys (Trojan.Bubnix) -> Quarantined and deleted successfully.

mentre da HijackThis credo che le responsabili siamo almeno queste righe, ma preferisco il parere di esperti prima di agire:


O4 - HKUS\S-1-5-18\..\Run: [moosse] C:\Documents and Settings\NetworkService\Dati applicazioni\Microsoft\nukodujem.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [moosse] C:\Documents and Settings\NetworkService\Dati applicazioni\Microsoft\nukodujem.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [moosse] C:\Documents and Settings\NetworkService\Dati applicazioni\Microsoft\nukodujem.exe (User 'Default user')

O23 - Service: BeTwin Terminal Services (uvijdehleh) - Unknown owner - C:\Documents and Settings\NetworkService\Dati applicazioni\Microsoft\wagihil.exe (file missing)

il file wagihil.exe l'ho rimosso manualmente in preda ad una crisi di sconforto (non so se ho sbagliato)


lo stesso sys mi blocca tra l'altro l'aggiornamento del database di Malwarebyte causando un crash con schermata blu nella quale compare proprio il .sys come causa del blocco.

ho ripulito dei .exe che cambiavano sempre nome plava[1].exe, nukodujem.exe (ma vedo che è ancora li), houjounikoos.exe che generavano dei .tmp in memoria anch'essi ripuliti, ma ora rimane sempre quel .sys (se non compaiono altri problemi).

sono pronto con tutti i software che citate in altri post ed allego l'intero log HijackThis e ringrazio anticipatamente.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18.59.01, on 01/03/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Programmi\Prevx\prevx.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\CAP3RSK.EXE
c:\Programmi\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmi\Prevx\prevx.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmi\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
C:\Programmi\Dell Printers\paperport\pptd40nt.exe
C:\Programmi\Spyware Terminator\sp_rsser.exe
C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3LAK.EXE
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Programmi\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.siqu.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_16\bin\ssv.dll
O3 - Toolbar: Toolbar &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Programmi\Crawler\Toolbar\ctbr.dll (file missing)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmi\File comuni\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [CAP3ON] C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3ONN.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ClamWin] "C:\Programmi\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [Dell MFP Color Laser Printer 3115cn Launcher] "C:\Programmi\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe" /s
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Programmi\Dell Printers\paperport\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Programmi\Dell Printers\paperport\IndexSearch.exe"
O4 - HKLM\..\Run: [DLPSP] "C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [moosse] C:\Documents and Settings\NetworkService\Dati applicazioni\Microsoft\nukodujem.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [moosse] C:\Documents and Settings\NetworkService\Dati applicazioni\Microsoft\nukodujem.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [moosse] C:\Documents and Settings\NetworkService\Dati applicazioni\Microsoft\nukodujem.exe (User 'Default user')
O4 - Global Startup: Finestra di stato di Canon LASER SHOT LBP-1120.LNK = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3LAK.EXE
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.aifos.it
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1156931281744
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1239866031250
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Programmi\Crawler\Toolbar\ctbr.dll (file missing)
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: CSIScanner - Prevx - C:\Programmi\Prevx\prevx.exe
O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Programmi\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
O23 - Service: BeTwin Terminal Services (uvijdehleh) - Unknown owner - C:\Documents and Settings\NetworkService\Dati applicazioni\Microsoft\wagihil.exe (file missing)

--
End of file - 9976 bytes
Sponsor
Inviato: Tuesday, March 01, 2011 7:09:41 PM

 
himaco
Inviato: Tuesday, March 01, 2011 7:21:36 PM
Rank: AiutAmico

Iscritto dal : 12/7/2010
Posts: 269
abroel
Inviato: Wednesday, March 02, 2011 11:22:12 AM
Rank: Newbie

Iscritto dal : 3/1/2011
Posts: 8
ho fatto quanto dicevi, anche se ora non vedo più la risposta, allego di seguito log di combofix e di HijackThis. Faccio notare che rimane però sempre il file
c:\WINDOWS\SYSTEM32\DRIVERS\jksysbqod.sys
che continua a bloccare l'aggiornamento del database di malwarebytes

ComboFix 11-02-28.07 - Silvia 02/03/2011 10.38.29.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1022.484 [GMT 1:00]
Eseguito da: c:\documents and settings\Silvia\Desktop\ComboFix.exe
AV: AVG 7.5.560 *Disabled/Outdated* {41564737-3200-1071-989B-0000E87B4FB1}
AV: Prevx 3.0 *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D901}

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\NetworkService\Dati applicazioni\Microsoft\nukodujem.exe
c:\programmi\pdfforge Toolbar\SearchSettings.dll
C:\Thumbs.db
c:\windows\system32\dz1.txt
c:\windows\system32\p1.txt
c:\windows\system32\r24.txt
c:\windows\system32\xma

.
((((((((((((((((((((((((( Files Creati Da 2011-02-02 al 2011-03-02 )))))))))))))))))))))))))))))))))))
.

2011-03-01 17:37 . 2011-03-01 17:37 388096 ----a-r- c:\documents and settings\Silvia\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-01 17:37 . 2011-03-01 17:37 -------- d-----w- c:\programmi\Trend Micro
2011-02-28 17:24 . 2011-03-01 10:56 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Spyware Terminator
2011-02-28 07:22 . 2011-03-02 09:46 742912 ----a-w- c:\windows\system32\drivers\jksysbqod.sys
2011-02-25 08:25 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2011-02-25 08:25 . 1998-08-05 06:45 122128 ----a-w- c:\windows\system32\VB6IT.DLL
2011-02-25 08:25 . 1998-08-05 06:45 150528 ----a-w- c:\windows\system32\MSCMCIT.DLL
2011-02-25 08:25 . 2011-02-25 08:25 -------- d-----w- c:\programmi\PDFCreator
2011-02-25 08:25 . 1998-08-05 06:45 63488 ----a-w- c:\windows\system32\MSCC2IT.DLL
2011-02-25 08:25 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2011-02-18 10:48 . 2011-02-18 10:46 1272849 ----a-w- C:\clamwin-update-0.96.5-0.97.exe
2011-02-03 08:35 . 2007-03-01 02:31 49152 ----a-w- c:\windows\system32\Rockey2.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 17:09 . 2009-04-29 07:52 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2009-04-29 07:52 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"UpdateManager"="c:\programmi\File comuni\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"CAP3ON"="c:\windows\system32\spool\drivers\w32x86\3\CAP3ONN.EXE" [2002-07-29 22528]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"!AVG Anti-Spyware"="c:\programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"PCSuiteTrayApplication"="c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"SpywareTerminator"="c:\programmi\Spyware Terminator\SpywareTerminatorShield.exe" [2008-08-30 1783808]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2009-03-10 590848]
"ClamWin"="c:\programmi\ClamWin\bin\ClamTray.exe" [2011-02-15 86016]
"Dell MFP Color Laser Printer 3115cn Launcher"="c:\programmi\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe" [2006-12-23 635800]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\programmi\Dell Printers\paperport\pptd40nt.exe" [2006-06-30 36864]
"IndexSearch"="c:\programmi\Dell Printers\paperport\IndexSearch.exe" [2006-06-30 40960]
"DLPSP"="c:\programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE" [2006-12-07 340888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-02-25 219136]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Finestra di stato di Canon LASER SHOT LBP-1120.LNK - c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3LAK.EXE [2005-10-3 30720]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\FXSCLNT.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Programmi\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Programmi\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Programmi\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\WINDOWS\\SYSTEM32\\dlcxcoms.exe"=

R0 pxscan;pxscan;c:\windows\SYSTEM32\DRIVERS\pxscan.sys [28/04/2009 9.27.58 22024]
R0 pxsec;pxsec;c:\windows\SYSTEM32\DRIVERS\pxsec.sys [28/04/2009 9.27.58 27656]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\SYSTEM32\DRIVERS\sp_rsdrv2.sys [05/02/2008 13.16.09 141312]
R2 CSIScanner;CSIScanner;c:\programmi\Prevx\prevx.exe [29/04/2009 10.06.29 4403256]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 DLSDB;Dell Printer Status Database;c:\programmi\Dell Printers\Additional Color Laser Software\Status Monitor\dlsdbnt.exe [12/03/2009 15.46.24 140184]
R2 MSSQL$SQLINFOTEL;SQL Server (SQLINFOTEL);c:\programmi\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe [27/05/2009 2.27.04 29262680]
R3 eusk3usb;SmartKey 3 USB;c:\windows\SYSTEM32\DRIVERS\eusk3usb.sys [30/06/2008 14.54.40 43968]
R3 SvanRT2Wave;SvanRT2Wave Service;c:\windows\SYSTEM32\DRIVERS\SvanRT2Wave.sys [17/04/2009 9.22.01 23424]
S2 gupdate;Google Update Service (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [06/05/2010 15.36.41 136176]
S2 USBHSB;GeneLink File Transfer Driver;c:\windows\SYSTEM32\DRIVERS\usbhsb.sys [25/01/2005 9.48.24 18690]
S2 uvijdehleh;BeTwin Terminal Services;c:\documents and settings\NetworkService\Dati applicazioni\Microsoft\wagihil.exe --> c:\documents and settings\NetworkService\Dati applicazioni\Microsoft\wagihil.exe [?]
S3 bmnpexnv;bmnpexnv;\??\c:\windows\System32\Drivers\bmnpexnv.sys --> c:\windows\System32\Drivers\bmnpexnv.sys [?]
S3 bsusbser;PHD USB Device for Legacy Serial Communication;c:\windows\SYSTEM32\DRIVERS\bsusbser.sys [09/09/2008 10.00.41 94848]
S3 skeyusb;SmartKey USB;c:\windows\SYSTEM32\DRIVERS\skeyusb.sys [23/03/2007 15.16.31 39197]
S3 svan_driver;Svan9xx;c:\windows\SYSTEM32\DRIVERS\svan_driver.sys [17/04/2009 9.22.01 14464]
S3 svan_driver_stream;SvanRT9xx;c:\windows\SYSTEM32\DRIVERS\svanRT_driver.sys [17/04/2009 9.22.01 16128]

--- Altri Servizi/Drivers In Memoria ---

*Deregistered* - jksysbqod
.
Contenuto della cartella 'Scheduled Tasks'

2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-05-06 14:36]

2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-05-06 14:36]

2011-03-01 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]

2011-03-02 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.siqu.it/
uInternet Settings,ProxyOverride = 127.0.0.1
IE: Crawler Search - tbr:iemenu
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: aifos.it\www
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} -
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Silvia\Dati applicazioni\Mozilla\Firefox\Profiles\i0ww722n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.siqu.it/
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Crawler Toolbar: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - c:\programmi\Crawler\Toolbar\firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKU-Default-RunServices-moosse - c:\documents and settings\NetworkService\Dati applicazioni\Microsoft\nukodujem.exe
SafeBoot-AVG Anti-Spyware Driver
AddRemove-HijackThis - c:\documents and settings\Silvia\Desktop\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-02 10:45
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\jksysbqod]

.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ñw*]
"0140311900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Ora fine scansione: 2011-03-02 10:49:12
ComboFix-quarantined-files.txt 2011-03-02 09:48

Pre-Run: 30.781.939.712 byte disponibili
Post-Run: 31.658.045.440 byte disponibili

- - End Of File - - 4A4C9E792E1A1C9BE1B449EA46BC0992


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11.01.57, on 02/03/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Programmi\Prevx\prevx.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Programmi\File comuni\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe
C:\Programmi\Dell Printers\paperport\pptd40nt.exe
C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE
C:\WINDOWS\system32\CAP3RSK.EXE
c:\Programmi\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Programmi\Spyware Terminator\sp_rsser.exe
C:\Programmi\Prevx\prevx.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3LAK.EXE
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.siqu.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_16\bin\ssv.dll
O3 - Toolbar: Toolbar &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Programmi\Crawler\Toolbar\ctbr.dll (file missing)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Programmi\File comuni\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [CAP3ON] C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3ONN.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ClamWin] "C:\Programmi\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [Dell MFP Color Laser Printer 3115cn Launcher] "C:\Programmi\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe" /s
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Programmi\Dell Printers\paperport\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Programmi\Dell Printers\paperport\IndexSearch.exe"
O4 - HKLM\..\Run: [DLPSP] "C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Finestra di stato di Canon LASER SHOT LBP-1120.LNK = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3LAK.EXE
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.aifos.it
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1156931281744
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1239866031250
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Programmi\Crawler\Toolbar\ctbr.dll (file missing)
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: CSIScanner - Prevx - C:\Programmi\Prevx\prevx.exe
O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - C:\Programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Programmi\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
O23 - Service: BeTwin Terminal Services (uvijdehleh) - Unknown owner - C:\Documents and Settings\NetworkService\Dati applicazioni\Microsoft\wagihil.exe (file missing)

--
End of file - 9268 bytes
himaco
Inviato: Wednesday, March 02, 2011 2:08:29 PM
Rank: AiutAmico

Iscritto dal : 12/7/2010
Posts: 269
abroel
Inviato: Wednesday, March 02, 2011 3:59:38 PM
Rank: Newbie

Iscritto dal : 3/1/2011
Posts: 8
Di seguito il log di combofix, il file c:\WINDOWS\SYSTEM32\DRIVERS\jksysbqod.sys continua però ad esserci anche se mi sembrano cambiate le proprietà (ora appare un file di Microsoft con una descrizione piena di lettere a casaccio).

P.S. Ora mi fa aggiornare il database di Malwarebyte e dopo una scansione completa mi ha trovato 3 PUP.Dealio che credo siano legati ad una toolbar generata dall'installazione di un software per generare PDF (PDF Creator) ... posso rimuovere e mettere in quarantena ???


ComboFix 11-02-28.07 - Silvia 02/03/2011 15.03.07.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1022.664 [GMT 1:00]
Eseguito da: c:\documents and settings\Silvia\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Silvia\Desktop\CFScript.txt
AV: Prevx 3.0 *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D901}

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_JKSYSBQOD
-------\Service_jksysbqod


((((((((((((((((((((((((( Files Creati Da 2011-02-02 al 2011-03-02 )))))))))))))))))))))))))))))))))))
.

2011-03-02 13:38 . 2011-03-02 13:38 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Avg7
2011-03-01 17:37 . 2011-03-01 17:37 388096 ----a-r- c:\documents and settings\Silvia\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-01 17:37 . 2011-03-01 17:37 -------- d-----w- c:\programmi\Trend Micro
2011-02-28 17:24 . 2011-03-01 10:56 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Spyware Terminator
2011-02-28 07:22 . 2011-03-02 14:11 742912 ----a-w- c:\windows\system32\drivers\jksysbqod.sys
2011-02-25 08:25 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2011-02-25 08:25 . 1998-08-05 06:45 122128 ----a-w- c:\windows\system32\VB6IT.DLL
2011-02-25 08:25 . 1998-08-05 06:45 150528 ----a-w- c:\windows\system32\MSCMCIT.DLL
2011-02-25 08:25 . 2011-02-25 08:25 -------- d-----w- c:\programmi\PDFCreator
2011-02-25 08:25 . 1998-08-05 06:45 63488 ----a-w- c:\windows\system32\MSCC2IT.DLL
2011-02-25 08:25 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2011-02-18 10:48 . 2011-02-18 10:46 1272849 ----a-w- C:\clamwin-update-0.96.5-0.97.exe
2011-02-03 08:35 . 2007-03-01 02:31 49152 ----a-w- c:\windows\system32\Rockey2.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 17:09 . 2009-04-29 07:52 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2009-04-29 07:52 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"UpdateManager"="c:\programmi\File comuni\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"CAP3ON"="c:\windows\system32\spool\drivers\w32x86\3\CAP3ONN.EXE" [2002-07-29 22528]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"!AVG Anti-Spyware"="c:\programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"PCSuiteTrayApplication"="c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"SpywareTerminator"="c:\programmi\Spyware Terminator\SpywareTerminatorShield.exe" [2008-08-30 1783808]
"Dell MFP Color Laser Printer 3115cn Launcher"="c:\programmi\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe" [2006-12-23 635800]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\programmi\Dell Printers\paperport\pptd40nt.exe" [2006-06-30 36864]
"IndexSearch"="c:\programmi\Dell Printers\paperport\IndexSearch.exe" [2006-06-30 40960]
"DLPSP"="c:\programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE" [2006-12-07 340888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Finestra di stato di Canon LASER SHOT LBP-1120.LNK - c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3LAK.EXE [2005-10-3 30720]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\FXSCLNT.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\dlcxcoms.exe"=

R0 pxscan;pxscan;c:\windows\SYSTEM32\DRIVERS\pxscan.sys [28/04/2009 9.27.58 22024]
R0 pxsec;pxsec;c:\windows\SYSTEM32\DRIVERS\pxsec.sys [28/04/2009 9.27.58 27656]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\SYSTEM32\DRIVERS\sp_rsdrv2.sys [05/02/2008 13.16.09 141312]
R2 CSIScanner;CSIScanner;c:\programmi\Prevx\prevx.exe [29/04/2009 10.06.29 4403256]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 DLSDB;Dell Printer Status Database;c:\programmi\Dell Printers\Additional Color Laser Software\Status Monitor\dlsdbnt.exe [12/03/2009 15.46.24 140184]
R2 MSSQL$SQLINFOTEL;SQL Server (SQLINFOTEL);c:\programmi\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe [27/05/2009 2.27.04 29262680]
R3 eusk3usb;SmartKey 3 USB;c:\windows\SYSTEM32\DRIVERS\eusk3usb.sys [30/06/2008 14.54.40 43968]
R3 SvanRT2Wave;SvanRT2Wave Service;c:\windows\SYSTEM32\DRIVERS\SvanRT2Wave.sys [17/04/2009 9.22.01 23424]
S2 gupdate;Google Update Service (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [06/05/2010 15.36.41 136176]
S2 USBHSB;GeneLink File Transfer Driver;c:\windows\SYSTEM32\DRIVERS\usbhsb.sys [25/01/2005 9.48.24 18690]
S2 uvijdehleh;BeTwin Terminal Services;c:\documents and settings\NetworkService\Dati applicazioni\Microsoft\wagihil.exe --> c:\documents and settings\NetworkService\Dati applicazioni\Microsoft\wagihil.exe [?]
S3 bmnpexnv;bmnpexnv;\??\c:\windows\System32\Drivers\bmnpexnv.sys --> c:\windows\System32\Drivers\bmnpexnv.sys [?]
S3 bsusbser;PHD USB Device for Legacy Serial Communication;c:\windows\SYSTEM32\DRIVERS\bsusbser.sys [09/09/2008 10.00.41 94848]
S3 skeyusb;SmartKey USB;c:\windows\SYSTEM32\DRIVERS\skeyusb.sys [23/03/2007 15.16.31 39197]
S3 svan_driver;Svan9xx;c:\windows\SYSTEM32\DRIVERS\svan_driver.sys [17/04/2009 9.22.01 14464]
S3 svan_driver_stream;SvanRT9xx;c:\windows\SYSTEM32\DRIVERS\svanRT_driver.sys [17/04/2009 9.22.01 16128]
.
Contenuto della cartella 'Scheduled Tasks'

2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-05-06 14:36]

2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-05-06 14:36]

2011-03-02 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]

2011-03-02 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.siqu.it/
uInternet Settings,ProxyOverride = 127.0.0.1
IE: Crawler Search - tbr:iemenu
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: aifos.it\www
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} -
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Silvia\Dati applicazioni\Mozilla\Firefox\Profiles\i0ww722n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.siqu.it/
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Crawler Toolbar: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - c:\programmi\Crawler\Toolbar\firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-02 15:13
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ñw*]
"0140311900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(1588)
c:\windows\system32\WININET.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\programmi\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\windows\system32\dlcxcoms.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\CAP3RSK.EXE
c:\programmi\Spyware Terminator\sp_rsser.exe
c:\programmi\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2011-03-02 15:17:58 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-03-02 14:17
ComboFix2.txt 2011-03-02 09:49

Pre-Run: 31.995.392.000 byte disponibili
Post-Run: 31.900.868.608 byte disponibili

- - End Of File - - 56B082B30E6CFDBAFC64732AED7C3800
r16
Inviato: Wednesday, March 02, 2011 6:17:54 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Apri un file di testo con il Block Note sul Desktop
Ci incolli il codice che vedi qui sotto, e salvi il file di testo obbligatoriamente con il nome CFScript.txt

Code:
KillAll::

Driver::
uvijdehleh
bmnpexnv

File::
c:\windows\system32\drivers\jksysbqod.sys
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\clamwin-update-0.96.5-0.97.exe

Folder::
c:\documents and settings\All Users\Dati applicazioni\Avg7
c:\programmi\Grisoft\AVG Anti-Spyware 7.5
c:\programmi\Grisoft
C:\clamwin-update-0.96.5-0.97.exe

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec NetDriver Warning"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]

RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]


e trascinalo sull'icona di ComboFix.
Attendi la fine dei lavori, senza toccare tastiera, mouse o altro.
Posta il log aggiornato di combofix.

Non dovrebbe più comparirti quel driver.
abroel
Inviato: Wednesday, March 02, 2011 6:23:28 PM
Rank: Newbie

Iscritto dal : 3/1/2011
Posts: 8
grazie ora lo faccio e cosa faccio con i PUP.Dealio rilevati da Malware??? ce li ho ancora con la maschera in attesa di istruzioni
r16
Inviato: Wednesday, March 02, 2011 6:29:38 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
abroel ha scritto:
grazie ora lo faccio e cosa faccio con i PUP.Dealio rilevati da Malware??? ce li ho ancora con la maschera in attesa di istruzioni

Controlla che le caselline siano selezionate (con la spunta), e clicca su "Rimuovi Selezionati"
abroel
Inviato: Wednesday, March 02, 2011 7:00:02 PM
Rank: Newbie

Iscritto dal : 3/1/2011
Posts: 8
Ecco il log, il file sembra sparito:

P.S. Però questa volta combofix mi ha chiesto di collegarmi ad internet (io avevo scollegato il cavo per evitare interferenze nella scansione) e poi dopo un tentativo di inviare dei dati ha lasciato un file .htm da inviare eventualmente (ma non so dove l'ha messo) è importante???


ComboFix 11-02-28.07 - Silvia 02/03/2011 18.37.59.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.1022.628 [GMT 1:00]
Eseguito da: c:\documents and settings\Silvia\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Silvia\Desktop\CFScript.txt
AV: Prevx 3.0 *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D901}

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!

FILE ::
"C:\clamwin-update-0.96.5-0.97.exe"
"c:\programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe"
"c:\windows\system32\drivers\jksysbqod.sys"
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\clamwin-update-0.96.5-0.97.exe
c:\documents and settings\All Users\Dati applicazioni\Avg7
c:\programmi\Grisoft\AVG Anti-Spyware 7.5
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\avgasc64.sys
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\avgascln.sys
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\clsid.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\context.dll
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\context64.dll
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\engine.dll
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\error.txt
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\guard.sys
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\guard64.sys
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\heuristic.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\lang.ini
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\logfile.txt
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook64.dll
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3100.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3101.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3102.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3103.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3104.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3105.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3106.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3107.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3108.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3109.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3110.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3111.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3112.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3113.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3114.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3115.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3116.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3117.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3118.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3119.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3120.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3121.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3122.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3123.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3124.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3125.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3126.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3127.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3128.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3129.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3130.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3131.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3132.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3133.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3134.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3135.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3136.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3137.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3138.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3139.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3140.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3141.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3142.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3143.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3144.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3145.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3146.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3147.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3148.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3149.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3150.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3151.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3152.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3153.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3154.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3155.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3156.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3157.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3158.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3159.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3160.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3161.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3162.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3163.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3164.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3165.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3166.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3167.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3168.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3169.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3170.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3171.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3172.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3173.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3174.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3175.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3176.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3177.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3178.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3179.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3180.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3181.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3182.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3183.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3184.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3185.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3186.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3187.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3188.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3189.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3190.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3191.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3192.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3193.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3194.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3195.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3196.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3197.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3198.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3199.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3200.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3201.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3202.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3203.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3204.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3205.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3206.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3207.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3208.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3209.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3210.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3211.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3212.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3213.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3214.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3215.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3216.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3217.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3218.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3219.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3220.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3221.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3222.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3223.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3224.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3225.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3226.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3227.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3228.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3229.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3230.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3231.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3232.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3233.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3234.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3235.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3236.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3237.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3238.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3239.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3240.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3241.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3242.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3243.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3244.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3245.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3246.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3247.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3248.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3249.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3250.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3251.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3252.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3253.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3254.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3255.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3256.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3257.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3258.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3259.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3260.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3261.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3262.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3263.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3264.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3265.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3266.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3267.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3268.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3269.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3270.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3271.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3272.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3273.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3274.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3275.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3276.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3277.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3278.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3279.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3280.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3281.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3282.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3283.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3284.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3285.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3286.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3287.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3288.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3289.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3290.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3291.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3292.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3293.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3294.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3295.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3296.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3297.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3298.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3299.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3300.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3301.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3302.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3303.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3304.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3305.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3306.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3307.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3308.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3309.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3310.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3311.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3312.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3313.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3314.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3315.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3316.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3317.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3318.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3319.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3320.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3321.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3322.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3323.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3324.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3325.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3326.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3327.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3328.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3329.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3330.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3331.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3332.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3333.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3334.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3335.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3336.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3337.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3338.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3339.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3340.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3341.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3342.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3343.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3344.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3345.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3346.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3347.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3348.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3349.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3350.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3351.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3352.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3353.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3354.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3355.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3356.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3357.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3358.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3359.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3360.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3361.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3362.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3363.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3364.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3365.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3366.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3367.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3368.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3369.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3370.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3371.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3372.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3373.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3374.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3375.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3376.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3377.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3378.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3379.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3380.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3381.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3382.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3383.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3384.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3385.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3386.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3387.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3388.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3389.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3390.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3391.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3392.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3393.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3394.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3395.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3396.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3397.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3398.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3399.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3400.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3401.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3402.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3403.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3404.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3405.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3406.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3407.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3408.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3409.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3410.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3411.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3412.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3413.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3414.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3415.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3416.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3417.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3418.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3419.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3420.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3421.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3422.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3423.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3424.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3425.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3426.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3427.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3428.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3429.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3430.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3431.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3432.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3433.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3434.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3435.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3436.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3437.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3438.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3439.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3440.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3441.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3442.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3443.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3444.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3445.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3446.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3447.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3448.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3449.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3450.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3451.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3452.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3453.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3454.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3455.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3456.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3457.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3458.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3459.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3460.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3461.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3462.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3463.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3464.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3465.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3466.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3467.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3468.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3469.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3470.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3471.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3472.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3473.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3474.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3475.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3476.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3477.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3478.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3479.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3480.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3481.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3482.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3483.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3484.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3485.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3486.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3487.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3488.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3489.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3490.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3491.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3492.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3493.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3494.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3495.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3496.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3497.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3498.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3499.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3500.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3501.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3502.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3503.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3504.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3505.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3506.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3507.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3508.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3509.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3510.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3511.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3512.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3513.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3514.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3515.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3516.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3517.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3518.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3519.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3520.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3521.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3522.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3523.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3524.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3525.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3526.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3527.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3528.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3529.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3530.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3531.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3532.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3533.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3534.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3535.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3536.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3537.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3538.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3539.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3540.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3541.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3542.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3543.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3544.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3545.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3546.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3547.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3548.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3549.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3550.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3551.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3552.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3553.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3554.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3555.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3556.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3557.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3558.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3559.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3560.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3561.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3562.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3563.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3564.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3565.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3566.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3567.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3568.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3569.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3570.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3571.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3572.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3573.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3574.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3575.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3576.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3577.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3578.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3579.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3580.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3581.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3582.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3583.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3584.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3585.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3586.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3587.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3588.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3589.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3590.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3591.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3592.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3593.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3594.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3595.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3596.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3597.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3598.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3599.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3600.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3601.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3602.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3603.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3604.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3605.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3606.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3607.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3608.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3609.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3610.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3611.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3612.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Signatures\3613.dat
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Translations\czech.mo
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Translations\english.mo
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Translations\french.mo
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Translations\german.mo
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Translations\italian.mo
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Translations\portuguese.mo
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Translations\slovak.mo
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Translations\spanish.mo
c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
c:\windows\system32\drivers\jksysbqod.sys

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BMNPEXNV
-------\Legacy_UVIJDEHLEH
-------\Service_bmnpexnv
-------\Service_uvijdehleh


((((((((((((((((((((((((( Files Creati Da 2011-02-02 al 2011-03-02 )))))))))))))))))))))))))))))))))))
.

2011-03-01 17:37 . 2011-03-01 17:37 388096 ----a-r- c:\documents and settings\Silvia\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-01 17:37 . 2011-03-01 17:37 -------- d-----w- c:\programmi\Trend Micro
2011-02-28 17:24 . 2011-03-01 10:56 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\Spyware Terminator
2011-02-25 08:25 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2011-02-25 08:25 . 1998-08-05 06:45 122128 ----a-w- c:\windows\system32\VB6IT.DLL
2011-02-25 08:25 . 1998-08-05 06:45 150528 ----a-w- c:\windows\system32\MSCMCIT.DLL
2011-02-25 08:25 . 2011-02-25 08:25 -------- d-----w- c:\programmi\PDFCreator
2011-02-25 08:25 . 1998-08-05 06:45 63488 ----a-w- c:\windows\system32\MSCC2IT.DLL
2011-02-25 08:25 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2011-02-03 08:35 . 2007-03-01 02:31 49152 ----a-w- c:\windows\system32\Rockey2.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 17:09 . 2009-04-29 07:52 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2009-04-29 07:52 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"UpdateManager"="c:\programmi\File comuni\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"CAP3ON"="c:\windows\system32\spool\drivers\w32x86\3\CAP3ONN.EXE" [2002-07-29 22528]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"PCSuiteTrayApplication"="c:\programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"SpywareTerminator"="c:\programmi\Spyware Terminator\SpywareTerminatorShield.exe" [2008-08-30 1783808]
"Dell MFP Color Laser Printer 3115cn Launcher"="c:\programmi\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe" [2006-12-23 635800]
"SSBkgdUpdate"="c:\programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\programmi\Dell Printers\paperport\pptd40nt.exe" [2006-06-30 36864]
"IndexSearch"="c:\programmi\Dell Printers\paperport\IndexSearch.exe" [2006-06-30 40960]
"DLPSP"="c:\programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE" [2006-12-07 340888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
"Nokia.PCSync"="c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Finestra di stato di Canon LASER SHOT LBP-1120.LNK - c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3LAK.EXE [2005-10-3 30720]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\FXSCLNT.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\dlcxcoms.exe"=

R0 pxscan;pxscan;c:\windows\SYSTEM32\DRIVERS\pxscan.sys [28/04/2009 9.27.58 22024]
R0 pxsec;pxsec;c:\windows\SYSTEM32\DRIVERS\pxsec.sys [28/04/2009 9.27.58 27656]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\SYSTEM32\DRIVERS\sp_rsdrv2.sys [05/02/2008 13.16.09 141312]
R2 CSIScanner;CSIScanner;c:\programmi\Prevx\prevx.exe [29/04/2009 10.06.29 4403256]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 DLSDB;Dell Printer Status Database;c:\programmi\Dell Printers\Additional Color Laser Software\Status Monitor\dlsdbnt.exe [12/03/2009 15.46.24 140184]
R2 MSSQL$SQLINFOTEL;SQL Server (SQLINFOTEL);c:\programmi\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe [27/05/2009 2.27.04 29262680]
R3 eusk3usb;SmartKey 3 USB;c:\windows\SYSTEM32\DRIVERS\eusk3usb.sys [30/06/2008 14.54.40 43968]
R3 SvanRT2Wave;SvanRT2Wave Service;c:\windows\SYSTEM32\DRIVERS\SvanRT2Wave.sys [17/04/2009 9.22.01 23424]
S2 gupdate;Google Update Service (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [06/05/2010 15.36.41 136176]
S2 USBHSB;GeneLink File Transfer Driver;c:\windows\SYSTEM32\DRIVERS\usbhsb.sys [25/01/2005 9.48.24 18690]
S3 bsusbser;PHD USB Device for Legacy Serial Communication;c:\windows\SYSTEM32\DRIVERS\bsusbser.sys [09/09/2008 10.00.41 94848]
S3 skeyusb;SmartKey USB;c:\windows\SYSTEM32\DRIVERS\skeyusb.sys [23/03/2007 15.16.31 39197]
S3 svan_driver;Svan9xx;c:\windows\SYSTEM32\DRIVERS\svan_driver.sys [17/04/2009 9.22.01 14464]
S3 svan_driver_stream;SvanRT9xx;c:\windows\SYSTEM32\DRIVERS\svanRT_driver.sys [17/04/2009 9.22.01 16128]
.
Contenuto della cartella 'Scheduled Tasks'

2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-05-06 14:36]

2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2010-05-06 14:36]

2011-03-02 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]

2011-03-02 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 15:04]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.siqu.it/
uInternet Settings,ProxyOverride = 127.0.0.1
IE: Crawler Search - tbr:iemenu
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: aifos.it\www
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} -
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Silvia\Dati applicazioni\Mozilla\Firefox\Profiles\i0ww722n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.siqu.it/
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Crawler Toolbar: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - c:\programmi\Crawler\Toolbar\firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

AddRemove-AVGAntiSpyware75 - c:\programmi\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-02 18:48
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ñw*]
"0140311900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(3908)
c:\windows\system32\WININET.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\programmi\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\dlcxcoms.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\CAP3RSK.EXE
c:\programmi\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\programmi\Spyware Terminator\sp_rsser.exe
c:\programmi\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\programmi\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2011-03-02 18:53:31 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-03-02 17:53
ComboFix2.txt 2011-03-02 14:17
ComboFix3.txt 2011-03-02 09:49

Pre-Run: 31.880.978.432 byte disponibili
Post-Run: 31.859.290.112 byte disponibili

- - End Of File - - 6BA945433880FE0AFC6E4DDBAC5138BD
r16
Inviato: Wednesday, March 02, 2011 7:11:08 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Disattiva il ripristino configurazione di sistema,
http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121

Scarica TFC by OldTimer sul desktop
http://oldtimer.geekstogo.com/TFC.exe
chiudi tutti i programmi
avvia TFC, clicca su "start"
al termine della scansione ti chiederà il riavvio, dai ok.

Per eliminare i vari Tooll scaricati:
Scarica OTC by OldTimer sul desktop:
http://oldtimer.geekstogo.com/OTC.exe
doppio clic per eseguirlo
Clicca su CleanUp.
Ti chiederà di riavviare il pc.
Clicca sì.

Segui questo percorso e svuota la cartella Prefetch : (non eliminare la cartella)
C:\Windows\Prefetch
Svuota il cestino.

Riattiva il ripristino configurazione di sistema.

Non ho capito che antivirus usi.
abroel
Inviato: Wednesday, March 02, 2011 7:14:04 PM
Rank: Newbie

Iscritto dal : 3/1/2011
Posts: 8
ora purtroppo devo tornare a casa, ci proverò domani mattina e ti posterò le informazioni. Io usavo clamwin e prevx e spywareterminator. Ma clamwin mi è stato detto di eliminarlo.
r16
Inviato: Wednesday, March 02, 2011 7:26:54 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Puoi benissimo eliminarli tutti e tre, (a meno che, non siano a pagamento)
Questi i software che consiglio:

Antivirus: Avira.
http://www.aiutamici.com/software?ID=10908

Antispyware: Superantispyware:
http://www.aiutamici.com/software?ID=11397

Per Malware generici:
Malwarebyte. (che hai già installato)

Firewall:
http://www.aiutamici.com/software?ID=80361

Non ti serve altro, se non una certa attenzione, a cosa scarichi, e a dove navighi.

N.B:
Questi sono, solo consigli.
abroel
Inviato: Thursday, March 03, 2011 9:17:16 AM
Rank: Newbie

Iscritto dal : 3/1/2011
Posts: 8
Ho fatto tutto e sembrano rientrati tutti i problemi, poi con la pulizia finale va anche più veloce. Grazie di tutto.
R16 grazie per i consigli sugli antivirus, volevo precisare che il pc in questione lo uso in azienda, per cui avevo scelto quelli perchè consentivano l'uso commerciale, ed anche perchè sono in genere molto prudente e lo uso per lavoro con applicazioni tranquille, purtroppo sabato la chiavetta di un mio collaboratore (tutt'altro che tranquillo) mi ha fregato. Vedrò comunque tra gli antivirus che mi hai segnalato la possibilità di avere licenze a pagamento. Grazie di nuovo.
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.