Uno sprovvedutissimo collega mi ha incasinato il Pc di lavoro che domani, al riavvio dovrò per forza di cose renrere operativo. Praticamente è stato installato un pseudo programma antivirus che blocca tutto perchè riferisce di fare fantomatiche scansioni, trovare dei virus e no aprire i programmi richiesti. Sul desktop sono apparse collegamenti (nudeporn. com, porntube.com... spam001.exe...) (A proposito si può conoscere l'ora di installazione di tali applicazioni?). Non funziona nemmeno il Task Manager. Le scansioni le ho fatte in modalità provvisoria.
SI ringrazia sentitamente: Giovanni
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11.09.36, on 10/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17080)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://it.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://it.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programmi\ConduitEngine\ConduitEngine.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: VenditaMotori Toolbar - {ae335179-0533-44ab-8b59-cd68b0000006} - C:\Programmi\VenditaMotori\tbVend.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: VenditaMotori Toolbar - {ae335179-0533-44ab-8b59-cd68b0000006} - C:\Programmi\VenditaMotori\tbVend.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programmi\ConduitEngine\ConduitEngine.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SoundMax] "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Programmi\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Xxaniyaloguj] rundll32.exe "C:\WINDOWS\axpatuti.dll",Startup
O4 - HKCU\..\Run: [dfrgsnapnt.exe] C:\DOCUME~1\ORTOPE~1\IMPOST~1\Temp\dfrgsnapnt.exe
O4 - HKCU\..\Run: [Antivirus] "C:\Programmi\AnVi\avt.exe" -noscan
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {15CAC53B-5F45-4D70-BE98-386E6F3B3328} (MedstWeb Control) -
http://192.168.0.200:8085/resources/medweb/MedstWWW.cab
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) -
http://king.it.msn.com/ctl/kingcomie.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cabO16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///E:/CDVIEWER/CdViewer.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = aoumberto.local
O17 - HKLM\Software\..\Telephony: DomainName = aoumberto.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF0C2A40-906E-404E-A2ED-55A6A85EBA46}: NameServer = 151.99.125.2,151.99.250.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = aoumberto.local
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe
O23 - Service: Servizio di Google Update (gupdate1c98e7a6d003cfa) (gupdate1c98e7a6d003cfa) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ManageEngine Desktop Central 6 - Agent - Unknown owner - C:\Programmi\DesktopCentral_Agent\\bin\dcagentservice.exe
O23 - Service: ManageEngine Desktop Central 6 - Remote Control - Unknown owner - C:\Programmi\DesktopCentral_Agent\\bin\dcrdservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\oracle\ora81\BIN\ONRSD.EXE
O23 - Service: VNC Server (winvnc) - UltraVNC - C:\Programmi\UltraVNC\WinVNC.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ORTOPE~1/IMPOST~1/Temp/msohtml1/01/clip_image002.jpg
--
End of file - 6858 bytes
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.orgVersione database: 4747
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 7.0.5730.11
10/10/2010 12.07.15
mbam-log-2010-10-10 (12-06-45).txt
Tipo di scansione: Scansione completa (C:\|)
Elementi esaminati: 206975
Tempo trascorso: 53 minuti, 7 secondi
Processi infetti in memoria: 0
Moduli di memoria infetti: 0
Chiavi di registro infette: 4
Valori di registro infetti: 5
Voci infette nei dati di registro: 2
Cartelle infette: 3
File infetti: 142
Processi infetti in memoria:
(Non sono stati rilevati elementi nocivi)
Moduli di memoria infetti:
(Non sono stati rilevati elementi nocivi)
Chiavi di registro infette:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pragmatrdcdxrqqm (Trojan.DNSChanger) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\AnVi (Rogue.AnVi) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus (Rogue.AntiVirus) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\PRAGMA (Rootkit.TDSS) -> No action taken.
Valori di registro infetti:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xxaniyaloguj (Trojan.Hiloti) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dfrgsnapnt.exe (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\24d1ca9a-a864-4f7b-86fe-495eb56529d8 (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\7bde84a2-f58f-46ec-9eac-f1f90fead080 (Malware.Trace) -> No action taken.
Voci infette nei dati di registro:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
Cartelle infette:
C:\Programmi\AnVi (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Menu Avvio\Programmi\AnVi (Rogue.AntiVirus) -> No action taken.
C:\WINDOWS\PRAGMAtrdcdxrqqm (Trojan.DNSChanger) -> No action taken.
File infetti:
C:\WINDOWS\axpatuti.dll (Trojan.Hiloti) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temp\dfrgsnapnt.exe (Trojan.FakeAlert) -> No action taken.
C:\Programmi\AnVi\avt.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\baadd[1].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\baadd[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\baadd[2].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\hwaaf[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\irptrpih[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[1].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[2].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[2].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[2].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[3].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[3].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[4].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[4].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[5].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[5].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\rmrmgfe[6].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\vfwwhc[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\vfwwhc[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\vfwwhc[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\vfwwhc[2].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\wflayr[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\wflayr[1].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\wflayr[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\wflayr[2].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\BJOK9BAC\wflayr[3].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\baadd[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\baadd[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\baadd[2].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\ibmiht[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\rmrmgfe[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\rmrmgfe[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\rmrmgfe[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\rmrmgfe[2].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\rmrmgfe[2].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\rmrmgfe[3].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\rmrmgfe[4].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\rmrmgfe[5].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\vfwwhc[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\vfwwhc[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\vfwwhc[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\vfwwhc[2].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\vtjk[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\wflayr[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\wflayr[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\IRK7JHCK\wflayr[2].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\baadd[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\baadd[2].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\hwaaf[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[1].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[2].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[2].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[2].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[2].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[3].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[3].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[3].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\rmrmgfe[4].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\vfwwhc[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\vfwwhc[1].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\vfwwhc[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\vfwwhc[2].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\wflayr[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\wflayr[1].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZF094IKG\wflayr[2].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\baadd[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\baadd[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\baadd[1].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\comz[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\ezvg[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\hwaaf[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\kfqkgvlt[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\rmrmgfe[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\rmrmgfe[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\rmrmgfe[1].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\rmrmgfe[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\rmrmgfe[2].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\rmrmgfe[2].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\rmrmgfe[2].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\rmrmgfe[3].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\rmrmgfe[4].jpg (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\vdcuys[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\vfwwhc[1].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\vfwwhc[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\vfwwhc[2].bmp (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\wflayr[1].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\wflayr[1].png (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\ZUFUUENU\wflayr[2].gif (Extension.Mismatch) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temp\0.22419103889931657.exe (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temp\0.9798431820304941.exe (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temp\asd5D.tmp.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temp\asd5E.tmp.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temp\eapp32hst.dll (Trojan.FakeAV) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temp\fiu1.tmp (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temp\JoYqXMfeAp.exe (Trojan.Hiloti) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temp\wscsvc32.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temporary Internet Files\Content.IE5\MEIQCEPA\5-direct[2].ex (Trojan.DNSChanger) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temporary Internet Files\Content.IE5\MMDHJXZN\5-direct[1].ex (Trojan.DNSChanger) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temporary Internet Files\Content.IE5\W312R1HE\setup[1].exe (Trojan.Hiloti) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temporary Internet Files\Content.IE5\W312R1HE\setup[2].exe (Trojan.FakeAlert) -> No action taken.
C:\Programmi\AnVi\avtext.dll (Trojan.FakeAlert) -> No action taken.
C:\Programmi\AnVi\avthook.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\PRAGMAtrdcdxrqqm\PRAGMAc.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAtrdcdxrqqm\PRAGMAd.sys (Trojan.DNSChanger) -> No action taken.
C:\Programmi\AnVi\about.ico (Rogue.AntiVirus) -> No action taken.
C:\Programmi\AnVi\activate.ico (Rogue.AntiVirus) -> No action taken.
C:\Programmi\AnVi\avt.db (Rogue.AntiVirus) -> No action taken.
C:\Programmi\AnVi\buy.ico (Rogue.AntiVirus) -> No action taken.
C:\Programmi\AnVi\help.ico (Rogue.AntiVirus) -> No action taken.
C:\Programmi\AnVi\scan.ico (Rogue.AntiVirus) -> No action taken.
C:\Programmi\AnVi\settings.ico (Rogue.AntiVirus) -> No action taken.
C:\Programmi\AnVi\splash.mp3 (Rogue.AntiVirus) -> No action taken.
C:\Programmi\AnVi\Uninstall.exe (Rogue.AntiVirus) -> No action taken.
C:\Programmi\AnVi\update.ico (Rogue.AntiVirus) -> No action taken.
C:\Programmi\AnVi\virus.mp3 (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Menu Avvio\Programmi\AnVi\About.lnk (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Menu Avvio\Programmi\AnVi\Activate.lnk (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Menu Avvio\Programmi\AnVi\Antivirus Support.lnk (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Menu Avvio\Programmi\AnVi\Antivirus.lnk (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Menu Avvio\Programmi\AnVi\Buy.lnk (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Menu Avvio\Programmi\AnVi\Scan.lnk (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Menu Avvio\Programmi\AnVi\Settings.lnk (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Menu Avvio\Programmi\AnVi\Update.lnk (Rogue.AntiVirus) -> No action taken.
C:\WINDOWS\PRAGMAtrdcdxrqqm\PRAGMAcfg.ini (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAtrdcdxrqqm\PRAGMAsrcr.dat (Trojan.DNSChanger) -> No action taken.
C:\Documents and Settings\ortopediamedici\Dati applicazioni\Bitrix Security\kahvux.dll (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\ortopediamedici\Desktop\AntiVirus.lnk (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Desktop\nudetube.com.lnk (Rogue.Link) -> No action taken.
C:\Documents and Settings\ortopediamedici\Desktop\pornotube.com.lnk (Rogue.Link) -> No action taken.
C:\Documents and Settings\ortopediamedici\Desktop\spam001.exe (Malware.Trace) -> No action taken.
C:\Documents and Settings\ortopediamedici\Desktop\spam003.exe (Malware.Trace) -> No action taken.
C:\Documents and Settings\ortopediamedici\Desktop\troj000.exe (Malware.Trave) -> No action taken.
C:\Documents and Settings\ortopediamedici\Desktop\youporn.com.lnk (Rogue.Link) -> No action taken.
C:\Documents and Settings\ortopediamedici\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk (Rogue.AntiVirus) -> No action taken.
C:\Documents and Settings\ortopediamedici\Impostazioni locali\Temp\PRAGMA61de.tmp (Trojan.DNSChanger) -> No action taken.