Logfile of Spyware Terminator v2.3.0.488 (db:2.009.002.001)
Scan Time: 02/09/2008 18.53.27 length: 2422 s
Platform: WXP (5.1.0.2600)
User: Admin
Boot Mode: Normal
Scan type: Full_Virus__Spyware_Scan
Scanned Objects: 84621 (Critical:59)
Filter: No System items, No Safe items, No Invalid items
Running Processes
sched.exe [Avira GmbH] : C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
avguard.exe [Avira GmbH] : C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
RichVideo.exe : C:\Programmi\CyberLink\Shared files\RichVideo.exe
igfxpers.exe [Intel Corporation] : C:\WINDOWS\system32\igfxpers.exe
NSLauncher.exe : C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe
avgnt.exe [Avira GmbH] : C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
MsnMsgr.Exe [Microsoft Corporation] : C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
PCSuite.exe [Nokia] : C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe
NMIndexStoreSvr.exe [Nero AG] : C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
ServiceLayer.exe [Nokia.] : C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
MPAPI3s.exe [Nokia Corporation] : C:\Programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
NclUSBSrv.exe : C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
NclRSSrv.exe : C:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
usnsvc.exe [Microsoft Corporation] : C:\Programmi\Windows Live\Messenger\usnsvc.exe
WLLoginProxy.exe [Microsoft Corporation] : C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
Internet Settings
R - HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar =
http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60327R - HKLM\Software\Microsoft\Internet Explorer\Main, SearchAssistant =
http://www.crawler.com/search/ie.aspx?tb_id=60327R - HKLM\Software\Microsoft\Internet Explorer\Main, CustomizeSearch =
http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant =
http://www.crawler.com/search/ie.aspx?tb_id=60327R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch =
http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =
BHO
02 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - [Yahoo! Inc.] : C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
02 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - [Google Inc.] : C:\Programmi\google\googletoolbar2.dll
02 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - [Microsoft Corporation] : C:\Programmi\Windows Live Toolbar\msntb.dll
Toolbars
03 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - [Microsoft Corporation] : C:\Programmi\Windows Live Toolbar\msntb.dll
03 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - [Yahoo! Inc.] : C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
03 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - [Google Inc.] : C:\Programmi\google\googletoolbar2.dll
StartUps
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MsnMsgr : [Microsoft Corporation] : C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, PC Suite Tray : [Nokia] : C:\Programmi\Nokia\Nokia PC Suite 6\PCSuite.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, igfxpers : [Intel Corporation] : C:\WINDOWS\system32\igfxpers.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NeroFilterCheck : [Nero AG] : C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NSLauncher : : C:\Programmi\Nokia\Nokia Software Launcher\NSLauncher.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, avgnt : [Avira GmbH] : C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgnt.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Adobe Reader Speed Launcher : [Adobe Systems Incorporated] : C:\Programmi\ADOBE\READER 8.0\READER\READER_SL.EXE
Shell Extensions
Microsoft Office Outlook - {00020D75-0000-0000-C000-000000000046} - [Microsoft Corporation] : C:\Programmi\Microsoft Office\OFFICE11\MLSHEXT.DLL
Estensione dell'icona del file di Outlook - {0006F045-0000-0000-C000-000000000046} - [Microsoft Corporation] : C:\Programmi\Microsoft Office\OFFICE11\OLKFSTUB.DLL
Cartelle condivise - {FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} - [Microsoft Corporation] : C:\Programmi\Windows Live\Messenger\fsshext.8.5.1302.1018.dll
Nokia Phone Browser - {416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} - [Nokia] : C:\Programmi\Nokia\Nokia PC Suite 6\phonebrowser.dll
- {06A2568A-CED6-4187-BB20-400B8C02BE5A} - [Microsoft Corporation] : C:\Programmi\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
Shell Extension for Malware scanning - {45AC2688-0253-4ED8-97DE-B5370FA7D48A} - [Avira GmbH] : C:\Programmi\Avira\AntiVir PersonalEdition Classic\shlext.dll
Protocol Handler
CZipHandler Object - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - [Hewlett-Packard Company] : C:\Programmi\HP\hpcoretech\comp\hpuiprot.dll
- {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Programmi\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
- {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Programmi\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
Data Page Pluggable Protocol mso-offdap Handler - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - [Microsoft Corporation] : C:\Programmi\File comuni\Microsoft Shared\Web Components\10\OWC10.DLL
Services
23 - [Avira GmbH] : C:\Programmi\Avira\AntiVir PersonalEdition Classic\sched.exe
23 - [Avira GmbH] : C:\Programmi\Avira\AntiVir PersonalEdition Classic\avguard.exe
23 - [Avira GmbH] : C:\Programmi\Avira\AntiVir PersonalEdition Classic\avgntflt.sys
23 - [Avira GmbH] : C:\WINDOWS\system32\DRIVERS\avipbb.sys
23 - [Intel Corporation] : C:\WINDOWS\system32\DRIVERS\e100b325.sys
23 - [Intel Corporation] : C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
23 - : C:\Programmi\CyberLink\Shared files\RichVideo.exe
23 - [Nokia.] : C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
23 - [Analog Devices, Inc.] : C:\WINDOWS\system32\drivers\smwdm.sys
23 - [Avira GmbH] : C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
23 - [Microsoft Corporation] : C:\Programmi\Windows Live\Messenger\usnsvc.exe
Winlogon Notify
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui, DLLName : [Intel Corporation] : C:\WINDOWS\system32\igfxdev.dll
IE URL Search Hooks
Yahoo! Toolbar con blocco Pop-Up - {{EF99BD32-C1FB-11D2-892F-0090271D4F88}} - [Yahoo! Inc.] : C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
Threat Files
<SpyWare Secure> : C:\Programmi\Spyware-Secure\config.s3db
<SpyWare Secure> : C:\Programmi\Spyware-Secure\Gfx_it.bin
<SpyWare Secure> : C:\Programmi\Spyware-Secure\language
<SpyWare Secure> : C:\Programmi\Spyware-Secure\nbmw
<SpyWare Secure> : C:\Programmi\Spyware-Secure\quarantine.s3db
<SpyWare Secure> : C:\Programmi\Spyware-Secure\skin
<SpyWare Secure> : C:\Programmi\Spyware-Secure\Spyware-Secure.url
<SpyWare Secure> : C:\Programmi\Spyware-Secure\sqlite3.dll
<SpyWare Secure> : C:\Programmi\Spyware-Secure\sws_translations.xml
<SpyWare Secure> : C:\Programmi\Spyware-Secure\uninst.exe
<SpyWare Secure> : C:\Programmi\Spyware-Secure\unrar.dll
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT.zip
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\explo_intro.htm
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\explo_menu.htm
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\file.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\fleche.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\folder.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\folder_f.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\folder_o.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\index.htm
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\menu.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\menu3.js
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\spy.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\trait_coud.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\trait_droit.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\trait_vert.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\images\fleche.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\images\folder.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\images\key.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\images\menu.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\images\support.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\images\title-hepfile.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\images\EN\dowload-file-antispyware.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\images\EN\menu.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\images\EN\scstep2.gif
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\rubs\3differentscan.htm
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\rubs\contactus.htm
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\rubs\found-objects.htm
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\rubs\lexic.htm
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\rubs\navigtabs.htm
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\rubs\quarantine.htm
<SpyWare Secure> : C:\Programmi\Spyware-Secure\help\help_Trial_IT\rubs\register.htm
<SpyWare Secure> : C:\Programmi\Spyware-Secure\resources\cookies_1-12.dat
<SpyWare Secure> : C:\Programmi\Spyware-Secure\resources\filesDesc_1-12.dat
<SpyWare Secure> : C:\Programmi\Spyware-Secure\resources\filesDesc_1-12.dic
<SpyWare Secure> : C:\Programmi\Spyware-Secure\resources\filesExt_1-12.dat
<SpyWare Secure> : C:\Programmi\Spyware-Secure\resources\filesMulti_1-12.idx
<SpyWare Secure> : C:\Programmi\Spyware-Secure\resources\filesSimple_1-12.idx
<SpyWare Secure> : C:\Programmi\Spyware-Secure\resources\malwaresDB_1-12
<SpyWare Secure> : C:\Programmi\Spyware-Secure\resources\register_1-12.dat
<SpyWare Secure> : C:\Documents and Settings\Disigual\Menu Avvio\Programmi\Spyware-Secure\Website.lnk
<SpyWare Secure> : C:\Documents and Settings\Disigual\Menu Avvio\Programmi\Spyware-Secure\Spyware-Secure trial.lnk
<Trojan.Agent-32908> : C:\Programmi\DaneaEasyfatt2006\EasyfattAdmin.exe
Advanced Files Report
%SYSDIR%\PTQL5L.DLL [Brother Industries, Ltd.] [Brother QL-500/QL-550] MD5=6A41D16C94253EC0C516C32EDCA28745 SIZE=30385
%SYSDIR%\PTQL65L.DLL [Brother Industries, Ltd.] [Brother QL-650TD] MD5=244B5BF07F4FE1C05F3A5F49E3168EC3 SIZE=30387
%SYSDIR%\hpzsnt10.dll [HP] [HP DeskJet] MD5=900E7E6601B14C8D8640D02A70D37E59 SIZE=180315
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\sched.exe [Avira GmbH] [AntiVir Workstation] MD5=9773E0650E0BAB7AE161D2A0ECC7678A SIZE=68865
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\schedr.dll [Avira GmbH] [AntiVir Workstation] MD5=EFBABD350FA0E4804CD98CE6FFE98743 SIZE=7937
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\avevtlog.dll [Avira GmbH] [AntiVir Workstation] MD5=61DBB2959632400D4D7E397EBBCEB88F SIZE=119041
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\sqlite3.dll [SQLite Database] MD5=A467ACDA6C73AE3F8DBC6B94602921B5 SIZE=339968
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\avguard.exe [Avira GmbH] [AntiVir Workstation] MD5=6BB24E08C602E1E023FC15E25CD32490 SIZE=149761
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\guardmsg.dll [Avira GmbH] [AntiVir Workstation] MD5=FD1A14DE29EC44ED90CB2BE560B3707A SIZE=46337
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\AVPREF.DLL [Avira GmbH] [AntiVir Workstation] MD5=BF8228DD8B40E0BA612CE75CC3A9818C SIZE=38657
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\SMTPLIB.DLL [Avira GmbH] [AntiVir Workstation] MD5=8DC92F512184DBC0A0FA0117BE55BC55 SIZE=28929
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\AVGIO.DLL [Avira GmbH] MD5=7769B062FBEB74A07D47509B4140383A SIZE=124161
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\avipc.dll [Avira GmbH] [AntiVir Workstation] MD5=922EE25E719104E6D0E166451118E9F4 SIZE=73985
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aecore.dll [Avira GmbH] [AVCORE] MD5=362C15749B2BA559E64D508935E3146C SIZE=172406
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aevdf.dll [Avira GmbH] [AVVDF] MD5=C9FFFD5005F4FE7131DF6128E98E3A6A SIZE=102772
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aescript.dll [Avira GmbH] [AVSCRIPT] MD5=AB21044752F14AA52F1EA39AAFBB7D50 SIZE=315770
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aescn.dll [Avira GmbH] [AVSCN] MD5=F519C10B10D73B2B6B75CFEBC5096236 SIZE=119156
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aerdl.dll [Avira GmbH] [AVRDL] MD5=352C02CD46F42A12635297AB0AA7BFC6 SIZE=418165
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aepack.dll [Avira GmbH] [AVPACK] MD5=BC3A6DDC19C4511CA2C37F0938EB8853 SIZE=364917
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\unacev2.dll [ACE Compression Software] [UNACE - freeware ACE extraction component] MD5=DE02C4D04088B69E64ECC30A3D9E22E5 SIZE=77312
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aeoffice.dll [Avira GmbH] [AVOFFICE] MD5=F2E24228155D496D4B0EE5CFDC3B62FB SIZE=192890
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aeheur.dll [Avira GmbH] [AVHEUR] MD5=8C0EA77695842C6B559E918925F3CE53 SIZE=1388918
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aehelp.dll [Avira GmbH] [AVHELP] MD5=83BAC707A4B7682201A1EB9766B54CEB SIZE=115063
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aegen.dll [Avira GmbH] [AVGEN] MD5=63F18A1FD1A6D1069B892EC25280E595 SIZE=315764
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aeemu.dll [Avira GmbH] [AVEMU] MD5=87A6C6E3993D3A635F8E7152FC6D1907 SIZE=430452
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\aebb.dll [Avira GmbH] [AVBB] MD5=BBAD1D9B0694F5E8FE2ACB85283CC5FE SIZE=53617
%PROGRAMFILES%\CyberLink\Shared files\RichVideo.exe [RichVideo Module] MD5=BD517C7FB119997EFFBE39D5E4B37B05 SIZE=167936
%PROGRAMFILES%\Nokia\Nokia PC Suite 6\phonebrowser.dll [Nokia] [Phone Browser] MD5=8009FF7E45469458E7AFCC2783FDC447 SIZE=616960
%PROGRAMFILES%\Nokia\Nokia PC Suite 6\NGSCM.DLL [Nokia] [Next Gen Suite Common Modules] MD5=987E2B48798261A65B949F1134A0CD16 SIZE=815104
%PROGRAMFILES%\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_ita.nlr [Nokia] [Nokia Phone Browser] MD5=B61F518F6AB57F877B23D470896EC973 SIZE=29184
%PROGRAMFILES%\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr [Nokia] [Nokia Phone Browser] MD5=3BAB7E780608054364DDB7A6CBE68DF4 SIZE=573440
%PROGRAMFILES%\Nero\Nero 7\Nero BackItUp\NBShell.dll [Nero AG] [Nero BackItUp] MD5=8AE2CC145F9DE7FEAA272D3D8DD90ACC SIZE=73728
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\shlext.dll [Avira GmbH] [AntiVir Workstation] MD5=09B3D3F6AD9744417574676E5A2836EE SIZE=65793
%COMMONFILES%\Adobe\Acrobat\ActiveX\PDFShell.ITA [Adobe Systems, Inc.] [Adobe PDF Shell Extension] MD5=25FAF84103DB2F272835337A4391173C SIZE=311296
%SYSDIR%\igfxpph.dll [Intel Corporation] [Intel(R) Common User Interface] MD5=3AB3A2948B034B1C7F18B2B20E13D4E8 SIZE=147456
%SYSDIR%\hccutils.DLL [Intel Corporation] [Intel(R) Common User Interface] MD5=CF833AC004268E1C3C4BF543656200A9 SIZE=73728
%SYSDIR%\igfxres.dll [Intel Corporation] [Intel(R) Common User Interface] MD5=9390B43F207E1875005209EB9DA8FF7D SIZE=151552
%SYSDIR%\igfxress.dll [Intel Corporation] [Intel(R) Common User Interface] MD5=95C346BF3B8856AC84D158FAA3E3F2B6 SIZE=1503232
%SYSDIR%\igfxsrvc.dll [Intel Corporation] [Intel(R) Common User Interface] MD5=25A2C1F0A75AB0B6508784220D1B102C SIZE=57344
%PROGRAMFILES%\CyberLink\PowerDVD\CLRCEngine3.dll [CyberLink Corp.] [Cyberlink PowerCinema] MD5=ACD326014941167733074BFBF77296E1 SIZE=69632
%SYSDIR%\spool\drivers\w32x86\3\HPZR3210.dll [HP] [Driver UI dlll] MD5=C63808A7C514D05A6D9BF69A3546F3B7 SIZE=3203072
%PROGRAMFILES%\PC Connectivity Solution\connapi.dll [Nokia.] [PC Connectivity Solution] MD5=80893904E9DB09803F8DAAB9371CA381 SIZE=524288
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\cclib.dll [Avira GmbH] [AntiVir Workstation] MD5=C27FD26297D360251B6B4D6782330E98 SIZE=160001
%PROGRAMFILES%\avira\antivir personaledition classic\ccgen.dll [Avira GmbH] [AntiVir Workstation] MD5=AFFEC62925CF3779CF776CA4B534124E SIZE=270593
%PROGRAMFILES%\avira\antivir personaledition classic\ccgenrc.dll [Avira GmbH] [AntiVir Workstation] MD5=58DA316F458B8A17A3C7216E1794956E SIZE=17665
%PROGRAMFILES%\avira\antivir personaledition classic\ccguard.dll [Avira GmbH] [AntiVir Workstation] MD5=2CB68354DCFFB53151A8152EAECE3612 SIZE=213249
%PROGRAMFILES%\avira\antivir personaledition classic\ccgrdrc.dll [Avira GmbH] [AntiVir Workstation] MD5=B8357197B0D864D67D9FD9C5043E3456 SIZE=20225
%PROGRAMFILES%\avira\antivir personaledition classic\ccupdate.dll [Avira GmbH] [AntiVir Workstation] MD5=5364855ACDCCCFC8B64DE64946657FB0 SIZE=110849
%PROGRAMFILES%\avira\antivir personaledition classic\ccupdrc.dll [Avira GmbH] [AntiVir Workstation] MD5=AF87BFE66DF01B07FB4F4FC4B3AD3129 SIZE=12545
%PROGRAMFILES%\avira\antivir personaledition classic\cclic.dll [Avira GmbH] [AntiVir Workstation] MD5=97108140E1D381108C3216BC15E739E1 SIZE=53505
%PROGRAMFILES%\avira\antivir personaledition classic\cclicrc.dll [Avira GmbH] [AntiVir Workstation] MD5=208A14217848520CB3DFFB5AD9DAB82E SIZE=5889
%PROGRAMFILES%\avira\antivir personaledition classic\ccmsg.dll [Avira GmbH] [AntiVir Workstation] MD5=2DC1EC49D108D3CDA9F94BF256E42B90 SIZE=155905
%PROGRAMFILES%\Windows Live\Messenger\MSIMG32.dll [Patchou] [Messenger Plus! Live] MD5=67DE23C7D320590168DAD1B59CF59F3A SIZE=59728
%PROGRAMFILES%\Messenger Plus! Live\MsgPlusLive.dll [Patchou] [Messenger Plus! Live] MD5=EB73B015ABE61E67F02FB14B95E6E8C2 SIZE=3374928
%PROGRAMFILES%\Messenger Plus! Live\Detoured.dll MD5=6256684495C499B22DCDBA266E4F2494 SIZE=4096
%PROGRAMFILES%\Messenger Plus! Live\MsgPlusLiveRes.dll [Patchou] [Messenger Plus! Live] MD5=68262E065949567D7B38F4EC757B09E7 SIZE=1831248
%PROGRAMFILES%\Messenger Plus! Live\MPScripts.dll [Patchou] [Messenger Plus! Live] MD5=F2D30D144F973E02A5F0F8ACEBF53E5B SIZE=8528
%COMMONFILES%\Ahead\Lib\AdvrCntr2.dll [Nero AG] [AdvrCntr Module] MD5=58638D54FBFF495D812D1C1F7A032CBF SIZE=2854912
%COMMONFILES%\Ahead\Lib\NMIndexStoreSvrPS.dll [Nero AG] [Nero Home] MD5=7157B4ED863CDEDD405E07786CB632C9 SIZE=15360
%COMMONFILES%\Ahead\Lib\NMDataServices.dll [Nero AG] [Nero Home] MD5=27FA2BCB4D397305AF0A1891F875A91D SIZE=1294336
%PROGRAMFILES%\NOKIA\NOKIA PC SUITE 6\PCSL.dll [Nokia] [Nokia PCSL] MD5=A2935F1CA56CEDB2AB0A82146A4E4477 SIZE=4608
%PROGRAMFILES%\NOKIA\NOKIA PC SUITE 6\Lang\PcSync2_ita.nlr [Time Information Services Ltd.] [PcSync 2.0] MD5=B02A8552372B029D61B09A652E3F3698 SIZE=94720
%PROGRAMFILES%\NOKIA\NOKIA PC SUITE 6\Resource\PcSync2_Nokia.ngr [Time Information Services Ltd.] [PcSync 2.0] MD5=7611CCE9D0F079D942051B6F67AB40D2 SIZE=569344
%PROGRAMFILES%\PC Connectivity Solution\ConfServer.dll [Nokia] [PC Connectivity Solution] MD5=CCE77BA4090E816DAD77D4DAD926BB3E SIZE=190464
%COMMONFILES%\Nokia\Adapters\NclSet.dll [Nokia] [Nokia Connectivity Library] MD5=0461A2DCC217F158683B615097481031 SIZE=269824
%COMMONFILES%\Nokia\Adapters\Nclaeo.dsc [Nokia Mobile Phones Ltd.] [Nokia Connectivity Library] MD5=12B95F15B418E60E8B2FC649836D631D SIZE=20480
%COMMONFILES%\Nokia\MPAPI\MPAPIps.dll [Nokia Corporation] [Nokia Connectivity Library] MD5=9B5458DE3EB3CD2E0E9C35B743FA8376 SIZE=48128
%PROGRAMFILES%\Nokia\Nokia PC Suite 6\QtCore4.dll [Trolltech ASA] [Qt4] MD5=2F276C59243D3C051547888727D8CC78 SIZE=1581056
%PROGRAMFILES%\Nokia\Nokia PC Suite 6\QtGui4.dll [Trolltech ASA] [Qt4] MD5=235AAFE9B205013A22E3E52754A52FF6 SIZE=6434816
%PROGRAMFILES%\Nokia\Nokia PC Suite 6\QtXml4.dll [Trolltech ASA] [Qt4] MD5=0901D37EC3339EF06DBA0A9AFB0AC97C SIZE=356352
%PROGRAMFILES%\Nokia\Nokia PC Suite 6\PCSSupportSetup.DLL [Nokia] [Nokia Connectivity Library] MD5=5E1B8040F8D8F0A76CD87EF0F8597E6D SIZE=94720
%PROGRAMFILES%\PC Connectivity Solution\DAAPI.dll [Nokia] [PC Connectivity Solution] MD5=7476D646F6439166F365D44D2B0CD327 SIZE=1028608
%PROGRAMFILES%\PC Connectivity Solution\PCCS_DBAPI.DLL [Nokia] [Nokia Database API] MD5=3B9948D798495F611FD0A09E543C2782 SIZE=192000
%PROGRAMFILES%\Nokia\Nokia PC Suite 6\styles\NGLStyle.dll [Nokia] [Launch Application Style Plugin] MD5=073A6892302F5606012CEE68439DFB93 SIZE=879104
%PROGRAMFILES%\Nokia\Nokia PC Suite 6\imageformats\qjpeg4.dll [Trolltech ASA] [Qt4] MD5=8B9826BE8D54C01F3ED9A72ECE7A7664 SIZE=131072
%COMMONFILES%\Ahead\Lib\NMIndexStoreSvr.exe [Nero AG] [Nero Home] MD5=1E55333843B8398B2EB60EA8C39569FA SIZE=884736
%COMMONFILES%\Ahead\Lib\NMSQLDB.dll [Nero AG] [Nero Home] MD5=193DD6FB64D5626DD589698B3568AA81 SIZE=286720
%COMMONFILES%\Ahead\Lib\NMLogCxx.dll [Nero AG] [Nero Home] MD5=CE6CE5B27B9EE425F79D246FFACB4442 SIZE=65536
%COMMONFILES%\Ahead\Lib\NMCoFoundation.dll [Nero AG] [Nero Home] MD5=90F435A7D1B0627906079ED6F5C86999 SIZE=499712
%COMMONFILES%\Ahead\Lib\NMPluginBase.dll [Nero AG] [Nero Home] MD5=1317A02A628E8A271BEC3B27EB91817B SIZE=102400
%COMMONFILES%\Ahead\Lib\NMFullTextExtraction.dll [Nero AG] [Nero Home] MD5=703823CF46B56B746827E48968CF2D6B SIZE=155648
%COMMONFILES%\Ahead\Lib\NMSearchPluginSimilarImages.dll [Nero AG] [Nero Home] MD5=6D352B04256E96CA57F13414D4C3CC76 SIZE=172032
%COMMONFILES%\Ahead\Lib\NeroIPP.dll [Nero AG] [Nero Suite] MD5=6D6D8C61D844CB4FDC7DFE534E9235D0 SIZE=3371008
%PROGRAMFILES%\PC Connectivity Solution\ServiceLayer.exe [Nokia.] [PC Connectivity Solution] MD5=9D38320BB32230349379DF5DDBBF7FCE SIZE=430592
%PROGRAMFILES%\PC Connectivity Solution\NclDS.dll [Nokia] [PC Connectivity Solution] MD5=BAF5CED507B5CA0CB4A9665C15733ACB SIZE=126976
%PROGRAMFILES%\PC Connectivity Solution\NclTools.dll [Nokia] [PC Connectivity Solution] MD5=AD9D89AE9688BA4CA36949C9C7568CB3 SIZE=126464
%COMMONFILES%\Nokia\MPAPI\MPAPI3s.exe [Nokia Corporation] [Nokia Connectivity Library] MD5=D54D5E5518A148851509A5E5906D80CD SIZE=474624
%PROGRAMFILES%\PC Connectivity Solution\Transports\NclUSBSrv.exe [PC Connectivity Solution] MD5=2A1BF3BCF15675083277C9357BE0FCAE SIZE=130560
%PROGRAMFILES%\PC Connectivity Solution\Transports\NclRSSrv.exe [PC Connectivity Solution] MD5=7CE05DE53433201C0B57E4E0666C6D44 SIZE=120320
%PROGRAMFILES%\Windows Live\Messenger\usnsvc.exe [Microsoft Corporation] [Messenger] MD5=9D19B042A4FD5C02195071EA2FE0C821 SIZE=98328
%PROGRAMFILES%\Windows Live Toolbar\Components\it-it\SmaMenRes.dll.mui [Microsoft Corporation.] [Windows Live Toolbar] MD5=19E1E2D40D040F7EEE107DD238DF2B5D SIZE=3072
%PROGRAMFILES%\Windows Live Toolbar\Components\SmaMenRes.dll [Microsoft Corporation.] [Windows Live Toolbar] MD5=F2B21EB38BDAFF558DAEDD55EF7C0659 SIZE=4096
%PROGRAMFILES%\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Inc.] [Yahoo! Toolbar] MD5=EAEEA6DDC9924A49FA047D66DBBFF665 SIZE=439872
%PROGRAMFILES%\google\googletoolbar2.dll [Google Inc.] [Google Toolbar per IE] MD5=F0B634B957E774E90EDF0F90D0039303 SIZE=2423872
%PROGRAMFILES%\Windows Live Toolbar\Components\smamen.dll [Microsoft Corporation.] [Windows Live Toolbar] MD5=6B5F084334FBA9F634DC8CB185EFACC7 SIZE=505856
%PROGRAMFILES%\Windows Live Toolbar\Components\COMCRF\COMCRF.dll [Microsoft Corporation.] [Windows Live Toolbar] MD5=99FA7977A3FC14F594BC295C83D31216 SIZE=140288
%PROGRAMFILES%\Yahoo!\Companion\Installs\cpn\pubmod.dll [Yahoo! Inc.] [PopupBlocker Module for Yahoo! Companion] MD5=1E06DEF75CCF5796C75C2E46E57C5C0A SIZE=65536
%PROGRAMFILES%\Yahoo!\Companion\Installs\cpn\ypubc.dll [Yahoo! Inc.] [Yahoo! Pop-Up Blocker] MD5=1AB322D59EB28E6695A66E22A72D8485 SIZE=196096
%COMMONFILES%\Microsoft Shared\Windows Live\WLLoginProxy.exe [Microsoft Corporation] [Microsoft® Windows Live Login Helper] MD5=7FA0AA2F3DABA5BEB2C4AC1EEC054EFA SIZE=118336
%SYSDIR%\Macromed\Flash\Flash9e.ocx [Adobe Systems, Inc.] [Shockwave Flash] MD5=D3C50535C26190FEAD7785A03499C0AC SIZE=2987392
%PROGRAMFILES%\Windows Live Toolbar\msntb.dll [Microsoft Corporation] [Windows Live Toolbar] MD5=CEE1BE1DA21300208D07FBEAE9EA2B51 SIZE=546320
deskpan.dll
%PROGRAMFILES%\Microsoft Office\OFFICE11\MLSHEXT.DLL [Microsoft Corporation] [Microsoft Office Outlook] MD5=08FD97BE0DAC21FD0D25BC97372D53B0 SIZE=31104
%PROGRAMFILES%\Microsoft Office\OFFICE11\OLKFSTUB.DLL [Microsoft Corporation] [Microsoft Office Outlook] MD5=CCF3C1FCFCBE20735DC3AA00E57A1CCB SIZE=235904
%PROGRAMFILES%\Windows Live\Messenger\fsshext.8.5.1302.1018.dll [Microsoft Corporation] [Messenger] MD5=8BDE1F61DFBAAE7A2916170E8B75FE0F SIZE=329240
%PROGRAMFILES%\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe [Microsoft Corporation] [Windows Live Photo Gallery] MD5=47851C6AFE59E6B850D14E347A2FA4FC SIZE=229920
%SYSDIR%\rundll32.exe "C:\Programmi\Windows Live\Photo Gallery\WLXPhotoViewer.dll",PhotoViewerComServer {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C}
%SYSDIR%\rundll32.exe "C:\Programmi\Windows Live\Photo Gallery\WLXPhotoViewer.dll",PhotoViewerComServer {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C}
%SYSDIR%\rundll32.exe "C:\Programmi\Windows Live\Photo Gallery\WLXPhotoViewer.dll",PhotoViewerComServer {00F374B7-B390-4884-B372-2FC349F2172B}
%SYSDIR%\igfxdev.dll [Intel Corporation] [Intel(R) Common User Interface] MD5=09DC1F2A2293E5536FE31D23AF3E8C05 SIZE=135168
%SYSDIR%\svchost.exe -k netsvcs
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Classic\avgntflt.sys [Avira GmbH] [AntiVir Workstation] MD5=509BB9F79F7986CB0D4D7A7BEF35C6D5 SIZE=52032
%SYSDIR%\DRIVERS\avipbb.sys [Avira GmbH] MD5=C132C2F16A99C0EAD91C600BB81A31F0 SIZE=75072
%SYSDIR%\svchost -k DcomLaunch
%SYSDIR%\svchost.exe -k NetworkService
%SYSDIR%\DRIVERS\e100b325.sys [Intel Corporation] [Intel(R) PRO/100 Adapter] MD5=83403675CAB29E7A4B885B11E7C855D8 SIZE=163328
%SYSDIR%\DRIVERS\ialmnt5.sys [Intel Corporation] [Intel Graphics Accelerator Drivers for Windows NT(R)] MD5=9A883C3C4D91292C0D09DE7C728E781C SIZE=1302332
%SYSDIR%\svchost.exe -k LocalService
%SYSDIR%\svchost -k rpcss
%SYSDIR%\drivers\smwdm.sys [Analog Devices, Inc.] [SoundMAX Digital Audio Driver] MD5=BF208C85119770E6A9B6577019A3D810 SIZE=578304
%SYSDIR%\DRIVERS\ssmdrv.sys [Avira GmbH] MD5=3D2829FDE1C52FC64DA5413889CE4DEE SIZE=28352
%SYSDIR%\svchost.exe -k imgsvc
%SYSDIR%\svchost.exe -k WudfServiceGroup
%PROGRAMFILES%\HP\hpcoretech\comp\hpuiprot.dll [Hewlett-Packard Company] [hp coretech (COmponent REuse TECHnology)] MD5=25709AEA0B57A61E67C35DDD7994C9ED SIZE=81920
%PROGRAMFILES%\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll [Microsoft Corporation] [Messenger] MD5=56319E6B4D190A2DEB4463A9CE4D4F74 SIZE=66072
%COMMONFILES%\Microsoft Shared\Web Components\10\OWC10.DLL [Microsoft Corporation] [Microsoft Office XP] MD5=AA2204BD7F9FBFAA09EF15C212A67D69 SIZE=7255384
%COMMONFILES%\Adobe\Updater5\AdobeUpdater.es_ES [Adobe Systems Incorporated] [Adobe Updater] MD5=9CD71F31D3D66802F41CB85FC40E351B SIZE=65728
%SYSDIR%\pxdrv.dll [Sonic Solutions] [Px] MD5=09BA2A524D95884E2D6B973167BC696F SIZE=518904
%PROGRAMFILES%\Java\jre1.6.0_07\bin\JdbcOdbc.dll [Sun Microsystems, Inc.] [Java(TM) Platform SE 6 U7] MD5=F708430AE09C4102933E24CD6D12780D SIZE=36352
%PROGRAMFILES%\Java\jre1.6.0_07\bin\dcpr.dll [Sun Microsystems, Inc.] [Java(TM) Platform SE 6 U7] MD5=D6E7FFCD38ECDFE4BD8DCE29D8D1A654 SIZE=143360
%PROGRAMFILES%\Java\jre1.6.0_07\bin\ioser12.dll [Sun Microsystems, Inc.] [Java(TM) Platform SE 6 U7] MD5=5CF15BC4493299F6645DB27B51278D2A SIZE=12800
%PROGRAMFILES%\Java\jre1.6.0_07\bin\javacpl.cpl [Sun Microsystems, Inc.] [Java(TM) Platform SE 6 U7] MD5=370716E3CA99E6A4346F272DA56017C1 SIZE=73728
%PROGRAMFILES%\Java\jre1.6.0_07\bin\policytool.exe [Sun Microsystems, Inc.] [Java(TM) Platform SE 6 U7] MD5=1C0C6888952D9EC22A7B5C6FAD0E8160 SIZE=25600
%COMMONFILES%\Microsoft Shared\GRPHFLT\CGMIMP32.FLT [Microsoft Corporation] [Microsoft Office 2003] MD5=7416984B33F98032239EE8089340426C SIZE=289152
%COMMONFILES%\Microsoft Shared\Smart Tag\FPERSON.DLL [Microsoft Corporation] [Microsoft Office 2003] MD5=DD55EF4AE8244FAED88AC71F69B2ECEC SIZE=186208
%PROGRAMFILES%\Microsoft Works\ltkrn13n.dll [LEAD Technologies, Inc.] [LEADTOOLS(r) DLL for Win32] MD5=6D853FA6843DF479F456D0B498D654FE SIZE=446976
End of RepoRT
E ADESSO????