Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

per favore un'occhiatina..(urgente!!) Opzioni
simo95
Inviato: Thursday, June 04, 2009 7:54:58 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
Cia ragazzi...oggi ho eseguito una scnsione sul pc di un mio amico ed ecco gli allarmanti risultati...indovinate l'ospite?? MyWebSearch!!

ecco i log, entrambi mooolto infetti...

hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19.40.19, on 04/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\McAfee\SiteAdvisor\McSACore.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Programmi\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmi\Logitech\Video\LogiTray.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe
C:\documents and settings\emilio\impostazioni locali\dati applicazioni\eegmims.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\Trend Micro\Client Server Security Agent\Pop3Trap.exe
C:\Programmi\Logitech\Video\FxSvr2.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\Trend Micro\Client Server Security Agent\pccntupd.exe
K:\CodySafe\Launcher.exe
C:\Documents and Settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\WINDOWS\explorer.exe
C:\hijackthis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Programmi\ToggleEN\tbTog1.dll
R3 - URLSearchHook: PHPNukeIT Toolbar - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - C:\Programmi\PHPNukeIT\tbPHP1.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programmi\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programmi\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
O2 - BHO: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Programmi\ToggleEN\tbTog1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programmi\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: PHPNukeIT Toolbar - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - C:\Programmi\PHPNukeIT\tbPHP1.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Programmi\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programmi\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programmi\Free Download Manager\iefdm2.dll
O2 - BHO: 441465 helper - {d311c486-7d5f-4d73-b791-ee56c47d3b2e} - C:\WINDOWS\system32\441465\441465.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programmi\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programmi\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Programmi\ToggleEN\tbTog1.dll
O3 - Toolbar: PHPNukeIT Toolbar - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - C:\Programmi\PHPNukeIT\tbPHP1.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programmi\MyWebSearch\bar\2.bin\MWSBAR.DLL
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Programmi\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programmi\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmi\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmi\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=2 /w
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programmi\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [EPSON SX100 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\WINDOWS\TEMP\E_S51.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [VeohPlugin] "C:\Programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKCU\..\Run: [Free Download Manager] "C:\Programmi\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [GameShadow] C:\Programmi\GameShadow\GameShadow.exe /q
O4 - HKCU\..\Run: [eegmims] "c:\documents and settings\emilio\impostazioni locali\dati applicazioni\eegmims.exe" eegmims
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNman000
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Scarica con Free Download Manager - file://C:\Programmi\Free Download Manager\dllink.htm
O8 - Extra context menu item: Scarica i video con Free Download Manager - file://C:\Programmi\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Scarica selezionati con Free Download Manager - file://C:\Programmi\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Scarica tutto con Free Download Manager - file://C:\Programmi\Free Download Manager\dlall.htm
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Guida alla connessione - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Guida alla connessione - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {5d6f45b3-9043-443d-a792-115447494d24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {bd393c14-72ad-4790-a095-76522973d6b8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: winctrl32 - WinCtrl32.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Programmi\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe
O23 - Service: Scansione in tempo reale di Trend Micro Client/Server Security Agent (ntrtscan) - Trend Micro Inc. - C:\Programmi\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Personal Firewall di Trend Micro Client/Server Security Agent (ofcpfwsvc) - Trend Micro Inc. - C:\Programmi\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Programmi\Trend Micro\Client Server Security Agent\tmlisten.exe

--
End of file - 14126 bytes


malwarebytes:

Malwarebytes' Anti-Malware 1.37
Versione del database: 2227
Windows 5.1.2600 Service Pack 2

04/06/2009 19.03.54
mbam-log-2009-06-04 (19-03-45).txt

Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi scansionati: 207265
Tempo trascorso: 57 minute(s), 32 second(s)

Processi delle memoria infetti: 1
Moduli della memoria infetti: 0
Chiavi di registro infette: 165
Valori di registro infetti: 16
Elementi dato del registro infetti: 8
Cartelle infette: 18
File infetti: 94

Processi delle memoria infetti:
C:\Programmi\MyWebSearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> No action taken.

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
HKEY_CLASSES_ROOT\e405.e405mgr (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\e405.e405mgr.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{d311c486-7d5f-4d73-b791-ee56c47d3b2e} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{73364d99-1240-4dff-b12a-67e448373148} (Spyware.Bzub) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d311c486-7d5f-4d73-b791-ee56c47d3b2e} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7aa32fc7-133b-4ae7-998e-ced0d9829b12} (Trojan.Dialer) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d311c486-7d5f-4d73-b791-ee56c47d3b2e} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mywebsearchservice (Adware.MyWeb) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\mywebsearchservice (Adware.MyWeb) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mywebsearchservice (Adware.MyWeb) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpsr (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DataDisp32 (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\NetProject (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pe386 (Rootkit.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gsbgqpwwfw (Rootkit.Rustock) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gsbgqpwwfw (Rootkit.Rustock) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\gsbgqpwwfw (Rootkit.Rustock) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gsbgqpwwfw (Rootkit.Rustock) -> No action taken.
HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> No action taken.

Valori di registro infetti:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eegmims (Trojan.Agent.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch email plugin (Adware.MyWeb) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch email plugin (Adware.MyWeb) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\my web search bar search scope monitor (Adware.MyWeb) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch plugin (Adware.MyWeb) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\searchassistant (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\search bar (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\searchurl (Trojan.Zlob) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> No action taken.

Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\(default) (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (http://internetsearchservice.com/ie6.html) Good: (http://www.google.com/) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Cartelle infette:
C:\Programmi\MyWebSearch (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Game (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\History (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\icons (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Message (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Settings (Adware.MyWebSearch) -> No action taken.
C:\Programmi\FunWebProducts (Adware.MyWebSearch) -> No action taken.
c:\programmi\funwebproducts\ScreenSaver (Adware.MyWebSearch) -> No action taken.
c:\programmi\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> No action taken.
c:\programmi\funwebproducts\Shared (Adware.MyWebSearch) -> No action taken.
c:\programmi\funwebproducts\Shared\Cache (Adware.MyWebSearch) -> No action taken.
C:\WINDOWS\system32\441465 (Trojan.BHO) -> No action taken.

File infetti:
c:\documents and settings\Emilio\impostazioni locali\dati applicazioni\eegmims.exe (Trojan.Agent.H) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\MWSOESTB.DLL (Adware.MyWeb) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWeb) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\M3SRCHMN.EXE (Adware.MyWeb) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\M3PLUGIN.DLL (Adware.MyWeb) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\M3MSG.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\M3HTML.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\M3SKIN.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\MWSBAR.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\F3REPROX.DLL (Adware.MyWebSearch) -> No action taken.
C:\Programmi\MyWebSearch\bar\2.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> No action taken.
c:\documents and settings\Emilio\documenti\downloads\Speed-Downloading_setup (1).exe (Adware.Navipromo) -> No action taken.
c:\documents and settings\Emilio\documenti\downloads\Speed-Downloading_setup.exe (Adware.Navipromo) -> No action taken.
c:\documents and settings\localservice\impostazioni locali\temporary internet files\Content.IE5\4XU3WP2J\dkfwejkf[1].jpg (Trojan.Downloader) -> No action taken.
c:\programmi\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWeb) -> No action taken.
c:\programmi\mywebsearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWeb) -> No action taken.
c:\programmi\mywebsearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWeb) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\M3HIGHIN.EXE (Adware.MyWeb) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\M3IDLE.DLL (Adware.MyWeb) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\M3IMPIPE.EXE (Adware.MyWeb) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\M3MEDINT.EXE (Adware.MyWeb) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\M3SKPLAY.EXE (Adware.MyWeb) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\M3SLSRCH.EXE (Adware.MyWeb) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\MWSSVC.EXE (Adware.MyWeb) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\NPMYWEBS.DLL (Adware.MyWeb) -> No action taken.
c:\programmi\internet explorer\msimg32.dll (Adware.MyWebSearch) -> No action taken.
c:\programmi\windows live\messenger\msimg32.dll (Adware.MyWebSearch) -> No action taken.
c:\programmi\windows live\messenger\riched20.dll (Adware.MyWebSearch) -> No action taken.
c:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\F3SPACER.WMV (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\M3FFXTBR.MANIFEST (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\2.bin\M3NTSTBR.MANIFEST (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0003F6D4.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0003F945.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0003FB1A.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0003FD2D.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\00074525.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0016AD4C (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0016AEF2.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0016B105.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0016B54B.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0016B71F.bin (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0016B8A6 (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\0057A2D0 (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> No action taken.
c:\programmi\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> No action taken.
c:\programmi\funwebproducts\Shared\Cache\CursorManiaBtn.html (Adware.MyWebSearch) -> No action taken.
c:\programmi\funwebproducts\Shared\Cache\MyFunCardsIMBtn.html (Adware.MyWebSearch) -> No action taken.
c:\programmi\funwebproducts\Shared\Cache\SmileyCentralBtn.html (Adware.MyWebSearch) -> No action taken.
c:\programmi\funwebproducts\Shared\Cache\WebfettiBtn.html (Adware.MyWebSearch) -> No action taken.
C:\WINDOWS\system32\gsbgqpwwfw.sys (Rootkit.Rustock) -> No action taken.

grazie mille.
Sponsor
Inviato: Thursday, June 04, 2009 7:54:58 PM

 
r16
Inviato: Thursday, June 04, 2009 11:34:25 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Elimina tutto.
Rifai la scansione con MBAM, vedi se rileva ancora qualcosa.

Da Installazione Applicazioni cerca queste eventuali voci e procedi alla disinstallazione:
My Web Search (Smiley Central or FunWebProduct)
My Way Speedbar (Smiley Central o altri FunWebProduct)
My Way Speedbar (Outlook, Outlook Express, and IncrediMail)
Search Assistant - My Way

Nella cartella "Programmi" cerca ed eventualmente elimina le cartelle:
FunWebProducts
MyWebSearch
Smiley Central


Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.

Scarica Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Salvalo sul desktop.
Doppio click su combofix.exe (comparirà una videata.)
Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.
E' probabile che ti siano inviati messaggi dall'antivirus, tu ignorali.
Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.

Disinstalla combofix in questo modo: (dopo che avrò visto il log)
Start
Esegui
nella finestra di dialogo, copia ed incolla questo comando: Combofix /u e premi Invio poi cancella le cartelle in "C" di combofix (qoobox)

Posta un log aggiornato di HJT.
simo95
Inviato: Friday, June 05, 2009 1:48:05 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
Grazie 1000, r16. Dopo vado da lui, eseguo e ti faccio sapere.
simo95
Inviato: Friday, June 05, 2009 2:44:59 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
ecco il log di malwarebytes, dopo eseguo combofix:
Malwarebytes' Anti-Malware 1.37
Versione del database: 2227
Windows 5.1.2600 Service Pack 2

05/06/2009 14.33.05
mbam-log-2009-06-05 (14-33-05).txt

Tipo di scansione: Scansione completa (C:\|D:\|)
Elementi scansionati: 197203
Tempo trascorso: 50 minute(s), 32 second(s)

Processi delle memoria infetti: 1
Moduli della memoria infetti: 0
Chiavi di registro infette: 164
Valori di registro infetti: 16
Elementi dato del registro infetti: 8
Cartelle infette: 18
File infetti: 94

Processi delle memoria infetti:
C:\Programmi\MyWebSearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Unloaded process successfully.

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
HKEY_CLASSES_ROOT\e405.e405mgr (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\e405.e405mgr.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d311c486-7d5f-4d73-b791-ee56c47d3b2e} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{73364d99-1240-4dff-b12a-67e448373148} (Spyware.Bzub) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d311c486-7d5f-4d73-b791-ee56c47d3b2e} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7aa32fc7-133b-4ae7-998e-ced0d9829b12} (Trojan.Dialer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d311c486-7d5f-4d73-b791-ee56c47d3b2e} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mywebsearchservice (Adware.MyWeb) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\mywebsearchservice (Adware.MyWeb) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mywebsearchservice (Adware.MyWeb) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpsr (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DataDisp32 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NetProject (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pe386 (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gsbgqpwwfw (Rootkit.Rustock) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gsbgqpwwfw (Rootkit.Rustock) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\gsbgqpwwfw (Rootkit.Rustock) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gsbgqpwwfw (Rootkit.Rustock) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.

Valori di registro infetti:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eegmims (Trojan.Agent.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch email plugin (Adware.MyWeb) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch email plugin (Adware.MyWeb) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\my web search bar search scope monitor (Adware.MyWeb) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch plugin (Adware.MyWeb) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\searchassistant (Trojan.Zlob) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\search bar (Trojan.Zlob) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl (Trojan.Zlob) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\searchurl (Trojan.Zlob) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\(default) (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (http://internetsearchservice.com/ie6.html) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Cartelle infette:
C:\Programmi\MyWebSearch (Adware.MyWebSearch) -> Delete on reboot.
c:\programmi\mywebsearch\bar (Adware.MyWebSearch) -> Delete on reboot.
c:\programmi\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin (Adware.MyWebSearch) -> Delete on reboot.
c:\programmi\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\441465 (Trojan.BHO) -> Quarantined and deleted successfully.

File infetti:
c:\documents and settings\Emilio\impostazioni locali\dati applicazioni\eegmims.exe (Trojan.Agent.H) -> Delete on reboot.
C:\Programmi\MyWebSearch\bar\2.bin\MWSOESTB.DLL (Adware.MyWeb) -> Delete on reboot.
C:\Programmi\MyWebSearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\M3SRCHMN.EXE (Adware.MyWeb) -> Delete on reboot.
C:\Programmi\MyWebSearch\bar\2.bin\M3PLUGIN.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programmi\MyWebSearch\bar\2.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\Emilio\documenti\downloads\Speed-Downloading_setup (1).exe (Adware.Navipromo) -> Quarantined and deleted successfully.
c:\documents and settings\Emilio\documenti\downloads\Speed-Downloading_setup.exe (Adware.Navipromo) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\impostazioni locali\temporary internet files\Content.IE5\4XU3WP2J\dkfwejkf[1].jpg (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\programmi\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3HIGHIN.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3IDLE.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3IMPIPE.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3MEDINT.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3SKPLAY.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3SLSRCH.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\MWSSVC.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\NPMYWEBS.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\programmi\internet explorer\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\windows live\messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\windows live\messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3FFXTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3NTSTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0003F6D4.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0003F945.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0003FB1A.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0003FD2D.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\00074525.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0016AD4C (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0016AEF2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0016B105.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0016B54B.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0016B71F.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0016B8A6 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0057A2D0 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared\Cache\CursorManiaBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared\Cache\MyFunCardsIMBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared\Cache\SmileyCentralBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared\Cache\WebfettiBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gsbgqpwwfw.sys (Rootkit.Rustock) -> Quarantined and deleted successfully.
r16
Inviato: Friday, June 05, 2009 3:34:46 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Alcuni file infetti rilevati da MBAM, richiedono il riavvio del pc.
Devi riavviare, e rifare la scansione finchè non viene rilevato più nulla.
simo95
Inviato: Friday, June 05, 2009 3:46:07 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
Avevo già riavviato...la seconda scansione non ha rilevato nulla. Ecco il log di combofix:

ComboFix 09-06-04.08 - Emilio 05/06/2009 15.13.26.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.39.1040.18.511.213 [GMT 2:00]
Eseguito da: c:\documents and settings\Emilio\Desktop\ComboFix.exe
AV: Antivirus Trend Micro Client-Server Security Agent *On-access scanning disabled* (Outdated) {9D1A1152-196F-4AB1-B439-8A6E03D7DD5E}
AV: ThreatFire *On-access scanning enabled* (Updated) {67B2B9A1-25C8-4057-962D-807958FFC9E3}
FW: Firewall Trend Micro Client-Server Security Agent *disabled* {9D1A1152-196F-4AB1-B439-8A6E03D7DD5E}
* Creato nuovo punto di ripristino
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Emilio\IMPOST~1\Temp\IadHide4.dll
c:\documents and settings\Emilio\Impostazioni locali\Dati applicazioni\eegmims.dat
c:\documents and settings\Emilio\Impostazioni locali\Dati applicazioni\eegmims_nav.dat
c:\documents and settings\Emilio\Impostazioni locali\Dati applicazioni\eegmims_navps.dat
c:\documents and settings\Emilio\Impostazioni locali\Temp\IadHide4.dll
c:\documents and settings\Emilio\Preferiti\Videos.url
D:\Autorun.inf
D:\Desktop.ini

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_tcpsr


((((((((((((((((((((((((( Files Creati Da 2009-05-05 al 2009-06-05 )))))))))))))))))))))))))))))))))))
.

2009-06-04 13:36 . 2009-06-04 13:36 -------- d-----w- c:\documents and settings\Emilio\Dati applicazioni\Malwarebytes
2009-06-04 13:36 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-04 13:36 . 2009-06-04 13:36 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2009-06-04 13:36 . 2009-06-04 13:36 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2009-06-04 13:36 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-04 13:35 . 2009-06-05 13:06 -------- d-----w- C:\hijackthis
2009-05-31 10:25 . 2009-05-31 10:25 81920 ----a-w- c:\documents and settings\All Users\Dati applicazioni\NexonEU\NGM\npNxGameeu.dll
2009-05-31 10:25 . 2009-05-31 10:25 98304 ----a-w- c:\documents and settings\All Users\Dati applicazioni\NexonEU\NGM\nxgameeu.dll
2009-05-31 10:25 . 2009-05-31 10:25 331776 ----a-w- c:\documents and settings\All Users\Dati applicazioni\NexonEU\NGM\NGMResource.dll
2009-05-31 10:25 . 2009-05-31 10:25 258352 ----a-w- c:\documents and settings\All Users\Dati applicazioni\NexonEU\NGM\unicows.dll
2009-05-31 10:25 . 2009-05-31 10:52 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\NexonEU
2009-05-31 10:25 . 2009-05-31 10:25 532480 ----a-w- c:\documents and settings\All Users\Dati applicazioni\NexonEU\NGM\NGMDll.dll
2009-05-31 10:25 . 2009-05-31 10:25 155648 ----a-w- c:\documents and settings\All Users\Dati applicazioni\NexonEU\NGM\NGM.exe
2009-05-31 09:00 . 2009-05-31 10:29 -------- d-----w- C:\download
2009-05-31 09:00 . 2009-05-31 10:25 -------- d-----w- C:\Nexon
2009-05-31 09:00 . 2009-05-31 09:00 421888 ----a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
2009-05-20 13:41 . 2009-05-20 17:31 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Firefly Studios
2009-05-17 09:34 . 2009-06-05 12:59 -------- d-----w- c:\documents and settings\Emilio\Dati applicazioni\Free Download Manager
2009-05-17 09:34 . 2009-05-17 09:34 -------- d-----w- c:\programmi\Free Download Manager
2009-05-15 13:36 . 2009-05-15 13:36 152576 ----a-w- c:\documents and settings\Emilio\Dati applicazioni\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-13 12:02 . 2009-06-04 19:34 -------- d-----w- c:\documents and settings\LocalService\Dati applicazioni\SACore
2009-05-13 12:01 . 2009-05-13 12:01 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\SiteAdvisor
2009-05-13 12:00 . 2009-05-13 12:00 -------- d-----w- c:\programmi\File comuni\McAfee
2009-05-13 11:59 . 2009-05-13 13:37 -------- d-----w- c:\programmi\McAfee
2009-05-13 11:59 . 2009-05-13 12:00 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\McAfee
2009-05-07 01:14 . 2009-05-07 01:14 -------- d-----w- C:\CrashReport

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-04 20:24 . 2008-05-10 13:12 -------- d-----w- c:\documents and settings\Emilio\Dati applicazioni\LimeWire
2009-06-01 17:32 . 2007-03-04 10:07 -------- d-----w- c:\programmi\GameShadow
2009-05-23 12:11 . 2006-04-30 15:54 81872 ----a-w- c:\documents and settings\Emilio\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2009-05-20 17:25 . 2006-10-18 18:30 -------- d-----w- c:\programmi\Firefly Studios
2009-05-20 17:25 . 2005-12-12 22:59 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-05-05 11:51 . 2009-05-05 11:51 -------- d-----w- c:\documents and settings\Emilio\Dati applicazioni\FOG Downloader
2009-04-28 12:54 . 2009-04-28 11:56 -------- d-----w- c:\documents and settings\Emilio\Dati applicazioni\U3
2009-04-26 15:45 . 2008-05-11 17:20 -------- d-----w- c:\programmi\DivX
2009-04-26 15:45 . 2009-04-26 15:45 -------- d-----w- c:\programmi\File comuni\DivX Shared
2009-04-24 16:45 . 2009-04-24 16:45 -------- d-----w- c:\programmi\Netlog Uploader
2009-04-17 12:47 . 2009-03-19 20:59 -------- d-----w- c:\programmi\PHPNukeIT
2009-04-17 12:47 . 2009-03-19 20:39 -------- d-----w- c:\programmi\ToggleEN
2009-04-10 12:10 . 2009-04-10 12:09 -------- d-----w- c:\programmi\iTunes
2009-04-10 12:10 . 2009-04-10 12:09 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-10 12:10 . 2009-04-10 12:10 -------- d-----w- c:\programmi\iPod
2009-04-10 12:09 . 2008-04-30 18:01 -------- d-----w- c:\programmi\File comuni\Apple
2009-04-10 11:59 . 2009-04-10 11:59 75048 ----a-w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-05 15:40 . 2004-12-10 21:24 75902 ----a-w- c:\windows\system32\perfc010.dat
2009-04-05 15:40 . 2004-12-10 21:24 451608 ----a-w- c:\windows\system32\perfh010.dat
2009-03-19 14:32 . 2009-03-19 14:32 23400 ----a-w- c:\documents and settings\All Users\Dati applicazioni\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 14:32 . 2008-01-29 10:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\programmi\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\programmi\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
2009-04-17 12:47 1883672 ----a-w- c:\programmi\ToggleEN\tbTog1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2c965f3f-8efd-4bfc-a2c5-1672845fdbbf}]
2009-04-17 12:47 1883672 ----a-w- c:\programmi\PHPNukeIT\tbPHP1.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-10-10 20480]
"LogitechSoftwareUpdate"="c:\programmi\Logitech\Video\ManifestEngine.exe" [2004-10-08 196608]
"Google Update"="c:\documents and settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2008-11-25 133104]
"VeohPlugin"="c:\programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-12-16 3528440]
"Free Download Manager"="c:\programmi\Free Download Manager\fdm.exe" [2009-02-27 3399727]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-08-02 7110656]
"SpeedTouch USB Diagnostics"="c:\programmi\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"OfficeScanNT Monitor"="c:\programmi\Trend Micro\Client Server Security Agent\pccntmon.exe" [2007-04-27 399048]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"LogitechVideoRepair"="c:\programmi\Logitech\Video\ISStart.exe" [2004-10-08 458752]
"LogitechVideoTray"="c:\programmi\Logitech\Video\LogiTray.exe" [2004-10-08 217088]
"AppleSyncNotifier"="c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-05 177472]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-08-02 1519616]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-10-15 14864384]

c:\documents and settings\Francesca\Menu Avvio\Programmi\Esecuzione automatica\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-12-13 27136]

c:\documents and settings\zkb\Menu Avvio\Programmi\Esecuzione automatica\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-12-13 27136]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
HP Digital Imaging Monitor.lnk - c:\programmi\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-10-10 450560]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\avq53.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\bjc35.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\bqr80.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\cno13.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\cps28.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\cyr01.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\def10.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dwb34.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ecb28.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ffk65.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\fic73.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\gto66.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hch23.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hlg16.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\huv07.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ila72.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioi75.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\jsa33.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\kbm26.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\kgf06.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ksl34.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ktx10.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\kvs10.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\kyq25.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lav54.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lcp43.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\leh74.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\llr65.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lut85.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lyr73.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mrk06.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mxu67.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\nlo13.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\nqn60.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\nvs28.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\obj78.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\okp54.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\olf13.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\olm55.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ovk53.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ovy48.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pab04.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pjo62.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pxe58.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pxk83.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\qgh43.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\qnt34.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sjm05.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tcy43.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tqt44.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tyw78.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\upm57.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uqh51.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\val45.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vbc06.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vrd08.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wet06.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winad20.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winam34.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winas16.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winas71.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winau85.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winba27.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winbr71.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wince51.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winch58.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wincn84.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\windw66.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wineb54.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wineq01.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wineu61.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winew66.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winfo68.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winfu33.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wingf81.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winhc70.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winhg08.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winhr45.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winht02.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winif50.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winil16.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winjc27.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winjg14.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winjp23.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winju16.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winjv34.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winkh86.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winlw40.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winmk61.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winml15.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winmm60.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winmy80.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winng88.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winnm26.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winoi35.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winol44.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winom74.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winpe33.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winpg86.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winpq41.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winpv75.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winpx01.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winqm08.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winri32.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winsb45.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winsd35.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winsg61.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wintd72.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wintd88.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winuy55.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winve12.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winvi40.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winvi82.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winvo32.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winwd10.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winwi02.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winws33.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winwt01.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winwu68.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winwv07.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winxw62.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winyc65.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\winyl82.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wmd42.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wvj20.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\xcw68.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\xuj70.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ygr46.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\yhr21.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ykv81.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Programmi\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Firefly Studios\\Stronghold Crusader\\Stronghold Crusader.exe"=
"c:\\Programmi\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Games-Masters.com\\CABAL Online (Europe)\\launcher\\update\\ESTdnheadless.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\programmi\McAfee\SiteAdvisor\McSACore.exe [13/05/2009 14.00.01 210216]
R2 tmfilter;Trend Micro Filter;c:\programmi\Trend Micro\Client Server Security Agent\tmxpflt.sys [12/06/2007 19.00.54 225296]
R2 tmprefilter;Trend Micro PreFilter;c:\programmi\Trend Micro\Client Server Security Agent\tmpreflt.sys [12/06/2007 19.00.50 36368]
S3 avq53;avq53;\??\c:\windows\System32\drivers\avQ53.sys --> c:\windows\System32\drivers\avQ53.sys [?]
S3 bjc35;bjc35;\??\c:\windows\System32\drivers\bjC35.sys --> c:\windows\System32\drivers\bjC35.sys [?]
S3 bqr80;bqr80;\??\c:\windows\System32\drivers\bqR80.sys --> c:\windows\System32\drivers\bqR80.sys [?]
S3 cno13;cno13;\??\c:\windows\System32\drivers\cnO13.sys --> c:\windows\System32\drivers\cnO13.sys [?]
S3 cps28;cps28;\??\c:\windows\System32\drivers\Cps28.sys --> c:\windows\System32\drivers\Cps28.sys [?]
S3 cyr01;cyr01;\??\c:\windows\System32\drivers\Cyr01.sys --> c:\windows\System32\drivers\Cyr01.sys [?]
S3 def10;def10;\??\c:\windows\System32\drivers\Def10.sys --> c:\windows\System32\drivers\Def10.sys [?]
S3 dump_wmimmc;dump_wmimmc;\??\c:\documents and settings\Emilio\Desktop\Giovanni\Cabal\GameGuard\dump_wmimmc.sys --> c:\documents and settings\Emilio\Desktop\Giovanni\Cabal\GameGuard\dump_wmimmc.sys [?]
S3 dwb34;dwb34;\??\c:\windows\System32\drivers\Dwb34.sys --> c:\windows\System32\drivers\Dwb34.sys [?]
S3 ecb28;ecb28;\??\c:\windows\System32\drivers\ecB28.sys --> c:\windows\System32\drivers\ecB28.sys [?]
S3 ffk65;ffk65;\??\c:\windows\System32\drivers\Ffk65.sys --> c:\windows\System32\drivers\Ffk65.sys [?]
S3 fic73;fic73;\??\c:\windows\System32\drivers\fiC73.sys --> c:\windows\System32\drivers\fiC73.sys [?]
S3 gto66;gto66;\??\c:\windows\System32\drivers\gtO66.sys --> c:\windows\System32\drivers\gtO66.sys [?]
S3 hch23;hch23;\??\c:\windows\System32\drivers\Hch23.sys --> c:\windows\System32\drivers\Hch23.sys [?]
S3 hlg16;hlg16;\??\c:\windows\System32\drivers\hlG16.sys --> c:\windows\System32\drivers\hlG16.sys [?]
S3 huv07;huv07;\??\c:\windows\System32\drivers\huV07.sys --> c:\windows\System32\drivers\huV07.sys [?]
S3 ila72;ila72;\??\c:\windows\System32\drivers\ilA72.sys --> c:\windows\System32\drivers\ilA72.sys [?]
S3 ioi75;ioi75;\??\c:\windows\System32\drivers\ioI75.sys --> c:\windows\System32\drivers\ioI75.sys [?]
S3 jsa33;jsa33;\??\c:\windows\System32\drivers\jsA33.sys --> c:\windows\System32\drivers\jsA33.sys [?]
S3 kbm26;kbm26;\??\c:\windows\System32\drivers\kbM26.sys --> c:\windows\System32\drivers\kbM26.sys [?]
S3 kgf06;kgf06;\??\c:\windows\System32\drivers\kgF06.sys --> c:\windows\System32\drivers\kgF06.sys [?]
S3 ksl34;ksl34;\??\c:\windows\System32\drivers\ksL34.sys --> c:\windows\System32\drivers\ksL34.sys [?]
S3 ktx10;ktx10;\??\c:\windows\System32\drivers\ktX10.sys --> c:\windows\System32\drivers\ktX10.sys [?]
S3 kvs10;kvs10;\??\c:\windows\System32\drivers\kvS10.sys --> c:\windows\System32\drivers\kvS10.sys [?]
S3 kyq25;kyq25;\??\c:\windows\System32\drivers\Kyq25.sys --> c:\windows\System32\drivers\Kyq25.sys [?]
S3 lav54;lav54;\??\c:\windows\System32\drivers\laV54.sys --> c:\windows\System32\drivers\laV54.sys [?]
S3 lcp43;lcp43;\??\c:\windows\System32\drivers\Lcp43.sys --> c:\windows\System32\drivers\Lcp43.sys [?]
S3 leh74;leh74;\??\c:\windows\System32\drivers\leH74.sys --> c:\windows\System32\drivers\leH74.sys [?]
S3 llr65;llr65;\??\c:\windows\System32\drivers\llR65.sys --> c:\windows\System32\drivers\llR65.sys [?]
S3 lut85;lut85;\??\c:\windows\System32\drivers\luT85.sys --> c:\windows\System32\drivers\luT85.sys [?]
S3 lyr73;lyr73;\??\c:\windows\System32\drivers\lyR73.sys --> c:\windows\System32\drivers\lyR73.sys [?]
S3 mrk06;mrk06;\??\c:\windows\System32\drivers\Mrk06.sys --> c:\windows\System32\drivers\Mrk06.sys [?]
S3 mxu67;mxu67;\??\c:\windows\System32\drivers\mxU67.sys --> c:\windows\System32\drivers\mxU67.sys [?]
S3 nlo13;nlo13;\??\c:\windows\System32\drivers\nlO13.sys --> c:\windows\System32\drivers\nlO13.sys [?]
S3 nqn60;nqn60;\??\c:\windows\System32\drivers\nqN60.sys --> c:\windows\System32\drivers\nqN60.sys [?]
S3 nvs28;nvs28;\??\c:\windows\System32\drivers\Nvs28.sys --> c:\windows\System32\drivers\Nvs28.sys [?]
S3 obj78;obj78;\??\c:\windows\System32\drivers\obJ78.sys --> c:\windows\System32\drivers\obJ78.sys [?]
S3 okp54;okp54;\??\c:\windows\System32\drivers\okP54.sys --> c:\windows\System32\drivers\okP54.sys [?]
S3 olf13;olf13;\??\c:\windows\System32\drivers\Olf13.sys --> c:\windows\System32\drivers\Olf13.sys [?]
S3 olm55;olm55;\??\c:\windows\System32\drivers\olM55.sys --> c:\windows\System32\drivers\olM55.sys [?]
S3 ovk53;ovk53;\??\c:\windows\System32\drivers\ovK53.sys --> c:\windows\System32\drivers\ovK53.sys [?]
S3 ovy48;ovy48;\??\c:\windows\System32\drivers\ovY48.sys --> c:\windows\System32\drivers\ovY48.sys [?]
S3 pab04;pab04;\??\c:\windows\System32\drivers\paB04.sys --> c:\windows\System32\drivers\paB04.sys [?]
S3 pjo62;pjo62;\??\c:\windows\System32\drivers\Pjo62.sys --> c:\windows\System32\drivers\Pjo62.sys [?]
S3 pxe58;pxe58;\??\c:\windows\System32\drivers\pxE58.sys --> c:\windows\System32\drivers\pxE58.sys [?]
S3 pxk83;pxk83;\??\c:\windows\System32\drivers\Pxk83.sys --> c:\windows\System32\drivers\Pxk83.sys [?]
S3 qgh43;qgh43;\??\c:\windows\System32\drivers\qgH43.sys --> c:\windows\System32\drivers\qgH43.sys [?]
S3 qnt34;qnt34;\??\c:\windows\System32\drivers\qnT34.sys --> c:\windows\System32\drivers\qnT34.sys [?]
S3 sjm05;sjm05;\??\c:\windows\System32\drivers\sjM05.sys --> c:\windows\System32\drivers\sjM05.sys [?]
S3 tcy43;tcy43;\??\c:\windows\System32\drivers\tcY43.sys --> c:\windows\System32\drivers\tcY43.sys [?]
S3 tqt44;tqt44;\??\c:\windows\System32\drivers\Tqt44.sys --> c:\windows\System32\drivers\Tqt44.sys [?]
S3 tyw78;tyw78;\??\c:\windows\System32\drivers\Tyw78.sys --> c:\windows\System32\drivers\Tyw78.sys [?]
S3 upm57;upm57;\??\c:\windows\System32\drivers\upM57.sys --> c:\windows\System32\drivers\upM57.sys [?]
S3 uqh51;uqh51;\??\c:\windows\System32\drivers\Uqh51.sys --> c:\windows\System32\drivers\Uqh51.sys [?]
S3 val45;val45;\??\c:\windows\System32\drivers\Val45.sys --> c:\windows\System32\drivers\Val45.sys [?]
S3 vbc06;vbc06;\??\c:\windows\System32\drivers\vbC06.sys --> c:\windows\System32\drivers\vbC06.sys [?]
S3 vrd08;vrd08;\??\c:\windows\System32\drivers\Vrd08.sys --> c:\windows\System32\drivers\Vrd08.sys [?]
S3 wet06;wet06;\??\c:\windows\System32\drivers\Wet06.sys --> c:\windows\System32\drivers\Wet06.sys [?]
S3 winad20;winad20;\??\c:\windows\System32\drivers\Winad20.sys --> c:\windows\System32\drivers\Winad20.sys [?]
S3 winam34;winam34;\??\c:\windows\System32\drivers\Winam34.sys --> c:\windows\System32\drivers\Winam34.sys [?]
S3 winas16;winas16;\??\c:\windows\System32\drivers\Winas16.sys --> c:\windows\System32\drivers\Winas16.sys [?]
S3 winas71;winas71;\??\c:\windows\System32\drivers\Winas71.sys --> c:\windows\System32\drivers\Winas71.sys [?]
S3 winau85;winau85;\??\c:\windows\System32\drivers\Winau85.sys --> c:\windows\System32\drivers\Winau85.sys [?]
S3 winba27;winba27;\??\c:\windows\System32\drivers\Winba27.sys --> c:\windows\System32\drivers\Winba27.sys [?]
S3 winbr71;winbr71;\??\c:\windows\System32\drivers\Winbr71.sys --> c:\windows\System32\drivers\Winbr71.sys [?]
S3 wince51;wince51;\??\c:\windows\System32\drivers\Wince51.sys --> c:\windows\System32\drivers\Wince51.sys [?]
S3 winch58;winch58;\??\c:\windows\System32\drivers\Winch58.sys --> c:\windows\System32\drivers\Winch58.sys [?]
S3 wincn84;wincn84;\??\c:\windows\System32\drivers\Wincn84.sys --> c:\windows\System32\drivers\Wincn84.sys [?]
S3 windw66;windw66;\??\c:\windows\System32\drivers\Windw66.sys --> c:\windows\System32\drivers\Windw66.sys [?]
S3 wineb54;wineb54;\??\c:\windows\System32\drivers\Wineb54.sys --> c:\windows\System32\drivers\Wineb54.sys [?]
S3 wineq01;wineq01;\??\c:\windows\System32\drivers\Wineq01.sys --> c:\windows\System32\drivers\Wineq01.sys [?]
S3 wineu61;wineu61;\??\c:\windows\System32\drivers\Wineu61.sys --> c:\windows\System32\drivers\Wineu61.sys [?]
S3 winew66;winew66;\??\c:\windows\System32\drivers\Winew66.sys --> c:\windows\System32\drivers\Winew66.sys [?]
S3 winfo68;winfo68;\??\c:\windows\System32\drivers\Winfo68.sys --> c:\windows\System32\drivers\Winfo68.sys [?]
S3 winfu33;winfu33;\??\c:\windows\System32\drivers\Winfu33.sys --> c:\windows\System32\drivers\Winfu33.sys [?]
S3 wingf81;wingf81;\??\c:\windows\System32\drivers\Wingf81.sys --> c:\windows\System32\drivers\Wingf81.sys [?]
S3 winhc70;winhc70;\??\c:\windows\System32\drivers\Winhc70.sys --> c:\windows\System32\drivers\Winhc70.sys [?]
S3 winhg08;winhg08;\??\c:\windows\System32\drivers\Winhg08.sys --> c:\windows\System32\drivers\Winhg08.sys [?]
S3 winhr45;winhr45;\??\c:\windows\System32\drivers\Winhr45.sys --> c:\windows\System32\drivers\Winhr45.sys [?]
S3 winht02;winht02;\??\c:\windows\System32\drivers\Winht02.sys --> c:\windows\System32\drivers\Winht02.sys [?]
S3 winif50;winif50;\??\c:\windows\System32\drivers\Winif50.sys --> c:\windows\System32\drivers\Winif50.sys [?]
S3 winil16;winil16;\??\c:\windows\System32\drivers\Winil16.sys --> c:\windows\System32\drivers\Winil16.sys [?]
S3 winjc27;winjc27;\??\c:\windows\System32\drivers\Winjc27.sys --> c:\windows\System32\drivers\Winjc27.sys [?]
S3 winjg14;winjg14;\??\c:\windows\System32\drivers\Winjg14.sys --> c:\windows\System32\drivers\Winjg14.sys [?]
S3 winjp23;winjp23;\??\c:\windows\System32\drivers\Winjp23.sys --> c:\windows\System32\drivers\Winjp23.sys [?]
S3 winju16;winju16;\??\c:\windows\System32\drivers\Winju16.sys --> c:\windows\System32\drivers\Winju16.sys [?]
S3 winjv34;winjv34;\??\c:\windows\System32\drivers\Winjv34.sys --> c:\windows\System32\drivers\Winjv34.sys [?]
S3 winkh86;winkh86;\??\c:\windows\System32\drivers\Winkh86.sys --> c:\windows\System32\drivers\Winkh86.sys [?]
S3 winlw40;winlw40;\??\c:\windows\System32\drivers\Winlw40.sys --> c:\windows\System32\drivers\Winlw40.sys [?]
S3 winmk61;winmk61;\??\c:\windows\System32\drivers\Winmk61.sys --> c:\windows\System32\drivers\Winmk61.sys [?]
S3 winml15;winml15;\??\c:\windows\System32\drivers\Winml15.sys --> c:\windows\System32\drivers\Winml15.sys [?]
S3 winmm60;winmm60;\??\c:\windows\System32\drivers\Winmm60.sys --> c:\windows\System32\drivers\Winmm60.sys [?]
S3 winmy80;winmy80;\??\c:\windows\System32\drivers\Winmy80.sys --> c:\windows\System32\drivers\Winmy80.sys [?]
S3 winng88;winng88;\??\c:\windows\System32\drivers\Winng88.sys --> c:\windows\System32\drivers\Winng88.sys [?]
S3 winnm26;winnm26;\??\c:\windows\System32\drivers\Winnm26.sys --> c:\windows\System32\drivers\Winnm26.sys [?]
S3 winoi35;winoi35;\??\c:\windows\System32\drivers\Winoi35.sys --> c:\windows\System32\drivers\Winoi35.sys [?]
S3 winol44;winol44;\??\c:\windows\System32\drivers\Winol44.sys --> c:\windows\System32\drivers\Winol44.sys [?]
S3 winom74;winom74;\??\c:\windows\System32\drivers\Winom74.sys --> c:\windows\System32\drivers\Winom74.sys [?]
S3 winpe33;winpe33;\??\c:\windows\System32\drivers\Winpe33.sys --> c:\windows\System32\drivers\Winpe33.sys [?]
S3 winpg86;winpg86;\??\c:\windows\System32\drivers\Winpg86.sys --> c:\windows\System32\drivers\Winpg86.sys [?]
S3 winpq41;winpq41;\??\c:\windows\System32\drivers\Winpq41.sys --> c:\windows\System32\drivers\Winpq41.sys [?]
S3 winpv75;winpv75;\??\c:\windows\System32\drivers\Winpv75.sys --> c:\windows\System32\drivers\Winpv75.sys [?]
S3 winpx01;winpx01;\??\c:\windows\System32\drivers\Winpx01.sys --> c:\windows\System32\drivers\Winpx01.sys [?]
S3 winqm08;winqm08;\??\c:\windows\System32\drivers\Winqm08.sys --> c:\windows\System32\drivers\Winqm08.sys [?]
S3 winri32;winri32;\??\c:\windows\System32\drivers\Winri32.sys --> c:\windows\System32\drivers\Winri32.sys [?]
S3 winsb45;winsb45;\??\c:\windows\System32\drivers\Winsb45.sys --> c:\windows\System32\drivers\Winsb45.sys [?]
S3 winsd35;winsd35;\??\c:\windows\System32\drivers\Winsd35.sys --> c:\windows\System32\drivers\Winsd35.sys [?]
S3 winsg61;winsg61;\??\c:\windows\System32\drivers\Winsg61.sys --> c:\windows\System32\drivers\Winsg61.sys [?]
S3 wintd72;wintd72;\??\c:\windows\System32\drivers\Wintd72.sys --> c:\windows\System32\drivers\Wintd72.sys [?]
S3 wintd88;wintd88;\??\c:\windows\System32\drivers\Wintd88.sys --> c:\windows\System32\drivers\Wintd88.sys [?]
S3 winuy55;winuy55;\??\c:\windows\System32\drivers\Winuy55.sys --> c:\windows\System32\drivers\Winuy55.sys [?]
S3 winve12;winve12;\??\c:\windows\System32\drivers\Winve12.sys --> c:\windows\System32\drivers\Winve12.sys [?]
S3 winvi40;winvi40;\??\c:\windows\System32\drivers\Winvi40.sys --> c:\windows\System32\drivers\Winvi40.sys [?]
S3 winvi82;winvi82;\??\c:\windows\System32\drivers\Winvi82.sys --> c:\windows\System32\drivers\Winvi82.sys [?]
S3 winvo32;winvo32;\??\c:\windows\System32\drivers\Winvo32.sys --> c:\windows\System32\drivers\Winvo32.sys [?]
S3 winwd10;winwd10;\??\c:\windows\System32\drivers\Winwd10.sys --> c:\windows\System32\drivers\Winwd10.sys [?]
S3 winwi02;winwi02;\??\c:\windows\System32\drivers\Winwi02.sys --> c:\windows\System32\drivers\Winwi02.sys [?]
S3 winws33;winws33;\??\c:\windows\System32\drivers\Winws33.sys --> c:\windows\System32\drivers\Winws33.sys [?]
S3 winwt01;winwt01;\??\c:\windows\System32\drivers\Winwt01.sys --> c:\windows\System32\drivers\Winwt01.sys [?]
S3 winwu68;winwu68;\??\c:\windows\System32\drivers\Winwu68.sys --> c:\windows\System32\drivers\Winwu68.sys [?]
S3 winwv07;winwv07;\??\c:\windows\System32\drivers\Winwv07.sys --> c:\windows\System32\drivers\Winwv07.sys [?]
S3 winxw62;winxw62;\??\c:\windows\System32\drivers\Winxw62.sys --> c:\windows\System32\drivers\Winxw62.sys [?]
S3 winyc65;winyc65;\??\c:\windows\System32\drivers\Winyc65.sys --> c:\windows\System32\drivers\Winyc65.sys [?]
S3 winyl82;winyl82;\??\c:\windows\System32\drivers\Winyl82.sys --> c:\windows\System32\drivers\Winyl82.sys [?]
S3 wmd42;wmd42;\??\c:\windows\System32\drivers\wmD42.sys --> c:\windows\System32\drivers\wmD42.sys [?]
S3 wvj20;wvj20;\??\c:\windows\System32\drivers\wvJ20.sys --> c:\windows\System32\drivers\wvJ20.sys [?]
S3 xcw68;xcw68;\??\c:\windows\System32\drivers\Xcw68.sys --> c:\windows\System32\drivers\Xcw68.sys [?]
S3 xuj70;xuj70;\??\c:\windows\System32\drivers\xuJ70.sys --> c:\windows\System32\drivers\xuJ70.sys [?]
S3 ygr46;ygr46;\??\c:\windows\System32\drivers\Ygr46.sys --> c:\windows\System32\drivers\Ygr46.sys [?]
S3 yhr21;yhr21;\??\c:\windows\System32\drivers\Yhr21.sys --> c:\windows\System32\drivers\Yhr21.sys [?]
S3 ykv81;ykv81;\??\c:\windows\System32\drivers\ykV81.sys --> c:\windows\System32\drivers\ykV81.sys [?]
S4 LogKpu;LogKpu;"\\?\c:\programmi\File comuni\System\com4.exe" --> \\?\c:\programmi\File comuni\System\com4.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenuto della cartella 'Scheduled Tasks'

2009-05-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2007-08-29 10:34]

2009-06-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2821843351-1064444744-683492359-1010.job
- c:\documents and settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2008-11-25 12:19]

2009-06-05 c:\windows\Tasks\RegCure Program Check.job
- c:\programmi\RegCure\RegCure.exe [2008-04-21 21:21]

2009-05-07 c:\windows\Tasks\RegCure.job
- c:\programmi\RegCure\RegCure.exe [2008-04-21 21:21]

2009-06-05 c:\windows\Tasks\User_Feed_Synchronization-{11ADD861-CF62-41EB-8F5D-46A3D43A6B38}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 01:01]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKCU-Run-GameShadow - c:\programmi\GameShadow\GameShadow.exe
SafeBoot-mwf34.sys
SafeBoot-procexp90.Sys


.
------- Scansione supplementare -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = 687474703a2f2f7777772e676f6f676c652e636f6d2f
mSearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1;localhost;*.local
mSearchURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
IE: &Search
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Scarica con Free Download Manager - file://c:\programmi\Free Download Manager\dllink.htm
IE: Scarica i video con Free Download Manager - file://c:\programmi\Free Download Manager\dlfvideo.htm
IE: Scarica selezionati con Free Download Manager - file://c:\programmi\Free Download Manager\dlselected.htm
IE: Scarica tutto con Free Download Manager - file://c:\programmi\Free Download Manager\dlall.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Emilio\Dati applicazioni\Mozilla\Firefox\Profiles\7vy62lo4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2102507&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=it-IT&FORM=MICI05&q=
FF - component: c:\programmi\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - component: c:\programmi\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\All Users\Dati applicazioni\NexonEU\NGM\npNxGameeu.dll
FF - plugin: c:\documents and settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\programmi\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmi\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\programmi\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-05 15:20
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(3440)
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSIT.DLL
c:\programmi\McAfee\SiteAdvisor\saHook.dll
c:\programmi\iTunes\iTunesMiniPlayer.dll
c:\programmi\iTunes\iTunesMiniPlayer.Resources\it.lproj\iTunesMiniPlayerLocalized.dll
c:\programmi\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmi\Trend Micro\Client Server Security Agent\NTRtScan.exe
c:\windows\system32\nvsvc32.exe
c:\programmi\Trend Micro\Client Server Security Agent\TmListen.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\programmi\Trend Micro\Client Server Security Agent\POP3Trap.exe
c:\programmi\Logitech\Video\FxSvr2.exe
c:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2009-06-05 15.28.53 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-06-05 13:28

Pre-Run: 157.059.649.536 byte disponibili
Post-Run: 157.010.956.288 byte disponibili

632 --- E O F --- 2008-02-22 17:59
r16
Inviato: Friday, June 05, 2009 4:03:15 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Posta un log di HJT.
Chiedi al tuo amico se è disponibile a disistallare McAfee , per installare Avira. (in cui vedo tracce di Avira nel log di Combofix)
Lo trovi anche nel sito Aiutamici.
Per disistallare McAfee:
http://majorgeeks.com/downloadget.php?id=5420&file=1&evp=24176563d608d7bfb04f95b4c72f1b9e
Pagina istruzioni:
http://www.majorgeeks.com/McAfee_Consumer_Product_Removal_Tool_d5420.html
simo95
Inviato: Friday, June 05, 2009 4:28:19 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
Come antivirus ha installato non ha mcAfee ma trend micro client server(...e non ricordo il resto). Gli avevo già consigliato avg 8.5 o avira 9. (forse le voci di mcAfee appartengono a siteadvisor) Oro vado a casa sua e faccio Hjt.
Grazie, aspetto tue istruzioni.
Simone
simo95
Inviato: Friday, June 05, 2009 5:26:45 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17.26.03, on 05/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\McAfee\SiteAdvisor\McSACore.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Programmi\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmi\Logitech\Video\LogiTray.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Documents and Settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe
C:\Programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\Programmi\Free Download Manager\fdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\TEMP\OQ9FF7.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\Trend Micro\Client Server Security Agent\TSC.EXE
C:\Programmi\Trend Micro\Client Server Security Agent\Pop3Trap.exe
C:\Programmi\Logitech\Video\FxSvr2.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Programmi\ToggleEN\tbTog1.dll
R3 - URLSearchHook: PHPNukeIT Toolbar - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - C:\Programmi\PHPNukeIT\tbPHP1.dll
O2 - BHO: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Programmi\ToggleEN\tbTog1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PHPNukeIT Toolbar - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - C:\Programmi\PHPNukeIT\tbPHP1.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Programmi\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programmi\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programmi\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programmi\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programmi\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Programmi\ToggleEN\tbTog1.dll
O3 - Toolbar: PHPNukeIT Toolbar - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - C:\Programmi\PHPNukeIT\tbPHP1.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Programmi\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programmi\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmi\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmi\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programmi\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [VeohPlugin] "C:\Programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
O4 - HKCU\..\Run: [Free Download Manager] "C:\Programmi\Free Download Manager\fdm.exe" -autorun
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Scarica con Free Download Manager - file://C:\Programmi\Free Download Manager\dllink.htm
O8 - Extra context menu item: Scarica i video con Free Download Manager - file://C:\Programmi\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Scarica selezionati con Free Download Manager - file://C:\Programmi\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Scarica tutto con Free Download Manager - file://C:\Programmi\Free Download Manager\dlall.htm
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Guida alla connessione - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Guida alla connessione - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {5d6f45b3-9043-443d-a792-115447494d24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {bd393c14-72ad-4790-a095-76522973d6b8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Programmi\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Scansione in tempo reale di Trend Micro Client/Server Security Agent (ntrtscan) - Trend Micro Inc. - C:\Programmi\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Personal Firewall di Trend Micro Client/Server Security Agent (ofcpfwsvc) - Trend Micro Inc. - C:\Programmi\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Programmi\Trend Micro\Client Server Security Agent\tmlisten.exe

--
End of file - 11496 bytes
r16
Inviato: Friday, June 05, 2009 10:46:20 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Ha tutto il pc incasinato...
Disattiva il ripristino configurazione di sistema, e tienilo disattivato, fino alla soluzione del problema http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121
Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su fix checked
R3 - URLSearchHook: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Programmi\ToggleEN\tbTog1.dll
R3 - URLSearchHook: PHPNukeIT Toolbar - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - C:\Programmi\PHPNukeIT\tbPHP1.dll
O2 - BHO: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Programmi\ToggleEN\tbTog1.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Programmi\AVG\AVG8\avgssie.dll (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
TUTTE le 016

Trova e cancella i file in rosso:
C:\WINDOWS\TEMP\OQ9FF7.EXE

Scarica VIRIT :
http://www.tgsoft.it/italy/download.htm lo aggiorni (cliccando sulla parabola in alto) e fai la scansione in Modalità Provvisoria (è molto importante).
Posta anche il log. (lo trovi sull'icona in alto, con raffigurato un block notes ,con una penna)
Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223

Riavvia il computer.
Posta un nuovo log di HJT, e riferisci i problemi che riscontra.
simo95
Inviato: Saturday, June 06, 2009 8:49:02 AM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
Ok, questo pomeriggio eseguo. Per il momento grazie, ci sentiamo più tardi. Per ora i sintomi sono una lentezza impressionante del pc e prima della pulizia con malwarebytes non riuscivo ad installare una versione aggiornata di ccleaner (mentre ora sono riuscito) e, ogni tanto, il pc si riavviava da solo.
r16
Inviato: Saturday, June 06, 2009 11:34:39 AM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao simo95 .
Se il tuo amico vuole sistemare un pò quel pc, deve disistallare il suo attuale antivirus, e installare Avira.
Disistallare McAfee SiteAdvisor Service .
Aggiornare il S.O, e tutti quei programmi obsoleti che si ritrova.
Altrimenti, non se ne viene a capo.
simo95
Inviato: Saturday, June 06, 2009 12:53:14 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
e si, ieri ho fatto partire il winndows update e aveva bisogno di 48 aggiornamenti critici, oltre che installare l' sp3 ecc ecc. Comunque oggi gli parlo e ti so dire.
simo95
Inviato: Saturday, June 06, 2009 4:36:49 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
Mentre facevo la scansione con virit un fulmine ha fatto mancare la corrente e avrei dovuto far riavviare tutta la scansione, ma non c'era tempo...Per ora non posso fare altro, credo che ci risentiremo lunedì. Per ora grazie mille per la pazienza.
Simone
r16
Inviato: Saturday, June 06, 2009 7:42:59 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
simo95 ha scritto:
Mentre facevo la scansione con virit un fulmine ha fatto mancare la corrente

Ma digli al tuo amico, che vada a Lourdes a farsi benedire.....(che sfiga).
Questi "inconvenienti", possono essere letali per la salute del pc.
Specialmente durante una scansione.
simo95
Inviato: Saturday, June 06, 2009 8:14:28 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
Eh si, sapevo che era rischioso frlo durante una bella tempesta (da quanta grandine è scesa sembrava che avesse nevicato)...una bella mazzata per l'hardaware..ho preso un colpo qunando si è spento, sperando che il pc si riavviasse senza problemi..è andata liscia, per fortuna...
simo95
Inviato: Sunday, June 07, 2009 1:19:30 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
r16 ha scritto:
Ciao.
Ha tutto il pc incasinato...
Disattiva il ripristino configurazione di sistema, e tienilo disattivato, fino alla soluzione del problema http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121
Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su fix checked
R3 - URLSearchHook: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Programmi\ToggleEN\tbTog1.dll
R3 - URLSearchHook: PHPNukeIT Toolbar - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - C:\Programmi\PHPNukeIT\tbPHP1.dll
O2 - BHO: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Programmi\ToggleEN\tbTog1.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Programmi\AVG\AVG8\avgssie.dll (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Emilio\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
TUTTE le 016

Trova e cancella i file in rosso:
C:\WINDOWS\TEMP\OQ9FF7.EXE

Scarica VIRIT :
http://www.tgsoft.it/italy/download.htm lo aggiorni (cliccando sulla parabola in alto) e fai la scansione in Modalità Provvisoria (è molto importante).
Posta anche il log. (lo trovi sull'icona in alto, con raffigurato un block notes ,con una penna)
Dai una pulita (registro compreso)con CCleaner http://www.aiutaamici.com/software?ID=11223

Riavvia il computer.
Posta un nuovo log di HJT, e riferisci i problemi che riscontra.

Ecco fatto adesso ti dò il log di virit:(Non ho potuto togliere i virus dal pc del mio amico perchè aveva il programma da tanto tempo e la licenza gli era scaduta)
VirIT eXplorer Lite Log

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

29/01/2007 - 19:17:09

[SCANSIONE DEL REGISTRO]
{2a6af021-17a2-4014-8624-cf6015f82fad} Infetto da BHO.Agent.BA
* * * RIMOSSO * * *
{73364D99-1240-4dff-B12A-67E448373148} Infetto da Trojan.Win32.Agent.AHY
* * * RIMOSSO * * *

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\5C.tmp Infetto da BHO.Agent.BA
* * * RIMOSSO * * *
C:\Documents and Settings\Giovanni\Impostazioni locali\Temp\hmn.exe Infetto da Trojan.Win32.Small.OA
* * * RIMOSSO * * *
C:\Documents and Settings\Giovanni\Impostazioni locali\Temp\it_0183.exe Infetto da Trojan.Win32.Dialer.IH
* * * RIMOSSO * * *
C:\Documents and Settings\Giovanni\Impostazioni locali\Temporary Internet Files\Content.IE5\I1B3P83J\counter21[1].php Infetto da Trojan.Win32.Small.OA
* * * RIMOSSO * * *
C:\Documents and Settings\Giovanni\Impostazioni locali\Temporary Internet Files\Content.IE5\I1B3P83J\service32[1].exe Infetto da Trojan.Win32.Small.NE
* * * RIMOSSO * * *
C:\Programmi\247Cams\Camnotifier.exe Infetto da Adware.MetaDirect.A
* * * RIMOSSO * * *
C:\Programmi\License_Manager\license_manager.exe Infetto da Adware.MovieLand.A
* * * RIMOSSO * * *
C:\quarantine\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft
C:\WINDOWS\12112761190.exe Infetto da Trojan.Win32.Small.NE
* * * RIMOSSO * * *
C:\WINDOWS\system32\mlaa.dll Infetto da BHO.Agent.BA
* * * RIMOSSO * * *

[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]


[G:]
BOOT SECTOR: OK


[H:]
BOOT SECTOR: OK


[I:]
BOOT SECTOR: OK


[J:]
BOOT SECTOR: OK


[K:]


[L:]


Chiavi Registro infette: 2.
Files Infetti: 10.
Files Sospetti: 0.
Files Analizzati: 71492.
Files Totali: 71492.
Chiavi Registro rimosse: 2.
Virus Rimossi: 9.

[SCANSIONE DELLA MEMORIA]
OK

02/02/2007 - 19:54:50

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\quarantine\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 53015.
Files Totali: 53015.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

02/02/2007 - 20:25:32

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

03/02/2007 - 12:41:55

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

03/02/2007 - 12:58:09

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

03/02/2007 - 13:37:28

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

03/02/2007 - 13:41:16

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

03/02/2007 - 14:59:57

[SCANSIONE DELLA MEMORIA]
OK

03/02/2007 - 17:42:27

[SCANSIONE DELLA MEMORIA]
OK

04/02/2007 - 20:02:41

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\quarantine\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 56519.
Files Totali: 56519.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
[SCANSIONE DELLA MEMORIA]
OK

05/02/2007 - 13:41:44

[SCANSIONE DELLA MEMORIA]
OK

05/02/2007 - 19:00:41

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\quarantine\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 56543.
Files Totali: 56543.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

Adesso puoi RIAVVIARE il computer per spostare il file nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

06/02/2007 - 12:50:42

[SCANSIONE DELLA MEMORIA]
OK

06/02/2007 - 15:55:21

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

06/02/2007 - 18:38:11

[SCANSIONE DELLA MEMORIA]
OK

06/02/2007 - 20:57:30

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

07/02/2007 - 13:39:08

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

07/02/2007 - 14:31:06

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

07/02/2007 - 17:00:04

[SCANSIONE DELLA MEMORIA]
OK

07/02/2007 - 17:58:51

[SCANSIONE DEL REGISTRO]
OK

[C:]
[SCANSIONE DELLA MEMORIA]
OK

07/02/2007 - 20:10:45

[SCANSIONE DELLA MEMORIA]
OK

08/02/2007 - 13:50:55

[SCANSIONE DELLA MEMORIA]
[SCANSIONE DELLA MEMORIA]
OK

08/02/2007 - 14:01:26

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft
[SCANSIONE DELLA MEMORIA]
OK

08/02/2007 - 18:39:24

[SCANSIONE DELLA MEMORIA]
OK

09/02/2007 - 13:46:05

[SCANSIONE DELLA MEMORIA]
OK

09/02/2007 - 19:45:33

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
[SCANSIONE DELLA MEMORIA]
OK

10/02/2007 - 13:09:38

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

10/02/2007 - 13:46:20

[SCANSIONE DELLA MEMORIA]
OK

11/02/2007 - 11:57:33

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

11/02/2007 - 13:36:11

[SCANSIONE DELLA MEMORIA]
OK

11/02/2007 - 16:20:44

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

11/02/2007 - 16:40:42

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

12/02/2007 - 12:48:16

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

12/02/2007 - 16:38:10

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

12/02/2007 - 19:53:53

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

13/02/2007 - 12:43:22

[SCANSIONE DELLA MEMORIA]
OK

13/02/2007 - 13:15:03

[SCANSIONE DELLA MEMORIA]
OK

13/02/2007 - 18:31:57

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

13/02/2007 - 18:35:00

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

13/02/2007 - 19:20:17

[SCANSIONE DELLA MEMORIA]
OK

14/02/2007 - 07:33:11

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
[SCANSIONE DELLA MEMORIA]
OK

14/02/2007 - 08:49:09

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

14/02/2007 - 13:44:57

[SCANSIONE DELLA MEMORIA]
OK

14/02/2007 - 19:05:36

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

14/02/2007 - 20:19:36

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

15/02/2007 - 15:02:28

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

15/02/2007 - 15:06:12

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 57649.
Files Totali: 57649.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

Adesso puoi RIAVVIARE il computer per spostare il file nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

15/02/2007 - 16:13:56

[SCANSIONE DELLA MEMORIA]
OK

15/02/2007 - 20:05:08

[SCANSIONE DELLA MEMORIA]
OK

16/02/2007 - 12:17:20

[SCANSIONE DELLA MEMORIA]
OK

16/02/2007 - 13:41:02

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft
[SCANSIONE DELLA MEMORIA]
OK

16/02/2007 - 16:16:29

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft
[SCANSIONE DELLA MEMORIA]
OK

17/02/2007 - 12:52:14

[SCANSIONE DELLA MEMORIA]
OK

17/02/2007 - 18:17:47

[SCANSIONE DELLA MEMORIA]
OK

17/02/2007 - 20:52:11

[SCANSIONE DEL REGISTRO]
{14D1A72D-8705-11D8-B120-0040F46CB696} Infetto da BHO.Agent.AZ
* * * RIMOSSO * * *

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Adriano\Desktop\216154826.dll Infetto da BHO.Agent.AZ
[SCANSIONE DELLA MEMORIA]
OK

18/02/2007 - 19:22:51

[SCANSIONE DELLA MEMORIA]
OK

19/02/2007 - 13:24:59

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 55909.
Files Totali: 55909.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

Adesso puoi RIAVVIARE il computer per spostare il file nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

19/02/2007 - 17:03:23

[SCANSIONE DELLA MEMORIA]
OK

19/02/2007 - 17:45:59

[SCANSIONE DEL REGISTRO]
{14D1A72D-8705-11D8-B120-0040F46CB696} Infetto da BHO.Agent.AZ
* * * RIMOSSO * * *

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

19/02/2007 - 18:02:30

[SCANSIONE DELLA MEMORIA]
OK

20/02/2007 - 10:34:05

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Adriano\Impostazioni locali\Temp\winsyst32.exe Infetto da Trojan.Win32.Agent.AOJ
* * * RIMOSSO * * *
C:\DOCUMENTS AND SETTINGS\ADRIANO\IMPOSTAZIONI LOCALI\TEMPORARY INTERNET FILES\CONTENT.IE5\45Q3WDI3\2142[1].ZIP -> Cazzi Duri e Lunghi.URL Infetto da HTML.LinkShare.A
* * * RIMOSSO * * *
C:\Documents and Settings\Adriano\Impostazioni locali\Temporary Internet Files\Content.IE5\SXYFGPUR\winhp32[1].exe Infetto da Trojan.Win32.Small.OW
* * * RIMOSSO * * *
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft
C:\quarantine\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.
C:\RECYCLER\S-1-5-21-2821843351-1064444744-683492359-1012\Dc2.dll Infetto da BHO.Agent.AZ
* * * RIMOSSO * * *
C:\RECYCLER\S-1-5-21-2821843351-1064444744-683492359-1012\Dc3.dll Infetto da BHO.Agent.AZ
* * * RIMOSSO * * *
C:\WINDOWS\12155100116.exe Infetto da Trojan.Win32.Small.OW
* * * RIMOSSO * * *

Chiavi Registro infette: 0.
Files Infetti: 8.
Files Sospetti: 0.
Files Analizzati: 57562.
Files Totali: 57562.
Chiavi Registro rimosse: 0.
Virus Rimossi: 6.

Adesso puoi RIAVVIARE il computer per spostare il file nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

20/02/2007 - 10:56:17

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

20/02/2007 - 12:38:24

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
[SCANSIONE DELLA MEMORIA]
OK

20/02/2007 - 12:48:09

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Contattare il Supporto Tecnico TG Soft

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 56004.
Files Totali: 56004.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

Adesso puoi RIAVVIARE il computer per spostare il file nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

20/02/2007 - 13:18:28

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 56036.
Files Totali: 56036.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

Adesso puoi RIAVVIARE il computer per spostare il file nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

20/02/2007 - 20:27:31

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

21/02/2007 - 13:07:34

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 56066.
Files Totali: 56066.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

Adesso puoi RIAVVIARE il computer per spostare il file nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

22/02/2007 - 15:11:07

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 56072.
Files Totali: 56072.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

Adesso puoi RIAVVIARE il computer per spostare il file nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

22/02/2007 - 21:14:04

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 12:09:08

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 12:13:47

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 12:17:35

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 12:40:13

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 13:55:39

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 14:00:25

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 14:05:04

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 17:14:34

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 17:19:24

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 17:26:49

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 17:30:22

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 17:35:23

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 17:39:07

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 17:44:16

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 17:55:47

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 21:04:56

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

23/02/2007 - 21:20:38

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

24/02/2007 - 13:56:32

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

24/02/2007 - 15:46:08

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

24/02/2007 - 20:09:35

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

24/02/2007 - 21:36:58

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

24/02/2007 - 21:48:52

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

24/02/2007 - 23:18:36

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

25/02/2007 - 12:37:28

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

25/02/2007 - 13:26:41

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Contattare il Supporto Tecnico TG Soft
[SCANSIONE DELLA MEMORIA]
OK

25/02/2007 - 16:18:20

[SCANSIONE DELLA MEMORIA]
OK

25/02/2007 - 16:19:45

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

26/02/2007 - 12:56:00

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

26/02/2007 - 13:36:24

[SCANSIONE DELLA MEMORIA]
OK

26/02/2007 - 13:38:11

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

26/02/2007 - 14:53:16

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

26/02/2007 - 16:54:40

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Contattare il Supporto Tecnico TG Soft
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

26/02/2007 - 18:38:15

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

27/02/2007 - 13:38:17

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

27/02/2007 - 13:42:33

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

27/02/2007 - 13:43:07

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
[SCANSIONE DELLA MEMORIA]
OK

27/02/2007 - 14:32:55

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

27/02/2007 - 18:56:23

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

27/02/2007 - 19:19:04

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

27/02/2007 - 19:20:40

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

28/02/2007 - 13:46:28

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
Il file sarà spostato nella cartella di quarantena.

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 54547.
Files Totali: 54547.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

Adesso puoi RIAVVIARE il computer per spostare il file nella cartella di quarantena.
[SCANSIONE DELLA MEMORIA]
OK

28/02/2007 - 15:00:59

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

28/02/2007 - 15:08:04

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

28/02/2007 - 20:32:42

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
Il file sarà spostato nella cartella di quarantena.
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
[SCANSIONE DELLA MEMORIA]
OK

01/03/2007 - 13:46:46

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 54584.
Files Totali: 54584.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

01/03/2007 - 14:58:35

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 56699.
Files Totali: 56699.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

01/03/2007 - 16:32:01

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

01/03/2007 - 18:28:14

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

01/03/2007 - 18:44:27

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 54636.
Files Totali: 54636.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

02/03/2007 - 13:40:27

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 54646.
Files Totali: 54646.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

02/03/2007 - 14:52:03

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

02/03/2007 - 15:09:40

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 56776.
Files Totali: 56776.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

04/03/2007 - 11:08:12

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

05/03/2007 - 08:35:29

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 59789.
Files Totali: 59789.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

05/03/2007 - 09:41:52

[SCANSIONE DELLA MEMORIA]
OK

05/03/2007 - 09:43:23

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

05/03/2007 - 10:30:29

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 62720.
Files Totali: 62720.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

05/03/2007 - 13:21:37

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 62726.
Files Totali: 62726.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

05/03/2007 - 15:18:01

[SCANSIONE DELLA MEMORIA]
OK

05/03/2007 - 18:37:26

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 60606.
Files Totali: 60606.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

06/03/2007 - 09:04:39

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 60617.
Files Totali: 60617.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


06/03/2007 - 09:39:25

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]


[G:]
BOOT SECTOR: OK


[H:]
BOOT SECTOR: OK


[I:]
BOOT SECTOR: OK


[J:]
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 73218.
Files Totali: 73218.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


06/03/2007 - 11:09:01

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]


[G:]
BOOT SECTOR: OK


[H:]
BOOT SECTOR: OK


[I:]
BOOT SECTOR: OK


[J:]
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 73225.
Files Totali: 73225.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


06/03/2007 - 11:28:13

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]


[G:]
BOOT SECTOR: OK


[H:]
BOOT SECTOR: OK


[I:]
BOOT SECTOR: OK


[J:]
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 73213.
Files Totali: 73213.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


06/03/2007 - 12:40:37

[SCANSIONE DELLA MEMORIA]
OK

06/03/2007 - 13:12:07

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 60647.
Files Totali: 60647.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

06/03/2007 - 15:00:33

[SCANSIONE DELLA MEMORIA]
OK

06/03/2007 - 15:06:29

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 0.
Files Sospetti: 0.
Files Analizzati: 2445.
Files Totali: 2445.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

06/03/2007 - 15:22:04

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 60661.
Files Totali: 60661.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

06/03/2007 - 18:58:05

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 60667.
Files Totali: 60667.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

06/03/2007 - 20:54:07

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 60674.
Files Totali: 60674.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

06/03/2007 - 21:27:42

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 62831.
Files Totali: 62831.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

07/03/2007 - 13:49:38

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 60692.
Files Totali: 60692.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

07/03/2007 - 15:18:34

[SCANSIONE DELLA MEMORIA]
OK

07/03/2007 - 16:02:44

[SCANSIONE DELLA MEMORIA]
OK

07/03/2007 - 16:08:49

[SCANSIONE DELLA MEMORIA]
OK

07/03/2007 - 16:14:21

[SCANSIONE DELLA MEMORIA]
OK

07/03/2007 - 16:42:48

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 0.
Files Sospetti: 0.
Files Analizzati: 1.
Files Totali: 1.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

07/03/2007 - 16:50:59

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 0.
Files Sospetti: 0.
Files Analizzati: 1.
Files Totali: 1.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

07/03/2007 - 18:31:01

[SCANSIONE DELLA MEMORIA]
OK

10/03/2007 - 09:18:06

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\uokmba.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW
[SCANSIONE DELLA MEMORIA]
OK

10/03/2007 - 12:16:06

[SCANSIONE DELLA MEMORIA]
OK

11/03/2007 - 09:34:18

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\uokmba.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\QUARANTENA_VIRIT\winhp32.exe.Vir Infetto da Trojan.Win32.Small.OW

Chiavi Registro infette: 0.
Files Infetti: 4.
Files Sospetti: 0.
Files Analizzati: 61140.
Files Totali: 61140.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

13/03/2007 - 15:25:08

[SCANSIONE DELLA MEMORIA]
OK

13/03/2007 - 15:58:49

[SCANSIONE DELLA MEMORIA]
OK

13/03/2007 - 20:45:27

[SCANSIONE DELLA MEMORIA]
OK

13/03/2007 - 20:54:24

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

13/03/2007 - 21:23:06

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\uokmba.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

13/03/2007 - 21:40:17

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\uokmba.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
[SCANSIONE DELLA MEMORIA]
OK

13/03/2007 - 21:47:51

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\uokmba.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
[SCANSIONE DELLA MEMORIA]
OK

13/03/2007 - 21:52:18

[SCANSIONE DELLA MEMORIA]
OK

14/03/2007 - 15:53:25

[SCANSIONE DELLA MEMORIA]
OK

14/03/2007 - 18:27:12

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

15/03/2007 - 12:22:20

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

15/03/2007 - 18:43:31

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

19/03/2007 - 16:12:06

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\uokmba.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 3.
Files Sospetti: 0.
Files Analizzati: 62657.
Files Totali: 62657.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


19/03/2007 - 16:36:20

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\uokmba.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 36302.
Files Totali: 36302.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


19/03/2007 - 16:43:51

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
C:\RECYCLER\S-1-5-21-2821843351-1064444744-683492359-1010\Dc2\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH

[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]


[G:]
BOOT SECTOR: OK


[H:]
BOOT SECTOR: OK


[I:]
BOOT SECTOR: OK


[J:]
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 74241.
Files Totali: 74241.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


19/03/2007 - 16:59:38

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 43784.
Files Totali: 43784.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


19/03/2007 - 17:08:38

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[fp8_archive]


[pulisci virus]


[F:]


[G:]
BOOT SECTOR: OK


[H:]
BOOT SECTOR: OK


[I:]
BOOT SECTOR: OK


[J:]
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 72185.
Files Totali: 72185.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

19/03/2007 - 17:32:11

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 0.
Files Sospetti: 0.
Files Analizzati: 250.
Files Totali: 250.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

19/03/2007 - 18:38:27

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

19/03/2007 - 18:46:37

[SCANSIONE DELLA MEMORIA]
OK

19/03/2007 - 18:52:36

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 30053.
Files Totali: 30053.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

19/03/2007 - 20:21:38

[SCANSIONE DELLA MEMORIA]
OK

19/03/2007 - 20:27:29

[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 11:22:10

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 11:27:39

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE
[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 11:47:53

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
[SCANSIONE DELLA MEMORIA]
OK
---------------------------OK

20/03/2007 - 11:56:47

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RC:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 64681.
Files Totali: 64681.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 12:29:00

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 12:47:23

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 12:56:01

[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 12:59:12

[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 13:04:08

[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 13:16:12

[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 13:30:21

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 64335.
Files Totali: 64335.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 14:01:12

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 14:32:08

[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 15:17:04

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 16:40:37

[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 19:44:41

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\zzzmaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 19:49:39

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\zzzmaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

20/03/2007 - 20:05:45

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

21/03/2007 - 08:43:45

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

21/03/2007 - 08:50:29

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

21/03/2007 - 08:55:03

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

21/03/2007 - 09:00:23

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

21/03/2007 - 12:14:11

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\zzzmaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 3.
Files Sospetti: 0.
Files Analizzati: 64485.
Files Totali: 64485.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

21/03/2007 - 12:41:04

[SCANSIONE DELLA MEMORIA]
OK

21/03/2007 - 13:44:12

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\zzzmaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
OK

22/03/2007 - 08:44:08

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

22/03/2007 - 08:49:31

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

22/03/2007 - 08:54:29

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

22/03/2007 - 11:53:31

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

22/03/2007 - 11:58:17

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

22/03/2007 - 12:03:30

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\zzzmaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 3.
Files Sospetti: 0.
Files Analizzati: 64990.
Files Totali: 64990.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

22/03/2007 - 13:44:20

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\zzzmaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 3.
Files Sospetti: 0.
Files Analizzati: 64679.
Files Totali: 64679.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

22/03/2007 - 17:26:03

[SCANSIONE DELLA MEMORIA]
OK

23/03/2007 - 09:17:24

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\zzzmaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 3.
Files Sospetti: 0.
Files Analizzati: 64844.
Files Totali: 64844.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

24/03/2007 - 08:51:52

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

24/03/2007 - 08:55:27

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\zzzmaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
[SCANSIONE DELLA MEMORIA]
OK

24/03/2007 - 09:07:44

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

24/03/2007 - 09:12:40

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

24/03/2007 - 09:20:24

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

24/03/2007 - 09:34:50

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\zzzmaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
OK

24/03/2007 - 09:43:58

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

24/03/2007 - 09:51:55

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

24/03/2007 - 11:44:34

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

26/03/2007 - 11:37:23

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

26/03/2007 - 11:41:02

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\zzzmaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 3.
Files Sospetti: 0.
Files Analizzati: 65032.
Files Totali: 65032.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

26/03/2007 - 17:25:47

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 65063.
Files Totali: 65063.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

27/03/2007 - 13:58:51

[SCANSIONE DELLA MEMORIA]
OK

27/03/2007 - 14:01:33

[SCANSIONE DELLA MEMORIA]
OK

27/03/2007 - 14:05:07

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\iryfaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\p€zkaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 4.
Files Sospetti: 0.
Files Analizzati: 65357.
Files Totali: 65357.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

27/03/2007 - 21:22:23

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\iryfaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\p€zkaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 4.
Files Sospetti: 0.
Files Analizzati: 65834.
Files Totali: 65834.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

28/03/2007 - 10:02:45

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\iryfaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\p€zkaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 4.
Files Sospetti: 0.
Files Analizzati: 66015.
Files Totali: 66015.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

28/03/2007 - 13:55:06

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\iryfaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\p€zkaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 4.
Files Sospetti: 0.
Files Analizzati: 66028.
Files Totali: 66028.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

28/03/2007 - 15:31:40

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

29/03/2007 - 14:09:16

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\iryfaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\p€zkaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 4.
Files Sospetti: 0.
Files Analizzati: 66051.
Files Totali: 66051.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

30/03/2007 - 13:50:37

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\iryfaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\p€zkaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 4.
Files Sospetti: 0.
Files Analizzati: 64298.
Files Totali: 64298.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

31/03/2007 - 09:02:33

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\iryfaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\p€zkaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 4.
Files Sospetti: 0.
Files Analizzati: 64369.
Files Totali: 64369.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

31/03/2007 - 14:15:10

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\iryfaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\p€zkaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
[SCANSIONE DELLA MEMORIA]
OK

31/03/2007 - 15:34:00

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\iryfaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\p€zkaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
[SCANSIONE DELLA MEMORIA]
OK

31/03/2007 - 15:45:49

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\iryfaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\Documents and Settings\Emilio\Impostazioni locali\Temp\VIRIT\ctfhwesr.exe Infetto da Trojan.Win32.Agent.AQH
C:\QUARANTENA_VIRIT\service32.exe.Vir Infetto da Trojan.Win32.Small.NE

Chiavi Registro infette: 0.
Files Infetti: 3.
Files Sospetti: 0.
Files Analizzati: 64452.
Files Totali: 64452.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


31/03/2007 - 16:26:08

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]


[G:]
BOOT SECTOR: OK


[H:]
BOOT SECTOR: OK


[I:]
BOOT SECTOR: OK


[J:]
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 0.
Files Sospetti: 0.
Files Analizzati: 75724.
Files Totali: 75724.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

01/04/2007 - 17:37:35

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 0.
Files Sospetti: 0.
Files Analizzati: 58796.
Files Totali: 58796.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

01/04/2007 - 19:05:12

[SCANSIONE DELLA MEMORIA]
OK

03/04/2007 - 09:02:47

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 58847.
Files Totali: 58847.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

03/04/2007 - 09:31:24

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 58922.
Files Totali: 58922.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

03/04/2007 - 14:48:23

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 58866.
Files Totali: 58866.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

03/04/2007 - 21:33:59

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

06/04/2007 - 12:35:17

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

06/04/2007 - 12:40:24

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

06/04/2007 - 17:39:30

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

06/04/2007 - 21:18:27

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

07/04/2007 - 20:35:32

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

08/04/2007 - 22:44:22

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

08/04/2007 - 23:12:39

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

10/04/2007 - 10:55:35

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

10/04/2007 - 20:52:59

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 59114.
Files Totali: 59114.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

12/04/2007 - 10:48:18

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 59377.
Files Totali: 59377.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

13/04/2007 - 09:13:43

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 59340.
Files Totali: 59340.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

13/04/2007 - 13:56:24

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 59346.
Files Totali: 59346.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

14/04/2007 - 12:00:52

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 59352.
Files Totali: 59352.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

14/04/2007 - 17:42:16

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 59351.
Files Totali: 59351.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

17/04/2007 - 22:00:14

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

20/04/2007 - 16:44:55

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

20/04/2007 - 17:13:31

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

20/04/2007 - 17:22:38

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

21/04/2007 - 15:27:03

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

21/04/2007 - 15:37:11

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

21/04/2007 - 19:10:02

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

22/04/2007 - 17:42:36

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

23/04/2007 - 10:16:09

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 58492.
Files Totali: 58492.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


23/04/2007 - 11:16:03

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]


[G:]
BOOT SECTOR: OK


[H:]
BOOT SECTOR: OK


[I:]
BOOT SECTOR: OK


[J:]
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 70891.
Files Totali: 70891.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.


23/04/2007 - 12:57:47

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]


[G:]
BOOT SECTOR: OK


[H:]
BOOT SECTOR: OK


[I:]
BOOT SECTOR: OK


[J:]
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 71140.
Files Totali: 71140.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

23/04/2007 - 16:49:27

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 58895.
Files Totali: 58895.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

24/04/2007 - 20:46:28

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

25/04/2007 - 13:08:40

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 58695.
Files Totali: 58695.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

25/04/2007 - 21:41:50

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 57907.
Files Totali: 57907.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

26/04/2007 - 13:40:34

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 60694.
Files Totali: 60694.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

26/04/2007 - 21:53:55

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

27/04/2007 - 14:10:15

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

27/04/2007 - 15:25:01

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 60629.
Files Totali: 60629.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

27/04/2007 - 17:07:46

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

27/04/2007 - 17:19:13

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

27/04/2007 - 21:07:47

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 60723.
Files Totali: 60723.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

28/04/2007 - 13:45:46

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 60846.
Files Totali: 60846.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

28/04/2007 - 18:32:37

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 60922.
Files Totali: 60922.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

28/04/2007 - 22:01:00

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

29/04/2007 - 10:17:37

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 61025.
Files Totali: 61025.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

29/04/2007 - 10:52:21

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

29/04/2007 - 21:40:54

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

30/04/2007 - 10:08:22

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

30/04/2007 - 11:24:11

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 61198.
Files Totali: 61198.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

30/04/2007 - 12:12:14

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

30/04/2007 - 12:36:14

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

30/04/2007 - 12:40:30

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

02/05/2007 - 13:39:42

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

02/05/2007 - 17:45:45

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 61796.
Files Totali: 61796.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

02/05/2007 - 20:04:55

[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

03/05/2007 - 13:41:08

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

03/05/2007 - 17:06:15

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

03/05/2007 - 18:34:56

[SCANSIONE DELLA MEMORIA]
[Hidden Services]
pe386 - Win23 lzx files loader - \??\C:\WINDOWS\system32:lzx32.sys

VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

03/05/2007 - 20:42:56

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
[Hidden Services]
pe386 - Win23 lzx files loader - \??\C:\WINDOWS\system32:lzx32.sys

VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

04/05/2007 - 14:33:17

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
[Hidden Services]
pe386 - Win23 lzx files loader - \??\C:\WINDOWS\system32:lzx32.sys

VIRUS ATTIVO IN MEMORIA: (Rootkit \??\C:\WINDOWS\SYSTEM32:LZX32.SYS) Trojan.Win32.Costrat.D

04/05/2007 - 15:31:20

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH

Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 62499.
Files Totali: 62499.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

04/05/2007 - 16:49:50

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

04/05/2007 - 16:58:52

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
OK

05/05/2007 - 16:04:58

[SCANSIONE DELLA MEMORIA]
OK

05/05/2007 - 17:44:26

[SCANSIONE DELLA MEMORIA]
OK

06/05/2007 - 13:30:48

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

06/05/2007 - 13:37:41

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\WINDOWS\system32:lzx32.sys:$DATA Infetto da Trojan.Win32.Costrat.D

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 67939.
Files Totali: 67939.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

06/05/2007 - 16:48:41

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
C:\WINDOWS\system32:lzx32.sys:$DATA Infetto da Trojan.Win32.Costrat.D

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 67943.
Files Totali: 67943.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
OK

07/05/2007 - 12:56:10

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

08/05/2007 - 19:28:26

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

[SCANSIONE DELLA MEMORIA]
OK

09/05/2007 - 15:34:06

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Impostazioni locali\Temp\yuzgaa.exe Infetto da Trojan.Win32.Dialer.IH
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

29/05/2007 - 21:26:08

[SCANSIONE DELLA MEMORIA]
OK

31/01/2008 - 08:24:32

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Preferiti\Whatsnew.url Infetto da HTML.LinkShare.A
[SCANSIONE DELLA MEMORIA]
OK

05/03/2008 - 15:51:46

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Preferiti\Whatsnew.url Infetto da HTML.LinkShare.A
--
05/03/2008 - 15:55:06

[SCANSIONE DELLA MEMORIA]
OK

17/03/2008 - 11:38:39

[SCANSIONE DELLA MEMORIA]
OK

16/04/2008 - 08:23:16

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Preferiti\Whatsnew.url Infetto da HTML.LinkShare.A
C:\WINDOWS\system32\dllcache\rasapi32.dll Infetto da Trojan.Win32.Agent.BCH
[SCANSIONE DELLA MEMORIA]
OK

17/04/2008 - 08:14:57

[SCANSIONE DELLA MEMORIA]
OK

21/05/2008 - 13:32:49

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Preferiti\Whatsnew.url Infetto da HTML.LinkShare.A
C:\WINDOWS\system32\rasapi32.dll Infetto da Trojan.Win32.Agent.BCH

Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 80815.
Files Totali: 80815.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

[SCANSIONE DELLA MEMORIA]
[Hidden Services]
gsbgqpwwfw - \??\C:\WINDOWS\system32\gsbgqpwwfw.sys

OK

08/06/2008 - 21:10:54

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

06/06/2009 - 14:35:25

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Preferiti\Whatsnew (Da Firefox).URL Infetto da HTML.LinkShare.A
C:\Documents and Settings\Emilio\Preferiti\Whatsnew.url Infetto da HTML.LinkShare.A
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK

06/06/2009 - 15:38:06

[SCANSIONE DELLA MEMORIA]
OK

07/06/2009 - 10:22:10

[SCANSIONE DEL REGISTRO]
OK

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\Emilio\Preferiti\Whatsnew (Da Firefox).URL Infetto da HTML.LinkShare.A
C:\Documents and Settings\Emilio\Preferiti\Whatsnew.url Infetto da HTML.LinkShare.A

[D:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK


[E:]


[F:]


[G:]
BOOT SECTOR: OK


[H:]
BOOT SECTOR: OK


[I:]
BOOT SECTOR: OK


[J:]
BOOT SECTOR: OK


Chiavi Registro infette: 0.
Files Infetti: 2.
Files Sospetti: 0.
Files Analizzati: 96735.
Files Totali: 96735.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

ADESSO COSA DOBBIAMO FARE???
ASPETTO TUE RISPOSTE.
GRAZIE DI TUTTO PER ORA
Simone
r16
Inviato: Sunday, June 07, 2009 1:35:27 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Disistalla Virit:
Per disistallare Virit,fai :
Start\Tutti Programmi, e trovi il suo Unistall.

Installa KASPERSKY VIRUS REMOVAL TOOL sul Desktop:
Doppio click sul Setup.exe.
verrà creata una apposta cartella sul Desktop e comparirà la schermata iniziale del Tool.
Imposta le aree che intendi scansionare (Startup Objects e Disk boot sector sono impostate di default) e clicca "SCAN"
al termine della scansione sarà possibile rimuovere e/o mettere in quarantena i file infetti rilevati
salva il log che verrà rilasciato.

Clicca "Reports" poi - "Save to file" e per comodità salvalo sul Desktop.
Posta il log in questo modo:

Collegati ad internet e vai alla pagina WikiSend: http://www.wikisend.com/
Clicca sul bottone "Sfoglia"
Seleziona il file appena salvato
Clicca su Upload file
Dopo qualche secondo, vieni spostato su una nuova pagina con il link in diversi formati:
Download Link / Forum Link
Seleziona Forum Link, copialo e incollalo in un nuovo messaggio per il forum.

simo95
Inviato: Sunday, June 07, 2009 9:21:31 PM

Rank: AiutAmico

Iscritto dal : 12/4/2008
Posts: 2,008
ho sbagliato ad incollare il log di virit, comunque aveva trovato due file infetti che li ho rimossi con file assassin di malwarebytes.

Ecco il log di kaspersky vrt:

Scan log.txt

Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.