BomberFerrara
01-03-2008, 15:29
vi mando i log della procedura di disinfestazione da virus su messenger; quelli di msn fix non li ho perchè il programma non mi parte!!
Io ho come S.O windows xp .
Log di LiveKillCleanMessenger
sabato 1 marzo 2008 11.58.27 build 1256
Microsoft Windows XP Professional(it-IT)
511 Mo (RAM)
Last DataBase update : NOT UPDATED
C:\Programmi\LiveKillCleanMessenger
NORMAL MODE
C:\WINDOWS\wr.txt
poi log msn cleaner
File di log MSNCleaner 1.5.6 by www.forospyware.com
- File di log creato: 01/03/08 on 12.04.26
- Sistema Operativo: Windows XP
- Modalità d'avvio: Normale
_________________________________________
File trovati: 0
File rimossi: 0
File non rimossi: 0
<<<<<<< Nessun file trovato >>>>>>>
Poi log kaspersky
Scan
----
Scanned: 614
Detected: 3
Untreated: 2
Start time: 01/03/08 11.23.47
Duration: 00.06.39
Finish time: 01/03/08 11.30.26
Detected
--------
Status Object
------ ------
deleted: virus Email-Worm.Win32.Agent.ax File: c:\windows\system32\jrckdbio.exe
detected: virus Email-Worm.Win32.Agent.ax File: c:\windows\system32\pq.exe
detected: Trojan program Trojan.Win32.Agent.dwa File: c:\docume~1\admin\impost~1\temp\rar$ex03.454\msnfix\backup\services.exe
Events
------
Time Name Status Reason
---- ---- ------ ------
01/03/08 11.23.50 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe ok scanned
01/03/08 11.23.50 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe ok scanned
01/03/08 11.23.50 Running module: C:\WINDOWS\system32\ntdll.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\ntdll.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\kernel32.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\kernel32.dll ok scanned
01/03/08 11.23.51 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prremote.dll ok scanned
01/03/08 11.23.51 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prremote.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\RPCRT4.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\RPCRT4.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\Secur32.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\Secur32.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\USER32.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\USER32.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\GDI32.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\GDI32.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCP80.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCP80.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCR80.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCR80.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\msvcrt.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\msvcrt.dll ok scanned
01/03/08 11.23.52 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\FSSync.dll ok scanned
01/03/08 11.23.52 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\FSSync.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\SHELL32.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\SHELL32.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\SHLWAPI.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\SHLWAPI.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\ole32.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\ole32.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\uxtheme.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\uxtheme.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\MSCTF.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\MSCTF.dll ok scanned
01/03/08 11.23.52 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\AVPGS.PPL ok scanned
01/03/08 11.23.52 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\AVPGS.PPL ok scanned
01/03/08 11.23.52 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prloader.dll ok scanned
01/03/08 11.23.52 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prloader.dll ok scanned
01/03/08 11.23.52 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prkernel.ppl ok scanned
01/03/08 11.23.52 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prkernel.ppl ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\userenv.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\userenv.dll ok scanned
01/03/08 11.23.52 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\pxstub.ppl ok scanned
01/03/08 11.23.52 File: c:\documents and settings\all users\desktop\kaspersky lab tool\pxstub.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\params.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\params.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\dtreg.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\dtreg.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\nfio.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\nfio.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\fsdrvplg.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\fsdrvplg.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\mkavio.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\mkavio.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\tempfile.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\tempfile.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\avpgui.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\avpgui.ppl ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\WININET.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\WININET.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\CRYPT32.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\CRYPT32.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\MSASN1.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\MSASN1.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\OLEAUT32.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\OLEAUT32.dll ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\basegui.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\basegui.ppl ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\VERSION.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\VERSION.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\WS2_32.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\WS2_32.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\WS2HELP.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\WS2HELP.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\CLBCATQ.DLL ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\CLBCATQ.DLL ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\COMRes.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\COMRes.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\xpsp2res.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll archive EmbeddedHTML
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0001.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0002.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0003.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0004.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0005.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0006.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0007.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0008.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0009.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0010.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0011.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0012.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\thpimpl.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\thpimpl.ppl ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\fltlib.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\fltlib.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\wtsapi32.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\wtsapi32.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\WINSTA.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\WINSTA.dll ok scanned
01/03/08 11.23.54 Running module: C:\WINDOWS\system32\NETAPI32.dll ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\system32\NETAPI32.dll ok scanned
01/03/08 11.23.54 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\qb.ppl ok scanned
01/03/08 11.23.54 File: c:\documents and settings\all users\desktop\kaspersky lab tool\qb.ppl ok scanned
01/03/08 11.23.54 Running module: C:\WINDOWS\system32\appHelp.dll ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\system32\appHelp.dll ok scanned
01/03/08 11.23.54 Running module: C:\WINDOWS\System32\cscui.dll ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\System32\cscui.dll ok scanned
01/03/08 11.23.54 Running module: C:\WINDOWS\System32\CSCDLL.dll ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\System32\CSCDLL.dll ok scanned
01/03/08 11.23.54 Running module: C:\WINDOWS\system32\SETUPAPI.dll ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\system32\SETUPAPI.dll ok scanned
01/03/08 11.23.54 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\report.ppl ok scanned
01/03/08 11.23.54 File: c:\documents and settings\all users\desktop\kaspersky lab tool\report.ppl ok scanned
01/03/08 11.23.54 File: c:\windows\system32\mmdrv.dll ok scanned
01/03/08 11.23.54 File: c:\windows\system\timer.drv ok scanned
01/03/08 11.23.54 File: c:\windows\system32\mshta.exe ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\system32\notepad.exe ok scanned
01/03/08 11.23.54 File: c:\windows\regedit.exe ok scanned
01/03/08 11.23.55 File: c:\programmi\microsoft office\office11\msaccess.exe ok scanned
01/03/08 11.23.56 File: c:\programmi\adobe\acrobat 6.0\reader\acrord32.exe ok scanned
01/03/08 11.23.56 File: C:\WINDOWS\system32\accwiz.exe ok scanned
01/03/08 11.23.56 File: c:\programmi\windows media player\wmplayer.exe ok scanned
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe packed file PE_Patch.PECompact
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe//PE_Patch.PECompact packed file PecBundle
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe//PE_Patch.PECompact//PecBundle packed file PECompact
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe//PE_Patch.PECompact//PecBundle//PECompact ok scanned
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe//PE_Patch.PECompact//PecBundle ok scanned
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe//PE_Patch.PECompact ok scanned
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe ok scanned
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe:Zone.Identifier ok scanned
01/03/08 11.23.56 File: c:\programmi\alwil software\avast4\ashsimpl.exe ok scanned
01/03/08 11.23.57 File: C:\Programmi\windows nt\accessori\wordpad.exe ok scanned
01/03/08 11.23.57 File: c:\windows\system32\rundll32.exe ok scanned
01/03/08 11.23.57 File: c:\windows\system32\cryptext.dll ok scanned
01/03/08 11.23.57 File: c:\programmi\outlook express\wab.exe ok scanned
01/03/08 11.23.57 File: c:\windows\explorer.exe ok scanned
01/03/08 11.23.57 File: C:\WINDOWS\system32\cdfview.dll ok scanned
01/03/08 11.23.57 File: c:\windows\hh.exe ok scanned
01/03/08 11.23.57 File: c:\windows\system32\clipbrd.exe ok scanned
01/03/08 11.23.59 File: c:\programmi\vso\convertxtodvd\convertxtodvd.exe ok scanned
01/03/08 11.23.59 File: c:\progra~1\micros~2\office11\excel.exe ok scanned
01/03/08 11.23.59 File: C:\WINDOWS\system32\rundll32.exe ok scanned
01/03/08 11.23.59 File: c:\windows\system32\netshell.dll ok scanned
01/03/08 11.24.00 File: c:\windows\system32\shimgvw.dll ok scanned
01/03/08 11.24.00 File: c:\programmi\microsoft office\office11\excel.exe ok scanned
01/03/08 11.24.00 File: C:\WINDOWS\explorer.exe ok scanned
01/03/08 11.24.00 File: C:\WINDOWS\system32\fontview.exe ok scanned
01/03/08 11.24.00 File: c:\programmi\bearshare\bearshare.exe packed file Armadillo
01/03/08 11.24.00 File: c:\programmi\bearshare\bearshare.exe//Armadillo ok scanned
01/03/08 11.24.01 File: c:\programmi\bearshare\bearshare.exe ok scanned
01/03/08 11.24.01 File: c:\windows\system32\msconf.dll ok scanned
01/03/08 11.24.01 File: c:\windows\winhlp32.exe ok scanned
01/03/08 11.24.01 File: C:\WINDOWS\system32\winhlp32.exe ok scanned
01/03/08 11.24.01 File: c:\progra~1\micros~2\office11\outlook.exe ok scanned
01/03/08 11.24.01 File: c:\programmi\windows nt\hypertrm.exe ok scanned
01/03/08 11.24.01 File: c:\programmi\internet explorer\iexplore.exe ok scanned
01/03/08 11.24.01 File: c:\programmi\intervideo\dvd6\windvd.exe ok scanned
01/03/08 11.24.02 File: c:\programmi\java\j2re1.4.2_05\bin\javaw.exe ok scanned
01/03/08 11.24.02 File: c:\programmi\java\j2re1.4.2_05\javaws\javaws.exe ok scanned
01/03/08 11.24.02 File: C:\WINDOWS\system32\wscript.exe ok scanned
01/03/08 11.24.02 File: c:\programmi\microsoft office\office11\mstore.exe ok scanned
01/03/08 11.24.02 File: C:\WINDOWS\system32\ntbackup.exe ok scanned
01/03/08 11.24.02 File: C:\WINDOWS\system32\mmc.exe ok scanned
01/03/08 11.24.02 File: c:\programmi\microsoft office\office11\outlook.exe ok scanned
01/03/08 11.24.02 File: C:\WINDOWS\system32\shell32.dll ok scanned
01/03/08 11.24.02 File: C:\WINDOWS\system32\desk.cpl ok scanned
01/03/08 11.24.02 File: c:\progra~1\micros~2\office11\ois.exe ok scanned
01/03/08 11.24.03 File: c:\programmi\microsoft office\office11\finder.exe ok scanned
01/03/08 11.24.03 File: C:\WINDOWS\system32\rasphone.exe ok scanned
01/03/08 11.24.03 File: C:\WINDOWS\system32\perfmon.exe ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe ok scanned
01/03/08 11.24.03 File: c:\programmi\microsoft office\office11\powerpnt.exe ok scanned
01/03/08 11.24.03 File: c:\windows\system32\msrating.dll ok scanned
01/03/08 11.24.04 File: c:\programmi\windows nt\accessori\wordpad.exe ok scanned
01/03/08 11.24.04 File: c:\windows\notepad.exe ok scanned
01/03/08 11.24.04 File: c:\programmi\file comuni\microsoft shared\snapshot viewer\snapview.exe ok scanned
01/03/08 11.24.04 File: C:\WINDOWS\system32\wpnpinst.exe ok scanned
01/03/08 11.24.04 File: c:\programmi\winamp\winamp.exe ok scanned
01/03/08 11.24.05 File: c:\programmi\microsoft office\office11\winword.exe ok scanned
01/03/08 11.24.05 File: c:\programmi\file comuni\microsoft shared\office11\msoxmled.exe ok scanned
01/03/08 11.24.05 File: c:\windows\system32\shell32.dll ok scanned
01/03/08 11.24.05 File: c:\windows\system32\drwtsn32.exe ok scanned
01/03/08 11.24.06 File: c:\windows\system32\userinit.exe ok scanned
01/03/08 11.24.06 File: c:\windows\system32\ati2evxx.dll ok scanned
01/03/08 11.24.06 File: c:\windows\system32\crypt32.dll ok scanned
01/03/08 11.24.06 File: c:\windows\system32\cryptnet.dll ok scanned
01/03/08 11.24.06 File: c:\windows\system32\cscdll.dll ok scanned
01/03/08 11.24.07 File: c:\windows\system32\wlnotify.dll ok scanned
01/03/08 11.24.07 File: c:\windows\system32\sclgntfy.dll ok scanned
01/03/08 11.24.07 File: c:\windows\system32\wgalogon.dll ok scanned
01/03/08 11.24.07 File: c:\windows\system32\nerocheck.exe ok scanned
01/03/08 11.24.07 File: c:\programmi\java\j2re1.4.2_05\bin\jusched.exe ok scanned
01/03/08 11.24.07 File: c:\programmi\analog devices\soundmax\smtray.exe ok scanned
01/03/08 11.24.07 File: c:\windows\system32\spool\drivers\w32x86\3\e_fatibee.exe ok scanned
01/03/08 11.24.07 File: c:\windows\temp\e_sa7.tmp ok scanned
01/03/08 11.24.07 File: c:\program files\globespanvirata\adsl\dslstat.exe ok scanned
01/03/08 11.24.07 File: c:\program files\globespanvirata\adsl\dslagent.exe ok scanned
01/03/08 11.24.07 File: c:\programmi\winamp\winampa.exe ok scanned
01/03/08 11.24.07 File: c:\programmi\quicktime\qttask.exe ok scanned
01/03/08 11.24.07 File: c:\programmi\d-tools\daemon.exe ok scanned
01/03/08 11.24.07 File: c:\progra~1\alwils~1\avast4\ashdisp.exe ok scanned
01/03/08 11.24.07 File: c:\windows\system32\jrckdbio.exe detected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.24.07 File: c:\windows\system32\jrckdbio.exe not disinfected postponed
01/03/08 11.24.08 File: c:\windows\system32\pq.exe detected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.24.08 File: c:\windows\system32\pq.exe not disinfected postponed
01/03/08 11.24.08 File: c:\docume~1\admin\impost~1\temp\rar$ex03.454\msnfix\backup\services.exe detected Trojan program 'Trojan.Win32.Agent.dwa'
01/03/08 11.24.08 File: c:\docume~1\admin\impost~1\temp\rar$ex03.454\msnfix\backup\services.exe not disinfected postponed
01/03/08 11.24.08 File: c:\documents and settings\all users\desktop\kaspersky lab tool\setup_7.0.0.180_29.02.2008_23-14.exe ok scanned
01/03/08 11.24.08 File: c:\windows\system32\ctfmon.exe ok scanned
01/03/08 11.24.08 File: c:\programmi\windows live\messenger\msnmsgr.exe ok scanned
01/03/08 11.24.08 File: c:\programmi\google\googletoolbarnotifier\googletoolbarnotifier.exe ok scanned
01/03/08 11.24.09 File: c:\programmi\skype\phone\skype.exe ok scanned
01/03/08 11.24.09 File: C:\WINDOWS\system32\alrsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\appmgmts.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\audiosrv.dll ok scanned
01/03/08 11.24.10 File: c:\windows\system32\qmgr.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\browser.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\cryptsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\rpcss.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\dhcpcsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\dmserver.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\dnsrslvr.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\ersvc.dll ok scanned
01/03/08 11.24.10 File: c:\windows\system32\es.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\shsvcs.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\hidserv.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\w3ssl.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\srvsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\wkssvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\lmhsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\msgsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\netman.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\mswsock.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\ntmssvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\rasauto.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\rasmans.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\mprdim.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\regsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\schedsvc.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\seclogon.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\sens.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\ipnathlp.dll ok scanned
01/03/08 11.24.11 File: c:\windows\system32\srsvc.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\ssdpsrv.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\wiaservc.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\tapisrv.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\termsrv.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\trkwks.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\upnphost.dll ok scanned
01/03/08 11.24.11 File: c:\windows\system32\w32time.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\webclnt.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\wbem\wmisvc.dll ok scanned
01/03/08 11.24.11 File: c:\windows\system32\mspmsnsv.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\advapi32.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\wscsvc.dll ok scanned
01/03/08 11.24.11 File: c:\windows\system32\wuauserv.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\wudfsvc.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\wzcsvc.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\xmlprov.dll ok scanned
01/03/08 11.24.11 File: c:\windows\system32\drivers\acpi.sys ok scanned
01/03/08 11.24.11 File: c:\windows\system32\drivers\aeaudio.sys ok scanned
01/03/08 11.24.11 File: c:\windows\system32\drivers\aec.sys ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\drivers\afd.sys ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\svchost.exe ok scanned
01/03/08 11.24.12 File: C:\WINDOWS\system32\alg.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\aliide.sys ok scanned
01/03/08 11.24.12 File: C:\WINDOWS\microsoft.net\framework\v1.1.4322\aspnet_state.exe ok scanned
01/03/08 11.24.12 File: c:\programmi\alwil software\avast4\aswupdsv.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\asyncmac.sys ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\atapi.sys ok scanned
01/03/08 11.24.12 File: C:\WINDOWS\system32\ati2evxx.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\ati2mtag.sys ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\atmarpc.sys ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\audstub.sys ok scanned
01/03/08 11.24.12 File: c:\programmi\alwil software\avast4\ashserv.exe ok scanned
01/03/08 11.24.12 File: c:\programmi\alwil software\avast4\ashmaisv.exe ok scanned
01/03/08 11.24.12 File: c:\programmi\alwil software\avast4\ashwebsv.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\cdrom.sys ok scanned
01/03/08 11.24.12 File: C:\WINDOWS\system32\cisvc.exe ok scanned
01/03/08 11.24.12 File: C:\WINDOWS\system32\clipsrv.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\dllhost.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\d347bus.sys ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\d347prt.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\disk.sys ok scanned
01/03/08 11.24.13 File: C:\WINDOWS\system32\dmadmin.exe ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmboot.sys packed file PE_Patch
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmboot.sys//PE_Patch ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmboot.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmio.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmload.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmusic.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\drmkaud.sys ok scanned
01/03/08 11.24.13 File: C:\WINDOWS\system32\services.exe ok scanned
01/03/08 11.24.13 File: c:\windows\system32\svchost.exe ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\fdc.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\flpydisk.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\fltmgr.sys packed file PE_Patch
01/03/08 11.24.13 File: c:\windows\system32\drivers\fltmgr.sys//PE_Patch ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\fltmgr.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ftdisk.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\msgpc.sys ok scanned
01/03/08 11.24.13 File: c:\programmi\google\common\google updater\googleupdaterservice.exe ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\hidusb.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\http.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\i8042prt.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\imapi.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\imapi.exe ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ip6fw.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ipfltdrv.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ipinip.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ipnat.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ipsec.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\irenum.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\isapnp.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\kbdclass.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\klif.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\kmixer.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\m5289.sys ok scanned
01/03/08 11.24.14 File: c:\programmi\file comuni\microsoft shared\vs7debug\mdm.exe ok scanned
01/03/08 11.24.14 File: c:\windows\system32\mnmsrvc.exe ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mouclass.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxdav.sys packed file PE_Patch
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxdav.sys//PE_Patch ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxdav.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxsmb.sys packed file PE_Patch
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxsmb.sys//PE_Patch ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxsmb.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\msdtc.exe ok scanned
01/03/08 11.24.14 File: c:\windows\system32\msiexec.exe ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mskssrv.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mspclock.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mspqm.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mssmbios.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\ndistapi.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\ndisuio.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\ndiswan.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\netbios.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\netbt.sys ok scanned
01/03/08 11.24.14 File: C:\WINDOWS\system32\netdde.exe ok scanned
01/03/08 11.24.14 File: C:\WINDOWS\system32\lsass.exe ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\nwlnkflt.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\nwlnkfwd.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\nwlnkipx.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\nwlnknb.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\nwlnkspx.sys ok scanned
01/03/08 11.24.15 File: c:\programmi\file comuni\microsoft shared\source engine\ose.exe ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\pci.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\pcouffin.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\raspptp.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\processr.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\psched.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\ptilink.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\pxhelp20.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\rasacd.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\rasl2tp.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\raspppoe.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\raspti.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\rdbss.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\rdpcdd.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\rdpdr.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\sessmgr.exe ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\redbook.sys ok scanned
01/03/08 11.24.15 File: C:\WINDOWS\system32\locator.exe ok scanned
01/03/08 11.24.15 File: c:\windows\system32\rpcss.dll ok scanned
01/03/08 11.24.15 File: C:\WINDOWS\system32\rsvp.exe ok scanned
01/03/08 11.24.15 File: C:\WINDOWS\system32\scardsvr.exe ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\secdrv.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\serenum.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\serial.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\smwdm.sys ok scanned
01/03/08 11.24.16 File: c:\programmi\analog devices\soundmax\smagent.exe ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\splitter.sys ok scanned
01/03/08 11.24.16 File: C:\WINDOWS\system32\spoolsv.exe ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\sptd.sys skipped locked
01/03/08 11.24.16 File: C:\WINDOWS\system32\drivers\sr.sys packed file PE_Patch
01/03/08 11.24.16 File: C:\WINDOWS\system32\drivers\sr.sys//PE_Patch ok scanned
01/03/08 11.24.16 File: C:\WINDOWS\system32\drivers\sr.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\srv.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\swenum.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\swmidi.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\sysaudio.sys ok scanned
01/03/08 11.24.16 File: C:\WINDOWS\system32\smlogsvc.exe ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\tcpip.sys ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\termdd.sys ok scanned
01/03/08 11.24.17 File: c:\windows\system32\tlntsvr.exe ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\ulilan.sys ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\agpkx.sys ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\update.sys ok scanned
01/03/08 11.24.17 File: C:\WINDOWS\system32\ups.exe ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\usbaudio.sys ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\usbccgp.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbehci.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbhub.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbohci.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbprint.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbscan.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbstor.sys ok scanned
01/03/08 11.24.18 File: c:\programmi\windows live\messenger\usnsvc.exe ok scanned
01/03/08 11.24.18 File: C:\WINDOWS\system32\drivers\vga.sys ok scanned
01/03/08 11.24.18 File: C:\WINDOWS\system32\vssvc.exe ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\wanarp.sys ok scanned
01/03/08 11.24.19 File: c:\windows\system32\drivers\gwausb.sys ok scanned
01/03/08 11.24.19 File: c:\windows\system32\drivers\wdmaud.sys ok scanned
01/03/08 11.24.19 File: c:\programmi\windows live\installer\wlsetupsvc.exe ok scanned
01/03/08 11.24.19 File: c:\windows\system32\wbem\wmiapsrv.exe ok scanned
01/03/08 11.24.20 File: c:\programmi\windows media player\wmpnetwk.exe ok scanned
01/03/08 11.24.20 File: c:\windows\system32\drivers\wudfpf.sys ok scanned
01/03/08 11.24.20 File: c:\windows\system32\drivers\wudfrd.sys ok scanned
01/03/08 11.24.20 File: c:\windows\system32\javasup.vxd ok scanned
01/03/08 11.24.20 File: c:\windows\system32\autochk.exe ok scanned
01/03/08 11.24.21 File: c:\windows\inf\unregmp2.exe ok scanned
01/03/08 11.24.21 File: C:\WINDOWS\system32\shmgrate.exe ok scanned
01/03/08 11.24.21 File: c:\windows\system32\iedkcs32.dll ok scanned
01/03/08 11.24.21 File: C:\WINDOWS\system32\regsvr32.exe ok scanned
01/03/08 11.24.21 File: C:\WINDOWS\system32\themeui.dll ok scanned
01/03/08 11.24.22 File: C:\Programmi\outlook express\setup50.exe//# ok scanned
01/03/08 11.24.22 File: C:\Programmi\outlook express\setup50.exe ok scanned
01/03/08 11.24.22 File: c:\windows\system32\user.exe ok scanned
01/03/08 11.24.22 File: c:\windows\system32\drivers\install.exe ok scanned
01/03/08 11.24.22 File: c:\windows\system32\advpack.dll ok scanned
01/03/08 11.24.22 File: c:\windows\inf\msnetmtg.inf ok scanned
01/03/08 11.24.22 File: c:\windows\inf\msmsgs.inf ok scanned
01/03/08 11.24.22 File: c:\windows\inf\wmp11.inf ok scanned
01/03/08 11.24.22 File: c:\windows\system32\regsvr32.exe ok scanned
01/03/08 11.24.22 File: C:\WINDOWS\system32\ie4uinit.exe ok scanned
01/03/08 11.24.22 File: c:\windows\system32\mscories.dll ok scanned
01/03/08 11.24.23 File: c:\windows\system32\comm.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system\vga.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system\mmsystem.dll ok scanned
01/03/08 11.24.23 File: c:\windows\system\keyboard.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system\mouse.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system\wfwnet.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system32\progman.exe ok scanned
01/03/08 11.24.23 File: c:\windows\system\sound.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system\system.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system32\midimap.dll ok scanned
01/03/08 11.24.23 File: c:\windows\system32\imaadp32.acm ok scanned
01/03/08 11.24.23 File: c:\windows\system32\msadp32.acm ok scanned
01/03/08 11.24.24 File: c:\windows\system32\msg711.acm ok scanned
01/03/08 11.24.24 File: c:\windows\system32\msgsm32.acm ok scanned
01/03/08 11.24.24 File: c:\windows\system32\tssoft32.acm ok scanned
01/03/08 11.24.24 File: c:\windows\system32\iccvid.dll ok scanned
01/03/08 11.24.24 File: c:\windows\system32\msh263.drv ok scanned
01/03/08 11.24.24 File: c:\windows\system32\ir32_32.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\ir41_32.ax ok scanned
01/03/08 11.24.25 File: c:\windows\system32\iyuv_32.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msrle32.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msvidc32.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msyuv.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\tsbyuv.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msacm32.drv ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msg723.acm ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msh261.drv ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msaud32.acm ok scanned
01/03/08 11.24.25 File: c:\windows\system32\sl_anet.acm ok scanned
01/03/08 11.24.25 File: c:\windows\system32\iac25_32.ax ok scanned
01/03/08 11.24.25 File: c:\windows\system32\ir50_32.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\l3codeca.acm ok scanned
01/03/08 11.24.25 File: c:\windows\system32\wdmaud.drv ok scanned
01/03/08 11.24.25 File: c:\windows\system32\syncor11.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\sirenacm.dll ok scanned
01/03/08 11.24.25 File: C:\WINDOWS\system32\webcheck.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\stobject.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\wpdshserviceobj.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\logon.scr ok scanned
01/03/08 11.24.26 File: C:\WINDOWS\system32\logon.scr ok scanned
01/03/08 11.24.26 File: C:\WINDOWS\system32\browseui.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\mmsys.cpl ok scanned
01/03/08 11.24.26 File: c:\windows\system32\icmui.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\rshx32.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\docprop.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\ntshrui.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\deskadp.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\deskmon.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\dssec.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\slayerxp.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\shscrap.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\diskcopy.dll ok scanned
01/03/08 11.24.27 File: c:\windows\system32\ntlanui2.dll ok scanned
01/03/08 11.24.27 File: C:\WINDOWS\system32\icmui.dll ok scanned
01/03/08 11.24.27 File: c:\windows\system32\printui.dll ok scanned
01/03/08 11.24.27 File: c:\windows\system32\dskquoui.dll ok scanned
01/03/08 11.24.27 File: c:\windows\system32\syncui.dll ok scanned
01/03/08 11.24.28 File: c:\windows\system32\hticons.dll ok scanned
01/03/08 11.24.28 File: c:\windows\system32\fontext.dll ok scanned
01/03/08 11.24.28 File: c:\windows\system32\deskperf.dll ok scanned
01/03/08 11.24.29 File: c:\windows\system32\wiashext.dll ok scanned
01/03/08 11.24.29 File: c:\windows\system32\remotepg.dll ok scanned
01/03/08 11.24.29 File: c:\windows\system32\wshext.dll ok scanned
01/03/08 11.24.30 File: c:\programmi\file comuni\system\ole db\oledb32.dll ok scanned
01/03/08 11.24.31 File: c:\windows\system32\mstask.dll ok scanned
01/03/08 11.24.32 File: C:\WINDOWS\system32\shdocvw.dll ok scanned
01/03/08 11.24.33 File: c:\windows\system32\wuaucpl.cpl ok scanned
01/03/08 11.24.33 File: C:\WINDOWS\system32\twext.dll ok scanned
01/03/08 11.24.33 File: C:\WINDOWS\system32\shmedia.dll ok scanned
01/03/08 11.24.35 File: c:\windows\system32\shdocvw.dll ok scanned
01/03/08 11.24.36 File: c:\windows\system32\sendmail.dll ok scanned
01/03/08 11.24.37 File: C:\WINDOWS\system32\occache.dll ok scanned
01/03/08 11.24.37 File: C:\WINDOWS\system32\appwiz.cpl ok scanned
01/03/08 11.24.37 File: C:\WINDOWS\system32\shimgvw.dll ok scanned
01/03/08 11.24.37 File: C:\WINDOWS\system32\netplwiz.dll ok scanned
01/03/08 11.24.38 File: C:\WINDOWS\system32\zipfldr.dll ok scanned
01/03/08 11.24.38 File: C:\WINDOWS\system32\extmgr.dll ok scanned
01/03/08 11.24.39 File: c:\windows\system32\msieftp.dll ok scanned
01/03/08 11.24.39 File: c:\windows\system32\docprop2.dll ok scanned
01/03/08 11.24.39 File: C:\WINDOWS\system32\dsquery.dll ok scanned
01/03/08 11.24.39 File: C:\WINDOWS\system32\dsuiext.dll ok scanned
01/03/08 11.24.39 File: C:\WINDOWS\system32\mydocs.dll ok scanned
01/03/08 11.24.39 File: C:\WINDOWS\system32\cscui.dll ok scanned
01/03/08 11.24.40 File: c:\windows\msagent\agentpsh.dll ok scanned
01/03/08 11.24.40 File: c:\windows\system32\dfsshlex.dll ok scanned
01/03/08 11.24.41 File: C:\WINDOWS\system32\photowiz.dll ok scanned
01/03/08 11.24.41 File: C:\WINDOWS\system32\mmcshext.dll ok scanned
01/03/08 11.24.42 File: c:\windows\system32\cabview.dll ok scanned
01/03/08 11.24.42 File: c:\programmi\outlook express\wabfind.dll ok scanned
01/03/08 11.24.42 File: c:\windows\system32\wmpshell.dll ok scanned
01/03/08 11.24.44 File: c:\progra~1\fileco~1\micros~1\webfol~1\msonsext.dll ok scanned
01/03/08 11.24.44 File: c:\progra~1\micros~2\office11\mlshext.dll ok scanned
01/03/08 11.24.44 File: c:\progra~1\micros~2\office11\olkfstub.dll ok scanned
01/03/08 11.24.44 File: c:\programmi\microsoft office\office11\msohev.dll ok scanned
01/03/08 11.24.44 File: c:\programmi\winrar\rarext.dll ok scanned
01/03/08 11.24.44 File: c:\windows\system32\mscoree.dll ok scanned
01/03/08 11.24.44 File: C:\WINDOWS\system32\audiodev.dll ok scanned
01/03/08 11.24.44 File: C:\WINDOWS\system32\wpdshext.dll ok scanned
01/03/08 11.24.44 File: c:\programmi\alwil software\avast4\ashshell.dll ok scanned
01/03/08 11.24.45 File: c:\programmi\windows live\mail\mailcomm.dll ok scanned
01/03/08 11.24.45 File: c:\programmi\windows live\photo gallery\wlxphotoacquirewizard.exe ok scanned
01/03/08 11.24.46 File: c:\programmi\windows live\photo gallery\photoviewershim.dll ok scanned
01/03/08 11.24.46 File: c:\programmi\windows live\photo gallery\wlxphotoviewer.dll ok scanned
01/03/08 11.24.46 File: c:\programmi\windows live\messenger\fsshext.8.5.1302.1018.dll ok scanned
01/03/08 11.24.46 File: c:\programmi\windows live toolbar\msntb.dll ok scanned
01/03/08 11.24.46 File: c:\programmi\alcohol toolbar\v3.2.0.0\alcohol_toolbar.dll ok scanned
01/03/08 11.24.47 File: c:\programmi\google\googletoolbar1.dll ok scanned
01/03/08 11.24.47 File: c:\programmi\yahoo!\companion\installs\cpn\yt.dll ok scanned
01/03/08 11.24.47 File: c:\programmi\windows live toolbar\components\it-it\msntabres.dll.mui ok scanned
01/03/08 11.24.47 File: c:\programmi\adobe\acrobat 6.0\reader\activex\acroiehelper.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\skype\toolbars\internet explorer\skypeieplugin.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\bearshare applications\bearshare mediabar\bearshareiehelper.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\file comuni\microsoft shared\windows live\windowslivelogin.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\google\googletoolbarnotifier\2.0.301.7164\swg.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\epson\epson web-to-page\epson web-to-page.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\alwil software\avast4\ashavast.exe ok scanned
01/03/08 11.24.50 File: c:\programmi\ahead\nero backitup\backitup.exe ok scanned
01/03/08 11.24.50 File: c:\programmi\msn gaming zone\windows\bckgzm.exe ok scanned
01/03/08 11.24.51 File: c:\programmi\ccleaner\ccleaner.exe ok scanned
01/03/08 11.24.51 File: c:\programmi\msn gaming zone\windows\chkrzm.exe ok scanned
01/03/08 11.24.51 File: c:\windows\system32\cmcfg32.dll ok scanned
01/03/08 11.24.51 File: c:\programmi\netmeeting\conf.exe ok scanned
01/03/08 11.24.51 File: c:\programmi\windows nt\dialer.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\epson\creativity suite\copy utility\ecopy.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\epson\creativity suite\file manager\efilemanager.exe ok scanned
01/03/08 11.24.52 File: c:\windows\twain_32\escndv\escndv.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\gimp-2.0\bin\gimp-2.0.exe ok scanned
01/03/08 11.24.52 File: c:\windows\pchealth\helpctr\binaries\helpctr.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\msn gaming zone\windows\hrtzzm.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\internet explorer\connection wizard\icwconn1.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\internet explorer\connection wizard\icwconn2.exe ok scanned
01/03/08 11.24.53 File: c:\programmi\ahead\imagedrive\imagedrive.exe ok scanned
01/03/08 11.24.53 File: c:\programmi\internet explorer\connection wizard\inetwiz.exe ok scanned
01/03/08 11.24.53 File: c:\programmi\internet explorer\connection wizard\isignup.exe ok scanned
01/03/08 11.24.53 File: C:\WINDOWS\system32\usmt\migwiz.exe ok scanned
01/03/08 11.24.53 File: c:\programmi\movie maker\moviemk.exe ok scanned
01/03/08 11.24.53 File: c:\programmi\windows media player\mplayer2.exe ok scanned
01/03/08 11.24.54 File: c:\progra~1\micros~2\office11\msaccess.exe ok scanned
01/03/08 11.24.54 File: c:\windows\pchealth\helpctr\binaries\msconfig.exe ok scanned
01/03/08 11.24.54 File: C:\Programmi\outlook express\msimn.exe ok scanned
01/03/08 11.24.54 File: c:\programmi\file comuni\microsoft shared\msinfo\msinfo32.exe ok scanned
01/03/08 11.24.54 File: c:\progra~1\micros~2\office11\mspub.exe ok scanned
01/03/08 11.24.54 File: c:\progra~1\fileco~1\micros~1\modi\11.0\mspview.exe ok scanned
01/03/08 11.24.55 File: c:\programmi\ahead\coverdesigner\coverdes.exe ok scanned
01/03/08 11.24.56 File: c:\programmi\ahead\nero\nero.exe ok scanned
01/03/08 11.24.57 File: c:\programmi\ahead\nero startsmart\nerostartsmart.exe ok scanned
01/03/08 11.24.57 File: C:\WINDOWS\system32\mspaint.exe ok scanned
01/03/08 11.24.57 File: c:\programmi\quicktime\pictureviewer.exe ok scanned
01/03/08 11.24.57 File: c:\programmi\windows nt\pinball\pinball.exe ok scanned
01/03/08 11.24.57 File: c:\progra~1\micros~2\office11\powerpnt.exe ok scanned
01/03/08 11.24.58 File: c:\programmi\quicktime\quicktimeplayer.exe ok scanned
01/03/08 11.24.58 File: c:\programmi\msn gaming zone\windows\rvsezm.exe ok scanned
01/03/08 11.24.58 File: c:\progra~1\micros~2\office11\1040\schdpl32.exe ok scanned
01/03/08 11.24.58 File: c:\programmi\msn gaming zone\windows\shvlzm.exe ok scanned
01/03/08 11.24.58 File: c:\documents and settings\admin\desktop\sopcast\sopcast.exe ok scanned
01/03/08 11.24.58 File: C:\Programmi\outlook express\wab.exe ok scanned
01/03/08 11.24.59 File: C:\Programmi\outlook express\wabmig.exe ok scanned
01/03/08 11.24.59 File: c:\programmi\winrar\winrar.exe ok scanned
01/03/08 11.24.59 File: c:\progra~1\micros~2\office11\winword.exe ok scanned
01/03/08 11.24.59 File: c:\programmi\windows live\mail\wlmail.exe ok scanned
01/03/08 11.25.00 File: c:\programmi\ahead\wmpburn\wmpburn.exe ok scanned
01/03/08 11.25.00 File: c:\windows\system32\ntsd.exe ok scanned
01/03/08 11.25.00 File: c:\programmi\windows live\writer\writerbrowserextension.dll ok scanned
01/03/08 11.25.00 File: c:\progra~1\skype\toolbars\intern~1\favicon.ico ok scanned
01/03/08 11.25.00 File: c:\progra~1\micros~2\office11\refiebar.dll ok scanned
01/03/08 11.25.00 File: c:\progra~1\micros~2\office11\refbar.ico ok scanned
01/03/08 11.25.00 File: c:\progra~1\micros~2\office11\refbarh.ico ok scanned
01/03/08 11.25.00 File: c:\programmi\yahoo!\common\yinsthelper.dll ok scanned
01/03/08 11.25.00 File: c:\windows\system32\java.exe ok scanned
01/03/08 11.25.00 File: c:\progra~1\yahoo!\common\yinsthelper.dll ok scanned
01/03/08 11.25.00 File: c:\programmi\java\j2re1.4.2_05\bin\npjpi142_05.dll ok scanned
01/03/08 11.25.01 File: c:\windows\system32\macromed\flash\flash9c.ocx ok scanned
01/03/08 11.25.01 File: c:\programmi\apple software update\softwareupdate.exe ok scanned
01/03/08 11.25.01 File: c:\programmi\windows live toolbar\msntbup.exe ok scanned
01/03/08 11.25.01 File: C:\WINDOWS\system32\rsvpsp.dll ok scanned
01/03/08 11.25.01 File: C:\WINDOWS\system32\winrnr.dll ok scanned
01/03/08 11.25.01 File: C:\WINDOWS\system32\nwprovau.dll ok scanned
01/03/08 11.25.01 Logical disk sector: C ok scanned
01/03/08 11.25.02 Physical disk sector: \Device\HarddiskVolume1 ok scanned
01/03/08 11.25.02 Physical disk sector: \Device\Harddisk0\DR0 ok scanned
01/03/08 11.25.02 File: c:\windows\system32\jrckdbio.exe detected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.28.13 File: c:\windows\system32\jrckdbio.exe backed up
01/03/08 11.28.15 Startup object: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\jrckdbio disinfected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.28.15 Startup object: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\jrckdbio disinfected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.28.24 File: c:\windows\system32\jrckdbio.exe deleted
01/03/08 11.28.24 File: c:\windows\system32\pq.exe detected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.30.08 File: c:\documents and settings\admin\impostazioni locali\temp\rar$ex03.454\msnfix\backup\services.exe detected Trojan program 'Trojan.Win32.Agent.dwa'
Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------
Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Quarantine
----------
Status Object Size Added
------ ------ ---- -----
Backup
------
Status Object Size
------ ------ ----
Infected: virus Email-Worm.Win32.Agent.ax c:\windows\system32\jrckdbio.exe 224 KB
Pi log HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15.52.37, on 01/03/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Java\j2re1.4.2_05\bin\jusched.exe
C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\GlobespanVirata\Adsl\dslstat.exe
C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
C:\Programmi\Winamp\winampa.exe
C:\Programmi\QuickTime\qttask.exe
C:\Programmi\D-Tools\daemon.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe
C:\Programmi\BearShare\BearShare.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX03.454\MSNFix\backup\services.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX00.828\HijackThis.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX00.032\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgilio.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Programmi\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Programmi\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: XBTP01621 Class - {F6104497-54FD-4688-9162-5115CC8AB0FB} - C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll (file missing)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Programmi\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Programmi\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_SA7.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\GlobespanVirata\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmi\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [BearShare] "C:\Programmi\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Servicee] C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX03.454\MSNFix\backup\services.exe
O4 - HKLM\..\RunServices: [pq] C:\WINDOWS\system32\pq.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?7be0d3f2ad3640e09d52c404a784eaf3
O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?7be0d3f2ad3640e09d52c404a784eaf3
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{474A9685-8DBB-4B40-B2A9-E410C4B11743}: NameServer = 85.37.17.9 85.38.28.75
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: setup_7.0.0.180_29.02.2008_23-14 - Kaspersky Lab - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Print Spooler Service (ui1oaleopa0o6e) - Unknown owner - C:\WINDOWS\system32\pq.exe (file missing)
--
End of file - 10123 bytes
Poi log HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15.52.37, on 01/03/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Java\j2re1.4.2_05\bin\jusched.exe
C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\GlobespanVirata\Adsl\dslstat.exe
C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
C:\Programmi\Winamp\winampa.exe
C:\Programmi\QuickTime\qttask.exe
C:\Programmi\D-Tools\daemon.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe
C:\Programmi\BearShare\BearShare.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX03.454\MSNFix\backup\services.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX00.828\HijackThis.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX00.032\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgilio.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Programmi\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Programmi\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: XBTP01621 Class - {F6104497-54FD-4688-9162-5115CC8AB0FB} - C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll (file missing)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Programmi\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Programmi\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_SA7.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\GlobespanVirata\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmi\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [BearShare] "C:\Programmi\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Servicee] C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX03.454\MSNFix\backup\services.exe
O4 - HKLM\..\RunServices: [pq] C:\WINDOWS\system32\pq.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?7be0d3f2ad3640e09d52c404a784eaf3
O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?7be0d3f2ad3640e09d52c404a784eaf3
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{474A9685-8DBB-4B40-B2A9-E410C4B11743}: NameServer = 85.37.17.9 85.38.28.75
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: setup_7.0.0.180_29.02.2008_23-14 - Kaspersky Lab - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Print Spooler Service (ui1oaleopa0o6e) - Unknown owner - C:\WINDOWS\system32\pq.exe (file missing)
--
End of file - 10123 bytes
Io ho come S.O windows xp .
Log di LiveKillCleanMessenger
sabato 1 marzo 2008 11.58.27 build 1256
Microsoft Windows XP Professional(it-IT)
511 Mo (RAM)
Last DataBase update : NOT UPDATED
C:\Programmi\LiveKillCleanMessenger
NORMAL MODE
C:\WINDOWS\wr.txt
poi log msn cleaner
File di log MSNCleaner 1.5.6 by www.forospyware.com
- File di log creato: 01/03/08 on 12.04.26
- Sistema Operativo: Windows XP
- Modalità d'avvio: Normale
_________________________________________
File trovati: 0
File rimossi: 0
File non rimossi: 0
<<<<<<< Nessun file trovato >>>>>>>
Poi log kaspersky
Scan
----
Scanned: 614
Detected: 3
Untreated: 2
Start time: 01/03/08 11.23.47
Duration: 00.06.39
Finish time: 01/03/08 11.30.26
Detected
--------
Status Object
------ ------
deleted: virus Email-Worm.Win32.Agent.ax File: c:\windows\system32\jrckdbio.exe
detected: virus Email-Worm.Win32.Agent.ax File: c:\windows\system32\pq.exe
detected: Trojan program Trojan.Win32.Agent.dwa File: c:\docume~1\admin\impost~1\temp\rar$ex03.454\msnfix\backup\services.exe
Events
------
Time Name Status Reason
---- ---- ------ ------
01/03/08 11.23.50 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe ok scanned
01/03/08 11.23.50 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe ok scanned
01/03/08 11.23.50 Running module: C:\WINDOWS\system32\ntdll.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\ntdll.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\kernel32.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\kernel32.dll ok scanned
01/03/08 11.23.51 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prremote.dll ok scanned
01/03/08 11.23.51 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prremote.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\RPCRT4.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\RPCRT4.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\Secur32.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\Secur32.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\USER32.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\USER32.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\GDI32.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\GDI32.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCP80.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCP80.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCR80.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCR80.dll ok scanned
01/03/08 11.23.51 Running module: C:\WINDOWS\system32\msvcrt.dll ok scanned
01/03/08 11.23.51 File: C:\WINDOWS\system32\msvcrt.dll ok scanned
01/03/08 11.23.52 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\FSSync.dll ok scanned
01/03/08 11.23.52 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\FSSync.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\SHELL32.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\SHELL32.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\SHLWAPI.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\SHLWAPI.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\ole32.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\ole32.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\uxtheme.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\uxtheme.dll ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\MSCTF.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\MSCTF.dll ok scanned
01/03/08 11.23.52 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\AVPGS.PPL ok scanned
01/03/08 11.23.52 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\AVPGS.PPL ok scanned
01/03/08 11.23.52 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prloader.dll ok scanned
01/03/08 11.23.52 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prloader.dll ok scanned
01/03/08 11.23.52 Running module: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prkernel.ppl ok scanned
01/03/08 11.23.52 File: C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\prkernel.ppl ok scanned
01/03/08 11.23.52 Running module: C:\WINDOWS\system32\userenv.dll ok scanned
01/03/08 11.23.52 File: C:\WINDOWS\system32\userenv.dll ok scanned
01/03/08 11.23.52 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\pxstub.ppl ok scanned
01/03/08 11.23.52 File: c:\documents and settings\all users\desktop\kaspersky lab tool\pxstub.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\params.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\params.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\dtreg.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\dtreg.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\nfio.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\nfio.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\fsdrvplg.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\fsdrvplg.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\mkavio.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\mkavio.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\tempfile.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\tempfile.ppl ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\avpgui.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\avpgui.ppl ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\WININET.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\WININET.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\CRYPT32.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\CRYPT32.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\MSASN1.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\MSASN1.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\OLEAUT32.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\OLEAUT32.dll ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\basegui.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\basegui.ppl ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\VERSION.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\VERSION.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\WS2_32.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\WS2_32.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\WS2HELP.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\WS2HELP.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\CLBCATQ.DLL ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\CLBCATQ.DLL ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\COMRes.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\COMRes.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\xpsp2res.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll archive EmbeddedHTML
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0001.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0002.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0003.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0004.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0005.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0006.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0007.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0008.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0009.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0010.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0011.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll//data0012.html ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\xpsp2res.dll ok scanned
01/03/08 11.23.53 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\thpimpl.ppl ok scanned
01/03/08 11.23.53 File: c:\documents and settings\all users\desktop\kaspersky lab tool\thpimpl.ppl ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\fltlib.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\fltlib.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\wtsapi32.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\wtsapi32.dll ok scanned
01/03/08 11.23.53 Running module: C:\WINDOWS\system32\WINSTA.dll ok scanned
01/03/08 11.23.53 File: C:\WINDOWS\system32\WINSTA.dll ok scanned
01/03/08 11.23.54 Running module: C:\WINDOWS\system32\NETAPI32.dll ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\system32\NETAPI32.dll ok scanned
01/03/08 11.23.54 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\qb.ppl ok scanned
01/03/08 11.23.54 File: c:\documents and settings\all users\desktop\kaspersky lab tool\qb.ppl ok scanned
01/03/08 11.23.54 Running module: C:\WINDOWS\system32\appHelp.dll ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\system32\appHelp.dll ok scanned
01/03/08 11.23.54 Running module: C:\WINDOWS\System32\cscui.dll ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\System32\cscui.dll ok scanned
01/03/08 11.23.54 Running module: C:\WINDOWS\System32\CSCDLL.dll ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\System32\CSCDLL.dll ok scanned
01/03/08 11.23.54 Running module: C:\WINDOWS\system32\SETUPAPI.dll ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\system32\SETUPAPI.dll ok scanned
01/03/08 11.23.54 Running module: c:\documents and settings\all users\desktop\kaspersky lab tool\report.ppl ok scanned
01/03/08 11.23.54 File: c:\documents and settings\all users\desktop\kaspersky lab tool\report.ppl ok scanned
01/03/08 11.23.54 File: c:\windows\system32\mmdrv.dll ok scanned
01/03/08 11.23.54 File: c:\windows\system\timer.drv ok scanned
01/03/08 11.23.54 File: c:\windows\system32\mshta.exe ok scanned
01/03/08 11.23.54 File: C:\WINDOWS\system32\notepad.exe ok scanned
01/03/08 11.23.54 File: c:\windows\regedit.exe ok scanned
01/03/08 11.23.55 File: c:\programmi\microsoft office\office11\msaccess.exe ok scanned
01/03/08 11.23.56 File: c:\programmi\adobe\acrobat 6.0\reader\acrord32.exe ok scanned
01/03/08 11.23.56 File: C:\WINDOWS\system32\accwiz.exe ok scanned
01/03/08 11.23.56 File: c:\programmi\windows media player\wmplayer.exe ok scanned
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe packed file PE_Patch.PECompact
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe//PE_Patch.PECompact packed file PecBundle
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe//PE_Patch.PECompact//PecBundle packed file PECompact
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe//PE_Patch.PECompact//PecBundle//PECompact ok scanned
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe//PE_Patch.PECompact//PecBundle ok scanned
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe//PE_Patch.PECompact ok scanned
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe ok scanned
01/03/08 11.23.56 File: c:\programmi\utorrent\utorrent.exe:Zone.Identifier ok scanned
01/03/08 11.23.56 File: c:\programmi\alwil software\avast4\ashsimpl.exe ok scanned
01/03/08 11.23.57 File: C:\Programmi\windows nt\accessori\wordpad.exe ok scanned
01/03/08 11.23.57 File: c:\windows\system32\rundll32.exe ok scanned
01/03/08 11.23.57 File: c:\windows\system32\cryptext.dll ok scanned
01/03/08 11.23.57 File: c:\programmi\outlook express\wab.exe ok scanned
01/03/08 11.23.57 File: c:\windows\explorer.exe ok scanned
01/03/08 11.23.57 File: C:\WINDOWS\system32\cdfview.dll ok scanned
01/03/08 11.23.57 File: c:\windows\hh.exe ok scanned
01/03/08 11.23.57 File: c:\windows\system32\clipbrd.exe ok scanned
01/03/08 11.23.59 File: c:\programmi\vso\convertxtodvd\convertxtodvd.exe ok scanned
01/03/08 11.23.59 File: c:\progra~1\micros~2\office11\excel.exe ok scanned
01/03/08 11.23.59 File: C:\WINDOWS\system32\rundll32.exe ok scanned
01/03/08 11.23.59 File: c:\windows\system32\netshell.dll ok scanned
01/03/08 11.24.00 File: c:\windows\system32\shimgvw.dll ok scanned
01/03/08 11.24.00 File: c:\programmi\microsoft office\office11\excel.exe ok scanned
01/03/08 11.24.00 File: C:\WINDOWS\explorer.exe ok scanned
01/03/08 11.24.00 File: C:\WINDOWS\system32\fontview.exe ok scanned
01/03/08 11.24.00 File: c:\programmi\bearshare\bearshare.exe packed file Armadillo
01/03/08 11.24.00 File: c:\programmi\bearshare\bearshare.exe//Armadillo ok scanned
01/03/08 11.24.01 File: c:\programmi\bearshare\bearshare.exe ok scanned
01/03/08 11.24.01 File: c:\windows\system32\msconf.dll ok scanned
01/03/08 11.24.01 File: c:\windows\winhlp32.exe ok scanned
01/03/08 11.24.01 File: C:\WINDOWS\system32\winhlp32.exe ok scanned
01/03/08 11.24.01 File: c:\progra~1\micros~2\office11\outlook.exe ok scanned
01/03/08 11.24.01 File: c:\programmi\windows nt\hypertrm.exe ok scanned
01/03/08 11.24.01 File: c:\programmi\internet explorer\iexplore.exe ok scanned
01/03/08 11.24.01 File: c:\programmi\intervideo\dvd6\windvd.exe ok scanned
01/03/08 11.24.02 File: c:\programmi\java\j2re1.4.2_05\bin\javaw.exe ok scanned
01/03/08 11.24.02 File: c:\programmi\java\j2re1.4.2_05\javaws\javaws.exe ok scanned
01/03/08 11.24.02 File: C:\WINDOWS\system32\wscript.exe ok scanned
01/03/08 11.24.02 File: c:\programmi\microsoft office\office11\mstore.exe ok scanned
01/03/08 11.24.02 File: C:\WINDOWS\system32\ntbackup.exe ok scanned
01/03/08 11.24.02 File: C:\WINDOWS\system32\mmc.exe ok scanned
01/03/08 11.24.02 File: c:\programmi\microsoft office\office11\outlook.exe ok scanned
01/03/08 11.24.02 File: C:\WINDOWS\system32\shell32.dll ok scanned
01/03/08 11.24.02 File: C:\WINDOWS\system32\desk.cpl ok scanned
01/03/08 11.24.02 File: c:\progra~1\micros~2\office11\ois.exe ok scanned
01/03/08 11.24.03 File: c:\programmi\microsoft office\office11\finder.exe ok scanned
01/03/08 11.24.03 File: C:\WINDOWS\system32\rasphone.exe ok scanned
01/03/08 11.24.03 File: C:\WINDOWS\system32\perfmon.exe ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe//# ok scanned
01/03/08 11.24.03 File: c:\programmi\epson\pif designer\pif designer.exe ok scanned
01/03/08 11.24.03 File: c:\programmi\microsoft office\office11\powerpnt.exe ok scanned
01/03/08 11.24.03 File: c:\windows\system32\msrating.dll ok scanned
01/03/08 11.24.04 File: c:\programmi\windows nt\accessori\wordpad.exe ok scanned
01/03/08 11.24.04 File: c:\windows\notepad.exe ok scanned
01/03/08 11.24.04 File: c:\programmi\file comuni\microsoft shared\snapshot viewer\snapview.exe ok scanned
01/03/08 11.24.04 File: C:\WINDOWS\system32\wpnpinst.exe ok scanned
01/03/08 11.24.04 File: c:\programmi\winamp\winamp.exe ok scanned
01/03/08 11.24.05 File: c:\programmi\microsoft office\office11\winword.exe ok scanned
01/03/08 11.24.05 File: c:\programmi\file comuni\microsoft shared\office11\msoxmled.exe ok scanned
01/03/08 11.24.05 File: c:\windows\system32\shell32.dll ok scanned
01/03/08 11.24.05 File: c:\windows\system32\drwtsn32.exe ok scanned
01/03/08 11.24.06 File: c:\windows\system32\userinit.exe ok scanned
01/03/08 11.24.06 File: c:\windows\system32\ati2evxx.dll ok scanned
01/03/08 11.24.06 File: c:\windows\system32\crypt32.dll ok scanned
01/03/08 11.24.06 File: c:\windows\system32\cryptnet.dll ok scanned
01/03/08 11.24.06 File: c:\windows\system32\cscdll.dll ok scanned
01/03/08 11.24.07 File: c:\windows\system32\wlnotify.dll ok scanned
01/03/08 11.24.07 File: c:\windows\system32\sclgntfy.dll ok scanned
01/03/08 11.24.07 File: c:\windows\system32\wgalogon.dll ok scanned
01/03/08 11.24.07 File: c:\windows\system32\nerocheck.exe ok scanned
01/03/08 11.24.07 File: c:\programmi\java\j2re1.4.2_05\bin\jusched.exe ok scanned
01/03/08 11.24.07 File: c:\programmi\analog devices\soundmax\smtray.exe ok scanned
01/03/08 11.24.07 File: c:\windows\system32\spool\drivers\w32x86\3\e_fatibee.exe ok scanned
01/03/08 11.24.07 File: c:\windows\temp\e_sa7.tmp ok scanned
01/03/08 11.24.07 File: c:\program files\globespanvirata\adsl\dslstat.exe ok scanned
01/03/08 11.24.07 File: c:\program files\globespanvirata\adsl\dslagent.exe ok scanned
01/03/08 11.24.07 File: c:\programmi\winamp\winampa.exe ok scanned
01/03/08 11.24.07 File: c:\programmi\quicktime\qttask.exe ok scanned
01/03/08 11.24.07 File: c:\programmi\d-tools\daemon.exe ok scanned
01/03/08 11.24.07 File: c:\progra~1\alwils~1\avast4\ashdisp.exe ok scanned
01/03/08 11.24.07 File: c:\windows\system32\jrckdbio.exe detected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.24.07 File: c:\windows\system32\jrckdbio.exe not disinfected postponed
01/03/08 11.24.08 File: c:\windows\system32\pq.exe detected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.24.08 File: c:\windows\system32\pq.exe not disinfected postponed
01/03/08 11.24.08 File: c:\docume~1\admin\impost~1\temp\rar$ex03.454\msnfix\backup\services.exe detected Trojan program 'Trojan.Win32.Agent.dwa'
01/03/08 11.24.08 File: c:\docume~1\admin\impost~1\temp\rar$ex03.454\msnfix\backup\services.exe not disinfected postponed
01/03/08 11.24.08 File: c:\documents and settings\all users\desktop\kaspersky lab tool\setup_7.0.0.180_29.02.2008_23-14.exe ok scanned
01/03/08 11.24.08 File: c:\windows\system32\ctfmon.exe ok scanned
01/03/08 11.24.08 File: c:\programmi\windows live\messenger\msnmsgr.exe ok scanned
01/03/08 11.24.08 File: c:\programmi\google\googletoolbarnotifier\googletoolbarnotifier.exe ok scanned
01/03/08 11.24.09 File: c:\programmi\skype\phone\skype.exe ok scanned
01/03/08 11.24.09 File: C:\WINDOWS\system32\alrsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\appmgmts.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\audiosrv.dll ok scanned
01/03/08 11.24.10 File: c:\windows\system32\qmgr.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\browser.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\cryptsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\rpcss.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\dhcpcsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\dmserver.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\dnsrslvr.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\ersvc.dll ok scanned
01/03/08 11.24.10 File: c:\windows\system32\es.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\shsvcs.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\hidserv.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\w3ssl.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\srvsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\wkssvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\lmhsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\msgsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\netman.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\mswsock.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\ntmssvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\rasauto.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\rasmans.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\mprdim.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\regsvc.dll ok scanned
01/03/08 11.24.10 File: C:\WINDOWS\system32\schedsvc.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\seclogon.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\sens.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\ipnathlp.dll ok scanned
01/03/08 11.24.11 File: c:\windows\system32\srsvc.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\ssdpsrv.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\wiaservc.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\tapisrv.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\termsrv.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\trkwks.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\upnphost.dll ok scanned
01/03/08 11.24.11 File: c:\windows\system32\w32time.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\webclnt.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\wbem\wmisvc.dll ok scanned
01/03/08 11.24.11 File: c:\windows\system32\mspmsnsv.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\advapi32.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\wscsvc.dll ok scanned
01/03/08 11.24.11 File: c:\windows\system32\wuauserv.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\wudfsvc.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\wzcsvc.dll ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\xmlprov.dll ok scanned
01/03/08 11.24.11 File: c:\windows\system32\drivers\acpi.sys ok scanned
01/03/08 11.24.11 File: c:\windows\system32\drivers\aeaudio.sys ok scanned
01/03/08 11.24.11 File: c:\windows\system32\drivers\aec.sys ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\drivers\afd.sys ok scanned
01/03/08 11.24.11 File: C:\WINDOWS\system32\svchost.exe ok scanned
01/03/08 11.24.12 File: C:\WINDOWS\system32\alg.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\aliide.sys ok scanned
01/03/08 11.24.12 File: C:\WINDOWS\microsoft.net\framework\v1.1.4322\aspnet_state.exe ok scanned
01/03/08 11.24.12 File: c:\programmi\alwil software\avast4\aswupdsv.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\asyncmac.sys ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\atapi.sys ok scanned
01/03/08 11.24.12 File: C:\WINDOWS\system32\ati2evxx.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\ati2mtag.sys ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\atmarpc.sys ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\audstub.sys ok scanned
01/03/08 11.24.12 File: c:\programmi\alwil software\avast4\ashserv.exe ok scanned
01/03/08 11.24.12 File: c:\programmi\alwil software\avast4\ashmaisv.exe ok scanned
01/03/08 11.24.12 File: c:\programmi\alwil software\avast4\ashwebsv.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\cdrom.sys ok scanned
01/03/08 11.24.12 File: C:\WINDOWS\system32\cisvc.exe ok scanned
01/03/08 11.24.12 File: C:\WINDOWS\system32\clipsrv.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\dllhost.exe ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\d347bus.sys ok scanned
01/03/08 11.24.12 File: c:\windows\system32\drivers\d347prt.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\disk.sys ok scanned
01/03/08 11.24.13 File: C:\WINDOWS\system32\dmadmin.exe ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmboot.sys packed file PE_Patch
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmboot.sys//PE_Patch ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmboot.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmio.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmload.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\dmusic.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\drmkaud.sys ok scanned
01/03/08 11.24.13 File: C:\WINDOWS\system32\services.exe ok scanned
01/03/08 11.24.13 File: c:\windows\system32\svchost.exe ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\fdc.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\flpydisk.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\fltmgr.sys packed file PE_Patch
01/03/08 11.24.13 File: c:\windows\system32\drivers\fltmgr.sys//PE_Patch ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\fltmgr.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ftdisk.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\msgpc.sys ok scanned
01/03/08 11.24.13 File: c:\programmi\google\common\google updater\googleupdaterservice.exe ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\hidusb.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\http.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\i8042prt.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\imapi.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\imapi.exe ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ip6fw.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ipfltdrv.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ipinip.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ipnat.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\ipsec.sys ok scanned
01/03/08 11.24.13 File: c:\windows\system32\drivers\irenum.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\isapnp.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\kbdclass.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\klif.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\kmixer.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\m5289.sys ok scanned
01/03/08 11.24.14 File: c:\programmi\file comuni\microsoft shared\vs7debug\mdm.exe ok scanned
01/03/08 11.24.14 File: c:\windows\system32\mnmsrvc.exe ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mouclass.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxdav.sys packed file PE_Patch
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxdav.sys//PE_Patch ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxdav.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxsmb.sys packed file PE_Patch
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxsmb.sys//PE_Patch ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mrxsmb.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\msdtc.exe ok scanned
01/03/08 11.24.14 File: c:\windows\system32\msiexec.exe ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mskssrv.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mspclock.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mspqm.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\mssmbios.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\ndistapi.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\ndisuio.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\ndiswan.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\netbios.sys ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\netbt.sys ok scanned
01/03/08 11.24.14 File: C:\WINDOWS\system32\netdde.exe ok scanned
01/03/08 11.24.14 File: C:\WINDOWS\system32\lsass.exe ok scanned
01/03/08 11.24.14 File: c:\windows\system32\drivers\nwlnkflt.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\nwlnkfwd.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\nwlnkipx.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\nwlnknb.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\nwlnkspx.sys ok scanned
01/03/08 11.24.15 File: c:\programmi\file comuni\microsoft shared\source engine\ose.exe ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\pci.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\pcouffin.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\raspptp.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\processr.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\psched.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\ptilink.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\pxhelp20.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\rasacd.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\rasl2tp.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\raspppoe.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\raspti.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\rdbss.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\rdpcdd.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\rdpdr.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\sessmgr.exe ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\redbook.sys ok scanned
01/03/08 11.24.15 File: C:\WINDOWS\system32\locator.exe ok scanned
01/03/08 11.24.15 File: c:\windows\system32\rpcss.dll ok scanned
01/03/08 11.24.15 File: C:\WINDOWS\system32\rsvp.exe ok scanned
01/03/08 11.24.15 File: C:\WINDOWS\system32\scardsvr.exe ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\secdrv.sys ok scanned
01/03/08 11.24.15 File: c:\windows\system32\drivers\serenum.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\serial.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\smwdm.sys ok scanned
01/03/08 11.24.16 File: c:\programmi\analog devices\soundmax\smagent.exe ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\splitter.sys ok scanned
01/03/08 11.24.16 File: C:\WINDOWS\system32\spoolsv.exe ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\sptd.sys skipped locked
01/03/08 11.24.16 File: C:\WINDOWS\system32\drivers\sr.sys packed file PE_Patch
01/03/08 11.24.16 File: C:\WINDOWS\system32\drivers\sr.sys//PE_Patch ok scanned
01/03/08 11.24.16 File: C:\WINDOWS\system32\drivers\sr.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\srv.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\swenum.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\swmidi.sys ok scanned
01/03/08 11.24.16 File: c:\windows\system32\drivers\sysaudio.sys ok scanned
01/03/08 11.24.16 File: C:\WINDOWS\system32\smlogsvc.exe ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\tcpip.sys ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\termdd.sys ok scanned
01/03/08 11.24.17 File: c:\windows\system32\tlntsvr.exe ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\ulilan.sys ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\agpkx.sys ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\update.sys ok scanned
01/03/08 11.24.17 File: C:\WINDOWS\system32\ups.exe ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\usbaudio.sys ok scanned
01/03/08 11.24.17 File: c:\windows\system32\drivers\usbccgp.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbehci.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbhub.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbohci.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbprint.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbscan.sys ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\usbstor.sys ok scanned
01/03/08 11.24.18 File: c:\programmi\windows live\messenger\usnsvc.exe ok scanned
01/03/08 11.24.18 File: C:\WINDOWS\system32\drivers\vga.sys ok scanned
01/03/08 11.24.18 File: C:\WINDOWS\system32\vssvc.exe ok scanned
01/03/08 11.24.18 File: c:\windows\system32\drivers\wanarp.sys ok scanned
01/03/08 11.24.19 File: c:\windows\system32\drivers\gwausb.sys ok scanned
01/03/08 11.24.19 File: c:\windows\system32\drivers\wdmaud.sys ok scanned
01/03/08 11.24.19 File: c:\programmi\windows live\installer\wlsetupsvc.exe ok scanned
01/03/08 11.24.19 File: c:\windows\system32\wbem\wmiapsrv.exe ok scanned
01/03/08 11.24.20 File: c:\programmi\windows media player\wmpnetwk.exe ok scanned
01/03/08 11.24.20 File: c:\windows\system32\drivers\wudfpf.sys ok scanned
01/03/08 11.24.20 File: c:\windows\system32\drivers\wudfrd.sys ok scanned
01/03/08 11.24.20 File: c:\windows\system32\javasup.vxd ok scanned
01/03/08 11.24.20 File: c:\windows\system32\autochk.exe ok scanned
01/03/08 11.24.21 File: c:\windows\inf\unregmp2.exe ok scanned
01/03/08 11.24.21 File: C:\WINDOWS\system32\shmgrate.exe ok scanned
01/03/08 11.24.21 File: c:\windows\system32\iedkcs32.dll ok scanned
01/03/08 11.24.21 File: C:\WINDOWS\system32\regsvr32.exe ok scanned
01/03/08 11.24.21 File: C:\WINDOWS\system32\themeui.dll ok scanned
01/03/08 11.24.22 File: C:\Programmi\outlook express\setup50.exe//# ok scanned
01/03/08 11.24.22 File: C:\Programmi\outlook express\setup50.exe ok scanned
01/03/08 11.24.22 File: c:\windows\system32\user.exe ok scanned
01/03/08 11.24.22 File: c:\windows\system32\drivers\install.exe ok scanned
01/03/08 11.24.22 File: c:\windows\system32\advpack.dll ok scanned
01/03/08 11.24.22 File: c:\windows\inf\msnetmtg.inf ok scanned
01/03/08 11.24.22 File: c:\windows\inf\msmsgs.inf ok scanned
01/03/08 11.24.22 File: c:\windows\inf\wmp11.inf ok scanned
01/03/08 11.24.22 File: c:\windows\system32\regsvr32.exe ok scanned
01/03/08 11.24.22 File: C:\WINDOWS\system32\ie4uinit.exe ok scanned
01/03/08 11.24.22 File: c:\windows\system32\mscories.dll ok scanned
01/03/08 11.24.23 File: c:\windows\system32\comm.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system\vga.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system\mmsystem.dll ok scanned
01/03/08 11.24.23 File: c:\windows\system\keyboard.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system\mouse.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system\wfwnet.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system32\progman.exe ok scanned
01/03/08 11.24.23 File: c:\windows\system\sound.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system\system.drv ok scanned
01/03/08 11.24.23 File: c:\windows\system32\midimap.dll ok scanned
01/03/08 11.24.23 File: c:\windows\system32\imaadp32.acm ok scanned
01/03/08 11.24.23 File: c:\windows\system32\msadp32.acm ok scanned
01/03/08 11.24.24 File: c:\windows\system32\msg711.acm ok scanned
01/03/08 11.24.24 File: c:\windows\system32\msgsm32.acm ok scanned
01/03/08 11.24.24 File: c:\windows\system32\tssoft32.acm ok scanned
01/03/08 11.24.24 File: c:\windows\system32\iccvid.dll ok scanned
01/03/08 11.24.24 File: c:\windows\system32\msh263.drv ok scanned
01/03/08 11.24.24 File: c:\windows\system32\ir32_32.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\ir41_32.ax ok scanned
01/03/08 11.24.25 File: c:\windows\system32\iyuv_32.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msrle32.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msvidc32.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msyuv.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\tsbyuv.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msacm32.drv ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msg723.acm ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msh261.drv ok scanned
01/03/08 11.24.25 File: c:\windows\system32\msaud32.acm ok scanned
01/03/08 11.24.25 File: c:\windows\system32\sl_anet.acm ok scanned
01/03/08 11.24.25 File: c:\windows\system32\iac25_32.ax ok scanned
01/03/08 11.24.25 File: c:\windows\system32\ir50_32.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\l3codeca.acm ok scanned
01/03/08 11.24.25 File: c:\windows\system32\wdmaud.drv ok scanned
01/03/08 11.24.25 File: c:\windows\system32\syncor11.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\sirenacm.dll ok scanned
01/03/08 11.24.25 File: C:\WINDOWS\system32\webcheck.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\stobject.dll ok scanned
01/03/08 11.24.25 File: c:\windows\system32\wpdshserviceobj.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\logon.scr ok scanned
01/03/08 11.24.26 File: C:\WINDOWS\system32\logon.scr ok scanned
01/03/08 11.24.26 File: C:\WINDOWS\system32\browseui.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\mmsys.cpl ok scanned
01/03/08 11.24.26 File: c:\windows\system32\icmui.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\rshx32.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\docprop.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\ntshrui.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\deskadp.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\deskmon.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\dssec.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\slayerxp.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\shscrap.dll ok scanned
01/03/08 11.24.26 File: c:\windows\system32\diskcopy.dll ok scanned
01/03/08 11.24.27 File: c:\windows\system32\ntlanui2.dll ok scanned
01/03/08 11.24.27 File: C:\WINDOWS\system32\icmui.dll ok scanned
01/03/08 11.24.27 File: c:\windows\system32\printui.dll ok scanned
01/03/08 11.24.27 File: c:\windows\system32\dskquoui.dll ok scanned
01/03/08 11.24.27 File: c:\windows\system32\syncui.dll ok scanned
01/03/08 11.24.28 File: c:\windows\system32\hticons.dll ok scanned
01/03/08 11.24.28 File: c:\windows\system32\fontext.dll ok scanned
01/03/08 11.24.28 File: c:\windows\system32\deskperf.dll ok scanned
01/03/08 11.24.29 File: c:\windows\system32\wiashext.dll ok scanned
01/03/08 11.24.29 File: c:\windows\system32\remotepg.dll ok scanned
01/03/08 11.24.29 File: c:\windows\system32\wshext.dll ok scanned
01/03/08 11.24.30 File: c:\programmi\file comuni\system\ole db\oledb32.dll ok scanned
01/03/08 11.24.31 File: c:\windows\system32\mstask.dll ok scanned
01/03/08 11.24.32 File: C:\WINDOWS\system32\shdocvw.dll ok scanned
01/03/08 11.24.33 File: c:\windows\system32\wuaucpl.cpl ok scanned
01/03/08 11.24.33 File: C:\WINDOWS\system32\twext.dll ok scanned
01/03/08 11.24.33 File: C:\WINDOWS\system32\shmedia.dll ok scanned
01/03/08 11.24.35 File: c:\windows\system32\shdocvw.dll ok scanned
01/03/08 11.24.36 File: c:\windows\system32\sendmail.dll ok scanned
01/03/08 11.24.37 File: C:\WINDOWS\system32\occache.dll ok scanned
01/03/08 11.24.37 File: C:\WINDOWS\system32\appwiz.cpl ok scanned
01/03/08 11.24.37 File: C:\WINDOWS\system32\shimgvw.dll ok scanned
01/03/08 11.24.37 File: C:\WINDOWS\system32\netplwiz.dll ok scanned
01/03/08 11.24.38 File: C:\WINDOWS\system32\zipfldr.dll ok scanned
01/03/08 11.24.38 File: C:\WINDOWS\system32\extmgr.dll ok scanned
01/03/08 11.24.39 File: c:\windows\system32\msieftp.dll ok scanned
01/03/08 11.24.39 File: c:\windows\system32\docprop2.dll ok scanned
01/03/08 11.24.39 File: C:\WINDOWS\system32\dsquery.dll ok scanned
01/03/08 11.24.39 File: C:\WINDOWS\system32\dsuiext.dll ok scanned
01/03/08 11.24.39 File: C:\WINDOWS\system32\mydocs.dll ok scanned
01/03/08 11.24.39 File: C:\WINDOWS\system32\cscui.dll ok scanned
01/03/08 11.24.40 File: c:\windows\msagent\agentpsh.dll ok scanned
01/03/08 11.24.40 File: c:\windows\system32\dfsshlex.dll ok scanned
01/03/08 11.24.41 File: C:\WINDOWS\system32\photowiz.dll ok scanned
01/03/08 11.24.41 File: C:\WINDOWS\system32\mmcshext.dll ok scanned
01/03/08 11.24.42 File: c:\windows\system32\cabview.dll ok scanned
01/03/08 11.24.42 File: c:\programmi\outlook express\wabfind.dll ok scanned
01/03/08 11.24.42 File: c:\windows\system32\wmpshell.dll ok scanned
01/03/08 11.24.44 File: c:\progra~1\fileco~1\micros~1\webfol~1\msonsext.dll ok scanned
01/03/08 11.24.44 File: c:\progra~1\micros~2\office11\mlshext.dll ok scanned
01/03/08 11.24.44 File: c:\progra~1\micros~2\office11\olkfstub.dll ok scanned
01/03/08 11.24.44 File: c:\programmi\microsoft office\office11\msohev.dll ok scanned
01/03/08 11.24.44 File: c:\programmi\winrar\rarext.dll ok scanned
01/03/08 11.24.44 File: c:\windows\system32\mscoree.dll ok scanned
01/03/08 11.24.44 File: C:\WINDOWS\system32\audiodev.dll ok scanned
01/03/08 11.24.44 File: C:\WINDOWS\system32\wpdshext.dll ok scanned
01/03/08 11.24.44 File: c:\programmi\alwil software\avast4\ashshell.dll ok scanned
01/03/08 11.24.45 File: c:\programmi\windows live\mail\mailcomm.dll ok scanned
01/03/08 11.24.45 File: c:\programmi\windows live\photo gallery\wlxphotoacquirewizard.exe ok scanned
01/03/08 11.24.46 File: c:\programmi\windows live\photo gallery\photoviewershim.dll ok scanned
01/03/08 11.24.46 File: c:\programmi\windows live\photo gallery\wlxphotoviewer.dll ok scanned
01/03/08 11.24.46 File: c:\programmi\windows live\messenger\fsshext.8.5.1302.1018.dll ok scanned
01/03/08 11.24.46 File: c:\programmi\windows live toolbar\msntb.dll ok scanned
01/03/08 11.24.46 File: c:\programmi\alcohol toolbar\v3.2.0.0\alcohol_toolbar.dll ok scanned
01/03/08 11.24.47 File: c:\programmi\google\googletoolbar1.dll ok scanned
01/03/08 11.24.47 File: c:\programmi\yahoo!\companion\installs\cpn\yt.dll ok scanned
01/03/08 11.24.47 File: c:\programmi\windows live toolbar\components\it-it\msntabres.dll.mui ok scanned
01/03/08 11.24.47 File: c:\programmi\adobe\acrobat 6.0\reader\activex\acroiehelper.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\skype\toolbars\internet explorer\skypeieplugin.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\bearshare applications\bearshare mediabar\bearshareiehelper.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\file comuni\microsoft shared\windows live\windowslivelogin.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\google\googletoolbarnotifier\2.0.301.7164\swg.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\epson\epson web-to-page\epson web-to-page.dll ok scanned
01/03/08 11.24.48 File: c:\programmi\alwil software\avast4\ashavast.exe ok scanned
01/03/08 11.24.50 File: c:\programmi\ahead\nero backitup\backitup.exe ok scanned
01/03/08 11.24.50 File: c:\programmi\msn gaming zone\windows\bckgzm.exe ok scanned
01/03/08 11.24.51 File: c:\programmi\ccleaner\ccleaner.exe ok scanned
01/03/08 11.24.51 File: c:\programmi\msn gaming zone\windows\chkrzm.exe ok scanned
01/03/08 11.24.51 File: c:\windows\system32\cmcfg32.dll ok scanned
01/03/08 11.24.51 File: c:\programmi\netmeeting\conf.exe ok scanned
01/03/08 11.24.51 File: c:\programmi\windows nt\dialer.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\epson\creativity suite\copy utility\ecopy.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\epson\creativity suite\file manager\efilemanager.exe ok scanned
01/03/08 11.24.52 File: c:\windows\twain_32\escndv\escndv.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\gimp-2.0\bin\gimp-2.0.exe ok scanned
01/03/08 11.24.52 File: c:\windows\pchealth\helpctr\binaries\helpctr.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\msn gaming zone\windows\hrtzzm.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\internet explorer\connection wizard\icwconn1.exe ok scanned
01/03/08 11.24.52 File: c:\programmi\internet explorer\connection wizard\icwconn2.exe ok scanned
01/03/08 11.24.53 File: c:\programmi\ahead\imagedrive\imagedrive.exe ok scanned
01/03/08 11.24.53 File: c:\programmi\internet explorer\connection wizard\inetwiz.exe ok scanned
01/03/08 11.24.53 File: c:\programmi\internet explorer\connection wizard\isignup.exe ok scanned
01/03/08 11.24.53 File: C:\WINDOWS\system32\usmt\migwiz.exe ok scanned
01/03/08 11.24.53 File: c:\programmi\movie maker\moviemk.exe ok scanned
01/03/08 11.24.53 File: c:\programmi\windows media player\mplayer2.exe ok scanned
01/03/08 11.24.54 File: c:\progra~1\micros~2\office11\msaccess.exe ok scanned
01/03/08 11.24.54 File: c:\windows\pchealth\helpctr\binaries\msconfig.exe ok scanned
01/03/08 11.24.54 File: C:\Programmi\outlook express\msimn.exe ok scanned
01/03/08 11.24.54 File: c:\programmi\file comuni\microsoft shared\msinfo\msinfo32.exe ok scanned
01/03/08 11.24.54 File: c:\progra~1\micros~2\office11\mspub.exe ok scanned
01/03/08 11.24.54 File: c:\progra~1\fileco~1\micros~1\modi\11.0\mspview.exe ok scanned
01/03/08 11.24.55 File: c:\programmi\ahead\coverdesigner\coverdes.exe ok scanned
01/03/08 11.24.56 File: c:\programmi\ahead\nero\nero.exe ok scanned
01/03/08 11.24.57 File: c:\programmi\ahead\nero startsmart\nerostartsmart.exe ok scanned
01/03/08 11.24.57 File: C:\WINDOWS\system32\mspaint.exe ok scanned
01/03/08 11.24.57 File: c:\programmi\quicktime\pictureviewer.exe ok scanned
01/03/08 11.24.57 File: c:\programmi\windows nt\pinball\pinball.exe ok scanned
01/03/08 11.24.57 File: c:\progra~1\micros~2\office11\powerpnt.exe ok scanned
01/03/08 11.24.58 File: c:\programmi\quicktime\quicktimeplayer.exe ok scanned
01/03/08 11.24.58 File: c:\programmi\msn gaming zone\windows\rvsezm.exe ok scanned
01/03/08 11.24.58 File: c:\progra~1\micros~2\office11\1040\schdpl32.exe ok scanned
01/03/08 11.24.58 File: c:\programmi\msn gaming zone\windows\shvlzm.exe ok scanned
01/03/08 11.24.58 File: c:\documents and settings\admin\desktop\sopcast\sopcast.exe ok scanned
01/03/08 11.24.58 File: C:\Programmi\outlook express\wab.exe ok scanned
01/03/08 11.24.59 File: C:\Programmi\outlook express\wabmig.exe ok scanned
01/03/08 11.24.59 File: c:\programmi\winrar\winrar.exe ok scanned
01/03/08 11.24.59 File: c:\progra~1\micros~2\office11\winword.exe ok scanned
01/03/08 11.24.59 File: c:\programmi\windows live\mail\wlmail.exe ok scanned
01/03/08 11.25.00 File: c:\programmi\ahead\wmpburn\wmpburn.exe ok scanned
01/03/08 11.25.00 File: c:\windows\system32\ntsd.exe ok scanned
01/03/08 11.25.00 File: c:\programmi\windows live\writer\writerbrowserextension.dll ok scanned
01/03/08 11.25.00 File: c:\progra~1\skype\toolbars\intern~1\favicon.ico ok scanned
01/03/08 11.25.00 File: c:\progra~1\micros~2\office11\refiebar.dll ok scanned
01/03/08 11.25.00 File: c:\progra~1\micros~2\office11\refbar.ico ok scanned
01/03/08 11.25.00 File: c:\progra~1\micros~2\office11\refbarh.ico ok scanned
01/03/08 11.25.00 File: c:\programmi\yahoo!\common\yinsthelper.dll ok scanned
01/03/08 11.25.00 File: c:\windows\system32\java.exe ok scanned
01/03/08 11.25.00 File: c:\progra~1\yahoo!\common\yinsthelper.dll ok scanned
01/03/08 11.25.00 File: c:\programmi\java\j2re1.4.2_05\bin\npjpi142_05.dll ok scanned
01/03/08 11.25.01 File: c:\windows\system32\macromed\flash\flash9c.ocx ok scanned
01/03/08 11.25.01 File: c:\programmi\apple software update\softwareupdate.exe ok scanned
01/03/08 11.25.01 File: c:\programmi\windows live toolbar\msntbup.exe ok scanned
01/03/08 11.25.01 File: C:\WINDOWS\system32\rsvpsp.dll ok scanned
01/03/08 11.25.01 File: C:\WINDOWS\system32\winrnr.dll ok scanned
01/03/08 11.25.01 File: C:\WINDOWS\system32\nwprovau.dll ok scanned
01/03/08 11.25.01 Logical disk sector: C ok scanned
01/03/08 11.25.02 Physical disk sector: \Device\HarddiskVolume1 ok scanned
01/03/08 11.25.02 Physical disk sector: \Device\Harddisk0\DR0 ok scanned
01/03/08 11.25.02 File: c:\windows\system32\jrckdbio.exe detected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.28.13 File: c:\windows\system32\jrckdbio.exe backed up
01/03/08 11.28.15 Startup object: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\jrckdbio disinfected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.28.15 Startup object: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\jrckdbio disinfected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.28.24 File: c:\windows\system32\jrckdbio.exe deleted
01/03/08 11.28.24 File: c:\windows\system32\pq.exe detected virus 'Email-Worm.Win32.Agent.ax'
01/03/08 11.30.08 File: c:\documents and settings\admin\impostazioni locali\temp\rar$ex03.454\msnfix\backup\services.exe detected Trojan program 'Trojan.Win32.Agent.dwa'
Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------
Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Quarantine
----------
Status Object Size Added
------ ------ ---- -----
Backup
------
Status Object Size
------ ------ ----
Infected: virus Email-Worm.Win32.Agent.ax c:\windows\system32\jrckdbio.exe 224 KB
Pi log HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15.52.37, on 01/03/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Java\j2re1.4.2_05\bin\jusched.exe
C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\GlobespanVirata\Adsl\dslstat.exe
C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
C:\Programmi\Winamp\winampa.exe
C:\Programmi\QuickTime\qttask.exe
C:\Programmi\D-Tools\daemon.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe
C:\Programmi\BearShare\BearShare.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX03.454\MSNFix\backup\services.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX00.828\HijackThis.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX00.032\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgilio.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Programmi\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Programmi\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: XBTP01621 Class - {F6104497-54FD-4688-9162-5115CC8AB0FB} - C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll (file missing)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Programmi\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Programmi\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_SA7.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\GlobespanVirata\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmi\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [BearShare] "C:\Programmi\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Servicee] C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX03.454\MSNFix\backup\services.exe
O4 - HKLM\..\RunServices: [pq] C:\WINDOWS\system32\pq.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?7be0d3f2ad3640e09d52c404a784eaf3
O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?7be0d3f2ad3640e09d52c404a784eaf3
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{474A9685-8DBB-4B40-B2A9-E410C4B11743}: NameServer = 85.37.17.9 85.38.28.75
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: setup_7.0.0.180_29.02.2008_23-14 - Kaspersky Lab - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Print Spooler Service (ui1oaleopa0o6e) - Unknown owner - C:\WINDOWS\system32\pq.exe (file missing)
--
End of file - 10123 bytes
Poi log HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15.52.37, on 01/03/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Java\j2re1.4.2_05\bin\jusched.exe
C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\GlobespanVirata\Adsl\dslstat.exe
C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
C:\Programmi\Winamp\winampa.exe
C:\Programmi\QuickTime\qttask.exe
C:\Programmi\D-Tools\daemon.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe
C:\Programmi\BearShare\BearShare.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX03.454\MSNFix\backup\services.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX00.828\HijackThis.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX00.032\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgilio.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Programmi\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Programmi\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: XBTP01621 Class - {F6104497-54FD-4688-9162-5115CC8AB0FB} - C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll (file missing)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Programmi\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Programmi\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_SA7.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\GlobespanVirata\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmi\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [BearShare] "C:\Programmi\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Servicee] C:\DOCUME~1\admin\IMPOST~1\Temp\Rar$EX03.454\MSNFix\backup\services.exe
O4 - HKLM\..\RunServices: [pq] C:\WINDOWS\system32\pq.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?7be0d3f2ad3640e09d52c404a784eaf3
O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?7be0d3f2ad3640e09d52c404a784eaf3
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{474A9685-8DBB-4B40-B2A9-E410C4B11743}: NameServer = 85.37.17.9 85.38.28.75
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: setup_7.0.0.180_29.02.2008_23-14 - Kaspersky Lab - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_29.02.2008_23-14.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Print Spooler Service (ui1oaleopa0o6e) - Unknown owner - C:\WINDOWS\system32\pq.exe (file missing)
--
End of file - 10123 bytes