Potete risolvermi, gentilmente, questo problema?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15.56.01, on 09/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmi\Java\jre6\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\IObit\Advanced SystemCare 3\AWC.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmi\CyberLink\Shared Files\RichVideo.exe
C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\eMule\emule.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Programmi\AGI\common\agcutils.dll
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Programmi\AGI\common\agcutils.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programmi\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Programmi\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKCU\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Tasto di scelta rapida per l'avvio di AutoCAD.lnk = C:\Programmi\File comuni\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: Aggiungi al banner Blocco pubblicità - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: Statistiche sulla protezione del traffico Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/ ... ontrol.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/ ... 586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Programmi\AGI\common\win32\PythonService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmi\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Programmi\WinPcap\rpcapd.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
--
End of file - 11703 bytes
Scan saved at 15.56.01, on 09/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
![Leggi le FAQ [faq]](http://www.megalab.it/forum/images/smilies/readfaq1.gif)
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmi\Java\jre6\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\IObit\Advanced SystemCare 3\AWC.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmi\CyberLink\Shared Files\RichVideo.exe
C:\Programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\eMule\emule.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Programmi\AGI\common\agcutils.dll
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Programmi\AGI\common\agcutils.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programmi\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre6\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programmi\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Programmi\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKCU\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Tasto di scelta rapida per l'avvio di AutoCAD.lnk = C:\Programmi\File comuni\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: Aggiungi al banner Blocco pubblicità - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: Statistiche sulla protezione del traffico Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/ ... ontrol.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/ ... 586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Programmi\AGI\common\win32\PythonService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programmi\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Programmi\WinPcap\rpcapd.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
--
End of file - 11703 bytes
RAPPORTO KASPERSKY:
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
10/02/2009 15.47.01 Attività completata
10/02/2009 15.44.37 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
09/02/2009 16.20.51 Attività completata
09/02/2009 16.15.02 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
08/02/2009 19.42.18 Attività completata
08/02/2009 19.40.20 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
08/02/2009 18.43.17 Attività completata
08/02/2009 17.58.51 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\FrWrkITA.dll
08/02/2009 17.58.50 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\iFrmewrk.exe
08/02/2009 17.57.16 Rilevato: http://www.viruslist.com/it/advisories/31744 C:\Programmi\File comuni\Microsoft Shared\Office10\MSO.DLL
08/02/2009 17.37.26 Rilevato: http://www.viruslist.com/it/advisories/26003 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
08/02/2009 17.18.06 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
08/02/2009 17.18.06 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
08/02/2009 17.17.07 Rilevato: http://www.viruslist.com/it/advisories/32270 C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
08/02/2009 15.55.58 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
08/02/2009 15.17.49 Attività completata
08/02/2009 15.15.17 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
07/02/2009 21.15.54 Attività completata
07/02/2009 19.58.47 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\FrWrkITA.dll
07/02/2009 19.57.11 Rilevato: http://www.viruslist.com/it/advisories/31744 C:\Programmi\File comuni\Microsoft Shared\Office10\MSO.DLL
07/02/2009 19.39.51 Rilevato: http://www.viruslist.com/it/advisories/26003 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
07/02/2009 19.33.04 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
07/02/2009 19.33.04 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
07/02/2009 19.31.58 Rilevato: http://www.viruslist.com/it/advisories/32270 C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
07/02/2009 19.12.52 Non isolati: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe Rimandato
07/02/2009 19.12.51 Rilevato: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe
07/02/2009 18.40.29 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
07/02/2009 9.29.26 Attività completata
07/02/2009 9.23.38 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
06/02/2009 18.11.39 Attività completata
06/02/2009 18.11.37 Non isolati: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe Scritto nel rapporto
06/02/2009 18.11.37 Rilevato: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe
06/02/2009 17.30.21 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\FrWrkITA.dll
06/02/2009 17.28.44 Rilevato: http://www.viruslist.com/it/advisories/31744 C:\Programmi\File comuni\Microsoft Shared\Office10\MSO.DLL
06/02/2009 17.22.39 Rilevato: http://www.viruslist.com/it/advisories/26003 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
06/02/2009 17.18.22 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
06/02/2009 17.18.22 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
06/02/2009 17.16.49 Rilevato: http://www.viruslist.com/it/advisories/32270 C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
06/02/2009 17.06.45 Non isolati: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe Rimandato
06/02/2009 17.06.45 Rilevato: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe
06/02/2009 16.52.50 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
04/02/2009 21.39.22 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 21.48.21 Attività completata
03/02/2009 21.48.16 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 20.42.15 Attività completata
03/02/2009 20.42.13 Eliminati: Trojan-Dropper.Win32.Agent.aang C:\Programmi\eMule\Incoming\Real Player 11.0.0.373 keygenerator-W0rking.rar/Setup+Patch.exe
03/02/2009 20.42.12 Rilevato: Trojan-Dropper.Win32.Agent.aang C:\Programmi\eMule\Incoming\Real Player 11.0.0.373 keygenerator-W0rking.rar/Setup+Patch.exe
03/02/2009 20.27.44 Non isolati: Trojan-Dropper.Win32.Agent.aang C:\Programmi\eMule\Incoming\Real Player 11.0.0.373 keygenerator-W0rking.rar/Setup+Patch.exe Rimandato
03/02/2009 20.27.43 Rilevato: Trojan-Dropper.Win32.Agent.aang C:\Programmi\eMule\Incoming\Real Player 11.0.0.373 keygenerator-W0rking.rar/Setup+Patch.exe
03/02/2009 19.59.57 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\FrWrkITA.dll
03/02/2009 19.57.36 Rilevato: http://www.viruslist.com/it/advisories/31744 C:\Programmi\File comuni\Microsoft Shared\Office10\MSO.DLL
03/02/2009 19.43.12 Rilevato: http://www.viruslist.com/it/advisories/26003 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
03/02/2009 19.39.48 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
03/02/2009 19.39.48 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
03/02/2009 19.38.18 Rilevato: http://www.viruslist.com/it/advisories/32270 C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
03/02/2009 19.19.31 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 18.33.13 Attività completata
03/02/2009 18.33.12 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 18.31.40 Attività completata
03/02/2009 18.31.40 Eliminati: P2P-Worm.Win32.Agent.ge C:\Programmi\eMule\Incoming\.Real Player 11.0.0.375 Crack-W0rking.rar/Installer-Crack-Keygen.exe
03/02/2009 18.31.40 Rilevato: P2P-Worm.Win32.Agent.ge C:\Programmi\eMule\Incoming\.Real Player 11.0.0.375 Crack-W0rking.rar/Installer-Crack-Keygen.exe/Armadillo
03/02/2009 18.31.40 Non isolati: P2P-Worm.Win32.Agent.ge C:\Programmi\eMule\Incoming\.Real Player 11.0.0.375 Crack-W0rking.rar/Installer-Crack-Keygen.exe/Armadillo Rimandato
03/02/2009 18.31.40 Rilevato: P2P-Worm.Win32.Agent.ge C:\Programmi\eMule\Incoming\.Real Player 11.0.0.375 Crack-W0rking.rar/Installer-Crack-Keygen.exe/Armadillo
03/02/2009 18.31.40 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 18.26.56 Attività completata
03/02/2009 18.26.53 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 18.25.52 Attività completata
03/02/2009 18.25.42 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
30/01/2009 11.23.45 Attività completata
30/01/2009 11.23.43 Non isolati: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe Scritto nel rapporto
30/01/2009 11.23.43 Rilevato: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe
30/01/2009 11.23.43 Spostato in Quarantena: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\SPYWARE DOCTOR\serial spyware doctor 6.0.0.386 genuine.advantage.validation.rar/Setup.exe
30/01/2009 11.23.43 Rilevato: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\SPYWARE DOCTOR\serial spyware doctor 6.0.0.386 genuine.advantage.validation.rar/Setup.exe/data0000.cab/win32.exe
30/01/2009 11.23.42 Eliminati: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe
30/01/2009 11.23.42 Rilevato: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe
30/01/2009 11.23.42 Rilevato: Trojan.Win32.Pakes.miu C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe/#
30/01/2009 11.23.41 Eliminati: Trojan.Win32.Monder.agpi C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\a0026688.exe
30/01/2009 11.23.41 Rilevato: Trojan.Win32.Monder.agpi C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\A0026688.exe/data0000.cab/LC_BAB~1.EXE/data0000.cab/is173713.exe
30/01/2009 11.23.39 Rilevato: Trojan-Downloader.Win32.AutoIt.il C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\A0026688.exe/data0000.cab/Empty_25.exe
30/01/2009 11.23.39 Non isolati: Trojan-Spy.Win32.Ardamax.t C:\Programmi\eMule\Incoming\Nod 32 v3.0.566 + crack.7z/Nod 32 v3.0.566 + crack/Crack/NOD32.FiX.v3.0-aRC-ReXBR-nsane.exe Ignorato dall'utente
30/01/2009 11.23.39 Rilevato: Trojan-Spy.Win32.Ardamax.t C:\Programmi\eMule\Incoming\Nod 32 v3.0.566 + crack.7z/Nod 32 v3.0.566 + crack/Crack/NOD32.FiX.v3.0-aRC-ReXBR-nsane.exe
30/01/2009 11.23.32 Spostato in Quarantena: HEUR:Trojan.Win32.Generic C:\Documents and Settings\Francesco\Impostazioni locali\Temp\install\setup.exe
30/01/2009 11.23.32 Rilevato: HEUR:Trojan.Win32.Generic C:\Documents and Settings\Francesco\Impostazioni locali\Temp\install\Setup.exe/data0000.cab/win32.exe
30/01/2009 11.23.32 Eliminati: Trojan.Win32.Monder.agpi C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe
30/01/2009 11.23.32 Rilevato: Trojan.Win32.Monder.agpi C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe/data0000.cab/LC_BAB~1.EXE/data0000.cab/is173713.exe
30/01/2009 11.23.16 Rilevato: Trojan-Downloader.Win32.AutoIt.il C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe/data0000.cab/Empty_25.exe
30/01/2009 11.07.51 Non isolati: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\SPYWARE DOCTOR\serial spyware doctor 6.0.0.386 genuine.advantage.validation.rar/Setup.exe/data0000.cab/win32.exe Rimandato
30/01/2009 11.07.51 Rilevato: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\SPYWARE DOCTOR\serial spyware doctor 6.0.0.386 genuine.advantage.validation.rar/Setup.exe/data0000.cab/win32.exe
30/01/2009 10.57.30 Rilevato: Trojan.Win32.Monder.agpi C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\A0026688.exe/data0000.cab/LC_BAB~1.EXE/data0000.cab/is173713.exe
30/01/2009 10.57.19 Non isolati: Trojan-Downloader.Win32.AutoIt.il C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\A0026688.exe/data0000.cab/Empty_25.exe Rimandato
30/01/2009 10.57.18 Rilevato: Trojan-Downloader.Win32.AutoIt.il C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\A0026688.exe/data0000.cab/Empty_25.exe
30/01/2009 10.51.52 Rilevato: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe
30/01/2009 10.51.51 Non isolati: Trojan.Win32.Pakes.miu C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe/# Rimandato
30/01/2009 10.51.51 Rilevato: Trojan.Win32.Pakes.miu C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe/#
30/01/2009 10.48.43 Non isolati: Trojan-Spy.Win32.Ardamax.t C:\Programmi\eMule\Incoming\Nod 32 v3.0.566 + crack.7z/Nod 32 v3.0.566 + crack/Crack/NOD32.FiX.v3.0-aRC-ReXBR-nsane.exe Rimandato
30/01/2009 10.48.43 Rilevato: Trojan-Spy.Win32.Ardamax.t C:\Programmi\eMule\Incoming\Nod 32 v3.0.566 + crack.7z/Nod 32 v3.0.566 + crack/Crack/NOD32.FiX.v3.0-aRC-ReXBR-nsane.exe
30/01/2009 10.43.42 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\FrWrkITA.dll
30/01/2009 10.42.52 Rilevato: http://www.viruslist.com/it/advisories/31744 C:\Programmi\File comuni\Microsoft Shared\Office10\MSO.DLL
30/01/2009 10.42.49 Rilevato: Trojan.Win32.Monder.agpi C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe/data0000.cab/LC_BAB~1.EXE/data0000.cab/is173713.exe
30/01/2009 10.42.45 Non isolati: Trojan-Downloader.Win32.AutoIt.il C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe/data0000.cab/Empty_25.exe Rimandato
30/01/2009 10.42.36 Rilevato: Trojan-Downloader.Win32.AutoIt.il C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe/data0000.cab/Empty_25.exe
30/01/2009 10.38.46 Non isolati: HEUR:Trojan.Win32.Generic C:\Documents and Settings\Francesco\Impostazioni locali\Temp\install\Setup.exe/data0000.cab/win32.exe Rimandato
30/01/2009 10.38.45 Rilevato: HEUR:Trojan.Win32.Generic C:\Documents and Settings\Francesco\Impostazioni locali\Temp\install\Setup.exe/data0000.cab/win32.exe
30/01/2009 10.35.33 Rilevato: http://www.viruslist.com/it/advisories/26003 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
30/01/2009 10.32.07 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
30/01/2009 10.32.07 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
30/01/2009 10.31.29 Rilevato: http://www.viruslist.com/it/advisories/32270 C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
30/01/2009 10.23.32 Non isolati: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe Rimandato
30/01/2009 10.23.31 Rilevato: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe
30/01/2009 10.23.25 Non isolati: Trojan.Win32.Monderb.acvx C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP117\A0025109.dll Rimandato
30/01/2009 10.23.23 Rilevato: Trojan.Win32.Monderb.acvx C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP117\A0025109.dll
30/01/2009 10.15.03 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
29/01/2009 23.31.40 Attività interrotta
29/01/2009 23.24.04 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
29/01/2009 22.33.20 Attività completata
29/01/2009 22.31.15 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
10/02/2009 15.47.01 Attività completata
10/02/2009 15.44.37 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
09/02/2009 16.20.51 Attività completata
09/02/2009 16.15.02 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
08/02/2009 19.42.18 Attività completata
08/02/2009 19.40.20 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
08/02/2009 18.43.17 Attività completata
08/02/2009 17.58.51 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\FrWrkITA.dll
08/02/2009 17.58.50 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\iFrmewrk.exe
08/02/2009 17.57.16 Rilevato: http://www.viruslist.com/it/advisories/31744 C:\Programmi\File comuni\Microsoft Shared\Office10\MSO.DLL
08/02/2009 17.37.26 Rilevato: http://www.viruslist.com/it/advisories/26003 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
08/02/2009 17.18.06 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
08/02/2009 17.18.06 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
08/02/2009 17.17.07 Rilevato: http://www.viruslist.com/it/advisories/32270 C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
08/02/2009 15.55.58 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
08/02/2009 15.17.49 Attività completata
08/02/2009 15.15.17 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
07/02/2009 21.15.54 Attività completata
07/02/2009 19.58.47 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\FrWrkITA.dll
07/02/2009 19.57.11 Rilevato: http://www.viruslist.com/it/advisories/31744 C:\Programmi\File comuni\Microsoft Shared\Office10\MSO.DLL
07/02/2009 19.39.51 Rilevato: http://www.viruslist.com/it/advisories/26003 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
07/02/2009 19.33.04 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
07/02/2009 19.33.04 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
07/02/2009 19.31.58 Rilevato: http://www.viruslist.com/it/advisories/32270 C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
07/02/2009 19.12.52 Non isolati: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe Rimandato
07/02/2009 19.12.51 Rilevato: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe
07/02/2009 18.40.29 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
07/02/2009 9.29.26 Attività completata
07/02/2009 9.23.38 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
06/02/2009 18.11.39 Attività completata
06/02/2009 18.11.37 Non isolati: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe Scritto nel rapporto
06/02/2009 18.11.37 Rilevato: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe
06/02/2009 17.30.21 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\FrWrkITA.dll
06/02/2009 17.28.44 Rilevato: http://www.viruslist.com/it/advisories/31744 C:\Programmi\File comuni\Microsoft Shared\Office10\MSO.DLL
06/02/2009 17.22.39 Rilevato: http://www.viruslist.com/it/advisories/26003 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
06/02/2009 17.18.22 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
06/02/2009 17.18.22 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
06/02/2009 17.16.49 Rilevato: http://www.viruslist.com/it/advisories/32270 C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
06/02/2009 17.06.45 Non isolati: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe Rimandato
06/02/2009 17.06.45 Rilevato: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe
06/02/2009 16.52.50 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
04/02/2009 21.39.22 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 21.48.21 Attività completata
03/02/2009 21.48.16 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 20.42.15 Attività completata
03/02/2009 20.42.13 Eliminati: Trojan-Dropper.Win32.Agent.aang C:\Programmi\eMule\Incoming\Real Player 11.0.0.373 keygenerator-W0rking.rar/Setup+Patch.exe
03/02/2009 20.42.12 Rilevato: Trojan-Dropper.Win32.Agent.aang C:\Programmi\eMule\Incoming\Real Player 11.0.0.373 keygenerator-W0rking.rar/Setup+Patch.exe
03/02/2009 20.27.44 Non isolati: Trojan-Dropper.Win32.Agent.aang C:\Programmi\eMule\Incoming\Real Player 11.0.0.373 keygenerator-W0rking.rar/Setup+Patch.exe Rimandato
03/02/2009 20.27.43 Rilevato: Trojan-Dropper.Win32.Agent.aang C:\Programmi\eMule\Incoming\Real Player 11.0.0.373 keygenerator-W0rking.rar/Setup+Patch.exe
03/02/2009 19.59.57 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\FrWrkITA.dll
03/02/2009 19.57.36 Rilevato: http://www.viruslist.com/it/advisories/31744 C:\Programmi\File comuni\Microsoft Shared\Office10\MSO.DLL
03/02/2009 19.43.12 Rilevato: http://www.viruslist.com/it/advisories/26003 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
03/02/2009 19.39.48 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
03/02/2009 19.39.48 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
03/02/2009 19.38.18 Rilevato: http://www.viruslist.com/it/advisories/32270 C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
03/02/2009 19.19.31 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 18.33.13 Attività completata
03/02/2009 18.33.12 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 18.31.40 Attività completata
03/02/2009 18.31.40 Eliminati: P2P-Worm.Win32.Agent.ge C:\Programmi\eMule\Incoming\.Real Player 11.0.0.375 Crack-W0rking.rar/Installer-Crack-Keygen.exe
03/02/2009 18.31.40 Rilevato: P2P-Worm.Win32.Agent.ge C:\Programmi\eMule\Incoming\.Real Player 11.0.0.375 Crack-W0rking.rar/Installer-Crack-Keygen.exe/Armadillo
03/02/2009 18.31.40 Non isolati: P2P-Worm.Win32.Agent.ge C:\Programmi\eMule\Incoming\.Real Player 11.0.0.375 Crack-W0rking.rar/Installer-Crack-Keygen.exe/Armadillo Rimandato
03/02/2009 18.31.40 Rilevato: P2P-Worm.Win32.Agent.ge C:\Programmi\eMule\Incoming\.Real Player 11.0.0.375 Crack-W0rking.rar/Installer-Crack-Keygen.exe/Armadillo
03/02/2009 18.31.40 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 18.26.56 Attività completata
03/02/2009 18.26.53 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
03/02/2009 18.25.52 Attività completata
03/02/2009 18.25.42 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
30/01/2009 11.23.45 Attività completata
30/01/2009 11.23.43 Non isolati: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe Scritto nel rapporto
30/01/2009 11.23.43 Rilevato: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe
30/01/2009 11.23.43 Spostato in Quarantena: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\SPYWARE DOCTOR\serial spyware doctor 6.0.0.386 genuine.advantage.validation.rar/Setup.exe
30/01/2009 11.23.43 Rilevato: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\SPYWARE DOCTOR\serial spyware doctor 6.0.0.386 genuine.advantage.validation.rar/Setup.exe/data0000.cab/win32.exe
30/01/2009 11.23.42 Eliminati: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe
30/01/2009 11.23.42 Rilevato: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe
30/01/2009 11.23.42 Rilevato: Trojan.Win32.Pakes.miu C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe/#
30/01/2009 11.23.41 Eliminati: Trojan.Win32.Monder.agpi C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\a0026688.exe
30/01/2009 11.23.41 Rilevato: Trojan.Win32.Monder.agpi C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\A0026688.exe/data0000.cab/LC_BAB~1.EXE/data0000.cab/is173713.exe
30/01/2009 11.23.39 Rilevato: Trojan-Downloader.Win32.AutoIt.il C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\A0026688.exe/data0000.cab/Empty_25.exe
30/01/2009 11.23.39 Non isolati: Trojan-Spy.Win32.Ardamax.t C:\Programmi\eMule\Incoming\Nod 32 v3.0.566 + crack.7z/Nod 32 v3.0.566 + crack/Crack/NOD32.FiX.v3.0-aRC-ReXBR-nsane.exe Ignorato dall'utente
30/01/2009 11.23.39 Rilevato: Trojan-Spy.Win32.Ardamax.t C:\Programmi\eMule\Incoming\Nod 32 v3.0.566 + crack.7z/Nod 32 v3.0.566 + crack/Crack/NOD32.FiX.v3.0-aRC-ReXBR-nsane.exe
30/01/2009 11.23.32 Spostato in Quarantena: HEUR:Trojan.Win32.Generic C:\Documents and Settings\Francesco\Impostazioni locali\Temp\install\setup.exe
30/01/2009 11.23.32 Rilevato: HEUR:Trojan.Win32.Generic C:\Documents and Settings\Francesco\Impostazioni locali\Temp\install\Setup.exe/data0000.cab/win32.exe
30/01/2009 11.23.32 Eliminati: Trojan.Win32.Monder.agpi C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe
30/01/2009 11.23.32 Rilevato: Trojan.Win32.Monder.agpi C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe/data0000.cab/LC_BAB~1.EXE/data0000.cab/is173713.exe
30/01/2009 11.23.16 Rilevato: Trojan-Downloader.Win32.AutoIt.il C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe/data0000.cab/Empty_25.exe
30/01/2009 11.07.51 Non isolati: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\SPYWARE DOCTOR\serial spyware doctor 6.0.0.386 genuine.advantage.validation.rar/Setup.exe/data0000.cab/win32.exe Rimandato
30/01/2009 11.07.51 Rilevato: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\SPYWARE DOCTOR\serial spyware doctor 6.0.0.386 genuine.advantage.validation.rar/Setup.exe/data0000.cab/win32.exe
30/01/2009 10.57.30 Rilevato: Trojan.Win32.Monder.agpi C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\A0026688.exe/data0000.cab/LC_BAB~1.EXE/data0000.cab/is173713.exe
30/01/2009 10.57.19 Non isolati: Trojan-Downloader.Win32.AutoIt.il C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\A0026688.exe/data0000.cab/Empty_25.exe Rimandato
30/01/2009 10.57.18 Rilevato: Trojan-Downloader.Win32.AutoIt.il C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP119\A0026688.exe/data0000.cab/Empty_25.exe
30/01/2009 10.51.52 Rilevato: HEUR:Trojan.Win32.Generic C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe
30/01/2009 10.51.51 Non isolati: Trojan.Win32.Pakes.miu C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe/# Rimandato
30/01/2009 10.51.51 Rilevato: Trojan.Win32.Pakes.miu C:\Programmi\eMule\Incoming\Serial Quad Registry Cleaner No Serial(Crack).rar/Setup.exe/#
30/01/2009 10.48.43 Non isolati: Trojan-Spy.Win32.Ardamax.t C:\Programmi\eMule\Incoming\Nod 32 v3.0.566 + crack.7z/Nod 32 v3.0.566 + crack/Crack/NOD32.FiX.v3.0-aRC-ReXBR-nsane.exe Rimandato
30/01/2009 10.48.43 Rilevato: Trojan-Spy.Win32.Ardamax.t C:\Programmi\eMule\Incoming\Nod 32 v3.0.566 + crack.7z/Nod 32 v3.0.566 + crack/Crack/NOD32.FiX.v3.0-aRC-ReXBR-nsane.exe
30/01/2009 10.43.42 Rilevato: http://www.viruslist.com/it/advisories/20001 C:\Programmi\Intel\Wireless\Bin\FrWrkITA.dll
30/01/2009 10.42.52 Rilevato: http://www.viruslist.com/it/advisories/31744 C:\Programmi\File comuni\Microsoft Shared\Office10\MSO.DLL
30/01/2009 10.42.49 Rilevato: Trojan.Win32.Monder.agpi C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe/data0000.cab/LC_BAB~1.EXE/data0000.cab/is173713.exe
30/01/2009 10.42.45 Non isolati: Trojan-Downloader.Win32.AutoIt.il C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe/data0000.cab/Empty_25.exe Rimandato
30/01/2009 10.42.36 Rilevato: Trojan-Downloader.Win32.AutoIt.il C:\Documents and Settings\Francesco\DoctorWeb\Quarantine\key quad registry cleaner crack(no cd).exe/data0000.cab/Empty_25.exe
30/01/2009 10.38.46 Non isolati: HEUR:Trojan.Win32.Generic C:\Documents and Settings\Francesco\Impostazioni locali\Temp\install\Setup.exe/data0000.cab/win32.exe Rimandato
30/01/2009 10.38.45 Rilevato: HEUR:Trojan.Win32.Generic C:\Documents and Settings\Francesco\Impostazioni locali\Temp\install\Setup.exe/data0000.cab/win32.exe
30/01/2009 10.35.33 Rilevato: http://www.viruslist.com/it/advisories/26003 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
30/01/2009 10.32.07 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
30/01/2009 10.32.07 Rilevato: http://www.viruslist.com/it/advisories/23655 C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
30/01/2009 10.31.29 Rilevato: http://www.viruslist.com/it/advisories/32270 C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
30/01/2009 10.23.32 Non isolati: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe Rimandato
30/01/2009 10.23.31 Rilevato: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP118\A0026259.exe
30/01/2009 10.23.25 Non isolati: Trojan.Win32.Monderb.acvx C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP117\A0025109.dll Rimandato
30/01/2009 10.23.23 Rilevato: Trojan.Win32.Monderb.acvx C:\System Volume Information\_restore{6199CBFC-D270-41B1-9A40-43F9DDBA3C18}\RP117\A0025109.dll
30/01/2009 10.15.03 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
29/01/2009 23.31.40 Attività interrotta
29/01/2009 23.24.04 Operazione avviata
Scansione rapida: completato 10/02/2009 15.47.01 (eventi: , oggetti: , time: 00.00.00)
29/01/2009 22.33.20 Attività completata
29/01/2009 22.31.15 Operazione avviata