giavembler
Topic Starter
Hello everybody
I followed "How to remove Outerinfo pop-ups" topic by LDTate to fix problems connected to Spyware.
Now everything seems to be good.
I just would like to post logs by HJT, Combo Fix and AVG 7.5.
I followed every step advised and now Outerinfo is not there and my pc is not showing any System Alert.
HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 14.17.31, on 21/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\GSICON.EXE
C:\WINDOWS\system32\dslagent.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmi\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\utente1\Desktop\controouterinfo\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [TZ Spyware Remover] C:\Programmi\TrackZapper.com\TZ Spyware Remover\SpyRem.exe /STARTUP
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://giavembler.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A5CBC46E-CB7A-40A2-A902-D8B0B0376739}: NameServer = 213.205.36.70 213.205.32.70
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs:
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users\Documenti\Settings\partnership.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - C:\WINDOWS\system32\gwquvw.dll (file missing)
O21 - SSODL: DCOM Server 3339 - {2C1CD3D7-86AC-4068-93BC-A02304BB3339} - C:\WINDOWS\system32\xqnle.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Combo Fix Log:
"utente1" - 07-01-21 12.55.20 Service Pack 2
ComboFix 07-01-21 - Running from: "C:\Documents and Settings\utente1\Desktop\controouterinfo"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\update00822631.exe
C:\WINDOWS\system32\unsvchosts.lzma
C:\Programmi\File comuni\{3C67D~1
C:\Programmi\File comuni\{8C67D~1
C:\WINDOWS\system32\rpcc.dll
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\WINDOWS\system32\ECURIT~1
((((((((((((((((((((((((((((((( Files Created from 2006-12-21 to 2007-01-21 ))))))))))))))))))))))))))))))))))
2007-01-21 12:57 d——– C:\WINDOWS\erdnt
2007-01-19 14:53 d——– C:\WINDOWS\system32\bak
2007-01-18 23:49 d——– C:\Programmi\NoAdware5.0
2007-01-18 17:41 d——– C:\Programmi\Lavasoft
2007-01-18 17:41 d——– C:\DOCUME~1\utente1\Dati applicazioni\Lavasoft
2007-01-18 17:34 57,344 –a—— C:\WINDOWS\system32\COMMTB32.DLL
2007-01-18 17:34 28,672 –a—— C:\WINDOWS\system32\HLP95EN.DLL
2007-01-18 17:34 25,872 –a—— C:\WINDOWS\system32\FM20ENU.DLL
2007-01-18 17:34 169,984 –a—— C:\WINDOWS\system32\P2D.DLL
2007-01-18 17:34 161,552 –a—— C:\WINDOWS\system32\ASYCPICT.DLL
2007-01-18 17:33 d——– C:\Programmi\ActiveX Control Pad
2007-01-18 16:45 d——– C:\DOCUME~1\ALLUSE~1\Dati applicazioni\Spybot - Search & Destroy
2007-01-18 16:29 512,688 –a—— C:\WINDOWS\system32\XceedCry.dll
2007-01-18 16:29 423,784 –a—— C:\WINDOWS\system32\XceedBkp.dll
2007-01-18 16:29 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2007-01-18 16:28 35,999 –a—— C:\WINDOWS\system32\lsasss.exe
2007-01-18 15:33 d——– C:\WINDOWS\system32\ActiveScan
2007-01-18 15:20 d–h—– C:\Programmi\File comuni\Uninstall Information
2007-01-18 14:23 d——– C:\Programmi\Malware-Wiped
2007-01-18 14:12 115,013 –a—— C:\tdd.exe
2007-01-18 13:11 d–h—– C:\WINDOWS\PIF
2007-01-18 09:40 6,819 –a—— C:\WINDOWS\system32\update83349740.exe
2007-01-18 09:40 38,358 –a—— C:\WINDOWS\system32\update56324761.exe
2007-01-18 09:35 6,819 –a—— C:\WINDOWS\system32\update54417805.exe
2007-01-18 09:35 35,628 –a—— C:\WINDOWS\system32\update60978402.exe
2007-01-18 09:30 5,389 –a—— C:\WINDOWS\system32\update91906356.exe
2007-01-18 09:30 38,488 –a—— C:\WINDOWS\system32\update89770330.exe
2007-01-18 09:25 6,819 –a—— C:\WINDOWS\system32\update80286011.exe
2007-01-18 09:25 38,488 –a—— C:\WINDOWS\system32\update54091001.exe
2007-01-18 09:20 6,819 –a—— C:\WINDOWS\system32\update92380205.exe
2007-01-18 09:20 38,488 –a—— C:\WINDOWS\system32\update33674268.exe
2007-01-18 09:15 38,488 –a—— C:\WINDOWS\system32\update18561603.exe
2007-01-18 09:15 20,992 –a—— C:\WINDOWS\system32\gwquvw.dll
2007-01-18 09:15 2,560 –a—— C:\WINDOWS\system32\update42851695.exe
2007-01-18 09:15 17,920 –a—— C:\WINDOWS\system32\ntio256.sys
2007-01-18 09:15 dr——- C:\DOCUME~1\LOCALS~1\Preferiti
2007-01-18 09:15 d——– C:\DOCUME~1\LOCALS~1\Menu Avvio
2007-01-18 09:14 60,377 –a—— C:\WINDOWS\system32\vcodec.exe
2007-01-18 09:14 6,819 –a—— C:\WINDOWS\system32\update21677000.exe
2007-01-13 23:46 d——– C:\DOCUME~1\utente1\Dati applicazioni\InterVideo
2007-01-13 23:45 d——– C:\Programmi\InterVideo
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-21 12:57 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\skype
2007-01-18 17:41 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\lavasoft
2007-01-18 16:22 ——– d——– C:\Programmi\msn messenger
2007-01-18 15:12 ——– d—s—- C:\Documents and Settings\utente1\Dati applicazioni\microsoft
2007-01-17 15:03 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\adobe
2007-01-13 23:46 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\intervideo
2007-01-13 23:45 ——– d–h—– C:\Programmi\installshield installation information
2006-12-20 14:44 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\image zone express
2006-12-17 23:03 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\adobeum
2006-12-17 23:02 ——– d——– C:\Programmi\elcomsoft
2006-12-14 20:48 ——– d——– C:\Programmi\radvideo
2006-12-14 09:05 ——– d——– C:\Programmi\ccleaner
2006-12-11 08:21 ——– d——– C:\Programmi\hp
2006-12-11 08:21 ——– d——– C:\Programmi\File comuni\hp
2006-12-11 08:17 ——– d——– C:\Programmi\hewlett-packard
2006-12-09 16:16 ——– d——– C:\Programmi\microsoft.net
2006-12-09 15:05 ——– d——– C:\Programmi\File comuni\hewlett-packard
2006-12-07 08:15 ——– d——– C:\Programmi\File comuni\adobe
2006-12-07 08:11 ——– d——– C:\Programmi\File comuni\installshield
2006-12-06 22:20 502368 –a—— C:\WINDOWS\system32\drivers\amon.sys
2006-12-06 22:20 270336 –a—— C:\WINDOWS\system32\imon.dll
2006-12-06 17:50 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\macromedia
2006-12-06 14:46 ——– d——– C:\Programmi\skype
2006-11-02 21:28 62 –ahs—- C:\Documents and Settings\utente1\Dati applicazioni\desktop.ini
2006-11-02 20:42 0 -rahs—- C:\MSDOS.SYS
2006-11-02 20:42 0 -rahs—- C:\IO.SYS
2006-11-02 20:42 0 –a—— C:\CONFIG.SYS
2006-11-02 20:42 0 –a—— C:\AUTOEXEC.BAT
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Skype"="\"C:\\Programmi\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"TZ Spyware Remover"="C:\\Programmi\\TrackZapper.com\\TZ Spyware Remover\\SpyRem.exe /STARTUP"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIModeChange"="Ati2mdxx.exe"
"ATIPTA"="C:\\Programmi\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"AGRSMMSG"="AGRSMMSG.exe"
"SoundMan"="SOUNDMAN.EXE"
"GSICONEXE"="GSICON.EXE"
"DSLAGENTEXE"="dslagent.exe USB"
"nod32kui"="\"C:\\Programmi\\Eset\\nod32kui.exe\" /WAITSERVICE"
"HP Software Update"="C:\\Programmi\\HP\\HP Software Update\\HPWuSchd2.exe"
"Lexmark_X79-55"="C:\\WINDOWS\\system32\\lsasss.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"
"{81E38CB4-FDDF-4CCE-A729-73854CE5C8A8}"="Microsoft Printer Sheduler"
"{2C1CD3D7-86AC-4068-93BC-A02304BB3339}"="DCOM Server 3339"
"{8A5849C4-93F3-429D-FF34-660A2068897C}"="OpenGL additional"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"carbinyl"="{8d8c2387-7f80-4022-9be6-43630a969558}"
"DCOM Server 3339"="{2C1CD3D7-86AC-4068-93BC-A02304BB3339}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"none"="C:\\Programmi\\Video ActiveX Object\\pmsngr.exe"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\partnershipreg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\HPpromotions psc 2350 series.job
Completion time: 07-01-21 12:58:42
AVG 7.5 Log:
AVG Anti-Spyware - Rapporto scansione
———————————————————
+ Creato alle: 13.30.57 21/01/2007
+ Risultato scansione:
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014147.exe -> Adware.AntiVermins : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014096.exe -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014101.exe -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014102.exe -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014103.dll -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Classes\CLSID\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Classes\CLSID\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-21-507921405-484763869-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-21-507921405-484763869-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.IntCodec : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014148.dll -> Adware.Maxifiles : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014273.dll -> Adware.PurityScan : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014016.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014017.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014018.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014019.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014020.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014021.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014028.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014029.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014030.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014031.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014282.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014284.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014285.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\gwquvw.dll -> Adware.WorldSecurityOnline : Ripulito con backup (in quarantena)
[1224] C:\WINDOWS\system32\gwquvw.dll -> Adware.WorldSecurityOnline : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe1169214827 -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe1169230346 -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe1169295803 -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ESET\nod32kui.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\HP\HP Software Update\HPWuSchd2.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014098.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014099.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014149.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014188.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014189.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014190.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014191.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014199.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014200.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014201.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014202.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014203.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014235.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014236.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014237.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014238.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014239.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014286.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\bak\lsasss.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\lsasss.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
[1636] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014216.exe/path.exe -> Downloader.Agent.bdr : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014218.exe -> Downloader.Agent.bdr : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update42851695.exe -> Downloader.Small.ebm : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update21677000.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update54417805.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update80286011.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update83349740.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update92380205.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014034.exe -> Downloader.Zlob.aon : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\vcodec.exe -> Downloader.Zlob.bio : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014107.exe -> Downloader.Zlob.bjy : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013849.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013850.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013851.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014045.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014046.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014048.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014064.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014065.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014066.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014086.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014087.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014088.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014104.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014105.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014106.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014109.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014110.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\tdd.exe -> Dropper.Agent.bbp : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013845.exe -> Dropper.Small.avb : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014038.dll -> Not-A-Virus.SpamTool.Win32.Agent.t : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014300.dll -> Proxy.Horst : Ripulito con backup (in quarantena)
C:\Documents and Settings\utente1\Cookies\utente1@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ripulito.
C:\Documents and Settings\utente1\Cookies\utente1@atdmt[2].txt -> TrackingCookie.Atdmt : Ripulito.
C:\Documents and Settings\utente1\Cookies\utente1@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ripulito.
C:\Documents and Settings\utente1\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Ripulito.
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014033.exe -> Trojan.Agent : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014035.exe -> Trojan.Agent.pk : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014039.dll -> Trojan.Agent.pk : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014267.exe -> Trojan.Small : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014221.exe -> Worm.Agent.v : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014216.exe/crack.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014216.exe/run.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014217.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014219.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
::Fine rapporto
Thanks in advance anyone who will check these logs and thanks for your help!
Greetings,
Luca
I followed "How to remove Outerinfo pop-ups" topic by LDTate to fix problems connected to Spyware.
Now everything seems to be good.
I just would like to post logs by HJT, Combo Fix and AVG 7.5.
I followed every step advised and now Outerinfo is not there and my pc is not showing any System Alert.
HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 14.17.31, on 21/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\GSICON.EXE
C:\WINDOWS\system32\dslagent.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmi\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\utente1\Desktop\controouterinfo\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [TZ Spyware Remover] C:\Programmi\TrackZapper.com\TZ Spyware Remover\SpyRem.exe /STARTUP
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://giavembler.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A5CBC46E-CB7A-40A2-A902-D8B0B0376739}: NameServer = 213.205.36.70 213.205.32.70
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs:
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users\Documenti\Settings\partnership.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - C:\WINDOWS\system32\gwquvw.dll (file missing)
O21 - SSODL: DCOM Server 3339 - {2C1CD3D7-86AC-4068-93BC-A02304BB3339} - C:\WINDOWS\system32\xqnle.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Combo Fix Log:
"utente1" - 07-01-21 12.55.20 Service Pack 2
ComboFix 07-01-21 - Running from: "C:\Documents and Settings\utente1\Desktop\controouterinfo"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\update00822631.exe
C:\WINDOWS\system32\unsvchosts.lzma
C:\Programmi\File comuni\{3C67D~1
C:\Programmi\File comuni\{8C67D~1
C:\WINDOWS\system32\rpcc.dll
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\WINDOWS\system32\ECURIT~1
((((((((((((((((((((((((((((((( Files Created from 2006-12-21 to 2007-01-21 ))))))))))))))))))))))))))))))))))
2007-01-21 12:57 d——– C:\WINDOWS\erdnt
2007-01-19 14:53 d——– C:\WINDOWS\system32\bak
2007-01-18 23:49 d——– C:\Programmi\NoAdware5.0
2007-01-18 17:41 d——– C:\Programmi\Lavasoft
2007-01-18 17:41 d——– C:\DOCUME~1\utente1\Dati applicazioni\Lavasoft
2007-01-18 17:34 57,344 –a—— C:\WINDOWS\system32\COMMTB32.DLL
2007-01-18 17:34 28,672 –a—— C:\WINDOWS\system32\HLP95EN.DLL
2007-01-18 17:34 25,872 –a—— C:\WINDOWS\system32\FM20ENU.DLL
2007-01-18 17:34 169,984 –a—— C:\WINDOWS\system32\P2D.DLL
2007-01-18 17:34 161,552 –a—— C:\WINDOWS\system32\ASYCPICT.DLL
2007-01-18 17:33 d——– C:\Programmi\ActiveX Control Pad
2007-01-18 16:45 d——– C:\DOCUME~1\ALLUSE~1\Dati applicazioni\Spybot - Search & Destroy
2007-01-18 16:29 512,688 –a—— C:\WINDOWS\system32\XceedCry.dll
2007-01-18 16:29 423,784 –a—— C:\WINDOWS\system32\XceedBkp.dll
2007-01-18 16:29 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2007-01-18 16:28 35,999 –a—— C:\WINDOWS\system32\lsasss.exe
2007-01-18 15:33 d——– C:\WINDOWS\system32\ActiveScan
2007-01-18 15:20 d–h—– C:\Programmi\File comuni\Uninstall Information
2007-01-18 14:23 d——– C:\Programmi\Malware-Wiped
2007-01-18 14:12 115,013 –a—— C:\tdd.exe
2007-01-18 13:11 d–h—– C:\WINDOWS\PIF
2007-01-18 09:40 6,819 –a—— C:\WINDOWS\system32\update83349740.exe
2007-01-18 09:40 38,358 –a—— C:\WINDOWS\system32\update56324761.exe
2007-01-18 09:35 6,819 –a—— C:\WINDOWS\system32\update54417805.exe
2007-01-18 09:35 35,628 –a—— C:\WINDOWS\system32\update60978402.exe
2007-01-18 09:30 5,389 –a—— C:\WINDOWS\system32\update91906356.exe
2007-01-18 09:30 38,488 –a—— C:\WINDOWS\system32\update89770330.exe
2007-01-18 09:25 6,819 –a—— C:\WINDOWS\system32\update80286011.exe
2007-01-18 09:25 38,488 –a—— C:\WINDOWS\system32\update54091001.exe
2007-01-18 09:20 6,819 –a—— C:\WINDOWS\system32\update92380205.exe
2007-01-18 09:20 38,488 –a—— C:\WINDOWS\system32\update33674268.exe
2007-01-18 09:15 38,488 –a—— C:\WINDOWS\system32\update18561603.exe
2007-01-18 09:15 20,992 –a—— C:\WINDOWS\system32\gwquvw.dll
2007-01-18 09:15 2,560 –a—— C:\WINDOWS\system32\update42851695.exe
2007-01-18 09:15 17,920 –a—— C:\WINDOWS\system32\ntio256.sys
2007-01-18 09:15 dr——- C:\DOCUME~1\LOCALS~1\Preferiti
2007-01-18 09:15 d——– C:\DOCUME~1\LOCALS~1\Menu Avvio
2007-01-18 09:14 60,377 –a—— C:\WINDOWS\system32\vcodec.exe
2007-01-18 09:14 6,819 –a—— C:\WINDOWS\system32\update21677000.exe
2007-01-13 23:46 d——– C:\DOCUME~1\utente1\Dati applicazioni\InterVideo
2007-01-13 23:45 d——– C:\Programmi\InterVideo
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-21 12:57 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\skype
2007-01-18 17:41 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\lavasoft
2007-01-18 16:22 ——– d——– C:\Programmi\msn messenger
2007-01-18 15:12 ——– d—s—- C:\Documents and Settings\utente1\Dati applicazioni\microsoft
2007-01-17 15:03 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\adobe
2007-01-13 23:46 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\intervideo
2007-01-13 23:45 ——– d–h—– C:\Programmi\installshield installation information
2006-12-20 14:44 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\image zone express
2006-12-17 23:03 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\adobeum
2006-12-17 23:02 ——– d——– C:\Programmi\elcomsoft
2006-12-14 20:48 ——– d——– C:\Programmi\radvideo
2006-12-14 09:05 ——– d——– C:\Programmi\ccleaner
2006-12-11 08:21 ——– d——– C:\Programmi\hp
2006-12-11 08:21 ——– d——– C:\Programmi\File comuni\hp
2006-12-11 08:17 ——– d——– C:\Programmi\hewlett-packard
2006-12-09 16:16 ——– d——– C:\Programmi\microsoft.net
2006-12-09 15:05 ——– d——– C:\Programmi\File comuni\hewlett-packard
2006-12-07 08:15 ——– d——– C:\Programmi\File comuni\adobe
2006-12-07 08:11 ——– d——– C:\Programmi\File comuni\installshield
2006-12-06 22:20 502368 –a—— C:\WINDOWS\system32\drivers\amon.sys
2006-12-06 22:20 270336 –a—— C:\WINDOWS\system32\imon.dll
2006-12-06 17:50 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\macromedia
2006-12-06 14:46 ——– d——– C:\Programmi\skype
2006-11-02 21:28 62 –ahs—- C:\Documents and Settings\utente1\Dati applicazioni\desktop.ini
2006-11-02 20:42 0 -rahs—- C:\MSDOS.SYS
2006-11-02 20:42 0 -rahs—- C:\IO.SYS
2006-11-02 20:42 0 –a—— C:\CONFIG.SYS
2006-11-02 20:42 0 –a—— C:\AUTOEXEC.BAT
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Skype"="\"C:\\Programmi\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"TZ Spyware Remover"="C:\\Programmi\\TrackZapper.com\\TZ Spyware Remover\\SpyRem.exe /STARTUP"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIModeChange"="Ati2mdxx.exe"
"ATIPTA"="C:\\Programmi\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"AGRSMMSG"="AGRSMMSG.exe"
"SoundMan"="SOUNDMAN.EXE"
"GSICONEXE"="GSICON.EXE"
"DSLAGENTEXE"="dslagent.exe USB"
"nod32kui"="\"C:\\Programmi\\Eset\\nod32kui.exe\" /WAITSERVICE"
"HP Software Update"="C:\\Programmi\\HP\\HP Software Update\\HPWuSchd2.exe"
"Lexmark_X79-55"="C:\\WINDOWS\\system32\\lsasss.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"
"{81E38CB4-FDDF-4CCE-A729-73854CE5C8A8}"="Microsoft Printer Sheduler"
"{2C1CD3D7-86AC-4068-93BC-A02304BB3339}"="DCOM Server 3339"
"{8A5849C4-93F3-429D-FF34-660A2068897C}"="OpenGL additional"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"carbinyl"="{8d8c2387-7f80-4022-9be6-43630a969558}"
"DCOM Server 3339"="{2C1CD3D7-86AC-4068-93BC-A02304BB3339}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"none"="C:\\Programmi\\Video ActiveX Object\\pmsngr.exe"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\partnershipreg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\HPpromotions psc 2350 series.job
Completion time: 07-01-21 12:58:42
AVG 7.5 Log:
AVG Anti-Spyware - Rapporto scansione
———————————————————
+ Creato alle: 13.30.57 21/01/2007
+ Risultato scansione:
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014147.exe -> Adware.AntiVermins : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014096.exe -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014101.exe -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014102.exe -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014103.dll -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Classes\CLSID\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Classes\CLSID\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-21-507921405-484763869-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-21-507921405-484763869-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.IntCodec : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014148.dll -> Adware.Maxifiles : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014273.dll -> Adware.PurityScan : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014016.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014017.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014018.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014019.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014020.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014021.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014028.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014029.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014030.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014031.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014282.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014284.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014285.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\gwquvw.dll -> Adware.WorldSecurityOnline : Ripulito con backup (in quarantena)
[1224] C:\WINDOWS\system32\gwquvw.dll -> Adware.WorldSecurityOnline : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe1169214827 -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe1169230346 -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe1169295803 -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ESET\nod32kui.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\HP\HP Software Update\HPWuSchd2.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014098.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014099.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014149.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014188.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014189.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014190.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014191.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014199.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014200.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014201.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014202.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014203.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014235.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014236.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014237.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014238.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014239.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014286.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\bak\lsasss.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\lsasss.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
[1636] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014216.exe/path.exe -> Downloader.Agent.bdr : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014218.exe -> Downloader.Agent.bdr : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update42851695.exe -> Downloader.Small.ebm : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update21677000.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update54417805.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update80286011.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update83349740.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update92380205.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014034.exe -> Downloader.Zlob.aon : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\vcodec.exe -> Downloader.Zlob.bio : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014107.exe -> Downloader.Zlob.bjy : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013849.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013850.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013851.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014045.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014046.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014048.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014064.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014065.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014066.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014086.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014087.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014088.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014104.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014105.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014106.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014109.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014110.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\tdd.exe -> Dropper.Agent.bbp : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013845.exe -> Dropper.Small.avb : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014038.dll -> Not-A-Virus.SpamTool.Win32.Agent.t : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014300.dll -> Proxy.Horst : Ripulito con backup (in quarantena)
C:\Documents and Settings\utente1\Cookies\utente1@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ripulito.
C:\Documents and Settings\utente1\Cookies\utente1@atdmt[2].txt -> TrackingCookie.Atdmt : Ripulito.
C:\Documents and Settings\utente1\Cookies\utente1@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ripulito.
C:\Documents and Settings\utente1\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Ripulito.
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014033.exe -> Trojan.Agent : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014035.exe -> Trojan.Agent.pk : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014039.dll -> Trojan.Agent.pk : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014267.exe -> Trojan.Small : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014221.exe -> Worm.Agent.v : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014216.exe/crack.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014216.exe/run.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014217.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014219.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
::Fine rapporto
Thanks in advance anyone who will check these logs and thanks for your help!
Greetings,
Luca