| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| redman71 Comune mortale
 
  
 
 Registrato: 26/06/07 23:28
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 26 Giu 2007 23:44    Oggetto: Virus- rilevata modifica a registro di sistema |   |  
				| 
 |  
				| Ciao a tutti. navigando con IE mi sono beccato un po' di virus. Ho installato Mc afee Security center 2007 e ne ha eliminati alcuni.
 
 Adesso ogni volta che avvio mi compare un alert di mcafee che dice:
 
 "McAfee ha rilevato una modifica al computer potenzialmente non autorizzata.
 
 Dettagli
 Nome SystemGuard: Aree di protezione di Internet Explorer
 Modifica: Registro di sistema Creato
 
 Ulteriori informazioni
 Descrizione SystemGuard: Internet Explorer dispone di quattro aree di protezione predefinite: Internet, Intranet locale, Siti affidabili e Siti con restrizioni. A ciascuna area di protezione sono associate impostazioni di protezione specifiche, predefinite o personalizzate. Le aree di protezione costituiscono il bersaglio di alcuni programmi spyware o potenzialmente indesiderati perché l'abbassamento del livello di protezione consente a questi programmi di evitare la visualizzazione di avvisi di protezione e di agire senza essere rilevati.
 
 Processo: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 Elementi interessati: HKEY_USERS\S-1-5-21-1123561945-789336058-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\me\
 
 Se la modifica è imprevista, McAfee consiglia di bloccarla. Se invece è prevista, consentirla.
 -----------------
 qualcuno ha dei consigli da darmi e soprattutto mi sa dire cosa significa?
 Come posso eliminare questo alert?
 grazie di ogni aiuto a tutti
 redman71
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Orange Dio maturo
 
  
 
 Registrato: 18/02/07 13:20
 Messaggi: 2224
 Residenza: Roma
 
 | 
			
				|  Inviato: 27 Giu 2007 10:58    Oggetto: |   |  
				| 
 |  
				| ciao! che dire: il processo atiptaxx.exe  è leggittimo. piuttosto è la chiave del registro che mi fà riflettere...
   potrebbe essere il sintomo di trojan Zonebac altrimenti noto come Instant Access..
 
 per togliersi il dubbio scarica questo tool, fai lo scan e metti qui il risultato.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 27 Giu 2007 11:32    Oggetto: |   |  
				| 
 |  
				|  	  | Citazione: |  	  | navigando con IE mi sono beccato un po' di virus. Ho installato Mc afee Security center 2007 e ne ha eliminati alcuni. | 
 Tieni conto che installare un antivirus su un pc con diversi virus, é come usare un estintore per cercare di estinguere un incendio di un gasdotto... (non so se rendo l'idea)
   Oltre al tool consigliato da Orange:
 scarica questo e salvalo in una sua cartella non temporanea e non sul desktop.
 Avvialo
 clicca su do a system scan and save a log file
 ti si apre il blocco note
 copia il contenuto e incollalo qui
 Così verifichiamo se McAfee ha potuto svolgere in toto il suo compito.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| redman71 Comune mortale
 
  
 
 Registrato: 26/06/07 23:28
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 03 Lug 2007 20:51    Oggetto: Virus- rilevata modifica a registro di sistema |   |  
				| 
 |  
				| ciao riporto qui il contenuto dei due log file consigliati, qualcuno ci capisce niente? primo log file
 -------------------------
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 20.43.15, on 03/07/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
 C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
 C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
 C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
 C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
 C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
 C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
 c:\program files\common files\mcafee\mna\mcnasvc.exe
 C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
 C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
 c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
 C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
 C:\PROGRA~1\mcafee.com\agent\mcagent.exe
 C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
 C:\Program Files\McAfee\MPF\MPFSrv.exe
 C:\Program Files\SiteAdvisor\6066\SAService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Hjt\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.corriere.it/
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = snmilan:8080
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
 O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
 O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
 O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
 O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
 O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
 O4 - HKLM\..\Run: [PDUiP6700DMon] C:\Program Files\Canon\Memory Card Utility\iP6700D\PDUiP6700DMon.exe
 O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
 O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
 O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
 O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
 O8 - Extra context menu item: Anteprima Easy-WebPrint - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Stampa ad alta velocità Easy-WebPrint - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
 O8 - Extra context menu item: Stampa Easy-WebPrint - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Crea preferiti portatile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
 O9 - Extra 'Tools' menuitem: Crea preferiti portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
 O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
 O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
 O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
 O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
 O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
 O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
 O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
 O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
 O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
 O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
 
 End of file - 8283 bytes
 
 --------------------------
 secondo log file
 
 Find AWF report by noahdfear ©2006
 
 
 bak folders found
 ~~~~~~~~~~~
 
 
 Directory of C:\PROGRA~1\ITUNES\BAK
 
 30/10/2006  10.36           256.576 iTunesHelper.exe
 1 File(s)        256.576 bytes
 
 Directory of C:\PROGRA~1\QUICKT~1\BAK
 
 25/10/2006  19.58           282.624 qttask.exe
 1 File(s)        282.624 bytes
 
 Directory of C:\PROGRA~1\WINAMP\BAK
 
 20/12/2004  20.41            33.792 winampa.exe
 1 File(s)         33.792 bytes
 
 Directory of C:\WINDOWS\SYSTEM32\BAK
 
 04/08/2004  03.07            15.360 ctfmon.exe
 1 File(s)         15.360 bytes
 
 Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK
 
 13/11/2003  21.10           335.872 atiptaxx.exe
 1 File(s)        335.872 bytes
 
 Directory of C:\PROGRA~1\CANON\EASY-P~2\BAK
 
 14/01/2004  03.10           409.600 BJPSMAIN.EXE
 1 File(s)        409.600 bytes
 
 Directory of C:\PROGRA~1\CANON\MEMORY~1\IP6700D\BAK
 
 16/03/2006  15.47            61.440 PDUiP6700DMon.exe
 1 File(s)         61.440 bytes
 
 Directory of C:\PROGRA~1\JAVA\JRE15~2.0_0\BIN\BAK
 
 10/11/2005  13.03            36.975 jusched.exe
 1 File(s)         36.975 bytes
 
 Directory of C:\PROGRA~1\ROXIO\EASYME~1\DRAGTO~1\BAK
 
 04/08/2004  20.36         1.691.648 DrgToDsc.exe
 1 File(s)      1.691.648 bytes
 
 
 Duplicate files of bak directory contents
 ~~~~~~~~~~~~~~~~~~~~~~~
 
 23564 17 Feb 2007 "C:\Program Files\iTunes\iTunesHelper.exe"
 256576 30 Oct 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
 102400 27 Dec 2006 "C:\WINDOWS\Installer\{446DBFFA-4088-48E3-8932-74316BA4CAE4}\iTunesIco.exe"
 108096 30 Oct 2006 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.0.2.16\iTunesSetupAdmin.exe"
 23564 17 Feb 2007 "C:\Program Files\QuickTime\qttask.exe"
 282624 25 Oct 2006 "C:\Program Files\QuickTime\bak\qttask.exe"
 23564 17 Feb 2007 "C:\Program Files\Winamp\winampa.exe"
 33792 20 Dec 2004 "C:\Program Files\Winamp\bak\winampa.exe"
 15360  4 Aug 2004 "C:\WINDOWS\system32\ctfmon.exe"
 15360  4 Aug 2004 "C:\WINDOWS\system32\bak\ctfmon.exe"
 23564 17 Feb 2007 "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
 335872 13 Nov 2003 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe"
 23564 17 Feb 2007 "C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE"
 409600 14 Jan 2004 "C:\Program Files\Canon\Easy-PrintToolBox\bak\BJPSMAIN.EXE"
 23564 17 Feb 2007 "C:\Program Files\Canon\Memory Card Utility\iP6700D\PDUiP6700DMon.exe"
 61440 16 Mar 2006 "C:\Program Files\Canon\Memory Card Utility\iP6700D\bak\PDUiP6700DMon.exe"
 36975  3 Jun 2005 "C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe"
 23564 17 Feb 2007 "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
 36975 10 Nov 2005 "C:\Program Files\Java\jre1.5.0_06\bin\bak\jusched.exe"
 23564 17 Feb 2007 "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
 1691648  4 Aug 2004 "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\bak\DrgToDsc.exe"
 
 
 end of report
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 03 Lug 2007 21:08    Oggetto: |   |  
				| 
 |  
				| Scarica questo e scompattalo in una sua cartella non temporanea e non sul desktop 
 Avvia AVENGER
 Clicca su input script manually
 Clicca sulla lente d'ingrandimento
 Inserisci queste righe:
 
  	  | Citazione: |  	  | Files to delete: C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\Winamp\winampa.exe
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
 C:\Program Files\Canon\Memory Card Utility\iP6700D\PDUiP6700DMon.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
 
 Files to move:
 C:\Program Files\iTunes\bak\iTunesHelper.exe | C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\bak\qttask.exe | C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\Winamp\bak\winampa.exe | C:\Program Files\Winamp\winampa.exe
 C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe | C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Program Files\Canon\Easy-PrintToolBox\bak\BJPSMAIN.EXE | C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
 C:\Program Files\Canon\Memory Card Utility\iP6700D\bak\PDUiP6700DMon.exe | C:\Program Files\Canon\Memory Card Utility\iP6700D\PDUiP6700DMon.exe
 C:\Program Files\Java\jre1.5.0_06\bin\bak\jusched.exe | C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\bak\DrgToDsc.exe | C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
 | 
 Clicca su Done
 Clicca sul semaforo
 Il pc dovrebbe riavviarsi, se così non fosse, riavvialo tu.
 Al termine dell'operazione, posta qui il risultato.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| redman71 Comune mortale
 
  
 
 Registrato: 26/06/07 23:28
 Messaggi: 3
 
 
 | 
			
				|  Inviato: 03 Lug 2007 22:03    Oggetto: |   |  
				| 
 |  
				| ciao Bdoriano ti riporto il log di avenger...e grazie dell'aiuto (a proposito, ravviando il pc non mi è più comparso l'alert di Mcafee)
 --------------------------
 Logfile of The Avenger version 1, by Swandog46
 Running from registry key:
 \Registry\Machine\System\CurrentControlSet\Services\outpamxt
 
 *******************
 
 Script file located at: \??\C:\ibfqpmtd.txt
 Script file opened successfully.
 
 Script file read successfully
 
 Backups directory opened successfully at C:\Avenger
 
 *******************
 
 Beginning to process script file:
 
 File C:\Program Files\iTunes\iTunesHelper.exe deleted successfully.
 File C:\Program Files\QuickTime\qttask.exe deleted successfully.
 File C:\Program Files\Winamp\winampa.exe deleted successfully.
 File C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe deleted successfully.
 File C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE deleted successfully.
 File C:\Program Files\Canon\Memory Card Utility\iP6700D\PDUiP6700DMon.exe deleted successfully.
 File C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe deleted successfully.
 File C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe deleted successfully.
 File move operation C:\Program Files\iTunes\bak\iTunesHelper.exe|C:\Program Files\iTunes\iTunesHelper.exe completed successfully.
 File move operation C:\Program Files\QuickTime\bak\qttask.exe|C:\Program Files\QuickTime\qttask.exe completed successfully.
 File move operation C:\Program Files\Winamp\bak\winampa.exe|C:\Program Files\Winamp\winampa.exe completed successfully.
 File move operation C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe|C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe completed successfully.
 File move operation C:\Program Files\Canon\Easy-PrintToolBox\bak\BJPSMAIN.EXE|C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE completed successfully.
 File move operation C:\Program Files\Canon\Memory Card Utility\iP6700D\bak\PDUiP6700DMon.exe|C:\Program Files\Canon\Memory Card Utility\iP6700D\PDUiP6700DMon.exe completed successfully.
 File move operation C:\Program Files\Java\jre1.5.0_06\bin\bak\jusched.exe|C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe completed successfully.
 File move operation C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\bak\DrgToDsc.exe|C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe completed successfully.
 
 Completed script processing.
 
 *******************
 
 Finished!  Terminate.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |