Logfile of HijackThis v1.99.0
Scan saved at 15.24.53, on gg/01/aa
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Programmi\AVPersonal\AVGUARD.EXE
C:\Programmi\AVPersonal\AVWUPSRV.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Programmi\RealVNC\WinVNC\WinVNC.exe
C:\WINNT\Explorer.exe
C:\Programmi\Compaq\Easy Access Keyboard\MMKeybd.exe
C:\WINNT\loadqm.exe
C:\WINNT\System32\qttask.exe
C:\Programmi\AVPersonal\AVGNT.EXE
C:\WINNT\system32\ntvdm.exe
C:\Programmi\Compaq\Easy Access Keyboard\MMUSBKB2.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Century\TinyTERM\tt.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\WINNT\Profiles\pc5.IT0408\Impostazioni locali\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINNT\Profiles\PC5~1.IT0\IMPOST~1\Temp\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINNT\Profiles\PC5~1.IT0\IMPOST~1\Temp\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CGE&Y for Channel 21
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL =
http://apc.channel21.eds.com/singlepac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O1 - Hosts: 192.109.189.254 bmw_dns
O1 - Hosts: 192.109.189.125 bmw_notes1
O1 - Hosts: 192.109.189.160 bmw_notes2
O1 - Hosts: 192.109.189.100 bmw_os2
O1 - Hosts: 192.109.189.120 bmw_ntserv
O1 - Hosts: 193.42.235.200 bmw_email
O1 - Hosts: 192.109.189.252 ftp.conc.zi
O1 - Hosts: 192.109.189.253 CZI00002
O1 - Hosts: 194.10.153.1 motor1
O1 - Hosts: 194.10.153.2 motor2
O2 - BHO: (no name) - {68B23809-C13C-4041-9056-58A18B808956} - C:\WINNT\System32\ofhg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [Easy Access Keyboard] C:\Programmi\Compaq\Easy Access Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Programmi\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINNT\System32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVGCtrl] C:\Programmi\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - Global Startup: Server Control.lnk = C:\LPDSERV\CTLAPP.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O12 - Plugin for .aiff: C:\PROGRA~1\Netscape\COMMUN~1\Program\PLUGINS\npaudio.dll
O12 - Plugin for .swf: C:\PROGRA~1\Netscape\COMMUN~1\Program\PLUGINS\npswf32.dll
O13 - WWW. Prefix: http://
O15 - Trusted Zone: *.opel.com.pl (HKLM)
O15 - Trusted Zone: *.opel.com.tw (HKLM)
O15 - Trusted Zone: *.opel.ofsn.de (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/ms ... b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {15320607-1001-1831-1000-118599957123} - ms-its:mhtml:file://C:\PATH.MHT!http://195.225.176.5//d//pgsszgc//edhqiej//xnwjsmh//rytgqp//IT//arct.chm::/painter.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by24fd.bay24.hotmail.msn.com/res ... nPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/msnme ... loader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary/ZI ... b32846.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = it0408
O17 - HKLM\System\CCS\Services\Tcpip\..\{66F1371B-5F6C-42A1-ADCD-CEA444A7B9E0}: Domain = it0408
O17 - HKLM\System\CCS\Services\Tcpip\..\{66F1371B-5F6C-42A1-ADCD-CEA444A7B9E0}: NameServer = 10.50.43.1,199.228.170.43
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = it0408
O17 - HKLM\System\CS1\Services\Tcpip\..\{66F1371B-5F6C-42A1-ADCD-CEA444A7B9E0}: Domain = it0408
O17 - HKLM\System\CS1\Services\Tcpip\..\{66F1371B-5F6C-42A1-ADCD-CEA444A7B9E0}: NameServer = 10.50.43.1,199.228.170.43
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = it0408
O17 - HKLM\System\CS2\Services\Tcpip\..\{66F1371B-5F6C-42A1-ADCD-CEA444A7B9E0}: Domain = it0408
O17 - HKLM\System\CS2\Services\Tcpip\..\{66F1371B-5F6C-42A1-ADCD-CEA444A7B9E0}: NameServer = 10.50.43.1,199.228.170.43
O18 - Filter: text/html - {88CC3BFF-7097-4AB5-AA4E-4369CB0ED1B2} - C:\WINNT\System32\ofhg.dll
O18 - Filter: text/plain - {88CC3BFF-7097-4AB5-AA4E-4369CB0ED1B2} - C:\WINNT\System32\ofhg.dll
O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - C:\Programmi\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - C:\Programmi\AVPersonal\AVWUPSRV.EXE
O23 - Service: Servizio amministrativo di Gestione disco logico - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: VNC Server - RealVNC Ltd. - C:\Programmi\RealVNC\WinVNC\WinVNC.exe