Ciao a tutti.
Innnanzi tutto Vi ringrazio anticipatamente per la vostra gradita disponibilità a risolvere il mio problema.
Il mio sistema antivurus (Antivir XP) rileva che "a bordo" abbiamo un the Trojan horse TR/Click.Small.JC.2 ed anche un Trojan horse TR/Click.Small.JC.1
Qui di seguito il log elaborato da HJT:
Logfile of HijackThis v1.99.0
Scan saved at 17.02.58, on 21/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\TrojanHunter 4.2\THGuard.exe
C:\Programmi\AVPersonal\AVGNT.EXE
C:\Programmi\Sinapsi Antispam\SinapsiAntispam.exe
C:\Programmi\MediaGateway\MediaGateway.exe
C:\Programmi\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Programmi\PeerGuardian2\pg2.exe
C:\Programmi\Labtec Wireless Desktop\MulMouse.exe
C:\Programmi\Labtec Wireless Desktop\MagicKey.exe
C:\Programmi\Outlook Express\msimn.exe
C:\PROGRAMMI\AVPERSONAL\AVGUARD.EXE
C:\Programmi\Netscape\Netscape Browser\netscape.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Fra\Desktop\Antivirus\HijackThis.exe
C:\Programmi\Internet Explorer\iexplore.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\PROGRA~1\RXTOOL~1\sfcont.dll (file missing)
O2 - BHO: IE Agent - {CC56A1F3-9B83-45FF-8CB6-D58959492F0F} - (no file)
O4 - HKLM\..\Run: [THGuard] "C:\Programmi\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [AVGCtrl] C:\Programmi\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [SinapsiAntispam] C:\Programmi\Sinapsi Antispam\SinapsiAntispam.exe
O4 - HKLM\..\Run: [MediaGateway] C:\Programmi\MediaGateway\MediaGateway.exe
O4 - HKCU\..\Run: [DW4] "C:\Programmi\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [PeerGuardian] C:\Programmi\PeerGuardian2\pg2.exe
O4 - Global Startup: Abilita Labtec Wireless Desktop.lnk = C:\Programmi\Labtec Wireless Desktop\MulMouse.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_05\bin\npjpi150_05.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://business.natuzzi.com/tsweb/msrdp.cab
O16 - DPF: {E5AA62F2-5095-44DF-9E50-4BE0647CAAE8} (MsgBoard.MsgBoardCtl) - http://business.natuzzi.com/MsgBoard.CAB
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol ... _en_dl.cab
O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - C:\PROGRAMMI\AVPERSONAL\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - C:\Programmi\AVPersonal\AVWUPSRV.EXE
---------------------------
Attendo Vs. gentili news.
Ciao, Francesco