Ciao,grazie per aver risposto..
ho fatto come mi hai detto tu.
Con "open process manager" di Hijack ho trovato solo il processo "svchosts.exe" e non
quello "AnyDVD.exe".
Ho poi seguito tutte le tue indicazioni, questi sono i log della scansione con l'antivirus:
--AVSCAN local hard disks:
AntiVir PersonalEdition Classic
Report file date: venerdì 9 marzo 2007 14:02
Scanning for 699201 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Dany
Computer name: DANIELE
Version information:
BUILD.DAT : 217 12749 Bytes 05/12/2006 17:00:00
AVSCAN.EXE : 7.0.3.5 208936 Bytes 22/01/2007 00:13:06
AVSCAN.DLL : 7.0.3.1 35880 Bytes 03/01/2007 10:57:38
LUKE.DLL : 7.0.3.2 143400 Bytes 03/01/2007 10:57:39
LUKERES.DLL : 7.0.2.0 9256 Bytes 03/01/2007 10:57:39
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 15:30:06
ANTIVIR1.VDF : 6.37.1.151 4303360 Bytes 23/02/2007 16:41:01
ANTIVIR2.VDF : 6.38.0.5 143360 Bytes 06/03/2007 21:56:17
ANTIVIR3.VDF : 6.38.0.27 110592 Bytes 09/03/2007 12:21:37
AVEWIN32.DLL : 7.3.1.41 2355712 Bytes 07/03/2007 22:01:07
AVPREF.DLL : 7.0.2.0 23592 Bytes 03/01/2007 10:57:38
AVREP.DLL : 6.38.0.6 1179688 Bytes 06/03/2007 21:56:18
AVRPBASE.DLL : 7.0.0.0 2162728 Bytes 09/05/2006 17:56:15
AVPACK32.DLL : 7.2.1.6 368680 Bytes 06/03/2007 21:56:18
AVREG.DLL : 7.0.1.2 30760 Bytes 22/01/2007 00:13:06
NETNT.DLL : 6.32.0.0 6696 Bytes 27/09/2005 06:56:50
RCIMAGE.DLL : 7.0.1.3 2097192 Bytes 03/01/2007 10:57:35
RCTEXT.DLL : 7.0.12.1 77864 Bytes 03/01/2007 10:57:35
Configuration settings for the scan:
Jobname..........................: Local Drives
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldrives.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: F:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Expanded search settings.........: 0x00007000
Start of the scan: venerdì 9 marzo 2007 14:02
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Modules have been scanned
Scan process 'avcenter.exe' - '1' Modules have been scanned
Scan process 'explorer.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'lsass.exe' - '1' Modules have been scanned
Scan process 'services.exe' - '1' Modules have been scanned
Scan process 'winlogon.exe' - '1' Modules have been scanned
Scan process 'csrss.exe' - '1' Modules have been scanned
Scan process 'smss.exe' - '1' Modules have been scanned
11 processes with 11 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'G:\'
[NOTE] No virus was found!
Boot sector 'H:\'
[NOTE] No virus was found!
Boot sector 'I:\'
[NOTE] No virus was found!
Boot sector 'K:\'
[NOTE] No virus was found!
Boot sector 'A:\'
[NOTE] In the drive 'A:\' no data medium is inserted!
Starting to scan the registry.
The registry was scanned ( 34 files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\atapi.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd9165.sys
[WARNING] The file could not be opened!
Begin scan in 'G:\'
Begin scan in 'H:\'
Begin scan in 'I:\'
I:\My Documents\Microsoft Windows XP Professional (SP2)\Extras\XP Stuff.zip
[0] Archive type: ZIP
--> XP Stuff/XP KeY ReCoVeRER AND DiSCOVErER.exe
[DETECTION] Is the Trojan horse TR/Bckdr.EDZ
[INFO] The file was moved to '46116d57.qua'!
Begin scan in 'K:\'
K:\Program files\InstallPREVX102030010.exe
[0] Archive type: ACE SFX (self extracting)
--> img\bins\AMD64\lclbrk.cache.2k
[WARNING] Error creating the file
--> img\bins\2k_2k3_xp\lclbrk.cache.2k
[WARNING] No further files can be extracted from this archive. The archive will be closed
[WARNING] No further files can be extracted from this archive. The archive will be closed
Begin scan in 'A:\'
The path A:\ could not be found!
The device is not ready.
Begin scan in 'D:\' <Pro Evolution Soccer 6>
Begin scan in 'E:\' <FM 2007>
Begin scan in 'F:\'
The path F:\ could not be found!
The device is not ready.
End of the scan: venerdì 9 marzo 2007 15:40
Used time: 1:38:01 min
The scan has been done completely.
28131 Scanning directories
834286 Files were scanned
1 viruses and/or unwanted programs were found
0 files were deleted
0 files were repaired
1 files were moved to quarantine
0 files were renamed
4 Files cannot be scanned
834285 Files not concerned
25428 Archives were scanned
7 Warnings
10 Notes
--AVSCAN Processes:
AntiVir PersonalEdition Classic
Report file date: venerdì 9 marzo 2007 14:01
Scanning for 699201 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Dany
Computer name: DANIELE
Version information:
BUILD.DAT : 217 12749 Bytes 05/12/2006 17:00:00
AVSCAN.EXE : 7.0.3.5 208936 Bytes 22/01/2007 00:13:06
AVSCAN.DLL : 7.0.3.1 35880 Bytes 03/01/2007 10:57:38
LUKE.DLL : 7.0.3.2 143400 Bytes 03/01/2007 10:57:39
LUKERES.DLL : 7.0.2.0 9256 Bytes 03/01/2007 10:57:39
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 15:30:06
ANTIVIR1.VDF : 6.37.1.151 4303360 Bytes 23/02/2007 16:41:01
ANTIVIR2.VDF : 6.38.0.5 143360 Bytes 06/03/2007 21:56:17
ANTIVIR3.VDF : 6.38.0.27 110592 Bytes 09/03/2007 12:21:37
AVEWIN32.DLL : 7.3.1.41 2355712 Bytes 07/03/2007 22:01:07
AVPREF.DLL : 7.0.2.0 23592 Bytes 03/01/2007 10:57:38
AVREP.DLL : 6.38.0.6 1179688 Bytes 06/03/2007 21:56:18
AVRPBASE.DLL : 7.0.0.0 2162728 Bytes 09/05/2006 17:56:15
AVPACK32.DLL : 7.2.1.6 368680 Bytes 06/03/2007 21:56:18
AVREG.DLL : 7.0.1.2 30760 Bytes 22/01/2007 00:13:06
NETNT.DLL : 6.32.0.0 6696 Bytes 27/09/2005 06:56:50
RCIMAGE.DLL : 7.0.1.3 2097192 Bytes 03/01/2007 10:57:35
RCTEXT.DLL : 7.0.12.1 77864 Bytes 03/01/2007 10:57:35
Configuration settings for the scan:
Jobname..........................: Processes
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\process.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Scan memory......................: on
Process scan.....................: on
Extended process scan............: on
Scan registry....................: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Expanded search settings.........: 0x000000c0
Start of the scan: venerdì 9 marzo 2007 14:01
The scan of running processes will be started
Scan process 'avscan.exe' - '31' Modules have been scanned
Scan process 'avcenter.exe' - '50' Modules have been scanned
Scan process 'explorer.exe' - '81' Modules have been scanned
Scan process 'svchost.exe' - '63' Modules have been scanned
Scan process 'svchost.exe' - '41' Modules have been scanned
Scan process 'svchost.exe' - '31' Modules have been scanned
Scan process 'lsass.exe' - '48' Modules have been scanned
Scan process 'services.exe' - '26' Modules have been scanned
Scan process 'winlogon.exe' - '56' Modules have been scanned
Scan process 'csrss.exe' - '11' Modules have been scanned
Scan process 'smss.exe' - '2' Modules have been scanned
11 processes with 440 modules were scanned
Start scanning boot sectors:
Starting to scan the registry.
The registry was scanned ( 34 files ).
End of the scan: venerdì 9 marzo 2007 14:01
Used time: 00:03 min
The scan has been done completely.
0 Scanning directories
474 Files were scanned
0 viruses and/or unwanted programs were found
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
474 Files not concerned
0 Archives were scanned
0 Warnings
0 Notes
--AVSCAN Windows system directory:
ntiVir PersonalEdition Classic
Report file date: venerdì 9 marzo 2007 15:45
Scanning for 699201 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Dany
Computer name: DANIELE
Version information:
BUILD.DAT : 217 12749 Bytes 05/12/2006 17:00:00
AVSCAN.EXE : 7.0.3.5 208936 Bytes 22/01/2007 00:13:06
AVSCAN.DLL : 7.0.3.1 35880 Bytes 03/01/2007 10:57:38
LUKE.DLL : 7.0.3.2 143400 Bytes 03/01/2007 10:57:39
LUKERES.DLL : 7.0.2.0 9256 Bytes 03/01/2007 10:57:39
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 15:30:06
ANTIVIR1.VDF : 6.37.1.151 4303360 Bytes 23/02/2007 16:41:01
ANTIVIR2.VDF : 6.38.0.5 143360 Bytes 06/03/2007 21:56:17
ANTIVIR3.VDF : 6.38.0.27 110592 Bytes 09/03/2007 12:21:37
AVEWIN32.DLL : 7.3.1.41 2355712 Bytes 07/03/2007 22:01:07
AVPREF.DLL : 7.0.2.0 23592 Bytes 03/01/2007 10:57:38
AVREP.DLL : 6.38.0.6 1179688 Bytes 06/03/2007 21:56:18
AVRPBASE.DLL : 7.0.0.0 2162728 Bytes 09/05/2006 17:56:15
AVPACK32.DLL : 7.2.1.6 368680 Bytes 06/03/2007 21:56:18
AVREG.DLL : 7.0.1.2 30760 Bytes 22/01/2007 00:13:06
NETNT.DLL : 6.32.0.0 6696 Bytes 27/09/2005 06:56:50
RCIMAGE.DLL : 7.0.1.3 2097192 Bytes 03/01/2007 10:57:35
RCTEXT.DLL : 7.0.12.1 77864 Bytes 03/01/2007 10:57:35
Configuration settings for the scan:
Jobname..........................: Windows System Directory
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\sysdir.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: venerdì 9 marzo 2007 15:45
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Modules have been scanned
Scan process 'avscan.exe' - '1' Modules have been scanned
Scan process 'avcenter.exe' - '1' Modules have been scanned
Scan process 'explorer.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'svchost.exe' - '1' Modules have been scanned
Scan process 'lsass.exe' - '1' Modules have been scanned
Scan process 'services.exe' - '1' Modules have been scanned
Scan process 'winlogon.exe' - '1' Modules have been scanned
Scan process 'csrss.exe' - '1' Modules have been scanned
Scan process 'smss.exe' - '1' Modules have been scanned
12 processes with 12 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( 34 files ).
Starting the file scan:
Begin scan in 'C:\WINDOWS\system32'
C:\WINDOWS\system32\drivers\atapi.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\sptd9165.sys
[WARNING] The file could not be opened!
End of the scan: venerdì 9 marzo 2007 15:47
Used time: 02:00 min
The scan has been done completely.
284 Scanning directories
6737 Files were scanned
0 viruses and/or unwanted programs were found
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
3 Files cannot be scanned
6737 Files not concerned
5 Archives were scanned
3 Warnings
0 Notes
--Questo invece è il log della scansione con Hijack:
Logfile of HijackThis v1.99.1
Scan saved at 16.03.29, on 09/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.1\MOUSE32A.EXE
C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraMD.exe
C:\WINDOWS\system32\AutoExNT.Exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HybridTM_IR(A)\RC620_A.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
K:\QuickTime\qttask.exe
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
K:\Program files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\{5883ED37-0BB0-1040-1014-051202050027}\Update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\ArcSoft\TotalMedia\TMMonitor.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
I:\My Documents\Hijack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.virgilio.it/free
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: Tensons.Application.DownloadAcceleratorManager.BHO - {00000003-1118-11da-8cd6-0800200c9888} - mscoree.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.1\MOUSE32A.EXE
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [HydraVisionViewport] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraMD.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [HybridTM_A] C:\Program Files\HybridTM_IR(A)\RC620_A.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "K:\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "K:\Program files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [VoipDiscount] "C:\Program Files\VoipDiscount.com\VoipDiscount\VoipDiscount.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia\TMMonitor.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} -
http://tmss.trendmicro.com/dashboard/da ... DAAJHCGGEC (file missing)
O9 - Extra 'Tools' menuitem: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} -
http://tmss.trendmicro.com/dashboard/da ... DAAJHCGGEC (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.virgilio.it/free
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) -
http://tmss.trendmicro.com/Dashboard/co ... eportW.CAB
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -
http://launch.gamespyarcade.com/softwar ... launch.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Me ... b55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://messenger.zone.msn.com/binary/ZI ... b55579.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) -
http://sib1.od2.com/common/musicmanager ... Plugin.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AutoExNT - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program Files\Alias\Maya7.0\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya7.0\docs\Wrapper.conf (file missing)
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
Scusa se avrai cosi tante cose da leggere...
Noti ancora qualcosa di anomalo?
Grazie mille ancora.