Aiuto anch'io mi trovo alle prese con lo stesso tipo di dialer e non riesco a liberarmene.... sembra che alcuni file come paytime.exe si rigenerino in continuazione!!!! non so che fare e non riesco a stare collegata per più di 3 minuti
ecco il log:
Logfile of HijackThis v1.99.1
Scan saved at 16.22.57, on 09/05/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP4 (6.00.2800.1106)
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\system32\algsys.exe
D:\Programmi\AntiVir PersonalEdition Classic\sched.exe
D:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
D:\Programmi\Bluetooth\Software Bluetooth\bin\btwdins.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\explorer.exe
D:\WINNT\SOUNDMAN.EXE
D:\Programmi\ATI Technologies\Pannello di controllo ATI\atiptaxx.exe
D:\WINNT\system32\carpserv.exe
D:\Programmi\Elaborate Bytes\CloneCD\CloneCDTray.exe
D:\Programmi\Real\RealPlayer\RealPlay.exe
D:\Programmi\Trust\Ami Mouse 300 Cordless Dual Scroll\Amoumain.exe
D:\Programmi\PCX 370\shwicon.exe
D:\Programmi\MusicMatch\MusicMatch Jukebox\mm_tray.exe
D:\Programmi\File comuni\ACD Systems\EN\DevDetect.exe
C:\programmi\hp\HP Share-to-Web\hpgs2wnd.exe
c:\PROGRA~1\hp\HPSHAR~1\hpgs2wnf.exe
D:\Program Files\Libero\Adsl\dslstat.exe
D:\Program Files\Libero\Adsl\dslagent.exe
D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE
C:\Programmi\iTunes\iTunesHelper.exe
D:\programmi\quicktimebis\qttask.exe
D:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
D:\WINNT\system32\internat.exe
C:\Programmi\iPod\bin\iPodService.exe
D:\Programmi\ATI Multimedia\main\launchpd.exe
D:\Programmi\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
D:\Programmi\WinZip\WZQKPICK.EXE
D:\Programmi\Microsoft Office\Office\1040\OLFSNT40.EXE
D:\Programmi\Bluetooth\Software Bluetooth\BTTray.exe
C:\StopDialers\StopDialer.exe
D:\WINNT\system32\wuauclt.exe
c:\Program Files\paytime.exe
D:\Programmi\AntiVir PersonalEdition Classic\avcenter.exe
D:\Programmi\Internet Explorer\iexplore.exe
c:\kl1.exe
c:\countrydial.exe
c:\Program Files\paytime.exe
D:\WINNT\system32\NOTEPAD.EXE
D:\PROGRA~1\WINZIP\winzip32.exe
D:\Documents and Settings\P4\Impostazioni locali\Temp\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=explorer.exe "D:\Programmi\File comuni\Microsoft Shared\Web Folders\ibm00123.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmi\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "D:\Programmi\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "D:\Programmi\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [RealTray] D:\Programmi\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NetWatcherPro] D:\Documents and Settings\Alessandro\Documenti\AlePC\My Documents\Shared File\netwatcher\NetWatcherPro.exe
O4 - HKLM\..\Run: [WheelMouse] Amoumain.exe
O4 - HKLM\..\Run: [ShowIcon_PC Expert TECH. CO., LTD._PCX 370 v1.01] "D:\Programmi\PCX 370\shwicon.exe" -t"PC Expert TECH. CO., LTD.\PCX 370 v1.01"
O4 - HKLM\..\Run: [MMTray] D:\Programmi\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Device Detector] "D:\Programmi\File comuni\ACD Systems\EN\DevDetect.exe" -autorun
O4 - HKLM\..\Run: [NeroCheck] D:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CXMon] "c:\programmi\hp\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\programmi\hp\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [DSLSTATEXE] D:\Program Files\Libero\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] D:\Program Files\Libero\Adsl\dslagent.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R240 Series] D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /P30 "EPSON Stylus Photo R240 Series" /O6 "USB002" /M "Stylus Photo R240"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\programmi\quicktimebis\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "D:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SysTray] c:\Program Files\paytime.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [ATI Launchpad] "D:\Programmi\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [EPSON Stylus Photo R240 Series] D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /P30 "EPSON Stylus Photo R240 Series" /M "Stylus Photo R240" /EF "HKCU"
O4 - Startup: Stop Dialers.lnk = C:\StopDialers\StopDialer.exe
O4 - Global Startup: Acrobat Assistant.lnk = D:\Programmi\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Programmi\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Programmi\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Porta Symantec Fax Starter Edition.lnk = D:\Programmi\Microsoft Office\Office\1040\OLFSNT40.EXE
O4 - Global Startup: BTTray.lnk = D:\Programmi\Bluetooth\Software Bluetooth\BTTray.exe
O8 - Extra context menu item: Invia a &Bluetooth - D:\Programmi\Bluetooth\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmi\Bluetooth\Software Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Programmi\Bluetooth\Software Bluetooth\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINNT\System32\Shdocvw.dll
O12 - Plugin for .dll: D:\Programmi\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: D:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupda ... 3014042671
O17 - HKLM\System\CCS\Services\Tcpip\..\{53880187-8C69-43B5-9C1F-3D8936F96AA9}: NameServer = 193.70.152.15 193.70.152.25
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - D:\WINNT\System32\btxppanel.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Programmi\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - D:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Programmi\Bluetooth\Software Bluetooth\bin\btwdins.exe
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Windows Update Manager (UpdateManager) - Unknown owner - D:\WINNT\system32\zjpmsb.exe (file missing)
Aiutatemi per favore... non sono molto abile