firefox mi crasha quando vado su siti tipo libero o alice per la posta (l'ho reinstallato ma niente), l'antivirus (pc-tools antivirus) mi ha trovato un trojan in _restore (trojan.dl.agent.rot)
questo è il log di hijackthis 1.99
Logfile of HijackThis v1.99.1
Scan saved at 18.00.32, on 15/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\IFXSPMGT.exe
C:\WINDOWS\system32\IFXTCS.exe
C:\Programmi\File comuni\LightScribe\LSSrvc.exe
C:\Programmi\PC Tools AntiVirus\PCTAVSvc.exe
C:\Programmi\ProtectTools\Embedded Security Software\PSDsrvc.EXE
C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Programmi\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\Programmi\ATI Technologies\ATI.ACE\CLIStart.exe
C:\Programmi\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
C:\Programmi\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Programmi\Comodo\Firewall\CPF.exe
C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\PC Tools AntiVirus\PCTAV.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Windows Media Player\WMPNSCFG.exe
C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmi\Windows Desktop Search\WindowsSearch.exe
C:\Programmi\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKCU\..\Run: [PCTAVApp] "C:\Programmi\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\programmi\file comuni\pc tools\lsp\pctlsp.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Backbone Service (BBDemon) - Unknown owner - C:\Programmi\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe" -service (file missing)