Grazie Alfonso, ecco cosa contiene il log.
Inoltre per maggiore chiarezza preciso che il blocco avviene prevalentemente (o esclusivamente ) quando non sono collegato ad Internet.Ultimo virus rilevato e messo in quarantena è :Trojan Byte Verify trovato nel file Parser.class nella cartella TEMP di Windows.Ultimi files cancellati:alcune iimagini della cartella Temp di Flip 5 Pro.(che funziona normalmente). Grazie ancora.
Logfile of HijackThis v1.98.0
Scan saved at 8.06.35, on 31/07/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ABCD.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\PTSNOOP.EXE
C:\WINDOWS\SYSTEM\CMMPU.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAMMI\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAMMI\NORTON ANTIVIRUS\POPROXY.EXE
C:\SCANJET\PRECISIONSCANLT\HPPWRSAV.EXE
C:\WINDOWS\SYSTEM\FPPDIS1A.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAMMI\FILE COMUNI\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAMMI\ZONE LABS\ZONEALARM\ZAPRO.EXE
C:\PROGRAMMI\STOPDIALERS\STOPDIALER.EXE
C:\PROGRAMMI\WEBSHOTS\WEBSHOTSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://it.my.yahoo.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.libero.it:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = libero.it;iol.it
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F1 - win.ini: load=ptsnoop.exe
F1 - win.ini: run=c:\windows\SYSTEM\cmmpu.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: DAPBHO Class - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\PROGRAMMI\DAP\DAPIEBAR.DLL
O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\PROGRAMMI\DAP\DAPBHO.DLL
O2 - BHO: Control Popups in Internet Explorer - {41353F8B-78CE-48A5-BE44-153ED293D192} - C:\PROGRAMMI\POPUPPOPPER\POPLIB.DLL
O2 - BHO: FlpLauncher Class - {4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} - C:\PROGRAMMI\E-BOOK SYSTEMS\FLIPALBUM 5 PRO\FPLAUNCH.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [Norton eMail Protect] C:\PROGRAMMI\NORTON ANTIVIRUS\POProxy.exe
O4 - HKLM\..\Run: [hppwrsav] C:\SCANJET\PrecisionScanLT\hppwrsav.exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [pdfFactory Schedulatore v1] C:\WINDOWS\SYSTEM\fppdis1a.exe
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [SoniqueQuickStart] C:\Program Files\Sonique\sqstart.exe -nostick
O4 - Startup: Stop Dialers.lnk = C:\Programmi\StopDialers\StopDialer.exe
O4 - Startup: Webshots.lnk = C:\Programmi\Webshots\WebshotsTray.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Programmi\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Apri fra&me in un'altra finestra - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: &Evidenzia - C:\WINDOWS\WEB\highlight.htm
O8 - Extra context menu item: Ricerca &Web - C:\WINDOWS\WEB\selsearch.htm
O8 - Extra context menu item: &Elenco collegamenti - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: &Zoom avanti - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom in&dietro - C:\WINDOWS\WEB\zoomout.htm
O8 - Extra context menu item: Elen&co immagini - C:\WINDOWS\Web\imglist.htm
O8 - Extra context menu item: AltaVista Home -
http://jump.altavista.com/avie5/homeO8 - Extra context menu item: AltaVista Search This Term -
http://jump.altavista.com/avie5/searchO8 - Extra context menu item: AltaVista Translate Selection -
http://jump.altavista.com/avie5/babelfishO8 - Extra context menu item: AltaVista Translate this Web Page -
http://jump.altavista.com/avie5/babelfishO8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Programmi\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {06FE5D00-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/home (file missing)
O9 - Extra 'Tools' menuitem: &AltaVista Home - {06FE5D00-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/home (file missing)
O9 - Extra button: MicroPortal - {06FE5D01-8F11-11d2-804F-00105A133818} - c:\windows\SYSTEM\shdocvw.dll
O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra 'Tools' menuitem: AltaVista &Translate - {06FE5D05-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: PopupPopper Control Panel - {3E94F358-9537-4BBA-8D12-D7F8A0136973} - C:\Programmi\PopupPopper\SiteList.exe
O12 - Plugin for .ivr: C:\PROGRA~1\INTERN~1\PLUGINS\NPRVRT32.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O16 - DPF: {02466323-75ED-11CF-A267-0020AF2546EA} (VivoActive Control) -
http://player.vivo.com/ie/vvweb.cabO16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) -
http://a1440.g.akamaitech.net/7/1440/291/02010110/central1.clevercontent.com/02010110/cccabs/CleverContent.cabO16 - DPF: {F313FC06-1311-11D1-A7F3-00A02478C1D3} (Dnwfc Control) -
http://www.meteo.it/activex/dnwfc.cabO16 - DPF: {86A889A6-7A20-11D2-8EDA-00600818EDB1} (ParallelGraphics VRML Automation Driver v3.0) -
http://www.parallelgraphics.com/bin/cortauto.cabO16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} (ParallelGraphics Cortona Control) -
http://www.parallelgraphics.com/bin/cortcore.cabO16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://193.45.228.166/activex/AxisCamControl.cabO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) -
http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) -
http://www.atlanteitaliano.it/ecwplugins/ncs.cabO16 - DPF: {56C6ED81-849D-41FF-B436-102530609286} (ActX.ArgoX) -
http://www.argoclima.it/webargo/AppDimensionamento/ActX.CABO16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) -
http://www2.incredimail.com/contents/setup/downloader/imloader.cab