mi controllate il log di hijack...???
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9.01.23, on 17/03/2016
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
C:\Programmi\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
C:\Programmi\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe
C:\Programmi\File comuni\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\spdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Avira\Launcher\Avira.ServiceHost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\DivX\DivX Update\DivXUpdate.exe
C:\Programmi\CyberLink\PowerDVD11\PDVD11Serv.exe
C:\Programmi\File comuni\Common Desktop Agent\CDASrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Avira\Launcher\Avira.Systray.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\DAEMON Tools Pro\DTAgent.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\CCleaner\CCleaner.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Programmi\Avira\AntiVir Desktop\sched.exe
C:\Programmi\Avira\AntiVir Desktop\avguard.exe
C:\Programmi\Avira\AntiVir Desktop\avshadow.exe
C:\Programmi\Avira\AntiVir Desktop\avgnt.exe
c:\programmi\avira\antivir desktop\avscan.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Programmi\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [RemoteControl11] C:\Programmi\CyberLink\PowerDVD11\PDVD11Serv.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Programmi\File comuni\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Avira SystrayStartTrigger] C:\Programmi\Avira\Launcher\Avira.SystrayStartTrigger.exe
O4 - HKLM\..\Run: [CDAServer] C:\Programmi\File comuni\Common Desktop Agent\CDASrv.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [{3b87484e-d70b-4b4f-ad59-2ae89571e2cf}] "C:\Documents and Settings\All Users\Dati applicazioni\Package Cache\{3b87484e-d70b-4b4f-ad59-2ae89571e2cf}\Avira.OE.Setup.Bundle.exe" /quiet /norestart /burn.log.append "C:\WINDOWS\TEMP\Avira_Launcher_20160219102317.log" /install CALLER_PARTNER_ID=avira /burn.runonce
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Programmi\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Programmi\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [_njwr] C:\WINDOWS\SYSTEM32\CMD.EXE /C START C:\Documents and Settings\Utente\Documenti\btioex.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [_ebik] C:\WINDOWS\SYSTEM32\CMD.EXE /C START C:\Documents and Settings\Utente\Documenti\btioex.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-21-527237240-562591055-682003330-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-527237240-562591055-682003330-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 Startup: RECOVERcnqiv.html (User '?')
O4 - S-1-5-21-527237240-562591055-682003330-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 Startup: RECOVERcnqiv.png (User '?')
O4 - S-1-5-21-527237240-562591055-682003330-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 Startup: RECOVERcnqiv.txt (User '?')
O4 - S-1-5-21-527237240-562591055-682003330-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 Startup: RECOVERfukdm.html (User '?')
O4 - S-1-5-21-527237240-562591055-682003330-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 Startup: RECOVERfukdm.png (User '?')
O4 - S-1-5-21-527237240-562591055-682003330-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 Startup: RECOVERfukdm.txt (User '?')
O4 - S-1-5-18 Startup: RECOVERcnqiv.html (User 'SYSTEM')
O4 - S-1-5-18 Startup: RECOVERcnqiv.png (User 'SYSTEM')
O4 - S-1-5-18 Startup: RECOVERcnqiv.txt (User 'SYSTEM')
O4 - S-1-5-18 Startup: RECOVERfukdm.html (User 'SYSTEM')
O4 - S-1-5-18 Startup: RECOVERfukdm.png (User 'SYSTEM')
O4 - S-1-5-18 Startup: RECOVERfukdm.txt (User 'SYSTEM')
O4 - .DEFAULT Startup: RECOVERcnqiv.html (User 'Default user')
O4 - .DEFAULT Startup: RECOVERcnqiv.png (User 'Default user')
O4 - .DEFAULT Startup: RECOVERcnqiv.txt (User 'Default user')
O4 - .DEFAULT Startup: RECOVERfukdm.html (User 'Default user')
O4 - .DEFAULT Startup: RECOVERfukdm.png (User 'Default user')
O4 - .DEFAULT Startup: RECOVERfukdm.txt (User 'Default user')
O4 - .DEFAULT User Startup: RECOVERcnqiv.html (User 'Default user')
O4 - .DEFAULT User Startup: RECOVERcnqiv.png (User 'Default user')
O4 - .DEFAULT User Startup: RECOVERcnqiv.txt (User 'Default user')
O4 - .DEFAULT User Startup: RECOVERfukdm.html (User 'Default user')
O4 - .DEFAULT User Startup: RECOVERfukdm.png (User 'Default user')
O4 - .DEFAULT User Startup: RECOVERfukdm.txt (User 'Default user')
O4 - Global Startup: RECOVERcnqiv.html
O4 - Global Startup: RECOVERcnqiv.png
O4 - Global Startup: RECOVERcnqiv.txt
O4 - Global Startup: RECOVERfukdm.html
O4 - Global Startup: RECOVERfukdm.png
O4 - Global Startup: RECOVERfukdm.txt
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Programmi\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira Pianificatore (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Programmi\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Programmi\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Programmi\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Programmi\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: CLHNServiceForPowerDVD - Unknown owner - C:\Programmi\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
O23 - Service: CyberLink PowerDVD 11.0 Monitor Service - CyberLink - C:\Programmi\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
O23 - Service: CyberLink PowerDVD 11.0 Service - CyberLink - C:\Programmi\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes - C:\Programmi\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Programmi\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Programmi\File comuni\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Samsung Printer Dianostics Service - Unknown owner - C:\WINDOWS\system32\\spdsvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 11056 bytes
grazie mille..!!!