Per la prima volta da quando uso la adsl ho beccato un dirottatore (penso) che modifica la pagina iniziale.
IN MODALITA' PROVVISORIA
Ho disattivato il ripristino di configurazione, ho svuotato le cartelle temp e temporany internet file, ho ripulito tutto con ad-aware e spy boot, ho cambiato la pagina iniziale predefinita, ma al riavvio il problema rimane. Mi sembra che ci sia da fare qualcosaltro ma non ricordo cosa, invio di seguito il log, chi mi può aiutare, GRAZIE!
Logfile of HijackThis v1.97.7
Scan saved at 10.47.25, on 19/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
F:\appoggio docte\dsp\dspt1\Nicola\Programmi utili\GESTIONE E RIPARAZIONE PC\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\grxih.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\grxih.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\grxih.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\grxih.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\grxih.dll/sp.html#37049
O2 - BHO: (no name) - {90706F45-D241-085D-C3F4-2CA0366EF00C} - C:\WINDOWS\system32\ipqu.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmi\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Programmi\File comuni\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [JobHisInit] C:\Program Files\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Program Files\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [Messenger Connection Log] MSNMSLOG.EXE
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Programmi\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AnyDVD] F:\ANY DVD\AnyDVD.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Programmi\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [netzx.exe] C:\WINDOWS\system32\netzx.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ATnotes.exe] F:\appoggio docte\dsp\dspt1\Nicola\Programmi utili\Post_it x pc\ATnotes.exe
O4 - HKLM\..\RunOnce: [addgb32.exe] C:\WINDOWS\addgb32.exe
O4 - HKLM\..\RunOnce: [ntca32.exe] C:\WINDOWS\system32\ntca32.exe
O4 - HKLM\..\RunOnce: [apiok32.exe] C:\WINDOWS\system32\apiok32.exe
O4 - HKLM\..\RunOnce: [atlfd32.exe] C:\WINDOWS\atlfd32.exe
O4 - HKLM\..\RunOnce: [addfa32.exe] C:\WINDOWS\addfa32.exe
O4 - HKLM\..\RunOnce: [apiwn.exe] C:\WINDOWS\system32\apiwn.exe
O4 - HKLM\..\RunOnce: [iekn32.exe] C:\WINDOWS\system32\iekn32.exe
O4 - HKLM\..\RunOnce: [ieie32.exe] C:\WINDOWS\ieie32.exe
O4 - HKLM\..\RunOnce: [wintz.exe] C:\WINDOWS\wintz.exe
O4 - HKLM\..\RunOnce: [wingg32.exe] C:\WINDOWS\wingg32.exe
O4 - HKLM\..\RunOnce: [atltc.exe] C:\WINDOWS\system32\atltc.exe
O4 - HKLM\..\RunOnce: [d3sk32.exe] C:\WINDOWS\system32\d3sk32.exe
O4 - HKLM\..\RunOnce: [addlo.exe] C:\WINDOWS\addlo.exe
O4 - HKLM\..\RunOnce: [netcb.exe] C:\WINDOWS\netcb.exe
O4 - HKLM\..\RunOnce: [ntxe32.exe] C:\WINDOWS\system32\ntxe32.exe
O4 - HKLM\..\RunOnce: [d3dh32.exe] C:\WINDOWS\system32\d3dh32.exe
O4 - HKLM\..\RunOnce: [mfcaa32.exe] C:\WINDOWS\mfcaa32.exe
O4 - HKLM\..\RunOnce: [winxc.exe] C:\WINDOWS\winxc.exe
O4 - HKLM\..\RunOnce: [crek32.exe] C:\WINDOWS\crek32.exe
O4 - HKLM\..\RunOnce: [msev32.exe] C:\WINDOWS\system32\msev32.exe
O4 - HKLM\..\RunOnce: [addcd.exe] C:\WINDOWS\system32\addcd.exe
O4 - HKLM\..\RunOnce: [javapr32.exe] C:\WINDOWS\system32\javapr32.exe
O4 - HKLM\..\RunOnce: [ntlj32.exe] C:\WINDOWS\ntlj32.exe
O4 - HKLM\..\RunOnce: [ipvf32.exe] C:\WINDOWS\system32\ipvf32.exe
O4 - HKLM\..\RunOnce: [nthw32.exe] C:\WINDOWS\nthw32.exe
O4 - HKLM\..\RunOnce: [msqj32.exe] C:\WINDOWS\msqj32.exe
O4 - HKLM\..\RunOnce: [ipky.exe] C:\WINDOWS\system32\ipky.exe
O4 - HKLM\..\RunOnce: [atlxi32.exe] C:\WINDOWS\system32\atlxi32.exe
O4 - HKLM\..\RunOnce: [sysyf32.exe] C:\WINDOWS\system32\sysyf32.exe
O4 - HKLM\..\RunOnce: [mscg.exe] C:\WINDOWS\mscg.exe
O4 - HKLM\..\RunOnce: [nthi32.exe] C:\WINDOWS\nthi32.exe
O4 - HKLM\..\RunOnce: [sdkbr32.exe] C:\WINDOWS\system32\sdkbr32.exe
O4 - HKLM\..\RunOnce: [apigc32.exe] C:\WINDOWS\system32\apigc32.exe
O4 - HKLM\..\RunOnce: [atllp.exe] C:\WINDOWS\atllp.exe
O4 - HKLM\..\RunOnce: [javadz.exe] C:\WINDOWS\javadz.exe
O4 - HKLM\..\RunOnce: [atlec.exe] C:\WINDOWS\system32\atlec.exe
O4 - HKLM\..\RunOnce: [msib.exe] C:\WINDOWS\system32\msib.exe
O4 - HKLM\..\RunOnce: [appbx32.exe] C:\WINDOWS\appbx32.exe
O4 - HKLM\..\RunOnce: [appnd.exe] C:\WINDOWS\appnd.exe
O4 - HKLM\..\RunOnce: [appim32.exe] C:\WINDOWS\system32\appim32.exe
O4 - HKLM\..\RunOnce: [atlah.exe] C:\WINDOWS\atlah.exe
O4 - HKLM\..\RunOnce: [iegc32.exe] C:\WINDOWS\iegc32.exe
O4 - HKLM\..\RunOnce: [atloo.exe] C:\WINDOWS\system32\atloo.exe
O4 - HKLM\..\RunOnce: [mszy32.exe] C:\WINDOWS\mszy32.exe
O4 - HKLM\..\RunOnce: [msem32.exe] C:\WINDOWS\msem32.exe
O4 - HKLM\..\RunOnce: [winec.exe] C:\WINDOWS\system32\winec.exe
O4 - HKLM\..\RunOnce: [apinp.exe] C:\WINDOWS\system32\apinp.exe
O4 - HKLM\..\RunOnce: [ievv32.exe] C:\WINDOWS\ievv32.exe
O4 - HKLM\..\RunOnce: [crad32.exe] C:\WINDOWS\crad32.exe
O4 - HKLM\..\RunOnce: [sdkdf.exe] C:\WINDOWS\sdkdf.exe
O4 - HKLM\..\RunOnce: [mfcox32.exe] C:\WINDOWS\system32\mfcox32.exe
O4 - HKLM\..\RunOnce: [winnl32.exe] C:\WINDOWS\winnl32.exe
O4 - HKLM\..\RunOnce: [msnr32.exe] C:\WINDOWS\system32\msnr32.exe
O4 - Global Startup: Avvia servizi di consegna.lnk = ?
O4 - Global Startup: Docking Director.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1098788456906O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} (ParallelGraphics Cortona Control) -
http://www.parallelgraphics.com/bin/cortvrml.cabO16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) -
http://support.f-secure.com/ols/fscax.cabO16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) -
http://ww3.atlanteitaliano.it/ecwplugins/ncs.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38131.3974652778O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab