Logfile of HijackThis v1.99.1
Scan saved at 18.43.15, on 17/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
H:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
H:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
H:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
H:\Programmi\Norton AntiVirus\IWP\NPFMntor.exe
H:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\Programmi\File comuni\Symantec Shared\ccApp.exe
H:\Programmi\QuickTime\qttask.exe
H:\Programmi\D-Tools\daemon.exe
H:\Programmi\Messenger\msmsgs.exe
H:\WINDOWS\system32\ctfmon.exe
H:\WINDOWS\system32\paytime.exe
H:\Programmi\Nikon\PictureProject\NkbMonitor.exe
H:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
H:\WINDOWS\BricoPacks\Vista Inspirat\UberIcon\UberIcon Manager.exe
H:\WINDOWS\System32\svchost.exe
H:\Programmi\Alice ti aiuta\bin\mpbtn.exe
H:\Programmi\Norton AntiVirus\navapsvc.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\paytime.exe
H:\WINDOWS\system32\aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.exe
H:\WINDOWS\system32\aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\explorer.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\paytime.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\Programmi\ewido\security suite\ewidoctrl.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\WINDOWS\system32\countrydial.exe
H:\Programmi\Mozilla Firefox\firefox.exe
H:\WINDOWS\system32\countrydial.exe
H:\Documents and Settings\user\Impostazioni locali\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - Default URLSearchHook is missing
O1 - Hosts: 213.215.208.4 L2authd.lineage2.com
O1 - Hosts: 217.144.68.123 nprotect.lineage2.com
O1 - Hosts: 205.238.40.2
www.winmx.comO1 - Hosts: 205.238.40.2 err.winmx.com
O1 - Hosts: 205.238.40.2 c3310.z1301.winmx.com
O1 - Hosts: 67.18.233.36 c3311.z1301.winmx.com
O1 - Hosts: 82.43.224.20 c3312.z1301.winmx.com
O1 - Hosts: 209.67.209.50 c3313.z1301.winmx.com
O1 - Hosts: 212.227.64.159 c3314.z1301.winmx.com
O1 - Hosts: 205.238.40.2 c3315.z1301.winmx.com
O1 - Hosts: 67.18.233.36 c3316.z1301.winmx.com
O1 - Hosts: 82.43.224.20 c3317.z1301.winmx.com
O1 - Hosts: 209.67.209.50 c3318.z1301.winmx.com
O1 - Hosts: 212.227.64.159 c3319.z1301.winmx.com
O1 - Hosts: 205.238.40.2 c3310.z1302.winmx.com
O1 - Hosts: 67.18.233.36 c3311.z1302.winmx.com
O1 - Hosts: 82.43.224.20 c3312.z1302.winmx.com
O1 - Hosts: 209.67.209.50 c3313.z1302.winmx.com
O1 - Hosts: 212.227.64.159 c3314.z1302.winmx.com
O1 - Hosts: 205.238.40.2 c3315.z1302.winmx.com
O1 - Hosts: 67.18.233.36 c3316.z1302.winmx.com
O1 - Hosts: 82.43.224.20 c3317.z1302.winmx.com
O1 - Hosts: 209.67.209.50 c3318.z1302.winmx.com
O1 - Hosts: 212.227.64.159 c3319.z1302.winmx.com
O1 - Hosts: 82.43.224.20 c3310.z1303.winmx.com
O1 - Hosts: 67.18.233.36 c3311.z1303.winmx.com
O1 - Hosts: 205.238.40.2 c3312.z1303.winmx.com
O1 - Hosts: 82.43.224.20 c3313.z1303.winmx.com
O1 - Hosts: 67.18.233.36 c3314.z1303.winmx.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: iMeshBar BHO - {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - H:\Programmi\iMeshBar\bar\1.bin\IMESHBAR.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - H:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - H:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: iMeshBar - {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - H:\Programmi\iMeshBar\bar\1.bin\IMESHBAR.DLL
O4 - HKLM\..\Run: [ccApp] "H:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "H:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [DAEMON Tools-1033] "H:\Programmi\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Media Gateway] H:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [Systems] H:\WINDOWS\system32\sysmon.exe
O4 - HKCU\..\Run: [MSMSGS] "H:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "H:\Programmi\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Stardock ObjectDock.lnk = H:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: Stop Dialers.lnk = H:\Programmi\StopDialers\StopDialers.exe
O4 - Startup: UberIcon.lnk = H:\WINDOWS\BricoPacks\Vista Inspirat\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z ToolBar.lnk = H:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Alice ti aiuta.lnk = H:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = H:\Programmi\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: NkbMonitor.exe.lnk = H:\Programmi\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Programmi\Messenger\msmsgs.exe
O15 - Trusted Zone:
www.archiviosex.netO15 - Trusted Zone:
www.redfunny.comO15 - Trusted Zone:
www.skymasters.bizO17 - HKLM\System\CCS\Services\Tcpip\..\{9A13D05A-C3B3-4AA7-B1E3-858B3F38AADC}: NameServer = 85.37.17.9 151.99.125.1
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - H:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - H:\Programmi\File comuni\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - H:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - H:\Programmi\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Servizio Auto-Protect di Norton AntiVirus (navapsvc) - Symantec Corporation - H:\Programmi\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - H:\Programmi\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - H:\Programmi\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - H:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - H:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - H:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - H:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe