Logfile of HijackThis v1.99.1
Scan saved at 14.47.41, on 25/01/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAMMI\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\PROGRAMMI\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\APPLICATION DATA\SGRUNT\IE4321.EXE
C:\PROGRAMMI\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETMSG.EXE
C:\PROGRAMMI\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
C:\PROGRAMMI\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAMMI\SONY CORPORATION\IMAGE TRANSFER\SONYTRAY.EXE
C:\PROGRAMMI\SAGEM\SAGEM F@ST 800-840\DSLMON.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://gw.aliceadsl.it/minisearchR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://libero.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://gw.aliceadsl.it/homeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Alice
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O1 - Hosts: 127.0.0.3
www.onedayoffer.bizO1 - Hosts: 127.0.0.3 onedayoffer.biz
O1 - Hosts: 127.0.0.3 callmachine.net
O1 - Hosts: 127.0.0.3
www.callmachine.netO1 - Hosts: 127.0.0.3 reportbucks.com
O1 - Hosts: 127.0.0.3
www.reportbucks.comO1 - Hosts: 127.0.0.3 isuckall.com
O1 - Hosts: 127.0.0.3
www.isuckall.comO1 - Hosts: 127.0.0.3 wbdialer.biz
O1 - Hosts: 127.0.0.3
www.wbdialer.bizO1 - Hosts: 127.0.0.3 alphadialer.com
O1 - Hosts: 127.0.0.3
www.alphadialer.comO1 - Hosts: 127.0.0.3 it.online-more.com
O1 - Hosts: 127.0.0.3
www.it.online-more.comO1 - Hosts: 127.0.0.3 statscash.net
O1 - Hosts: 127.0.0.3
www.statscash.netO1 - Hosts: 127.0.0.3 85.255.113.242
O1 - Hosts: 127.0.0.3 takeyourbucks.com
O1 - Hosts: 127.0.0.3
www.takeyourbucks.comO1 - Hosts: 127.0.0.3 195.225.176.25
O1 - Hosts: 127.0.0.3 iframebiz.biz
O1 - Hosts: 127.0.0.3 iframeurl.biz
O1 - Hosts: 127.0.0.3 iframesite.biz
O1 - Hosts: 127.0.0.3 toolbarbiz.biz
O1 - Hosts: 127.0.0.3 toolbarsite.biz
O1 - Hosts: 127.0.0.3 toolbarurl.biz
O1 - Hosts: 127.0.0.3 toolbartraff.biz
O1 - Hosts: 127.0.0.3 buytoolbar.biz
O1 - Hosts: 127.0.0.3
www.iframebiz.bizO1 - Hosts: 127.0.0.3
www.iframeurl.bizO1 - Hosts: 127.0.0.3
www.iframesite.bizO1 - Hosts: 127.0.0.3
www.toolbarbiz.bizO1 - Hosts: 127.0.0.3
www.toolbarsite.bizO1 - Hosts: 127.0.0.3
www.toolbarurl.bizO1 - Hosts: 127.0.0.3
www.toolbartraff.bizO1 - Hosts: 127.0.0.3
www.buytoolbar.bizO1 - Hosts: 127.0.0.3 81.9.5.9
O1 - Hosts: 127.0.0.3 n-glx.s-redirect.com
O1 - Hosts: 127.0.0.3
www.sexfiles.nuO1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3
www.allforadult.comO1 - Hosts: 127.0.0.3
www.iframe.bizO1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3 procounter.biz
O1 - Hosts: 127.0.0.3
www.procounter.bizO1 - Hosts: 127.0.0.3 advadmin.biz
O1 - Hosts: 127.0.0.3
www.advadmin.bizO1 - Hosts: 127.0.0.3 trafficbest.net
O1 - Hosts: 127.0.0.3
www.trafficbest.netO1 - Hosts: 127.0.0.3
www.newiframe.bizO1 - Hosts: 127.0.0.3 newiframe.biz
O1 - Hosts: 127.0.0.3
www.vesbiz.bizO1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3
www.pizdato.bizO1 - Hosts: 127.0.0.3 pizdato.biz
O1 - Hosts: 127.0.0.3
www.aaasexypics.comO1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3
www.virgin-tgp.netO1 - Hosts: 127.0.0.3 vparivalka.com
O1 - Hosts: 127.0.0.3
www.vparivalka.comO1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3
www.iframeprofit.comO1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3
www.awmcash.bizO1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3 buldog-stats.com
O1 - Hosts: 127.0.0.3
www.buldog-stats.comO1 - Hosts: 127.0.0.3 fregat.drocherway.com
O1 - Hosts: 127.0.0.3 slutmania.biz
O1 - Hosts: 127.0.0.3
www.slutmania.bizO1 - Hosts: 127.0.0.3 toolbarpartner.com
O1 - Hosts: 127.0.0.3
www.toolbarpartner.comO1 - Hosts: 127.0.0.3
www.megapornix.comO1 - Hosts: 127.0.0.3 megapornix.com
O1 - Hosts: 127.0.0.3
www.sp2fucked.bizO1 - Hosts: 127.0.0.3 sp2fucked.biz
O1 - Hosts: 127.0.0.3 greg-tut.com
O1 - Hosts: 127.0.0.3
www.greg-tut.comO1 - Hosts: 127.0.0.3 nylonsexy.com
O1 - Hosts: 127.0.0.3
www.nylonsexy.comO1 - Hosts: 127.0.0.3 topsearch10.com
O1 - Hosts: 127.0.0.3
www.topsearch10.comO1 - Hosts: 127.0.0.3 statscash.biz
O1 - Hosts: 127.0.0.3
www.statscash.bizO1 - Hosts: 127.0.0.3 vxiframe.biz
O1 - Hosts: 127.0.0.3
www.vxiframe.bizO1 - Hosts: 127.0.0.3 crazy-toolbar.com
O1 - Hosts: 127.0.0.3
www.crazy-toolbar.comO1 - Hosts: 127.0.0.3 topcash.biz
O1 - Hosts: 127.0.0.3
www.topcash.bizO1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3
www.loadcash.bizO1 - Hosts: 127.0.0.3 txiframe.biz
O1 - Hosts: 127.0.0.3
www.txiframe.bizO1 - Hosts: 127.0.0.3 besthvac.com
O1 - Hosts: 127.0.0.3
www.besthvac.comO1 - Hosts: 127.0.0.3 traff4.com
O1 - Hosts: 127.0.0.3
www.traff4.comO1 - Hosts: 127.0.0.3 porn-host.org
O2 - BHO: IEHlprObj Class - {01FB9C55-FC66-4476-A199-389241193188} - C:\WINDOWS\SYSTEM\EXETGA~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMI\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [RealTray] C:\Programmi\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [gCac] C:\WINDOWS\gcac.exe
O4 - HKLM\..\Run: [Olympic] C:\WINDOWS\Application Data\sgrunt\IE4321.exe
O4 - HKLM\..\Run: [SERVICES.EXE] C:\WINDOWS\__P9HEPQKBJ.EXE
O4 - HKLM\..\Run: [MAGIXautostart] D:\SETUP.EXE
O4 - HKLM\..\Run: [VetAlert] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETMSG.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Programmi\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - Startup: Avvio Office.lnk = C:\Programmi\Microsoft Office\Office\OSA.EXE
O4 - Startup: Ricerca rapida.lnk = C:\Programmi\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: EPSON Status Monitor 3.2 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
O4 - Startup: Image Transfer.lnk = C:\Programmi\Sony Corporation\Image Transfer\SonyTray.exe
O4 - Startup: DSLMON.lnk = C:\Programmi\SAGEM\SAGEM F@st 800-840\dslmon.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Organizzatore ricerche - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmi\File comuni\Microsoft Shared\Encarta Researcher\EROProj.dll
O9 - Extra button: Alice - {22FED253-3F5D-4A20-8E2F-B5F23DB41661} -
http://gw.aliceadsl.it/alice (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
O15 - Trusted Zone:
www.redfunny.comO15 - Trusted Zone:
www.skymasters.bizO15 - Trusted Zone:
www.archiviosex.netO15 - Trusted Zone:
www.linkautomatici.comO15 - Trusted Zone:
www.sgrunt.bizO15 - Trusted Zone: *.3
O15 - Trusted Zone:
www.superspots.bizO15 - Trusted Zone:
www.xbeta69.comO16 - DPF: {FFFF0003-0001-101A-A3C9-08002B2F49FB} -
http://www.sgrunt.biz/closer/close.exe