Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19.20.31, on 26/04/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\dvd43\DVD43_Tray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\win\Desktop\Lanterna\Lantmirc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\win\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=83&bd=Presario&pf=cnnbR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=83&bd=Presario&pf=cnnbR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://home.sweetim.comR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - {ecdee021-0d17-467f-a1ff-c7a115230949} - (no file)
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O1 - Hosts: ::1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 108.50.183.106
www.symantec.comO1 - Hosts: 160.132.76.9 symantec.com
O1 - Hosts: 158.0.171.217 securityresponse.symantec.com
O1 - Hosts: 227.234.245.214 symantecstore.com
O1 - Hosts: 105.182.145.209
www.symantecstore.comO1 - Hosts: 33.220.252.181 service1.symantec.com
O1 - Hosts: 220.190.246.87 sarc.com
O1 - Hosts: 111.248.161.19
www.sarc.coO1 - Hosts: 16.185.84.31
www.symantec.comO1 - Hosts: 152.206.218.230 symantec.com
O1 - Hosts: 45.95.165.205 securityresponse.symantec.com
O1 - Hosts: 38.240.232.227 symantecstore.com
O1 - Hosts: 232.5.216.41
www.symantecstore.comO1 - Hosts: 109.68.11.116 service1.symantec.com
O1 - Hosts: 250.156.140.198 sarc.com
O1 - Hosts: 136.37.213.84
www.sarc.comO1 - Hosts: 63.248.157.195
www.sophos.comO1 - Hosts: 4.100.188.103 sophos.com
O1 - Hosts: 22.136.140.119
www.mcafee.comO1 - Hosts: 12.227.6.142 mcafee.com
O1 - Hosts: 91.84.128.239 customer.symantec.com
O1 - Hosts: 162.3.87.83 liveupdate.symantec.com
O1 - Hosts: 226.215.88.70 liveupdate.symantecliveupdate.com
O1 - Hosts: 107.219.69.220
www.viruslist.comO1 - Hosts: 143.166.195.186 viruslist.com
O1 - Hosts: 135.204.127.184 f-secure.com
O1 - Hosts: 115.220.243.41 f-secure.de
O1 - Hosts: 253.90.130.122
www.f-secure.deO1 - Hosts: 131.101.91.71
www.f-secure.comO1 - Hosts: 187.213.96.150 f-prot.com
O1 - Hosts: 89.144.122.183
www.f-prot.comO1 - Hosts: 19.221.151.41 kaspersky.com
O1 - Hosts: 6.246.192.229 kaspersky-labs.com
O1 - Hosts: 226.40.250.245
www.avp.comO1 - Hosts: 242.172.118.186 avp.com
O1 - Hosts: 184.161.164.193
www.kaspersky.comO1 - Hosts: 88.198.193.28
www.networkassociates.comO1 - Hosts: 12.214.124.0 networkassociates.com
O1 - Hosts: 187.177.174.60
www.ca.comO1 - Hosts: 142.50.212.193 www3.ca.com
O1 - Hosts: 134.83.80.60 ca.com
O1 - Hosts: 0.10.136.137 store.ca.com
O1 - Hosts: 33.126.115.24 mast.mcafee.com
O1 - Hosts: 26.249.55.90 ca.mcafee.com
O1 - Hosts: 176.60.84.110 mx.mcafee.com
O1 - Hosts: 15.18.10.166 no.mcafee.com
O1 - Hosts: 203.218.116.137 uk.mcafee.com
O1 - Hosts: 143.210.9.131 tw.mcafee.com
O1 - Hosts: 220.86.117.70 cn.mcafee.com
O1 - Hosts: 230.119.132.53 de.mcafee.comwww.mcafeeasap.com
O1 - Hosts: 243.139.11.191 mcafeeasap.com
O1 - Hosts: 166.150.9.136 vil.mcafee.com
O1 - Hosts: 199.186.117.208
www.mcafeestore.comO1 - Hosts: 222.9.229.116 mcafeestore.com
O1 - Hosts: 175.222.143.232
www.shopmcafee.comO1 - Hosts: 234.172.197.28 shopmcafee.com
O1 - Hosts: 54.82.244.163 my-etrust.com
O1 - Hosts: 200.236.209.14
www.my-etrust.comO1 - Hosts: 193.192.37.196 dispatch.mcafee.com
O1 - Hosts: 8.159.109.228 secure.nai.com
O1 - Hosts: 192.109.204.110 nai.com
O1 - Hosts: 63.49.245.41
www.nai.comO1 - Hosts: 110.71.11.54 vil.nai.com
O1 - Hosts: 27.163.158.143 update.symantec.com
O1 - Hosts: 38.76.87.135 updates.symantec.com
O1 - Hosts: 247.89.86.124 us.mcafee.com
O1 - Hosts: 70.65.235.207 mcafee.net
O1 - Hosts: 135.49.185.221 rads.mcafee.com
O1 - Hosts: 30.178.196.129 download.mcafee.com
O1 - Hosts: 19.242.32.87 trendmicro.com
O1 - Hosts: 246.204.47.228
www.trendmicro.comO1 - Hosts: 190.140.45.55 housecall.trendmicro.com
O1 - Hosts: 163.250.232.182 housecall65.trendmicro.com
O1 - Hosts: 233.159.249.60 trendmicro-europe.com
O1 - Hosts: 31.224.203.154 nl.trendmicro-europe.com
O1 - Hosts: 23.219.200.54 de.trendmicro-europe.com
O1 - Hosts: 73.157.141.217
www.trendmicro-europe.comO1 - Hosts: 226.43.81.102 pandasoftware.com
O1 - Hosts: 155.224.16.247
www.pandasoftware.comO1 - Hosts: 150.49.13.61
www.pc-cillin.comO1 - Hosts: 7.203.60.138 pc-cillin.com
O1 - Hosts: 187.150.43.224
www.vsantivirus.comO1 - Hosts: 82.42.247.244 vsantivirus.com
O1 - Hosts: 200.162.122.3
www.trendmicro.comO1 - Hosts: 141.116.25.221 free.grisoft.com
O1 - Hosts: 93.171.247.144
www.grisoft.comO1 - Hosts: 143.166.125.137 grisoft.com
O1 - Hosts: 137.208.96.162 clamav.net
O1 - Hosts: 16.222.39.243
www.clamav.netO1 - Hosts: 43.9.92.76 free-av.com
O1 - Hosts: 70.217.102.66
www.free-av.comO1 - Hosts: 214.126.176.173
www.avast.comO1 - Hosts: 28.50.159.133 avast.com
O1 - Hosts: 82.183.136.100 cert.org
O1 - Hosts: 236.244.20.72
www.cert.orgO1 - Hosts: 161.28.75.58
www.microsoft.comO1 - Hosts: 97.10.192.242 microsoft.com
O1 - Hosts: 155.55.3.184
www.virustotal.comO1 - Hosts: 70.226.82.121 virustotal.com
O1 - Hosts: 28.90.81.244
www.teamanti-virus.orgO2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Window UDP Control Servic] winlogon.exe
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunServices: [Windows logon service] C:\Windows\System32\setup\winlogon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O8 - Extra context menu item: &AOL Toolbar Cerca - C:\ProgramData\AOL\ieToolbar\resources\it-IT\local\search.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233749846541O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233750013714O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
O23 - Service: UPnPService - Magix AG - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 15458 bytes
Graxie in anticipo