Sembrava debellato ma è rispuntato fuori, qualcuno mi aiuta?
Questo è il log:
Logfile of HijackThis v1.99.1
Scan saved at 10.15.34, on 01/09/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WXPH\System32\smss.exe
C:\WXPH\system32\winlogon.exe
C:\WXPH\system32\services.exe
C:\WXPH\system32\lsass.exe
C:\WXPH\system32\svchost.exe
C:\WXPH\System32\svchost.exe
C:\WXPH\system32\spoolsv.exe
C:\Programmi\CA\eTrust Antivirus\InoRpc.exe
C:\Programmi\CA\eTrust Antivirus\InoRT.exe
C:\Programmi\CA\eTrust Antivirus\InoTask.exe
C:\WXPH\System32\svchost.exe
C:\WXPH\Explorer.EXE
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\SCANJET\PrecisionScanLT\hppwrsav.exe
C:\Documents and Settings\mexal2\Dati applicazioni\ratorefaci\sysrtmvs.exe
C:\WXPH\System32\ctfmon.exe
C:\mexal_cli_ADP\prog\mxdesk.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Microsoft Office\Office\EXCEL.EXE
C:\Programmi\Internet Explorer\iexplore.exe
C:\SCANJET\PrecisionScanLT\hpprsclt.exe
C:\Programmi\ZipGenius 5\zipgenius.exe
C:\DOCUME~1\mexal2\IMPOST~1\Temp\ZGTemp\HijackThis.exe
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {0712FB8F-FE45-166D-F477-DDE972BE5CC5} - C:\WXPH\npbkp1.dll (file missing)
O2 - BHO: Class - {493C64A2-68D8-00DB-49B1-A424B3007DC4} - C:\WXPH\npbkp1.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WXPH\System32\msdxm.ocx
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [hppwrsav] C:\SCANJET\PrecisionScanLT\hppwrsav.exe
O4 - HKLM\..\Run: [aouei] C:\Documents and Settings\mexal2\Dati applicazioni\ratorefaci\sysrtmvs.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WXPH\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Avvia Pc.lnk = C:\Sysadm\Pc-Start.bat
O15 - Trusted Zone: http://www.adslconnection.name
O15 - Trusted Zone: http://www.softlab.name
O15 - Trusted Zone: http://www.xxx-content.name
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 8027531197
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B2F49FB} - http://www.softlab.name/closer/close.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = plasticacesena.lan
O17 - HKLM\Software\..\Telephony: DomainName = plasticacesena.lan
O17 - HKLM\System\CCS\Services\Tcpip\..\{38BAD992-0FEA-4017-B93B-713EE1AD01D7}: NameServer = 192.168.0.254
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = plasticacesena.lan
O17 - HKLM\System\CS1\Services\Tcpip\..\{38BAD992-0FEA-4017-B93B-713EE1AD01D7}: NameServer = 192.168.0.254
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = plasticacesena.lan
O17 - HKLM\System\CS2\Services\Tcpip\..\{38BAD992-0FEA-4017-B93B-713EE1AD01D7}: NameServer = 192.168.0.254
O23 - Service: Server RPC di eTrust Antivirus (InoRPC) - Computer Associates International, Inc. - C:\Programmi\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: Server Realtime di eTrust Antivirus (InoRT) - Computer Associates International, Inc. - C:\Programmi\CA\eTrust Antivirus\InoRT.exe
O23 - Service: Server Processi di eTrust Antivirus (InoTask) - Computer Associates International, Inc. - C:\Programmi\CA\eTrust Antivirus\InoTask.exe