| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| zanfe Mortale devoto
 
  
 
 Registrato: 15/02/07 21:07
 Messaggi: 13
 
 
 | 
			
				|  Inviato: 15 Feb 2007 21:12    Oggetto: Aiuto: hijackthis.log |   |  
				| 
 |  
				| Potete aiutarmi a capire cosa succede. In pratica mi si crea spesso un file .$$$ sul desktop o sul disco C: e IEXPLORER.EXE continua a fare richieste verso la rete (che io puntalmente blocco con un firewall).
 Vi posto il log:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 19.42.40, on 15/02/2007
 Platform: Windows 2000 SP4 (WinNT 5.00.2195)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 
 Running processes:
 C:\WINNT\System32\smss.exe
 C:\WINNT\system32\winlogon.exe
 C:\WINNT\system32\services.exe
 C:\WINNT\system32\lsass.exe
 C:\Programmi\Sygate\SPF\smc.exe
 C:\WINNT\system32\svchost.exe
 C:\WINNT\System32\svchost.exe
 C:\WINNT\system32\spoolsv.exe
 C:\Programmi\Apache Group\Apache2\bin\Apache.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Programmi\AMD\PowerNow!\GemServ.exe
 C:\Programmi\AMD\PowerNow!\gemback.exe
 C:\PROGRA~1\Alice\ALICEE~1\app\pppoeservice.exe
 C:\WINNT\system32\MSTask.exe
 C:\WINNT\system32\stisvc.exe
 C:\Programmi\Apache Group\Apache2\bin\Apache.exe
 C:\WINNT\System32\WBEM\WinMgmt.exe
 C:\WINNT\system32\svchost.exe
 C:\WINNT\Explorer.EXE
 C:\WINNT\Hcontrol.exe
 C:\WINNT\system32\pctspk.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\WINNT\system32\LVCOMSX.EXE
 C:\Programmi\Logitech\Video\LogiTray.exe
 C:\WINNT\StartupMonitor.exe
 C:\WINNT\ATKOSD.exe
 C:\WINNT\system32\khooker.exe
 C:\Programmi\Trust\Ami Mouse Single Scroll\Amoumain.exe
 D:\_Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
 C:\Programmi\Clipomatic\Clipomatic.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\Programmi\Apache Group\Apache2\bin\ApacheMonitor.exe
 C:\Programmi\Symmetricom\SymmTime\SymmTime.exe
 C:\Programmi\FreePOPs\freepopsd.exe
 C:\Programmi\Logitech\Video\FxSvr2.exe
 C:\Programmi\HijackThis\HijackThis.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\_Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar4.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar4.dll
 O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
 O4 - HKLM\..\Run: [Hcontrol] C:\WINNT\Hcontrol.exe
 O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
 O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmi\Logitech\Video\ISStart.exe
 O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmi\Logitech\Video\LogiTray.exe
 O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
 O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [SiS KHooker] C:\WINNT\system32\khooker.exe
 O4 - HKLM\..\Run: [WheelMouse] Amoumain.exe
 O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\_Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
 O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programmi\Logitech\Video\ManifestEngine.exe boot
 O4 - HKCU\..\Run: [Clipomatic] C:\Programmi\Clipomatic\Clipomatic.exe
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - Startup: FreePOPs.lnk = C:\Programmi\FreePOPs\freepopsd.exe
 O4 - Global Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Monitor Apache Servers.lnk = C:\Programmi\Apache Group\Apache2\bin\ApacheMonitor.exe
 O4 - Global Startup: SymmTime.lnk = C:\Programmi\Symmetricom\SymmTime\SymmTime.exe
 O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert link target to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
 O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
 O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert selection to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Convert to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.coolstreaming.us/webtv/tvkoo/KooPlayer.ocx
 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/028184244faf30caf422/netzip/RdxIE601_it.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1140127584018
 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
 O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Apache2 - Unknown owner - C:\Programmi\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
 O23 - Service: AMD PowerNow! (tm) Technology Service (GemServ) - Advanced Micro Devices - C:\Programmi\AMD\PowerNow!\GemServ.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
 O23 - Service: MySQL - Unknown owner - C:\Programmi\MySQL\MySQL.exe (file missing)
 O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\Alice\ALICEE~1\app\pppoeservice.exe
 O23 - Service: Service Hosts (ServiceHost) - Unknown owner - C:\WINNT\shost.exe (file missing)
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 15 Feb 2007 21:22    Oggetto: |   |  
				| 
 |  
				| Avvia HijackThis, premi Do a system scan only, spunta queste voci e poi premi FixChecked: 
 
  	  | Citazione: |  	  | O23 - Service: MySQL - Unknown owner - C:\Programmi\MySQL\MySQL.exe (file missing) O23 - Service: Service Hosts (ServiceHost) - Unknown owner - C:\WINNT\shost.exe (file missing)
 | 
 
 Scarica questo tool camuffato sul desktop
 
 Symantec (archivio)
 http://www.mytempdir.com/1213520
 
 Riavvia il pc in Modalità Provvisoria (quando ti fa il calcolo della memoria, ti segna gli hd collegati ecc premi continuamente F8 finchè non appare un menu, da lì scegli con le freccie la modalità).
 
 Da lì scompatta l'archivio e fai partire il tool Symantec facendogli fare una scansione.
 
 Quando ha finito:
 
  	  | Citazione: |  	  | Apri una cartella qualunque, vai su Strumenti->Opzioni Cartella->scheda Visualizzazione,
 spunta la voce "Visualizza cartelle e file nascosti", togli la spunta a
 "Nascondi file protetti di sistema" (digli di sì).
 
 | 
 
 Cancella questo file C:\WINNT\shost.exe
 
 Posta un nuovo log di HijackThis e il log del tool Symantec (FixLinkOpt.log).
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| zanfe Mortale devoto
 
  
 
 Registrato: 15/02/07 21:07
 Messaggi: 13
 
 
 | 
			
				|  Inviato: 15 Feb 2007 22:40    Oggetto: |   |  
				| 
 |  
				| Non c'era il file C:\WINNT\shost.exe 
 Ecco il log di Symantec:
 Symantec Trojan.Linkoptimizer Removal Tool 1.0.8
 
 Trojan.Linkoptimizer has not been found on your computer.
 
 Ecco il log HijackThis:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 21.37.53, on 15/02/2007
 Platform: Windows 2000 SP4 (WinNT 5.00.2195)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 
 Running processes:
 C:\WINNT\System32\smss.exe
 C:\WINNT\system32\winlogon.exe
 C:\WINNT\system32\services.exe
 C:\WINNT\system32\lsass.exe
 C:\Programmi\Sygate\SPF\smc.exe
 C:\WINNT\system32\svchost.exe
 C:\WINNT\System32\svchost.exe
 C:\WINNT\system32\spoolsv.exe
 C:\Programmi\Apache Group\Apache2\bin\Apache.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Programmi\AMD\PowerNow!\GemServ.exe
 C:\Programmi\AMD\PowerNow!\gemback.exe
 C:\PROGRA~1\Alice\ALICEE~1\app\pppoeservice.exe
 C:\Programmi\Apache Group\Apache2\bin\Apache.exe
 C:\WINNT\system32\MSTask.exe
 C:\WINNT\system32\stisvc.exe
 C:\WINNT\System32\WBEM\WinMgmt.exe
 C:\WINNT\system32\svchost.exe
 C:\WINNT\Explorer.EXE
 C:\WINNT\Hcontrol.exe
 C:\WINNT\system32\pctspk.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\WINNT\system32\LVCOMSX.EXE
 C:\Programmi\Logitech\Video\LogiTray.exe
 C:\WINNT\StartupMonitor.exe
 C:\WINNT\system32\khooker.exe
 C:\WINNT\ATKOSD.exe
 C:\Programmi\Trust\Ami Mouse Single Scroll\Amoumain.exe
 D:\_Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
 C:\Programmi\Clipomatic\Clipomatic.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\Programmi\Apache Group\Apache2\bin\ApacheMonitor.exe
 C:\Programmi\Symmetricom\SymmTime\SymmTime.exe
 C:\Programmi\FreePOPs\freepopsd.exe
 C:\Programmi\Logitech\Video\FxSvr2.exe
 C:\PROGRA~1\Alice\ALICEE~1\app\EnterNet.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\Programmi\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\_Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar4.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar4.dll
 O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
 O4 - HKLM\..\Run: [Hcontrol] C:\WINNT\Hcontrol.exe
 O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
 O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmi\Logitech\Video\ISStart.exe
 O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmi\Logitech\Video\LogiTray.exe
 O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
 O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [SiS KHooker] C:\WINNT\system32\khooker.exe
 O4 - HKLM\..\Run: [WheelMouse] Amoumain.exe
 O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\_Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
 O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programmi\Logitech\Video\ManifestEngine.exe boot
 O4 - HKCU\..\Run: [Clipomatic] C:\Programmi\Clipomatic\Clipomatic.exe
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - Startup: FreePOPs.lnk = C:\Programmi\FreePOPs\freepopsd.exe
 O4 - Global Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Monitor Apache Servers.lnk = C:\Programmi\Apache Group\Apache2\bin\ApacheMonitor.exe
 O4 - Global Startup: SymmTime.lnk = C:\Programmi\Symmetricom\SymmTime\SymmTime.exe
 O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert link target to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
 O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
 O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert selection to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Convert to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.coolstreaming.us/webtv/tvkoo/KooPlayer.ocx
 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/028184244faf30caf422/netzip/RdxIE601_it.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1140127584018
 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
 O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Apache2 - Unknown owner - C:\Programmi\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
 O23 - Service: AMD PowerNow! (tm) Technology Service (GemServ) - Advanced Micro Devices - C:\Programmi\AMD\PowerNow!\GemServ.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
 O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\Alice\ALICEE~1\app\pppoeservice.exe
 O23 - Service: Service Hosts (ServiceHost) - Unknown owner - C:\WINNT\shost.exe (file missing)
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 15 Feb 2007 23:04    Oggetto: |   |  
				| 
 |  
				| Sembra che tu non abbia fixato questa voce: 
 
  	  | Citazione: |  	  | O23 - Service: Service Hosts (ServiceHost) - Unknown owner - C:\WINNT\shost.exe (file missing) | 
 
 Rifixala!
 
 Se ritorna o hai altri problemi fatti una scansione online con Panda, posta poi il risultato.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| zanfe Mortale devoto
 
  
 
 Registrato: 15/02/07 21:07
 Messaggi: 13
 
 
 | 
			
				|  Inviato: 17 Feb 2007 00:46    Oggetto: |   |  
				| 
 |  
				| Sto cavolo di shost.exe continuo a fixarlo ma non se ne va via! 
 Ho fatto lo scan con Panda, ha trovato dei virus che ha curato; poi ho rifatto lo scan con Panda e non ha più trovato nulla.
 
 Vi rimando il log:
 Logfile of HijackThis v1.99.1
 Scan saved at 23.43.45, on 16/02/2007
 Platform: Windows 2000 SP4 (WinNT 5.00.2195)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 
 Running processes:
 C:\WINNT\System32\smss.exe
 C:\WINNT\system32\winlogon.exe
 C:\WINNT\system32\services.exe
 C:\WINNT\system32\lsass.exe
 C:\Programmi\Sygate\SPF\smc.exe
 C:\WINNT\system32\svchost.exe
 C:\WINNT\System32\svchost.exe
 C:\WINNT\system32\spoolsv.exe
 C:\Programmi\Apache Group\Apache2\bin\Apache.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Programmi\AMD\PowerNow!\GemServ.exe
 C:\Programmi\AMD\PowerNow!\gemback.exe
 C:\PROGRA~1\Alice\ALICEE~1\app\pppoeservice.exe
 C:\WINNT\system32\MSTask.exe
 C:\WINNT\system32\stisvc.exe
 C:\WINNT\System32\WBEM\WinMgmt.exe
 C:\WINNT\system32\svchost.exe
 C:\Programmi\Apache Group\Apache2\bin\Apache.exe
 C:\WINNT\Explorer.EXE
 C:\WINNT\Hcontrol.exe
 C:\WINNT\system32\pctspk.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\WINNT\system32\LVCOMSX.EXE
 C:\Programmi\Logitech\Video\LogiTray.exe
 C:\WINNT\StartupMonitor.exe
 C:\WINNT\ATKOSD.exe
 C:\WINNT\system32\khooker.exe
 C:\Programmi\Trust\Ami Mouse Single Scroll\Amoumain.exe
 D:\_Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
 C:\Programmi\Clipomatic\Clipomatic.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\Programmi\Apache Group\Apache2\bin\ApacheMonitor.exe
 C:\Programmi\Symmetricom\SymmTime\SymmTime.exe
 C:\Programmi\FreePOPs\freepopsd.exe
 C:\Programmi\Logitech\Video\FxSvr2.exe
 C:\PROGRA~1\Alice\ALICEE~1\app\EnterNet.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\Programmi\totalcmd\TOTALCMD.EXE
 C:\Programmi\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\_Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar4.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar4.dll
 O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
 O4 - HKLM\..\Run: [Hcontrol] C:\WINNT\Hcontrol.exe
 O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
 O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmi\Logitech\Video\ISStart.exe
 O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmi\Logitech\Video\LogiTray.exe
 O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
 O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [SiS KHooker] C:\WINNT\system32\khooker.exe
 O4 - HKLM\..\Run: [WheelMouse] Amoumain.exe
 O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\_Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
 O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programmi\Logitech\Video\ManifestEngine.exe boot
 O4 - HKCU\..\Run: [Clipomatic] C:\Programmi\Clipomatic\Clipomatic.exe
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - Startup: FreePOPs.lnk = C:\Programmi\FreePOPs\freepopsd.exe
 O4 - Global Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Monitor Apache Servers.lnk = C:\Programmi\Apache Group\Apache2\bin\ApacheMonitor.exe
 O4 - Global Startup: SymmTime.lnk = C:\Programmi\Symmetricom\SymmTime\SymmTime.exe
 O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert link target to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
 O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
 O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert selection to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Convert to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.coolstreaming.us/webtv/tvkoo/KooPlayer.ocx
 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/028184244faf30caf422/netzip/RdxIE601_it.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1140127584018
 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Apache2 - Unknown owner - C:\Programmi\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
 O23 - Service: AMD PowerNow! (tm) Technology Service (GemServ) - Advanced Micro Devices - C:\Programmi\AMD\PowerNow!\GemServ.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
 O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\Alice\ALICEE~1\app\pppoeservice.exe
 O23 - Service: Service Hosts (ServiceHost) - Unknown owner - C:\WINNT\shost.exe (file missing)
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| zanfe Mortale devoto
 
  
 
 Registrato: 15/02/07 21:07
 Messaggi: 13
 
 
 | 
			
				|  Inviato: 17 Feb 2007 16:00    Oggetto: |   |  
				| 
 |  
				| Sapete dirmi qualcosa? Non capisco se sono a posto.
 
 Ciao
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 17 Feb 2007 16:23    Oggetto: |   |  
				| 
 |  
				| Prova a scaricare stinger 2.6.0 e Spybot Search and Destroy. Installa Spybot, aggiornalo e poi riavvia il pc in Modalità Provvisoria.
 Da lì fai partire prima Stinger (doppioclick sull'exe e poi ScanNow) e poi fai una scansione con Spybot.
 Rifixa la voce, controlla nella cartella C:\Winnt\ che non ci sia il file (se c'è cancellalo).
 Dimmi poi com'è andata..
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| zanfe Mortale devoto
 
  
 
 Registrato: 15/02/07 21:07
 Messaggi: 13
 
 
 | 
			
				|  Inviato: 17 Feb 2007 18:23    Oggetto: |   |  
				| 
 |  
				| Ho disabilitato il servizio "Service Hosts" e ora non compare più shosts.exe. Il file non c'è mai stato in C:\Winnt\. 
 Faccio comunque la procedura che mi ha suggerito e poi ti dico.
 
 Grazie
 
 Ciao
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 17 Feb 2007 18:42    Oggetto: |   |  
				| 
 |  
				| Disabilitato o cancellato? Prova ad andare su Start->Esegui->digita sc delete ServiceHost, dai invio.
 Così dovrebbe rimuovertelo.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| zanfe Mortale devoto
 
  
 
 Registrato: 15/02/07 21:07
 Messaggi: 13
 
 
 | 
			
				|  Inviato: 17 Feb 2007 18:53    Oggetto: |   |  
				| 
 |  
				| L'ho disabilitato andando su Pannello di controllo->Strumenti di amministrazione->Servizi. Se faccio  Start->Esegui->digita sc delete ServiceHost mi dice: Impossibile trovare il file sc ...
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 17 Feb 2007 19:31    Oggetto: |   |  
				| 
 |  
				| Ah giusto! hai Windows 2000. Prova allora a dare msconfig, ti si aprirà una finestra, vai nel tab Servizi, lì (credo, non ricordo) c'è la lista di tutti i servizi e ci dovrebbe anche essere il pulsante Elimina.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| zanfe Mortale devoto
 
  
 
 Registrato: 15/02/07 21:07
 Messaggi: 13
 
 
 | 
			
				|  Inviato: 17 Feb 2007 19:43    Oggetto: |   |  
				| 
 |  
				| Fatto tutto. Ti ricordo che shost.exe l'ho disbilitato come da post precedente
 
 Ecco il log:
 Logfile of HijackThis v1.99.1
 Scan saved at 18.42.13, on 17/02/2007
 Platform: Windows 2000 SP4 (WinNT 5.00.2195)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 
 Running processes:
 C:\WINNT\System32\smss.exe
 C:\WINNT\system32\winlogon.exe
 C:\WINNT\system32\services.exe
 C:\WINNT\system32\lsass.exe
 C:\Programmi\Sygate\SPF\smc.exe
 C:\WINNT\system32\svchost.exe
 C:\WINNT\System32\svchost.exe
 C:\WINNT\system32\spoolsv.exe
 C:\Programmi\Apache Group\Apache2\bin\Apache.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Programmi\AMD\PowerNow!\GemServ.exe
 C:\Programmi\AMD\PowerNow!\gemback.exe
 C:\PROGRA~1\Alice\ALICEE~1\app\pppoeservice.exe
 C:\Programmi\Apache Group\Apache2\bin\Apache.exe
 C:\WINNT\system32\MSTask.exe
 C:\WINNT\system32\stisvc.exe
 C:\WINNT\System32\WBEM\WinMgmt.exe
 C:\WINNT\system32\svchost.exe
 C:\WINNT\Explorer.EXE
 C:\WINNT\Hcontrol.exe
 C:\WINNT\system32\pctspk.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\WINNT\system32\LVCOMSX.EXE
 C:\Programmi\Logitech\Video\LogiTray.exe
 C:\WINNT\ATKOSD.exe
 C:\WINNT\StartupMonitor.exe
 C:\WINNT\system32\khooker.exe
 C:\Programmi\Trust\Ami Mouse Single Scroll\Amoumain.exe
 D:\_Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
 C:\Programmi\Clipomatic\Clipomatic.exe
 C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 C:\Programmi\Apache Group\Apache2\bin\ApacheMonitor.exe
 C:\Programmi\Symmetricom\SymmTime\SymmTime.exe
 C:\Programmi\FreePOPs\freepopsd.exe
 C:\Programmi\Logitech\Video\FxSvr2.exe
 C:\PROGRA~1\Alice\ALICEE~1\app\EnterNet.exe
 C:\Programmi\iTunes\iTunes.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\iPod\bin\iPodService.exe
 C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 C:\Programmi\totalcmd\TOTALCMD.EXE
 C:\Programmi\MySQL\MySQL Administrator 1.1\MySQLSystemTrayMonitor.exe
 C:\Programmi\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
 C:\Programmi\Chami\HTML-Kit\Bin\HTMLKit.exe
 C:\Programmi\MySQL\MySQL Administrator 1.1\MySQLAdministrator.exe
 C:\Programmi\Internet Explorer\IEXPLORE.EXE
 C:\Programmi\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\_Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar4.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar4.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
 O4 - HKLM\..\Run: [Hcontrol] C:\WINNT\Hcontrol.exe
 O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
 O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmi\Logitech\Video\ISStart.exe
 O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmi\Logitech\Video\LogiTray.exe
 O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
 O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [SiS KHooker] C:\WINNT\system32\khooker.exe
 O4 - HKLM\..\Run: [WheelMouse] Amoumain.exe
 O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\_Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
 O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programmi\Logitech\Video\ManifestEngine.exe boot
 O4 - HKCU\..\Run: [Clipomatic] C:\Programmi\Clipomatic\Clipomatic.exe
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
 O4 - Startup: FreePOPs.lnk = C:\Programmi\FreePOPs\freepopsd.exe
 O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = D:\_Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe
 O4 - Global Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Monitor Apache Servers.lnk = C:\Programmi\Apache Group\Apache2\bin\ApacheMonitor.exe
 O4 - Global Startup: SymmTime.lnk = C:\Programmi\Symmetricom\SymmTime\SymmTime.exe
 O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert link target to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
 O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
 O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert selection to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: Convert to Adobe PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
 O8 - Extra context menu item: Convert to existing PDF - res://D:\_Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.coolstreaming.us/webtv/tvkoo/KooPlayer.ocx
 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/028184244faf30caf422/netzip/RdxIE601_it.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1140127584018
 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Apache2 - Unknown owner - C:\Programmi\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
 O23 - Service: AMD PowerNow! (tm) Technology Service (GemServ) - Advanced Micro Devices - C:\Programmi\AMD\PowerNow!\GemServ.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
 O23 - Service: MySQL - Unknown owner - C:\Programmi\MySQL\MySQL.exe (file missing)
 O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\Alice\ALICEE~1\app\pppoeservice.exe
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 17 Feb 2007 21:16    Oggetto: |   |  
				| 
 |  
				| Sì lo so che l'hai disabilitato ma qualcosa può sempre riabilitarlo.. mentre se lo cancelli è meglio. Il log mi sembra pulito
  |  | 
	
		| Top |  | 
	
		|  | 
	
		| zanfe Mortale devoto
 
  
 
 Registrato: 15/02/07 21:07
 Messaggi: 13
 
 
 | 
			
				|  Inviato: 19 Feb 2007 11:02    Oggetto: |   |  
				| 
 |  
				| Grazie mille. Usando msconfig.exe in effetti non riesco a eliminarlo del tutto.
 Se hai qualche altro suggerimento altrimenti lo terrò controllato ogni tanto.
 
 Ma scusa un attimo, ma cosa è questo shost.exe che devo eliminare? È pericoloso?
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |