• User

    mi controllate l'hijackthis per whatsnew.name?

    ciao a tutti ultimamente mi appare un popup di whatsnew.name, mi date una mano a rimuovere questo problema? vi posto la scansione di hijack

    Logfile of HijackThis v1.99.1
    Scan saved at 20.17.16, on 08/07/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\xampp\apache\bin\apache.exe
    C:\xampp\filezillaftp\filezillaserver.exe
    C:\Programmi\CA\eTrust Antivirus\InoRpc.exe
    C:\Programmi\CA\eTrust Antivirus\InoRT.exe
    C:\Programmi\CA\eTrust Antivirus\InoTask.exe
    C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
    C:\xampp\mysql\bin\mysqld-nt.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Programmi\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.00\SiSWLSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\CA\ETRUST~1\realmon.exe
    C:\Programmi\CA\eTrust Antivirus\eAVTrial.exe
    C:\Programmi\File comuni\Real\Update_OB\realsched.exe
    C:\PROGRA~1\TIMTUR~1.33I\N100EM~1.EXE
    C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe
    C:\Documents and Settings\PIERANGELO\Dati applicazioni\semanatiba\syslcznp.exe
    C:\Documents and Settings\PIERANGELO\Dati applicazioni\semanatiba\syslcznp.exe
    C:\Programmi\QuickTime\qttask.exe
    C:\Programmi\iTunes\iTunesHelper.exe
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\xampp\apache\bin\apache.exe
    C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Programmi\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.00\WlanCU.exe
    C:\PROGRA~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Programmi\iPod\bin\iPodService.exe
    C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
    C:\Programmi\MSN Messenger\usnsvc.exe
    C:\Documents and Settings\FRANCESCO\Dati applicazioni\Tack.exe
    C:\Documents and Settings\FRANCESCO\Dati applicazioni\Tack.exe
    C:\Documents and Settings\FRANCESCO\Dati applicazioni\Tack.exe
    C:\Documents and Settings\FRANCESCO\Dati applicazioni\Tack.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Documents and Settings\FRANCESCO\Dati applicazioni\Tack.exe
    C:\Programmi\Nokia\Nokia PC Suite 6\OneTouchAccess.exe
    C:\Documents and Settings\FRANCESCO\Dati applicazioni\Tack.exe
    C:\Programmi\MSN Messenger\msnmsgr.exe
    C:\Documents and Settings\FRANCESCO\Dati applicazioni\Tack.exe
    C:\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
    O4 - HKLM..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
    O4 - HKLM..\Run: [eAVTrial] C:\Programmi\CA\eTrust Antivirus\eAVTrial.exe
    O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM..\Run: [HomeKeyLogger] C:\Programmi\HomeKeyLogger\KeyLogger.exe
    O4 - HKLM..\Run: [PC98Monitor] "C:\PROGRA~1\TIMTUR~1.33I\N100EM~1.EXE"
    O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM..\Run: [auoie] C:\Documents and Settings\PIERANGELO\Dati applicazioni\semanatiba\syslcznp.exe
    O4 - HKLM..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
    O4 - HKLM..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
    O4 - HKLM..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
    O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmi\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Wireless Configuration Utility HW.32.lnk = ?
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Crea preferiti portatile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Crea preferiti portatile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmi\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O15 - Trusted Zone: www..nodialup.name
    O15 - Trusted Zone: www.
    .whatsnew.name
    O15 - Trusted Zone: www.nodialup.name
    O15 - Trusted Zone: *.nodialup.name
    O15 - Trusted Zone: www.sgnappo.com
    O15 - Trusted Zone: www.whatsnew.name
    O15 - Trusted Zone: *.whatsnew.name
    O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B2F49FB} - http://www.nodialup.name/ciuccia.exe
    O17 - HKLM\System\CCS\Services\Tcpip..{D3899F05-F5B2-4D5C-BCC8-F77120DD25DA}: NameServer = 213.230.130.222 213.230.155.94
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Apache2.2 - Unknown owner - C:\xampp\apache\bin\apache.exe" -k runservice (file missing)
    O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\xampp\filezillaftp\filezillaserver.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Server RPC di eTrust Antivirus (InoRPC) - Computer Associates International, Inc. - C:\Programmi\CA\eTrust Antivirus\InoRpc.exe
    O23 - Service: Server Realtime di eTrust Antivirus (InoRT) - Computer Associates International, Inc. - C:\Programmi\CA\eTrust Antivirus\InoRT.exe
    O23 - Service: Server Processi di eTrust Antivirus (InoTask) - Computer Associates International, Inc. - C:\Programmi\CA\eTrust Antivirus\InoTask.exe
    O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
    O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld-nt.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
    O23 - Service: SiS WirelessLan Service (SiSWLSvc) - Unknown owner - C:\Programmi\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.00\SiSWLSvc.exe

    GRAZIE


  • Consiglio Direttivo

    Ciao licciar,

    fixa queste voci:

           O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    

    O4 - HKLM..\Run: [HomeKeyLogger] C:\Programmi\HomeKeyLogger\KeyLogger.exe

    O4 - HKLM..\Run: [auoie] C:\Documents and Settings\PIERANGELO\Dati applicazioni\semanatiba\syslcznp.exe

    O15 - Trusted Zone: *.nodialup.name

    O15 - Trusted Zone: *.whatsnew.name

          O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B2F49FB} - http://www.nodialup.name/ciuccia.exe
    

    Fixate tutte le voci, scarica the avenger!
    Estrai Avenger.exe e spunta l'opzione Input Script Manually. Clicca sulla lente di ingrandimento e riporta all'interno della finestra queste righe:

    Files to delete: 
    C:\Documents and Settings\FRANCESCO\Dati applicazioni\Tack.exe
    ```Fatto questo, clicca su Done, 2 volte sul semaforo verde e due volte su yes! 
    Il pc dovrebbe riavviarsi da solo...  Posta poi il risultato di avenger che trovi qui C:/avenger.txt nel forum! :)

  • User

    ho eseguito avenger direttamente dalla cartella zip e da quanto ho capito ha funzionato, solo che forse non mi avrebbe salvato il log perciò l'ho estratto e ha rifatto l'operazione, comunque per adesso tutto ok.
    MA a cosa serve questo file?
    grazie ancora


  • Consiglio Direttivo

    Ciao licciar,
    @licciar said:

    MA a cosa serve questo file?

    ti riferisci al log di the avenger??? :mmm: Cmq, il log contiene i risultati di scansione di un software!!! 🙂


  • User Newbie

    scusami wolf saresti cosi gentile da controllare anche il mio. ho lo stesso problema con il file whatnew.name.....io uso firefox.grazie in anticipo.Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17.55.56, on 08/12/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Programmi\Eset\nod32krn.exe
    C:\Programmi\Olivetti\ANY_WAY\olMntrService.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
    C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
    C:\Programmi\D-Link\AirPlus G\AirGCFG.exe
    C:\Programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
    C:\Programmi\Real\RealPlayer\RealPlay.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Programmi\File comuni\Logitech\QCDriver2\LVCOMS.EXE
    C:\Programmi\Logitech\ImageStudio\LogiTray.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Programmi\Olivetti\ANY_WAY\olDvcStatus.exe
    C:\Programmi\Eset\nod32kui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Programmi\MSN Messenger\MsnMsgr.Exe
    C:\Programmi\Pando Networks\Pando\Pando.exe
    C:\Programmi\DAEMON Tools\daemon.exe
    C:\WINDOWS\slrundll.exe
    C:\Programmi\MSN Messenger\usnsvc.exe
    C:\Programmi\eMule\emule.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Programmi\MSN Messenger\livecall.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Programmi\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Documents and Settings\Davide R\Dati applicazioni\Tack.exe
    C:\Programmi\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://it.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://it.search.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
    O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM..\Run: [ATIPTA] "C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM..\Run: [D-Link AirPlus G] C:\Programmi\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM..\Run: [ANIWZCS2Service] C:\Programmi\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM..\Run: [RealTray] C:\Programmi\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM..\Run: [LVCOMS] C:\Programmi\File comuni\Logitech\QCDriver2\LVCOMS.EXE
    O4 - HKLM..\Run: [LogitechGalleryRepair] C:\Programmi\Logitech\ImageStudio\ISStart.exe
    O4 - HKLM..\Run: [LogitechImageStudioTray] C:\Programmi\Logitech\ImageStudio\LogiTray.exe
    O4 - HKLM..\Run: [OlStatusMon] "C:\Programmi\Olivetti\ANY_WAY\olDvcStatus.exe" dvcStatusMinimize
    O4 - HKLM..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU..\Run: [Pando] "C:\Programmi\Pando Networks\Pando\Pando.exe" /Minimized
    O4 - HKCU..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
    O4 - HKUS\S-1-5-19..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
    O4 - HKUS\S-1-5-18..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS.DEFAULT..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = D:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe
    O23 - Service: olMntrService - Olivetti - C:\Programmi\Olivetti\ANY_WAY\olMntrService.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O24 - Desktop Component 0: (no name) - http://thumbp1.mail.ukl.yahoo.com/tn?sid=2316905382&mid=ADgKDNkAAEUERuEZvAwldBA5BLU&partid=2&f=257&fid=Sent

    --
    End of file - 9156 bytes