PS. ho cercato altri casi a cui avete dato una risposta ed ho cercato di farmi una cultura.Ho pure scaricato dei programmi che voi consigliate tipo antivurus da cd e lo installerò al più presto.
Logfile of HijackThis v1.99.1
Scan saved at 10:37:26, on 24.08.2005
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\PROGRAMMI\PERSONAL COMMUNICATIONS\PCS_AGNT.EXE
C:\WINNT40\system32\pcssfrrx.exe
C:\WINNT40\Explorer.EXE
C:\WINNT40\system32\syshelp.exe
D:\Programmi\WinZip\WZQKPICK.EXE
C:\Programmi\Personal Communications\pcsws.exe
C:\Programmi\Personal Communications\PCSCM.EXE
C:\Programmi\ElsaWin\bin\ElsaWin.exe
C:\Programmi\Personal Communications\pcsws.exe
C:\Programmi\Personal Communications\pcsws.exe
C:\PROGRA~1\MICROS~1\Office\OUTLOOK.EXE
C:\WINNT40\msagent\AgentSvr.exe
D:\Programmi\HijackThis v.1.99.1\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.tiscali.it/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.tiscali.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.skymasters.biz?2015
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F2 - REG:system.ini: UserInit=C:\WINNT40\system32\userinit.exe,pcssfrrx.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0A16FBAB-C36B-11D8-BA34-0002E8DC2E66} - C:\WINNT40\madopew.dll (file missing)
O2 - BHO: CPubSR Object - {FC2593E3-3E5A-410F-AF3D-82613CCE58E5} - c:\winnt40\sr.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT40\System32\msdxm.ocx
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINNT40\System32\runonce.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Service Host] C:\WINNT40\system32\Services\{F080A6B6-14DE-4159-AF66-7871DC109F87}\SVCHOST.EXE
O4 - HKLM\..\Run: [atipatxx] C:\WINNT40\system32\atipatxx.exe
O4 - HKLM\..\Run: [vmtuner] gclib.exe
O4 - HKLM\..\Run: [Systems] C:\WINNT40\system32\syshelp.exe
O4 - HKLM\..\RunServices: [atipatxx] C:\WINNT40\system32\atipatxx.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: ET_Start.lnk = D:\ET_PROG\etka.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = w32x86\2\E_SRCV03.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Programmi\WinZip\WZQKPICK.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT40\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT40\web\related.htm
O13 - WWW. Prefix: http://
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: http://petra.agi.cpn.vwg
O15 - Trusted Zone: http://portal.agi.cpn.vwg
O15 - Trusted Zone: *.cpn.vwg
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.skymasters.biz
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid= ... lcid=0x409
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003 ... scan53.cab
O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) - http://ww3.atlanteitaliano.it/ecwplugins/ncs.cab
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} - http://www.180searchassistant.com/180saax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as/asinst.cab
O16 - DPF: {F5BC716E-2650-4B08-9235-C110CF95017F} (Connessione Tiscali) - http://selfcare.tiscali.it/scripts/onec ... iscali.cab
O18 - Protocol: vw-wi - {0F3C833F-FB28-40EA-8CB9-6A55B996C3F6} - C:\Programmi\ElsaWin\bin\wiprot.dll
O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINNT40\httpfilter.dll
O18 - Filter: text/plain - {70E801A6-C39A-11D8-BA38-00023FFA3EC2} - C:\WINNT40\madopew.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - D:\Programmi\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - D:\Programmi\AVPersonal\AVWUPSRV.EXE
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT40\System32\dmadmin.exe
O23 - Service: EAufServ - Unknown owner - \\ITA000071A\et_prog\EAufServ.exe (file missing)
O23 - Service: LocalSystem (ldlcserv) - Unknown owner - C:\WINNT40\System32\drivers\ldlcserv.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT40\system32\LEXBCES.EXE
O23 - Service: PipeCmd Service (PipeCmdSrv) - Unknown owner - C:\WINNT40\system32\PipeCmdSrv.exe (file missing)
O23 - Service: Security Agent (scagent) - Unknown owner - C:\WINNT40\system32\scagent.exe" start (file missing)
O23 - Service: TrcBoot - Unknown owner - C:\WINNT40\System32\drivers\trcboot.exe
NB questi programmi li uso per il lavoro:
ElsaWin.exe
petra.agi.cpn.vwg
portal.agi.cpn.vwg