Hi,
From a friend's pc,
which one can be safely deleted?
Thanks.
**************************
*****
Logfile of HijackThis v1.95.0
Scan saved at 23.04.56, on 27/06/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\System32\cisvc.
exe
C:\Programmi\File comuni\EPSON\EBAPI\SAgent2
.exe
C:\Programmi\Acceleration Software\StopSignProducts\
Firewall\f
wservice.e
xe
C:\Programmi\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Programmi\Microsoft Works\WksSb.exe
C:\PROGRA~1\NORTON~1\navap
w32.exe
C:\windows\mp3now[1].exe
C:\Programmi\File comuni\Real\Update_OB\real
sched.exe
C:\Programmi\QuickTime\qtt
ask.exe
C:\Programmi\Analog Devices\SoundMAX\Smtray.ex
e
C:\WINDOWS\Dit.exe
C:\Programmi\digicom\Miche
langelo USB ADSL\CnxDslTb.exe
C:\Programmi\Acceleration Software\Anti-Virus\defsca
ngui.exe
C:\Programmi\File comuni\eAcceleration\eanth
ology.exe
C:\Programmi\Messenger\msm
sgs.exe
C:\Programmi\EPSON\EPSON CardMonitor\EPSON CardMonitor1.0.exe
C:\Programmi\File comuni\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\DitExp.exe
C:\Programmi\File comuni\Real\Update_OB\rnat
hchk.exe
C:\Programmi\HELPExpress\b
in\mpbtn.e
xe
C:\Compaq\EAKDRV\EAUSBKBD.
EXE
C:\WINDOWS\System32\cidaem
on.exe
C:\Programmi\Acceleration Software\Anti-Virus\defsca
ngui.exe
C:\Programmi\Real\RealOne Player\realplay.exe
C:\Programmi\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.E
XE
C:\Programmi\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\PROGRA~1\Compaq\EASYAC~
1\BttnServ
.exe
C:\Documents and Settings\Maria\Documenti\H
ijackThis.
exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,SearchURL=
http://ie.marketdart.com R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar=file://C:\DOCUME~1\Mar
ia\IMPOST~
1\Temp\sp.
html
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page=file://C:\DOCUME~1\Ma
ria\IMPOST
~1\Temp\sp
.html
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant=file
://C:\DOCU
ME~1\Maria
\IMPOST~1\
Temp\sp.ht
ml
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar=file://C:\DOCUME~1\Mar
ia\IMPOST~
1\Temp\sp.
html
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page=file://C:\DOCUME~1\Ma
ria\IMPOST
~1\Temp\sp
.html
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL=
http://www.virgilio.it/free R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant=file
://C:\DOCU
ME~1\Maria
\IMPOST~1\
Temp\sp.ht
ml
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title=Tiscali 10.0
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page=C:\WINDOWS\System32\b
lank.htm
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-
00C04FD644
97} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Programmi\Adobe\Acrobat
6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {BA7270AE-5636-4618-BAF3-F
86ADA39F03
6} - C:\Programmi\ICOO Loader\addons7\icoourl.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Programmi\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E8D0FAB8-B613-42AA-837A-C
6BA40DBC6E
A} - C:\WINDOWS\System32\cckg.d
ll
O2 - BHO: (no name) - {ED657BAF-1EE5-4A07-9D2E-6
D0525EFC69
B} - C:\Programmi\ICOO Loader\addons7\icoourlext.
dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CPQEASYACC] C:\Programmi\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmi\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmi\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navap
w32.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCh
eck.exe
O4 - HKLM\..\Run: [zzz026v] c:\windows\mp3now[1].exe r
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\real
sched.exe"
-osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qt
task.exe" -atboottime
O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\Smtray.ex
e
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Programmi\digicom\Miche
langelo USB ADSL\CnxDslTb.exe
O4 - HKLM\..\Run: [WebScan] C:\Programmi\Acceleration Software\Anti-Virus\defsca
ngui.exe -k
O4 - HKLM\..\Run: [EanthologyApp] "C:\Programmi\File comuni\eAcceleration\eanth
ology.exe"
/b Startup
O4 - HKLM\..\Run: [fwservice] C:\Programmi\Acceleration Software\StopSignProducts\
Firewall\f
wservice.e
xe -startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\ms
msgs.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEU
P~1\SNDMon
.EXE
O4 - Global Startup: EPSON CardMonitor.lnk = ?
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\
drivers\w3
2x86\3\E_S
RCV02.EXE
O4 - Global Startup: HELPExpress.lnk = C:\Programmi\HELPExpress\b
in\matcli.
exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Promemoria del Calendario di Microsoft Works.lnk = ?
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .pdf: C:\Programmi\Internet Explorer\PLUGINS\nppdf32.d
ll
O14 - IERESET.INF: START_PAGE_URL=
http://www.virgilio.it/free O16 - DPF: {02BF25D5-8C17-4B23-BC80-D
3488ABDDC6
B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2
407B42F57C
9} (MSSecurityAdvisor Class) -
http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1083700896875 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} (RdxIE Class) -
http://207.188.7.150/2569f32da76d57033722/netzip/RdxIE601_it.cab O16 - DPF: {597C45C2-2D39-11D5-8D53-0
050048383F
E} (OPUCatalog Class) -
http://office.microsoft.com/productupdates/content/opuc.cab O16 - DPF: {5B7CACB9-EA2A-42A2-8BAC-4
9073B4F6B9
8} (Web_Service2.WebService2)
-
http://www.privatissimo.com/hard/Web_Service2.CAB O16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37864.6296412037 O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
0105AA9B6A
E} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {C606BA60-AB76-48B6-96A7-2
C4D5C386F7
0} (PreQualifier Class) -
http://help.virgilio.it/helpexpress/files/MotivePreQual.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-5
87CAF3EE8C
6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cab