Precedente :: Successivo |
Autore |
Messaggio |
ippopippo71 Comune mortale

Registrato: 24/06/07 18:25 Messaggi: 4
|
Inviato: 24 Giu 2007 18:30 Oggetto: MI DATE UNA MANO CON Hijackthis!!!!! |
|
|
Ho un problema con il pc...
non mi parte + explorer.exe = desktop vuoto niente barra di win
il mio s.o. Windows 2000 pro service pack 4
e questo e cio' che mi da Hijackthis
cosa devo fixare?????
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 14.30.38, on 24/06/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\Programmi\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\PROGRA~1\FILECO~1\ILSOLE~1\lm\lm.exe
C:\WINNT\system32\taskmgr.exe
C:\Programmi\Microsoft SQL Server\MSSQL$VLSOLE24\Binn\sqlservr.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\System32\pctspk.exe
C:\Programmi\Raxco\PerfectDisk\PDAgent.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\SetScardSvrService.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\Documents and Settings\Administrator.SERVERDATI\Desktop\HiJackThis_v2.exe
C:\WINNT\system32\stisvc.exe
C:\VEXPLITE\viritsvc.exe
C:\Documents and Settings\Administrator.SERVERDATI\Desktop\HiJackThis_v2.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\system32\mqsvc.exe
C:\WINNT\system32\svchost.exe
C:\Programmi\Alwil Software\Avast4\setup\avast.setup
C:\WINNT\system32\mobsync.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=c:\winnt\system32\userinit.exe,"c:\winnt\system32\samsungcenter.exe","c:\winnt\system32\officefind.exe",userinit.exe
O1 - Hosts: 66.40.16.218 auto.search.msn.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\VEXPLITE\MONLITE.EXE
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Programmi\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-21-1993962763-920026266-1202660629-1005\..\Run: [internat.exe] internat.exe (User 'rWIPlMTOleqmjurG')
O4 - HKUS\S-1-5-21-1993962763-920026266-1202660629-1005\..\RunOnce: [^SetupICWDesktop] C:\Programmi\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'rWIPlMTOleqmjurG')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] _old C:\Programmi\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182506349832
O17 - HKLM\System\CCS\Services\Tcpip\..\{0974BC9F-3925-40D3-AB2B-870BAADC4999}: NameServer = 155.99.125.1,151.99.0.100
O17 - HKLM\System\CS1\Services\Tcpip\..\{0974BC9F-3925-40D3-AB2B-870BAADC4999}: NameServer = 151.99.125.2,194.243.154.62
O17 - HKLM\System\CS2\Services\Tcpip\..\{0974BC9F-3925-40D3-AB2B-870BAADC4999}: NameServer = 155.99.125.1,151.99.0.100
O17 - HKLM\System\CS3\Services\Tcpip\..\{0974BC9F-3925-40D3-AB2B-870BAADC4999}: NameServer = 155.99.125.1,151.99.0.100
O18 - Filter hijack: text/html - {D89DBE71-B349-4FD2-BA6D-ABC8D510F19F} - (no file)
O20 - AppInit_DLLs: \\?\C:\WINNT\prn.buj
O20 - Winlogon Notify: winjwu32 - winjwu32.dll (file missing)
O20 - Winlogon Notify: winpnp32 - winpnp32.dll (file missing)
O20 - Winlogon Notify: winzxr32 - winzxr32.dll (file missing)
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINNT\System32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINNT\System32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Programmi\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: LMService - Il Sole 24 Ore - C:\PROGRA~1\FILECO~1\ILSOLE~1\lm\lm.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: PC-cillin Personal Firewall (PccPfw) - Unknown owner - C:\Programmi\Trend Micro\PC-cillin 2003\PccPfw.exe (file missing)
O23 - Service: W2K PCtel speaker phone (Pctspk) - PCtel, Inc. - C:\WINNT\System32\pctspk.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Smart Card Base Component Helper (SetScardSvrService) - Unknown owner - C:\WINNT\system32\SetScardSvrService.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Unknown owner - C:\Programmi\Trend Micro\PC-cillin 2003\Tmntsrv.exe (file missing)
O23 - Service: Trend Micro Proxy Service (tmproxy) - Unknown owner - C:\Programmi\Trend Micro\PC-cillin 2003\tmproxy.exe (file missing)
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
--
End of file - 7004 bytes |
|
Top |
|
 |
ippopippo71 Comune mortale

Registrato: 24/06/07 18:25 Messaggi: 4
|
Inviato: 24 Giu 2007 19:10 Oggetto: Mancato avvio di EXPLORER.EXE: desktop vuoto |
|
|
Win 2000 pro SP4
dopo aver lanciato AVAST e riscontrato x mia colpa un bel pò di
files infettati stupidamente li ho cancellati tutti
ho lanciato AVG che ha riscontrato alcuni Malware che ho cancellato anche questi stupidamente senza metterli in quarantena....
insomma al riavvio è sparito il desktop e la barra di win
prova di qua prova di là ho capito che non carica explorer.exe!!!!
cosa devo fare?????
formatttoo???? |
|
Top |
|
 |
Benny Moderatore Hardware e Networking


Registrato: 28/01/06 15:35 Messaggi: 6382 Residenza: Non troppo vicino, mai troppo lontano
|
Inviato: 24 Giu 2007 19:28 Oggetto: |
|
|
Ciao!
Riesci a recuperare i logfile delle ultime scansioni di avast e avg?
Magari vediamo quali files hai cancellato e se c'è modo di ripristinarli (se sono importanti). |
|
Top |
|
 |
ippopippo71 Comune mortale

Registrato: 24/06/07 18:25 Messaggi: 4
|
Inviato: 24 Giu 2007 19:55 Oggetto: |
|
|
niente da fare
non li ho trovati!!! sighhh!!! |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 24 Giu 2007 23:32 Oggetto: |
|
|
Dal task manager, avvia regedit e cerca questa chiave:
Citazione: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
Riporta qui il valore che trovi.
PS: sembra un'infezione da gromozon o un suo derivato. |
|
Top |
|
 |
ippopippo71 Comune mortale

Registrato: 24/06/07 18:25 Messaggi: 4
|
Inviato: 25 Giu 2007 11:19 Oggetto: |
|
|
eccoti servito
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
AutoRestartShell=01, 00, 00, 00
DefaultDomainName=SERVERDATI
DefaultUserName=Rosati
LegalNoticeCaption=
LegalNoticeText=
PowerdownAfterShutdown=0
ReportBootOk=1
Shell=Explorer.exe
ShutdownWithoutLogon=1
System=
Userinit=C:\WINNT\SYSTEM32\Userinit.exe,
VmApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota=ff, ff, ff, ff
allocatecdroms=0
allocatedasd=0
allocatefloppies=0
cachedlogonscount=10
passwordexpirywarning=0e, 00, 00, 00
scremoveoption=0
DebugServerCommand=no
SFCDisable=00, 00, 00, 00
AutoAdminLogon=0
ShowLogonOptions=01, 00, 00, 00
AltDefaultUserName=Rosati
AltDefaultDomainName=SERVERDATI
ScLogonReader=SERVERDATI
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
\{25537BA6-77A8-11D2-9B6C-0000F8080861}]
@=Folder Redirection
ProcessGroupPolicy=ProcessGroupPolicy
DllName=66, 00, 64, 00, 65, 00, 70, 00, 6c, 00, 6f, 00, 79, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
NoMachinePolicy=01, 00, 00, 00
NoSlowLink=01, 00, 00, 00
NoBackgroundPolicy=01, 00, 00, 00
PerUserLocalSettings=01, 00, 00, 00
NoGPOListChanges=00, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}]
Status=00, 00, 00, 00
LastPolicyTime=3f, 9d, d6, 00
PrevSlowLink=00, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
@=Microsoft Disk Quota
NoMachinePolicy=00, 00, 00, 00
NoUserPolicy=01, 00, 00, 00
NoSlowLink=01, 00, 00, 00
NoBackgroundPolicy=01, 00, 00, 00
NoGPOListChanges=01, 00, 00, 00
PerUserLocalSettings=00, 00, 00, 00
RequiresSuccessfulRegistry=01, 00, 00, 00
EnableAsynchronousProcessing=00, 00, 00, 00
DllName=64, 00, 73, 00, 6b, 00, 71, 00, 75, 00, 6f, 00, 74, 00, 61, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
ProcessGroupPolicy=ProcessGroupPolicy
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}]
@=Script
ProcessGroupPolicy=ProcessScriptsGroupPolicy
DllName=67, 00, 70, 00, 74, 00, 65, 00, 78, 00, 74, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
NoSlowLink=01, 00, 00, 00
NoGPOListChanges=01, 00, 00, 00
NotifyLinkTransition=01, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
ProcessGroupPolicy=SceProcessSecurityPolicyGPO
DllName=73, 00, 63, 00, 65, 00, 63, 00, 6c, 00, 69, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
@=Security
NoUserPolicy=01, 00, 00, 00
NoGPOListChanges=01, 00, 00, 00
EnableAsynchronousProcessing=01, 00, 00, 00
MaxNoGPOListChangesInterval=c0, 03, 00, 00
Status=00, 00, 00, 00
LastPolicyTime=c9, 88, dc, 00
PrevSlowLink=00, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
ProcessGroupPolicy=ProcessGroupPolicy
DllName=69, 00, 65, 00, 64, 00, 6b, 00, 63, 00, 73, 00, 33, 00, 32, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
@=Internet Explorer Branding
NoSlowLink=01, 00, 00, 00
NoBackgroundPolicy=00, 00, 00, 00
NoGPOListChanges=01, 00, 00, 00
NoMachinePolicy=01, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
ProcessGroupPolicy=SceProcessEFSRecoveryGPO
DllName=73, 00, 63, 00, 65, 00, 63, 00, 6c, 00, 69, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
@=EFS recovery
NoUserPolicy=01, 00, 00, 00
NoGPOListChanges=01, 00, 00, 00
RequireSuccessfulRegistry=01, 00, 00, 00
Status=00, 00, 00, 00
LastPolicyTime=a6, 9d, d6, 00
PrevSlowLink=00, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
@=Gestione applicazione
DllName=61, 00, 70, 00, 70, 00, 6d, 00, 67, 00, 6d, 00, 74, 00, 73, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
ProcessGroupPolicy=ProcessGroupPolicyObjects
NoBackgroundPolicy=01, 00, 00, 00
RequiresSucessfulRegistry=00, 00, 00, 00
NoSlowLink=01, 00, 00, 00
PerUserLocalSettings=01, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions
\{e437bc1c-aa7d-11d2-a382-00c04f991e27}]
@=Protezione IP
ProcessGroupPolicy=ProcessIPSECPolicy
DllName=67, 00, 70, 00, 74, 00, 65, 00, 78, 00, 74, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
NoUserPolicy=01, 00, 00, 00
NoGPOListChanges=01, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
\crypt32chain]
Asynchronous=00, 00, 00, 00
Impersonate=00, 00, 00, 00
DllName=63, 00, 72, 00, 79, 00, 70, 00, 74, 00, 33, 00, 32, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
Logoff=ChainWlxLogoffEvent
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
Asynchronous=00, 00, 00, 00
Impersonate=00, 00, 00, 00
DllName=63, 00, 72, 00, 79, 00, 70, 00, 74, 00, 6e, 00, 65, 00, 74, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
Logoff=CryptnetWlxLogoffEvent
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
DLLName=cscdll.dll
Logon=WinlogonLogonEvent
Logoff=WinlogonLogoffEvent
ScreenSaver=WinlogonScreenSaverEvent
Startup=WinlogonStartupEvent
Shutdown=WinlogonShutdownEvent
StartShell=WinlogonStartShellEvent
Impersonate=00, 00, 00, 00
Asynchronous=01, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
Logoff=WLEventLogoff
Impersonate=00, 00, 00, 00
Asynchronous=01, 00, 00, 00
DllName=73, 00, 63, 00, 6c, 00, 67, 00, 6e, 00, 74, 00, 66, 00, 79, 00, 2e, 00, 64, 00, 6c, 00, 6c, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
\SensLogn]
DLLName=WlNotify.dll
Lock=SensLockEvent
Logon=SensLogonEvent
Logoff=SensLogoffEvent
Safe=01, 00, 00, 00
MaxWait=58, 02, 00, 00
StartScreenSaver=SensStartScreenSaverEvent
StopScreenSaver=SensStopScreenSaverEvent
Startup=SensStartupEvent
Shutdown=SensShutdownEvent
StartShell=SensStartShellEvent
Unlock=SensUnlockEvent
Impersonate=01, 00, 00, 00
Asynchronous=01, 00, 00, 00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
DLLName=wzcdlg.dll
Logon=WZCEventLogon
Logoff=WZCEventLogoff
Impersonate=00, 00, 00, 00
Asynchronous=00, 00, 00, 00 |
|
Top |
|
 |
Orange Dio maturo

Registrato: 18/02/07 13:20 Messaggi: 2224 Residenza: Roma
|
Inviato: 25 Giu 2007 18:31 Oggetto: |
|
|
ciao! benvenuto anche dalla parte mia.
non ci servivano tutte quelle informazioni. bastava solo il valore della sottochiave Userinit
fai anche quest'altro controllo: dal task manager scegli: file -> nuova operazione --> digita regedit -->invio
trova questa chiave:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
e successivamente
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe
nella finestra di destra che valori vedi? |
|
Top |
|
 |
Sante62 Dio maturo


Registrato: 27/06/07 17:55 Messaggi: 3477 Residenza: Floridia
|
Inviato: 27 Giu 2007 18:07 Oggetto: |
|
|
Ciao, prova a fixare queste voci dal log di hjiackthis
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=c:\winnt\system32\userinit.exe,"c:\winnt\system32\samsungcenter.exe","c :\winnt\system32\officefind.exe",userinit.exe
O1 - Hosts: 66.40.16.218 auto.search.msn.com
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O18 - Filter hijack: text/html - {D89DBE71-B349-4FD2-BA6D-ABC8D510F19F} - (no file)
O20 - AppInit_DLLs: \?C:WINNTprn.buj
O20 - Winlogon Notify: winjwu32 - winjwu32.dll (file missing)
O20 - Winlogon Notify: winpnp32 - winpnp32.dll (file missing)
O20 - Winlogon Notify: winzxr32 - winzxr32.dll (file missing)
Dopodichè fai una scansione online con panda da quì:
http://www.nanoscan.com/as/v1/principal.aspx
Metti il puntino nella casella "Full Scan" e clicca su "Scan Now"
Adesso visualizzerai la licenza, clicca su "I Accept"
Installa l'Active X che ti servirà per il corretto funzionemento della scansione, quando ti esce la finestra clicca su "Installa"
Attendi la fine dell'installazione del software e delle firme virali
Finito, inizierà la scansione, finita la scansione, clicca sul pulsante "Save" adesso decidi dove salvarlo, salvato, lo alleghi qui sul forum.
Ciao. |
|
Top |
|
 |
bdoriano Amministratore


Registrato: 02/04/07 12:05 Messaggi: 14391 Residenza: 3° pianeta del sistema solare...
|
Inviato: 27 Giu 2007 18:16 Oggetto: |
|
|
Ciao Sante62,
purtroppo la situazione di ippopippo71 è cambiata qui.
Quindi, i passaggi che hai indicato, al momento non servono.
PS: se vuoi, puoi presentarti qui |
|
Top |
|
 |
|
|
Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento Non puoi modificare i tuoi messaggi Non puoi cancellare i tuoi messaggi Non puoi votare nei sondaggi
|
|