| 
                
                
                 
 
	
		| Precedente :: Successivo |  
		| Autore | Messaggio |  
		| ger.z Comune mortale
 
  
 
 Registrato: 15/02/08 01:11
 Messaggi: 2
 
 
 | 
			
				|  Inviato: 15 Feb 2008 02:36    Oggetto: disinstallare e rimuovere AVS scaduto |   |  
				| 
 |  
				| Salve a tutti, avrei bisogno dell?aiuto di un esperto: in data 09/02/08 mi è scaduta la licenza dell?antivirus AVS e non riesco a rimuoverlo (perché è sempre in esecuzione) per installarne un altro, di cui sono ancora alla ricerca. Credo di avere qualche virus ma non so cosa fare. Ho scaricato hijackthis
 (chiedo scusa per aver dimenticato di chiudere messenger) e ottenuto il seguente
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 0.30.32, on 15/02/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\AOL\Active Virus Shield\avp.exe
 C:\Acer\Empowering Technology\admServ.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
 C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 C:\Programmi\SMART Technologies Inc\SMART Board Software\SMARTBoardService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Programmi\File comuni\Real\Update_OB\realsched.exe
 C:\Programmi\AOL\Active Virus Shield\avp.exe
 C:\acer\Empowering Technology\ePower\epm-dm.exe
 C:\Programmi\ScanSoft\PaperPort\pptd40nt.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\Programmi\Brother\Brmfcmon\BrMfcWnd.exe
 C:\Programmi\Brother\ControlCenter3\brccMCtl.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\Programmi\Musicmatch\Musicmatch Jukebox\mm_tray.exe
 C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\Documents and Settings\All Users\Dati applicazioni\Macrovision\FLEXnet Connect\6\ISUSPM.exe
 C:\Programmi\SMART Technologies Inc\SMART Board Software\SMARTBoardTools.exe
 C:\Programmi\SMART Technologies Inc\SMART Board Software\Aware.exe
 C:\Programmi\SMART Technologies Inc\SMART Board Software\Marker.exe
 C:\Programmi\Brother\Brmfcmon\BrMfcmon.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\Programmi\Hijackthis\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: XBTP06568 - {311F9DE8-6126-4EEE-B15F-65CBB3B4F9F6} - C:\Programmi\AOL Security Toolbar\AOL_security_toolbar.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: SMART Notebook Download Plugin - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Programmi\SMART Technologies Inc\Notebook Software\NotebookPlugin.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
 O3 - Toolbar: AOL Security Toolbar - {3BB63FD4-3C00-44D7-94A9-5DE211900DEF} - C:\Programmi\AOL Security Toolbar\AOL_security_toolbar.dll
 O3 - Toolbar: SYSTRAN Web Translator 5.0  - {A5899B52-3AF9-4F56-85FE-AD7B3BE8490F} - C:\Programmi\SYSTRAN\5.0\Personal\IEPlugIn.dll
 O4 - HKLM\..\Run: [SynTPLpr] C:\Programmi\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
 O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [aol] "C:\Programmi\AOL\Active Virus Shield\avp.exe"
 O4 - HKLM\..\Run: [epm-dm] c:\acer\Empowering Technology\ePower\epm-dm.exe
 O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
 O4 - HKLM\..\Run: [PaperPort PTD] C:\Programmi\ScanSoft\PaperPort\pptd40nt.exe
 O4 - HKLM\..\Run: [IndexSearch] C:\Programmi\ScanSoft\PaperPort\IndexSearch.exe
 O4 - HKLM\..\Run: [BrMfcWnd] C:\Programmi\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
 O4 - HKLM\..\Run: [SetDefPrt] C:\Programmi\Brother\Brmfl06a\BrStDvPt.exe
 O4 - HKLM\..\Run: [ControlCenter3] C:\Programmi\Brother\ControlCenter3\brctrcen.exe /autorun
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [MMTray] "C:\Programmi\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Dati applicazioni\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Strumenti di SMART Board.lnk = C:\Programmi\SMART Technologies Inc\SMART Board Software\SMARTBoardTools.exe
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
 O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159558594421
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{02F19458-52DE-4531-B04E-AC080835699A}: NameServer = 151.99.0.100,217.59.193.243
 O17 - HKLM\System\CCS\Services\Tcpip\..\{CF931B5A-742F-4AC5-A62B-9F0ED06796E8}: NameServer = 151.99.0.100,217.59.193.243
 O17 - HKLM\System\CS1\Services\Tcpip\..\{02F19458-52DE-4531-B04E-AC080835699A}: NameServer = 151.99.0.100,217.59.193.243
 O17 - HKLM\System\CS2\Services\Tcpip\..\{02F19458-52DE-4531-B04E-AC080835699A}: NameServer = 151.99.0.100,217.59.193.243
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: Active Virus Shield (AVP) - AOL - C:\Programmi\AOL\Active Virus Shield\avp.exe
 O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
 O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
 O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Programmi\WinPcap\rpcapd.exe
 O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
 O23 - Service: SMART Board Service - SMART Technologies Inc. - C:\Programmi\SMART Technologies Inc\SMART Board Software\SMARTBoardService.exe
 O23 - Service: SMART Web Server - Unknown owner - C:\Programmi\SMART Technologies Inc\SMART Board Software\WebServer.exe
 
 --
 End of file - 9992 bytes
 
 
 Ho anche scaricato FindAWF e salvato sul desktop   da cui ho ottenuto
 
 Find AWF report by noahdfear ©2006
 Version 1.40
 
 
 
 bak folders found
 ~~~~~~~~~~~
 
 
 
 Duplicate files of bak directory contents
 ~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 end of report
 
 Sono tecnicamente inesperta, potreste darmi indicazioni precise su cosa posso fare, sia per rimuovere AVS sia per eliminare eventuali virus?
 Grazie anticipatamente.
 |  |  
		| Top |  |  
		|  |  
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 15 Feb 2008 07:42    Oggetto: |   |  
				| 
 |  
				| Ciao ger.z,   
 Hai provato a disinstallare AVS da Pannello di controllo - Installazione applicazioni?
 |  |  
		| Top |  |  
		|  |  
		| ger.z Comune mortale
 
  
 
 Registrato: 15/02/08 01:11
 Messaggi: 2
 
 
 | 
			
				|  Inviato: 15 Feb 2008 12:22    Oggetto: |   |  
				| 
 |  
				|  	  | bdoriano ha scritto: |  	  | Ciao ger.z,   
 Hai provato a disinstallare AVS da Pannello di controllo - Installazione applicazioni?
 | 
 
 ciao bdoriano,
 sì ho provato, ma mi dice che non posso perchè devo prima chiudere il programma (che è sempre attivo automaticamente)
 
 grazie comunque
 |  |  
		| Top |  |  
		|  |  
		| bdoriano Amministratore
 
  
  
 Registrato: 02/04/07 12:05
 Messaggi: 14391
 Residenza: 3° pianeta del sistema solare...
 
 | 
			
				|  Inviato: 15 Feb 2008 14:37    Oggetto: |   |  
				| 
 |  
				| Se clicchi con il tasto dx del mouse sull'icona di AVS vicino all'orologio, non c'è un comando tipo Close (o simile)? |  |  
		| Top |  |  
		|  |  
		|  |  
  
	| 
 
 | Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento
 Non puoi modificare i tuoi messaggi
 Non puoi cancellare i tuoi messaggi
 Non puoi votare nei sondaggi
 
 |  
 
 |