Indice del forum Olimpo Informatico
I Forum di Zeus News
Leggi la newsletter gratuita - Attiva il Menu compatto
 
 FAQFAQ   CercaCerca   Lista utentiLista utenti   GruppiGruppi   RegistratiRegistrati 
 ProfiloProfilo   Messaggi privatiMessaggi privati   Log inLog in 

    Newsletter RSS Facebook Twitter Contatti Ricerca
problema virus:http://controlpage.info/
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus
Precedente :: Successivo  
Autore Messaggio
mattia
Mortale adepto
Mortale adepto


Registrato: 31/07/07 15:07
Messaggi: 34

MessaggioInviato: 09 Apr 2008 22:22    Oggetto: problema virus:http://controlpage.info/ Rispondi citando

Ciao!
ogni volta che apro internet explorer vengo indirizzato alla pagina citata nel titolo. Poi mi compare una finesta che mi chiede se voglio eseguire l'accesso e compare sul desktop un'icona con scritto "accesso". Ho provato a fare uno scan con antivir ma non ha trovato niente mentre con spybot ha trovato un errore "win32.dialer.aeh" ma non riesce a ripararlo.

ecco il log di hjt

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22.17.19, on 09/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Programmi\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://controlpage.info/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://www.hp.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyServer = silv-mi-proxy.eu.corp.arrow.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyOverride = 192.168.1.1;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

Collegamenti
O2 - BHO: Supporto di collegamento per Adobe PDF Reader -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File

comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live -

{9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft

Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}

- C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -

C:\Programmi\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch

Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition

Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched]

"C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader

8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe"

/background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search &

Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User

'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User

'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User

'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User

'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft

Office\Office\OSA9.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows

Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -

http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano -

res://C:\Programmi\Windows Live

Toolbar\Components\it-it\msntabres.dll.mui/230?f063cfb8e05e48d493383af303d84d67
O8 - Extra context menu item: Apri in nuova scheda in secondo piano -

res://C:\Programmi\Windows Live

Toolbar\Components\it-it\msntabres.dll.mui/229?f063cfb8e05e48d493383af303d84d67
O8 - Extra context menu item: Invia a &Bluetooth -

C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} -

C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer -

{219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows

Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -

http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) -

http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -

http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_sit

e.cab?1163597914468
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -

http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class)

- http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -

http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB -

C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. -

C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) -

Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira

GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. -

C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. -

C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation

- c:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 8091 bytes

Grazie per l'aiuto!
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 10 Apr 2008 23:11    Oggetto: Rispondi citando

Ciao mattia Ciao

Lancia Combofix seguendo questa discussione;

scarica VirIT
Aggiornalo mediante l'icona della parabola posta nella barra in alto e fagli fare la scansione completa del PC.
Fai in modo che rimuova automaticamente i file infetti trovati.
Non dimenticare di disattivare momentaneamente il tuo antivirus.
Incolla poi quì il risultato;

rifai il log di Hijackthis, però incollalo possibilmente senza spazi fra le varie righe...
Top
Profilo Invia messaggio privato
mattia
Mortale adepto
Mortale adepto


Registrato: 31/07/07 15:07
Messaggi: 34

MessaggioInviato: 11 Apr 2008 12:58    Oggetto: Rispondi citando

Ho fatto ciò che hai detto, ora non mi indirizza più a quella pagina. Comunque ti posto i log per vedere se è tutto a posto.

virit

VirIT eXplorer Lite Log

[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK
--------------------------------------------------------
10/04/2008 - 23:30:11

[SCANSIONE DEL REGISTRO]
OK

StartPage di Internet Explorer Hijacked: http://controlpage.info/
* * * RIMOSSO * * *

[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK

C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Snapshots2\RegUBP1-Administrator.reg Infetto da Trojan.StartPage.L
Il file sarà spostato nella cartella di quarantena.

[D:]


[E:]


Chiavi Registro infette: 0.
Files Infetti: 1.
Files Sospetti: 0.
Files Analizzati: 118286.
Files Totali: 118286.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.

Adesso puoi RIAVVIARE il computer per spostare il file nella cartella di quarantena.
140.
Chiavi Registro rimosse: 0.
Virus Rimossi: 1.

HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12.49.17, on 11/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\VEXPLITE\MONLITE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\VEXPLITE\viritsvc.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\Rar$EX03.922\HiJackThis_v2.exe
C:\Programmi\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tgsoft.it/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = silv-mi-proxy.eu.corp.arrow.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.1.1;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\VEXPLITE\MONLITE.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?f063cfb8e05e48d493383af303d84d67
O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?f063cfb8e05e48d493383af303d84d67
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1163597914468
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas www.tgsoft.it - C:\VEXPLITE\viritsvc.exe

--
End of file - 8084 bytes

Grazie! Very Happy

Ps:ho notato che se faccio la scansione con spybot trova ancora il virus win32.dialer.aeh
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 11 Apr 2008 16:04    Oggetto: Rispondi citando

VirIT ha eliminato il reidirizzamento;

Fai la scansione con Combofix come sopra indicato;

falla anche con Norman Malware Cleaner
disattiva il ripristino di sistema e avvia il PC in modalità provvisoria
Avvia Norman Malware Cleaner.
Viene generato un log sul desktop chiamandolo NFix_2008-01-gg_hh-mm-ss.log, alla fine della scansione postalo qui.
Top
Profilo Invia messaggio privato
mattia
Mortale adepto
Mortale adepto


Registrato: 31/07/07 15:07
Messaggi: 34

MessaggioInviato: 11 Apr 2008 18:26    Oggetto: Rispondi citando

Si, scusa, l'avevo già fatta la scansione con combofix ma mi ero dimenticato di postare il log! Ecco tutto:

Combofix

ComboFix 08-04-09.9 - Administrator 2008-04-11 18.18.36.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1040.18.610 [GMT 2:00]
Eseguito da: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Creati Da 2008-03-11 al 2008-04-11 )))))))))))))))))))))))))))))))))))
.

2008-04-10 23:33 . 2008-04-10 23:33 <DIR> d-------- C:\QUARANTENA_VIRIT
2008-04-10 23:26 . 2008-03-17 19:23 39,808 --a------ C:\WINDOWS\system32\drivers\VIRAGTLT.SYS
2008-04-10 16:45 . 2008-04-10 16:47 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-04-09 22:14 . 2008-04-09 22:14 401,720 --a------ C:\Programmi\HJT.exe
2008-03-29 15:58 . 2008-04-09 20:56 <DIR> d-a------ C:\Documents and Settings\All Users\Dati applicazioni\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-11 15:44 --------- d-----w C:\Programmi\DAEMON Tools
2008-04-09 21:43 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-04-09 20:17 8,092 ----a-w C:\Programmi\hijackthis.log
2008-04-03 19:45 --------- d-----w C:\Programmi\eMule
2008-04-01 20:27 --------- d-----w C:\Programmi\MSN Messenger
2008-04-01 20:27 --------- d-----w C:\Programmi\Messenger Plus! Live
2008-03-29 18:11 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Messenger Plus!
2008-03-29 14:05 --------- d-----w C:\Programmi\Eusing Free Registry Cleaner
2008-03-29 14:00 --------- d-----w C:\Programmi\SpywareBlaster
2008-03-28 13:00 --------- d-----w C:\Programmi\Java
2008-03-20 08:06 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:06 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-02-21 10:54 --------- d-----w C:\Documents and Settings\Administrator\Dati applicazioni\Skype
2008-02-21 08:32 --------- d-----w C:\Documents and Settings\All Users\Dati applicazioni\Registry Helper
2008-02-21 08:00 --------- d-----w C:\Programmi\Spybot - Search & Destroy
2008-02-21 07:58 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-02-21 07:43 15,872 ------w C:\WINDOWS\system32\winskfr.dll
2008-02-21 07:43 119,568 ------w C:\WINDOWS\system32\vb6fr.dll
2008-02-20 06:50 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:50 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:33 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:33 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:33 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-16 22:31 3,080,704 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-15 09:23 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2008-02-01 10:17 586,752 ----a-w C:\WINDOWS\WLXPGSS.SCR
2007-07-31 15:32 502,055 ----a-w C:\Programmi\gmer.zip
2007-07-31 13:49 47,667 ----a-w C:\Programmi\BootSafe(Modalità provvisoria).zip
2007-07-31 13:49 363,363 ----a-w C:\Programmi\HiJackThis_v2.zip
2006-11-15 12:33 56 --sha-w C:\WINDOWS\SMINST\hpboot.sys
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 925,696 2005-05-20 08:11:06 C:\Programmi\Analog Devices\Core\bak\smax4pnp.exe

----a-w 716,800 2005-05-06 12:06:12 C:\Programmi\Analog Devices\SoundMAX\bak\Smax4.exe

----a-w 127,016 2004-09-30 08:10:56 C:\Programmi\AVPersonal\bak\AVGNT.EXE

----a-w 157,592 2006-09-14 20:09:07 C:\Programmi\DAEMON Tools\bak\daemon.exe

----a-w 1,159,168 2004-04-17 18:19:52 C:\Programmi\File comuni\PCSuite\DataLayer\bak\DATALA~1.EXE

----a-w 172,094 2006-01-26 12:35:10 C:\Programmi\HPQ\Default Settings\bak\cpqset.exe

----a-w 147,968 2004-03-23 11:20:24 C:\Programmi\Nokia\Nokia PC Suite 6\bak\TRAYAP~1.EXE

----a-w 761,948 2006-03-03 16:46:48 C:\Programmi\Synaptics\SynTP\bak\SynTPEnh.exe

----a-w 806,912 2006-03-09 15:38:42 C:\WINDOWS\CREATOR\bak\Remind_XP.exe

----a-w 1,187,840 2005-12-20 14:51:40 C:\WINDOWS\SMINST\bak\Recguard.exe

----a-w 892,928 2006-02-15 15:43:16 C:\WINDOWS\SMINST\bak\Scheduler.exe

----a-w 15,360 2004-08-19 08:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-19 13:00:00 C:\WINDOWS\system32\ctfmon.exe

----a-w 77,824 2006-03-23 12:13:40 C:\WINDOWS\system32\bak\hkcmd.exe

----a-w 118,784 2006-03-23 12:17:50 C:\WINDOWS\system32\bak\igfxpers.exe

----a-w 94,208 2006-03-23 12:17:04 C:\WINDOWS\system32\bak\igfxtray.exe

----a-w 155,648 2001-07-09 10:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe

----a-w 99,840 2003-09-11 03:00:00 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\E_S4I0H2.EXE

.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* i valori vuoti & legittimi/default non sono visualizzati.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:00 15360]
"MsnMsgr"="C:\Programmi\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"SpybotSD TeaTimer"="C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"AGRSMMSG"="AGRSMMSG.exe" [2006-01-30 03:00 88203 C:\WINDOWS\AGRSMMSG.exe]
"QlbCtrl"="C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-05-08 09:56 131072]
"avgnt"="C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-12 13:01 249896]
"SunJavaUpdateSched"="C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Adobe Reader Speed Launcher"="C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"VIRIT LITE MONITOR"="C:\VEXPLITE\MONLITE.EXE" [2008-04-10 23:27 245760]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15:00 15360]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Microsoft Office.lnk - C:\Programmi\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56 65588]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"C:\\Programmi\\Microsoft Platform Builder\\6.00\\cepb\\wcetk\\cetest.exe"=
"C:\\Programmi\\eMule\\emule.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmi\\Skype\\Phone\\Skype.exe"=

R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-03-17 19:23]
R2 SQLWriter;SQL Server VSS Writer;"c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R2 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2008-04-10 23:27]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2006-02-28 19:05]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2005-10-21 13:19]
S3 PAC207;Trust WB-1400T Webcam;C:\WINDOWS\system32\DRIVERS\pfc027.sys []
S3 pwalker;Process Walker Driver;C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\nsc2E.tmp\pwalker.sys []
S3 USBSTOR;Driver archiviazione di massa USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18029c72-748f-11db-b289-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

.
Contenuto della cartella 'Scheduled Tasks'
"2008-04-11 15:00:00 C:\WINDOWS\Tasks\BE24A32D88435B69.job"
- c:\docume~1\admini~1\datiap~1\objbib\About2drive.exe
"2008-04-11 15:24:00 C:\WINDOWS\Tasks\Verifica aggiornamenti per Windows Live Toolbar.job"
- C:\Programmi\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-11 18:20:12
Windows 5.1.2600 Service Pack 2 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
Ora fine scansione: 2008-04-11 18.21.23
ComboFix-quarantined-files.txt 2008-04-11 16:21:18
ComboFix2.txt 2008-04-10 21:20:18
16 Directory 51,788,496,896 byte disponibili
20 Directory 51,777,785,856 byte disponibili
.
2008-04-10 14:48:16 --- E O F ---


Norman malware

Norman Malware Cleaner
Copyright © 1990 - 2008, Norman ASA. Built 2008/04/08 19:04:26

Norman Scanner Engine Version: 5.92.04
Nvcbin.def Version: 5.92.00, Date: 2008/04/08 19:04:26, Variants: 1500380

Running pre-scan cleanup routine:
Operating System: Microsoft Windows XP Professional 5.1.2600(Safe mode) Service Pack 2
Logged on user: FAE1\Administrator

Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00000000
Removed hosts entry: 127.0.0.1 www.007guard.com
Removed hosts entry: 127.0.0.1 007guard.com
Removed hosts entry: 127.0.0.1 008i.com
Removed hosts entry: 127.0.0.1 www.008k.com
Removed hosts entry: 127.0.0.1 008k.com
Removed hosts entry: 127.0.0.1 www.00hq.com
Removed hosts entry: 127.0.0.1 00hq.com
Removed hosts entry: 127.0.0.1 010402.com
Removed hosts entry: 127.0.0.1 www.032439.com
Removed hosts entry: 127.0.0.1 032439.com
Removed hosts entry: 127.0.0.1 www.1001-search.info
Removed hosts entry: 127.0.0.1 1001-search.info
Removed hosts entry: 127.0.0.1 www.100888290cs.com
Removed hosts entry: 127.0.0.1 100888290cs.com
Removed hosts entry: 127.0.0.1 www.100sexlinks.com
Removed hosts entry: 127.0.0.1 100sexlinks.com
Removed hosts entry: 127.0.0.1 www.10sek.com
Removed hosts entry: 127.0.0.1 10sek.com
Removed hosts entry: 127.0.0.1 www.123topsearch.com
Removed hosts entry: 127.0.0.1 123topsearch.com
Removed hosts entry: 127.0.0.1 www.132.com
Removed hosts entry: 127.0.0.1 132.com
Removed hosts entry: 127.0.0.1 www.136136.net
Removed hosts entry: 127.0.0.1 136136.net
Removed hosts entry: 127.0.0.1 www.139mm.com
Removed hosts entry: 127.0.0.1 139mm.com
Removed hosts entry: 127.0.0.1 www.163ns.com
Removed hosts entry: 127.0.0.1 163ns.com
Removed hosts entry: 127.0.0.1 171203.com
Removed hosts entry: 127.0.0.1 17-plus.com
Removed hosts entry: 127.0.0.1 www.1800searchonline.com
Removed hosts entry: 127.0.0.1 1800searchonline.com
Removed hosts entry: 127.0.0.1 www.180searchassistant.com
Removed hosts entry: 127.0.0.1 180searchassistant.com
Removed hosts entry: 127.0.0.1 www.180solutions.com
Removed hosts entry: 127.0.0.1 180solutions.com
Removed hosts entry: 127.0.0.1 www.1987324.com
Removed hosts entry: 127.0.0.1 1987324.com
Removed hosts entry: 127.0.0.1 www.1-domains-registrations.com
Removed hosts entry: 127.0.0.1 1-domains-registrations.com
Removed hosts entry: 127.0.0.1 www.1-extreme.biz
Removed hosts entry: 127.0.0.1 1-extreme.biz
Removed hosts entry: 127.0.0.1 www.1sexparty.com
Removed hosts entry: 127.0.0.1 1sexparty.com
Removed hosts entry: 127.0.0.1 www.1stantivirus.com
Removed hosts entry: 127.0.0.1 1stantivirus.com
Removed hosts entry: 127.0.0.1 www.1stpagehere.com
Removed hosts entry: 127.0.0.1 1stpagehere.com
Removed hosts entry: 127.0.0.1 www.1stsearchportal.com
Removed hosts entry: 127.0.0.1 1stsearchportal.com
Removed hosts entry: 127.0.0.1 2.82211.net
Removed hosts entry: 127.0.0.1 www.2006ooo.com
Removed hosts entry: 127.0.0.1 www.2007-download.com
Removed hosts entry: 127.0.0.1 2007-download.com
Removed hosts entry: 127.0.0.1 www.2020search.com
Removed hosts entry: 127.0.0.1 2020search.com
Removed hosts entry: 127.0.0.1 20x2p.com
Removed hosts entry: 127.0.0.1 www.24-7searching-and-more.com
Removed hosts entry: 127.0.0.1 24-7searching-and-more.com
Removed hosts entry: 127.0.0.1 www.24teen.com
Removed hosts entry: 127.0.0.1 24teen.com
Removed hosts entry: 127.0.0.1 www.2every.net
Removed hosts entry: 127.0.0.1 2every.net
Removed hosts entry: 127.0.0.1 2ndpower.com
Removed hosts entry: 127.0.0.1 www.2search.com
Removed hosts entry: 127.0.0.1 2search.com
Removed hosts entry: 127.0.0.1 www.2search.org
Removed hosts entry: 127.0.0.1 2search.org
Removed hosts entry: 127.0.0.1 www.2squared.com
Removed hosts entry: 127.0.0.1 2squared.com
Removed hosts entry: 127.0.0.1 www.3322.org
Removed hosts entry: 127.0.0.1 3322.org
Removed hosts entry: 127.0.0.1 www.36site.com
Removed hosts entry: 127.0.0.1 36site.com
Removed hosts entry: 127.0.0.1 3721.com
Removed hosts entry: 127.0.0.1 39-93.com
Removed hosts entry: 127.0.0.1 www.3abetterinternet.com
Removed hosts entry: 127.0.0.1 3abetterinternet.com
Removed hosts entry: 127.0.0.1 www.3ebay.it
Removed hosts entry: 127.0.0.1 3ebay.it
Removed hosts entry: 127.0.0.1 www.3xclipsonline.com
Removed hosts entry: 127.0.0.1 3xclipsonline.com
Removed hosts entry: 127.0.0.1 www.3xcurves.com
Removed hosts entry: 127.0.0.1 3xcurves.com
Removed hosts entry: 127.0.0.1 www.3xfestival.com
Removed hosts entry: 127.0.0.1 3xfestival.com
Removed hosts entry: 127.0.0.1 www.3x-festival.com
Removed hosts entry: 127.0.0.1 3x-festival.com
Removed hosts entry: 127.0.0.1 www.3x-galls.com
Removed hosts entry: 127.0.0.1 3x-galls.com
Removed hosts entry: 127.0.0.1 www.3xmiracle.com
Removed hosts entry: 127.0.0.1 3xmiracle.com
Removed hosts entry: 127.0.0.1 www.3xmoviesblog.com
Removed hosts entry: 127.0.0.1 3xmoviesblog.com
Removed hosts entry: 127.0.0.1 www.404dns.com
Removed hosts entry: 127.0.0.1 404dns.com
Removed hosts entry: 127.0.0.1 www.4199.com
Removed hosts entry: 127.0.0.1 4199.com
Removed hosts entry: 127.0.0.1 www.4corn.net
Removed hosts entry: 127.0.0.1 4corn.net
Removed hosts entry: 127.0.0.1 www.4ebay.it
Removed hosts entry: 127.0.0.1 4ebay.it
Removed hosts entry: 127.0.0.1 4klm.com
Removed hosts entry: 127.0.0.1 www.4mpg.com
Removed hosts entry: 127.0.0.1 4mpg.com
Removed hosts entry: 127.0.0.1 www.4repubblica.it
Removed hosts entry: 127.0.0.1 4repubblica.it
Removed hosts entry: 127.0.0.1 www.4softget.com
Removed hosts entry: 127.0.0.1 4softget.com
Removed hosts entry: 127.0.0.1 www.5repubblica.it
Removed hosts entry: 127.0.0.1 5repubblica.it
Removed hosts entry: 127.0.0.1 www.5starvideos.com
Removed hosts entry: 127.0.0.1 5starvideos.com
Removed hosts entry: 127.0.0.1 www.5zgmu7o20kt5d8yq.com
Removed hosts entry: 127.0.0.1 5zgmu7o20kt5d8yq.com
Removed hosts entry: 127.0.0.1 www.680180.net
Removed hosts entry: 127.0.0.1 680180.net
Removed hosts entry: 127.0.0.1 www.6njaga.com
Removed hosts entry: 127.0.0.1 6njaga.com
Removed hosts entry: 127.0.0.1 www.6sek.com
Removed hosts entry: 127.0.0.1 6sek.com
Removed hosts entry: 127.0.0.1 www.70-music.com
Removed hosts entry: 127.0.0.1 70-music.com
Removed hosts entry: 127.0.0.1 www.7322.com
Removed hosts entry: 127.0.0.1 7322.com
Removed hosts entry: 127.0.0.1 75tz.com
Removed hosts entry: 127.0.0.1 www.777search.com
Removed hosts entry: 127.0.0.1 777search.com
Removed hosts entry: 127.0.0.1 www.777top.com
Removed hosts entry: 127.0.0.1 777top.com
Removed hosts entry: 127.0.0.1 www.7939.com
Removed hosts entry: 127.0.0.1 7939.com
Removed hosts entry: 127.0.0.1 www.7search.com
Removed hosts entry: 127.0.0.1 7search.com
Removed hosts entry: 127.0.0.1 80gw6ry3i3x3qbrkwhxhw.032439.com
Removed hosts entry: 127.0.0.1 www.80-music.com
Removed hosts entry: 127.0.0.1 80-music.com
Removed hosts entry: 127.0.0.1 82211.net
Removed hosts entry: 127.0.0.1 8866.org
Removed hosts entry: 127.0.0.1 www.888.com
Removed hosts entry: 127.0.0.1 888.com
Removed hosts entry: 127.0.0.1 www.8ad.com
Removed hosts entry: 127.0.0.1 8ad.com
Removed hosts entry: 127.0.0.1 www.90-music.com
Removed hosts entry: 127.0.0.1 90-music.com
Removed hosts entry: 127.0.0.1 www.9505.com
Removed hosts entry: 127.0.0.1 9505.com
Removed hosts entry: 127.0.0.1 www.971searchbox.com
Removed hosts entry: 127.0.0.1 971searchbox.com
Removed hosts entry: 127.0.0.1 a.bestmanage.org
Removed hosts entry: 127.0.0.1 www.aaabesthomepage.com
Removed hosts entry: 127.0.0.1 aaabesthomepage.com
Removed hosts entry: 127.0.0.1 aaasexypics.com
Removed hosts entry: 127.0.0.1 www.aaawebfinder.com
Removed hosts entry: 127.0.0.1 aaawebfinder.com
Removed hosts entry: 127.0.0.1 www.aaqadarsztriv.com
Removed hosts entry: 127.0.0.1 aaqadarsztriv.com
Removed hosts entry: 127.0.0.1 www.aaqada-rsztriv.com
Removed hosts entry: 127.0.0.1 aaqada-rsztriv.com
Removed hosts entry: 127.0.0.1 www.aaqadaueorn.com
Removed hosts entry: 127.0.0.1 aaqadaueorn.com
Removed hosts entry: 127.0.0.1 www.aaqada-ueorn.com
Removed hosts entry: 127.0.0.1 aaqada-ueorn.com
Removed hosts entry: 127.0.0.1 www.aaqada-ygco.com
Removed hosts entry: 127.0.0.1 aaqada-ygco.com
Removed hosts entry: 127.0.0.1 www.aaqada-ymct.com
Removed hosts entry: 127.0.0.1 aaqada-ymct.com
Removed hosts entry: 127.0.0.1 aavc.com
Removed hosts entry: 127.0.0.1 www.abcdperformance.com
Removed hosts entry: 127.0.0.1 abcdperformance.com
Removed hosts entry: 127.0.0.1 www.abcsearch.com
Removed hosts entry: 127.0.0.1 abcsearch.com
Removed hosts entry: 127.0.0.1 www.abetterinternet.com
Removed hosts entry: 127.0.0.1 abetterinternet.com
Removed hosts entry: 127.0.0.1 www.aboutclicker.com
Removed hosts entry: 127.0.0.1 aboutclicker.com
Removed hosts entry: 127.0.0.1 www.abrp.net
Removed hosts entry: 127.0.0.1 abrp.net
Removed hosts entry: 127.0.0.1 www.absolutee.com
Removed hosts entry: 127.0.0.1 absolutee.com
Removed hosts entry: 127.0.0.1 www.abyssmedia.com
Removed hosts entry: 127.0.0.1 abyssmedia.com
Removed hosts entry: 127.0.0.1 access.navinetwork.com
Removed hosts entry: 127.0.0.1 access.rapid-pass.net
Removed hosts entry: 127.0.0.1 www.accessactivexvideo.com
Removed hosts entry: 127.0.0.1 accessactivexvideo.com
Removed hosts entry: 127.0.0.1 www.accessclips.com
Removed hosts entry: 127.0.0.1 accessclips.com
Removed hosts entry: 127.0.0.1 www.access-dvd.com
Removed hosts entry: 127.0.0.1 access-dvd.com
Removed hosts entry: 127.0.0.1 www.accesskeygenerator.com
Removed hosts entry: 127.0.0.1 accesskeygenerator.com
Removed hosts entry: 127.0.0.1 www.accessorygeeks.com
Removed hosts entry: 127.0.0.1 accessorygeeks.com
Removed hosts entry: 127.0.0.1 www.accessthefuture.net
Removed hosts entry: 127.0.0.1 accessthefuture.net
Removed hosts entry: 127.0.0.1 www.accessvid.net
Removed hosts entry: 127.0.0.1 accessvid.net
Removed hosts entry: 127.0.0.1 www.acemedic.com
Removed hosts entry: 127.0.0.1 acemedic.com
Removed hosts entry: 127.0.0.1 www.ace-webmaster.com
Removed hosts entry: 127.0.0.1 ace-webmaster.com
Removed hosts entry: 127.0.0.1 acjp.com
Removed hosts entry: 127.0.0.1 www.acrobat-2007.com
Removed hosts entry: 127.0.0.1 acrobat-2007.com
Removed hosts entry: 127.0.0.1 www.acrobat-8.com
Removed hosts entry: 127.0.0.1 acrobat-8.com
Removed hosts entry: 127.0.0.1 www.acrobat-center.com
Removed hosts entry: 127.0.0.1 acrobat-center.com
Removed hosts entry: 127.0.0.1 www.acrobat-hq.com
Removed hosts entry: 127.0.0.1 acrobat-hq.com
Removed hosts entry: 127.0.0.1 www.acrobatreader-8.com
Removed hosts entry: 127.0.0.1 acrobatreader-8.com
Removed hosts entry: 127.0.0.1 www.acrobat-stop.com
Removed hosts entry: 127.0.0.1 acrobat-stop.com
Removed hosts entry: 127.0.0.1 www.actionbreastcancer.org
Removed hosts entry: 127.0.0.1 actionbreastcancer.org
Removed hosts entry: 127.0.0.1 www.activesearcher.info
Removed hosts entry: 127.0.0.1 activesearcher.info
Removed hosts entry: 127.0.0.1 www.activexaccessobject.com
Removed hosts entry: 127.0.0.1 activexaccessobject.com
Removed hosts entry: 127.0.0.1 www.activexaccessvideo.com
Removed hosts entry: 127.0.0.1 activexaccessvideo.com
Removed hosts entry: 127.0.0.1 www.activexemedia.com
Removed hosts entry: 127.0.0.1 activexemedia.com
Removed hosts entry: 127.0.0.1 www.activexmediaobject.com
Removed hosts entry: 127.0.0.1 activexmediaobject.com
Removed hosts entry: 127.0.0.1 www.activexmediapro.com
Removed hosts entry: 127.0.0.1 activexmediapro.com
Removed hosts entry: 127.0.0.1 www.activexmediasite.com
Removed hosts entry: 127.0.0.1 activexmediasite.com
Removed hosts entry: 127.0.0.1 www.activexmediasoftware.com
Removed hosts entry: 127.0.0.1 activexmediasoftware.com
Removed hosts entry: 127.0.0.1 www.activexmediasource.com
Removed hosts entry: 127.0.0.1 activexmediasource.com
Removed hosts entry: 127.0.0.1 www.activexmediatool.com
Removed hosts entry: 127.0.0.1 activexmediatool.com
Removed hosts entry: 127.0.0.1 www.activexmediatour.com
Removed hosts entry: 127.0.0.1 activexmediatour.com
Removed hosts entry: 127.0.0.1 www.activexsoftwares.com
Removed hosts entry: 127.0.0.1 activexsoftwares.com
Removed hosts entry: 127.0.0.1 www.activexsource.com
Removed hosts entry: 127.0.0.1 activexsource.com
Removed hosts entry: 127.0.0.1 www.activexupdate.com
Removed hosts entry: 127.0.0.1 activexupdate.com
Removed hosts entry: 127.0.0.1 www.activexvideo.com
Removed hosts entry: 127.0.0.1 activexvideo.com
Removed hosts entry: 127.0.0.1 www.activexvideotool.com
Removed hosts entry: 127.0.0.1 activexvideotool.com
Removed hosts entry: 127.0.0.1 www.ad.marketingsector.com
Removed hosts entry: 127.0.0.1 ad.marketingsector.com
Removed hosts entry: 127.0.0.1 www.ad.mokead.com
Removed hosts entry: 127.0.0.1 ad.mokead.com
Removed hosts entry: 127.0.0.1 ad.oinadserver.com
Removed hosts entry: 127.0.0.1 ad.outerinfoads.com
Removed hosts entry: 127.0.0.1 www.ad.yieldmanager.com
Removed hosts entry: 127.0.0.1 ad.yieldmanager.com
Removed hosts entry: 127.0.0.1 ad25.com
Removed hosts entry: 127.0.0.1 ad45.com
Removed hosts entry: 127.0.0.1 ad77.com
Removed hosts entry: 127.0.0.1 ad86.com
Removed hosts entry: 127.0.0.1 www.adamsupportgroup.org
Removed hosts entry: 127.0.0.1 adamsupportgroup.org
Removed hosts entry: 127.0.0.1 www.adarmor.com
Removed hosts entry: 127.0.0.1 adarmor.com
Removed hosts entry: 127.0.0.1 www.adasearch.com
Removed hosts entry: 127.0.0.1 adasearch.com
Removed hosts entry: 127.0.0.1 www.adawarenow.com
Removed hosts entry: 127.0.0.1 adawarenow.com
Removed hosts entry: 127.0.0.1 adchannel.contextplus.net
Removed hosts entry: 127.0.0.1 www.addetect.com
Removed hosts entry: 127.0.0.1 addetect.com
Removed hosts entry: 127.0.0.1 www.addictivetechnologies.com
Removed hosts entry: 127.0.0.1 addictivetechnologies.com
Removed hosts entry: 127.0.0.1 www.addictivetechnologies.net
Removed hosts entry: 127.0.0.1 addictivetechnologies.net
Removed hosts entry: 127.0.0.1 www.addioerrori.com
Removed hosts entry: 127.0.0.1 addioerrori.com
Removed hosts entry: 127.0.0.1 www.add-manager.com
Removed hosts entry: 127.0.0.1 add-manager.com
Removed hosts entry: 127.0.0.1 www.adintelligence.net
Removed hosts entry: 127.0.0.1 adintelligence.net
Removed hosts entry: 127.0.0.1 adioserrores.com
Removed hosts entry: 127.0.0.1 www.adioserrores.com
Removed hosts entry: 127.0.0.1 adipics.com
Removed hosts entry: 127.0.0.1 www.adipics.com
Removed hosts entry: 127.0.0.1 adlogix.com
Removed hosts entry: 127.0.0.1 www.adlogix.com
Removed hosts entry: 127.0.0.1 admin2cash.biz
Removed hosts entry: 127.0.0.1 www.admin2cash.biz
Removed hosts entry: 127.0.0.1 adnet-plus.com
Removed hosts entry: 127.0.0.1 adnetserver.com
Removed hosts entry: 127.0.0.1 www.adnetserver.com
Removed hosts entry: 127.0.0.1 adobe-download-now.com
Removed hosts entry: 127.0.0.1 adobe-downloads.com
Removed hosts entry: 127.0.0.1 www.adobe-downloads.com
Removed hosts entry: 127.0.0.1 adprotect.com
Removed hosts entry: 127.0.0.1 www.adprotect.com
Removed hosts entry: 127.0.0.1 ads.kmpads.com
Removed hosts entry: 127.0.0.1 ads.kw.revenue.net
Removed hosts entry: 127.0.0.1 ads.marketingsector.com
Removed hosts entry: 127.0.0.1 ads.searchingbooth.com
Removed hosts entry: 127.0.0.1 ads.z-quest.com
Removed hosts entry: 127.0.0.1 ads1.revenue.net
Removed hosts entry: 127.0.0.1 ads183.com
Removed hosts entry: 127.0.0.1 www.ads183.com
Removed hosts entry: 127.0.0.1 www.adscontex.com
Removed hosts entry: 127.0.0.1 adscontex.com
Removed hosts entry: 127.0.0.1 adservices1.enhance.com
Removed hosts entry: 127.0.0.1 www.adservices1.enhance.com
Removed hosts entry: 127.0.0.1 adservs.com
Removed hosts entry: 127.0.0.1 www.adsextend.net
Removed hosts entry: 127.0.0.1 adsextend.net
Removed hosts entry: 127.0.0.1 adshttp.com
Removed hosts entry: 127.0.0.1 www.adshttp.com
Removed hosts entry: 127.0.0.1 www.adsniffer.com
Removed hosts entry: 127.0.0.1 adsniffer.com
Removed hosts entry: 127.0.0.1 adsonwww.com
Removed hosts entry: 127.0.0.1 www.adsonwww.com
Removed hosts entry: 127.0.0.1 www.adspics.com
Removed hosts entry: 127.0.0.1 adspics.com
Removed hosts entry: 127.0.0.1 adsrevenue.net
Removed hosts entry: 127.0.0.1 www.adsrevenue.net
Removed hosts entry: 127.0.0.1 adtrak.net
Removed hosts entry: 127.0.0.1 www.adtrak.net
Removed hosts entry: 127.0.0.1 adtrgt.com
Removed hosts entry: 127.0.0.1 adult777search.info
Removed hosts entry: 127.0.0.1 www.adult777search.info
Removed hosts entry: 127.0.0.1 adultan.com
Removed hosts entry: 127.0.0.1 www.adultan.com
Removed hosts entry: 127.0.0.1 www.adult-engine-search.com
Removed hosts entry: 127.0.0.1 adult-engine-search.com
Removed hosts entry: 127.0.0.1 adult-erotic-guide.net
Removed hosts entry: 127.0.0.1 www.adult-erotic-guide.net
Removed hosts entry: 127.0.0.1 adultfilmsite.com
Removed hosts entry: 127.0.0.1 www.adultfilmsite.com
Removed hosts entry: 127.0.0.1 www.adult-friends-finder.net
Removed hosts entry: 127.0.0.1 adult-friends-finder.net
Removed hosts entry: 127.0.0.1 adultgambling.org
Removed hosts entry: 127.0.0.1 adult-host.org
Removed hosts entry: 127.0.0.1 adulthyperlinks.com
Removed hosts entry: 127.0.0.1 www.adulthyperlinks.com
Removed hosts entry: 127.0.0.1 adultmovieplus.com
Removed hosts entry: 127.0.0.1 www.adultmovieplus.com
Removed hosts entry: 127.0.0.1 adult-mpg.net
Removed hosts entry: 127.0.0.1 www.adult-mpg.net
Removed hosts entry: 127.0.0.1 adultsgames.net
Removed hosts entry: 127.0.0.1 adultsonlyvids.com
Removed hosts entry: 127.0.0.1 www.adultsonlyvids.com
Removed hosts entry: 127.0.0.1 adultsper.com
Removed hosts entry: 127.0.0.1 www.adultsper.com
Removed hosts entry: 127.0.0.1 www.adulttds.com
Removed hosts entry: 127.0.0.1 adulttds.com
Removed hosts entry: 127.0.0.1 adultzoneworld.com
Removed hosts entry: 127.0.0.1 www.adultzoneworld.com
Removed hosts entry: 127.0.0.1 www.advcash.biz
Removed hosts entry: 127.0.0.1 advcash.biz
Removed hosts entry: 127.0.0.1 advertisemoney.info
Removed hosts entry: 127.0.0.1 www.advertisemoney.info
Removed hosts entry: 127.0.0.1 advertising.paltalk.com
Removed hosts entry: 127.0.0.1 advertising-money.info
Removed hosts entry: 127.0.0.1 www.advertising-money.info
Removed hosts entry: 127.0.0.1 ad-w-a-r-e.com
Removed hosts entry: 127.0.0.1 www.ad-w-a-r-e.com
Removed hosts entry: 127.0.0.1 a-d-w-a-r-e.com
Removed hosts entry: 127.0.0.1 www.a-d-w-a-r-e.com
Removed hosts entry: 127.0.0.1 www.adwarealert.com
Removed hosts entry: 127.0.0.1 adwarealert.com
Removed hosts entry: 127.0.0.1 ad-warealert.com
Removed hosts entry: 127.0.0.1 www.ad-warealert.com
Removed hosts entry: 127.0.0.1 adwarearrest.com
Removed hosts entry: 127.0.0.1 www.adwarearrest.com
Removed hosts entry: 127.0.0.1 www.adwarebazooka.com
Removed hosts entry: 127.0.0.1 adwarebazooka.com
Removed hosts entry: 127.0.0.1 www.adwarecommander.com
Removed hosts entry: 127.0.0.1 adwarecommander.com
Removed hosts entry: 127.0.0.1 adwarefinder.com
Removed hosts entry: 127.0.0.1 www.adwarefinder.com
Removed hosts entry: 127.0.0.1 www.adwaregold.com
Removed hosts entry: 127.0.0.1 adwaregold.com
Removed hosts entry: 127.0.0.1 www.adwarepatrol.com
Removed hosts entry: 127.0.0.1 adwarepatrol.com
Removed hosts entry: 127.0.0.1 www.adwareplatinum.com
Removed hosts entry: 127.0.0.1 adwareplatinum.com
Removed hosts entry: 127.0.0.1 adwareprotectionsite.com
Removed hosts entry: 127.0.0.1 www.adwareprotectionsite.com
Removed hosts entry: 127.0.0.1 www.adwarepunisher.com
Removed hosts entry: 127.0.0.1 adwarepunisher.com
Removed hosts entry: 127.0.0.1 www.adwaresafety.com
Removed hosts entry: 127.0.0.1 adwaresafety.com
Removed hosts entry: 127.0.0.1 www.adwarexp.com
Removed hosts entry: 127.0.0.1 adwarexp.com
Removed hosts entry: 127.0.0.1 affiliate.idownload.com
Removed hosts entry: 127.0.0.1 aflgate.com
Removed hosts entry: 127.0.0.1 www.aflgate.com
Removed hosts entry: 127.0.0.1 africaspromise.org
Removed hosts entry: 127.0.0.1 agava.com
Removed hosts entry: 127.0.0.1 agentstudio.com
Removed hosts entry: 127.0.0.1 airtleworld.com
Removed hosts entry: 127.0.0.1 www.airtleworld.com
Removed hosts entry: 127.0.0.1 akamai.downloadv3.com
Removed hosts entry: 127.0.0.1 akril.com
Removed hosts entry: 127.0.0.1 www.alertspy.com
Removed hosts entry: 127.0.0.1 alertspy.com
Removed hosts entry: 127.0.0.1 alfacleaner.com
Removed hosts entry: 127.0.0.1 www.alfacleaner.com
Removed hosts entry: 127.0.0.1 alfa-search.com
Removed hosts entry: 127.0.0.1 all1count.net
Removed hosts entry: 127.0.0.1 www.all1count.net
Removed hosts entry: 127.0.0.1 www.all4internet.com
Removed hosts entry: 127.0.0.1 all4internet.com
Removed hosts entry: 127.0.0.1 allabtcars.com
Removed hosts entry: 127.0.0.1 allabtjeeps.com
Removed hosts entry: 127.0.0.1 all-bittorrent.com
Removed hosts entry: 127.0.0.1 www.all-bittorrent.com
Removed hosts entry: 127.0.0.1 www.allcollisions.com
Removed hosts entry: 127.0.0.1 allcollisions.com
Removed hosts entry: 127.0.0.1 allcybersearch.com
Removed hosts entry: 127.0.0.1 www.allcybersearch.com
Removed hosts entry: 127.0.0.1 www.alldnserrors.com
Removed hosts entry: 127.0.0.1 alldnserrors.com
Removed hosts entry: 127.0.0.1 www.all-downloads-now.com
Removed hosts entry: 127.0.0.1 all-downloads-now.com
Removed hosts entry: 127.0.0.1 www.all-edonkey.com
Removed hosts entry: 127.0.0.1 all-edonkey.com
Removed hosts entry: 127.0.0.1 www.allertaminacce.com
Removed hosts entry: 127.0.0.1 allertaminacce.com
Removed hosts entry: 127.0.0.1 allforadult.com
Removed hosts entry: 127.0.0.1 allhyperlinks.com
Removed hosts entry: 127.0.0.1 www.alliesecurity.com
Removed hosts entry: 127.0.0.1 alliesecurity.com
Removed hosts entry: 127.0.0.1 all-inet.com
Removed hosts entry: 127.0.0.1 allinternetbusiness.com
Removed hosts entry: 127.0.0.1 all-limewire.com
Removed hosts entry: 127.0.0.1 www.all-limewire.com
Removed hosts entry: 127.0.0.1 www.allmegabucks.com
Removed hosts entry: 127.0.0.1 allmegabucks.com
Removed hosts entry: 127.0.0.1 www.allprotections.com
Removed hosts entry: 127.0.0.1 allprotections.com
Removed hosts entry: 127.0.0.1 allresultz.net
Removed hosts entry: 127.0.0.1 www.allresultz.net
Removed hosts entry: 127.0.0.1 www.allsearch.us
Removed hosts entry: 127.0.0.1 allsearch.us
Removed hosts entry: 127.0.0.1 www.allsecuritynotes.com
Removed hosts entry: 127.0.0.1 allsecuritynotes.com
Removed hosts entry: 127.0.0.1 www.allsecuritysite.com
Removed hosts entry: 127.0.0.1 allsecuritysite.com
Removed hosts entry: 127.0.0.1 allstarsvideos.net
Removed hosts entry: 127.0.0.1 www.allstarsvideos.net
Removed hosts entry: 127.0.0.1 www.alltiettantivirus.com
Removed hosts entry: 127.0.0.1 alltiettantivirus.com
Removed hosts entry: 127.0.0.1 www.alltruesoftware.com
Removed hosts entry: 127.0.0.1 alltruesoftware.com
Removed hosts entry: 127.0.0.1 www.allvideoactivex.com
Removed hosts entry: 127.0.0.1 allvideoactivex.com
Removed hosts entry: 127.0.0.1 almanah.biz
Removed hosts entry: 127.0.0.1 www.almanah.biz
Removed hosts entry: 127.0.0.1 almarvideos.com
Removed hosts entry: 127.0.0.1 www.amaena.com
Removed hosts entry: 127.0.0.1 amaena.com
Removed hosts entry: 127.0.0.1 amandamountains.com
Removed hosts entry: 127.0.0.1 amateurliveshow.com
Removed hosts entry: 127.0.0.1 www.amateurliveshow.com
Removed hosts entry: 127.0.0.1 www.amediasoftware.com
Removed hosts entry: 127.0.0.1 amediasoftware.com
Removed hosts entry: 127.0.0.1 www.amediasource.com
Removed hosts entry: 127.0.0.1 amediasource.com
Removed hosts entry: 127.0.0.1 www.americanautobargains.com
Removed hosts entry: 127.0.0.1 americanautobargains.com
Removed hosts entry: 127.0.0.1 www.americancarbargains.com
Removed hosts entry: 127.0.0.1 americancarbargains.com
Removed hosts entry: 127.0.0.1 american-teens.net
Removed hosts entry: 127.0.0.1 amigeek.com
Removed hosts entry: 127.0.0.1 www.amigobore.com
Removed hosts entry: 127.0.0.1 amigobore.com
Removed hosts entry: 127.0.0.1 amisbusiness.com
Removed hosts entry: 127.0.0.1 www.ampmsearch.com
Removed hosts entry: 127.0.0.1 ampmsearch.com
Removed hosts entry: 127.0.0.1 analcord.com
Removed hosts entry: 127.0.0.1 www.analcord.com
Removed hosts entry: 127.0.0.1 analmovi.com
Removed hosts entry: 127.0.0.1 www.anarchylolita.com
Removed hosts entry: 127.0.0.1 anarchylolita.com
Removed hosts entry: 127.0.0.1 anarchyporn.com
Removed hosts entry: 127.0.0.1 www.andromedical.com
Removed hosts entry: 127.0.0.1 andromedical.com
Removed hosts entry: 127.0.0.1 animepornmag.com
Removed hosts entry: 127.0.0.1 www.animepornmag.com
Removed hosts entry: 127.0.0.1 anin.org
Removed hosts entry: 127.0.0.1 www.anjpn-avxiz.biz
Removed hosts entry: 127.0.0.1 anjpn-avxiz.biz
Removed hosts entry: 127.0.0.1 www.anjpnzqav.biz
Removed hosts entry: 127.0.0.1 anjpnzqav.biz
Removed hosts entry: 127.0.0.1 www.anjpn-zqav.biz
Removed hosts entry: 127.0.0.1 anjpn-zqav.biz
Removed hosts entry: 127.0.0.1 annaromeo.com
Removed hosts entry: 127.0.0.1 www.antiddos.us
Removed hosts entry: 127.0.0.1 antiddos.us
Removed hosts entry: 127.0.0.1 www.antiespiadorado.com
Removed hosts entry: 127.0.0.1 antiespiadorado.com
Removed hosts entry: 127.0.0.1 antiespionspack.com
Removed hosts entry: 127.0.0.1 www.antiespionspack.com
Removed hosts entry: 127.0.0.1 www.antigusanos2008.com
Removed hosts entry: 127.0.0.1 antigusanos2008.com
Removed hosts entry: 127.0.0.1 antispamassistant.com
Removed hosts entry: 127.0.0.1 www.antispamassistant.com
Removed hosts entry: 127.0.0.1 www.antispamdeluxe.com
Removed hosts entry: 127.0.0.1 antispamdeluxe.com
Removed hosts entry: 127.0.0.1 www.antispionage.com
Removed hosts entry: 127.0.0.1 antispionage.com
Removed hosts entry: 127.0.0.1 antispionagepro.com
Removed hosts entry: 127.0.0.1 www.antispionagepro.com
Removed hosts entry: 127.0.0.1 www.antispyadvanced.com
Removed hosts entry: 127.0.0.1 antispyadvanced.com
Removed hosts entry: 127.0.0.1 antispydns.biz
Removed hosts entry: 127.0.0.1 www.antispydns.biz
Removed hosts entry: 127.0.0.1 antispylab.com
Removed hosts entry: 127.0.0.1 www.antispylab.com
Removed hosts entry: 127.0.0.1 antispysolutions.com
Removed hosts entry: 127.0.0.1 www.antispysolutions.com
Removed hosts entry: 127.0.0.1 antispyware.com
Removed hosts entry: 127.0.0.1 www.antispyware.com
Removed hosts entry: 127.0.0.1 www.antispywareboot.com
Removed hosts entry: 127.0.0.1 antispywareboot.com
Removed hosts entry: 127.0.0.1 antispywarebot.com
Removed hosts entry: 127.0.0.1 www.antispywarebot.com
Removed hosts entry: 127.0.0.1 www.antispywarebox.com
Removed hosts entry: 127.0.0.1 antispywarebox.com
Removed hosts entry: 127.0.0.1 www.antispywaredownloads.com
Removed hosts entry: 127.0.0.1 antispywaredownloads.com
Removed hosts entry: 127.0.0.1 www.antispywaresuite.com
Removed hosts entry: 127.0.0.1 antispywaresuite.com
Removed hosts entry: 127.0.0.1 www.antispywaresuite.com
Removed hosts entry: 127.0.0.1 antispywaresuite.com
Removed hosts entry: 127.0.0.1 antispywarexp.com
Removed hosts entry: 127.0.0.1 www.antispywarexp.com
Removed hosts entry: 127.0.0.1 www.antispyweb.net
Removed hosts entry: 127.0.0.1 antispyweb.net
Removed hosts entry: 127.0.0.1 www.antiver2008.com
Removed hosts entry: 127.0.0.1 antiver2008.com
Removed hosts entry: 127.0.0.1 www.antivermins.com
Removed hosts entry: 127.0.0.1 antivermins.com
Removed hosts entry: 127.0.0.1 www.anti-vermins.com
Removed hosts entry: 127.0.0.1 anti-vermins.com
Removed hosts entry: 127.0.0.1 antivir2007.com
Removed hosts entry: 127.0.0.1 www.antivir2007.com
Removed hosts entry: 127.0.0.1 www.antivirgear.com
Removed hosts entry: 127.0.0.1 antivirgear.com
Removed hosts entry: 127.0.0.1 www.antivirus.fastfreedownload.com
Removed hosts entry: 127.0.0.1 antivirus.fastfreedownload.com
Removed hosts entry: 127.0.0.1 www.antivirusadvance.com
Removed hosts entry: 127.0.0.1 antivirusadvance.com
Removed hosts entry: 127.0.0.1 www.antivirusaskeladd.com
Removed hosts entry: 127.0.0.1 antivirusaskeladd.com
Removed hosts entry: 127.0.0.1 www.antivirusgereedschap.com
Removed hosts entry: 127.0.0.1 antivirusgereedschap.com
Removed hosts entry: 127.0.0.1 www.antivirusgolden.com
Removed hosts entry: 127.0.0.1 antivirusgolden.com
Removed hosts entry: 127.0.0.1 www.antivirus-hq.net
Removed hosts entry: 127.0.0.1 antivirus-hq.net
Removed hosts entry: 127.0.0.1 www.antiviruspcsuite.com
Removed hosts entry: 127.0.0.1 antiviruspcsuite.com
Removed hosts entry: 127.0.0.1 www.antiviruspremium.com
Removed hosts entry: 127.0.0.1 antiviruspremium.com
Removed hosts entry: 127.0.0.1 www.anti-virus-pro.com
Removed hosts entry: 127.0.0.1 anti-virus-pro.com
Removed hosts entry: 127.0.0.1 www.antivirusprotector.com
Removed hosts entry: 127.0.0.1 antivirusprotector.com
Removed hosts entry: 127.0.0.1 www.antivirusscherm.com
Removed hosts entry: 127.0.0.1 antivirusscherm.com
Removed hosts entry: 127.0.0.1 www.antivirussecuritypro.com
Removed hosts entry: 127.0.0.1 antivirussecuritypro.com
Removed hosts entry: 127.0.0.1 antivirus-stop.com
Removed hosts entry: 127.0.0.1 www.antivirus-stop.com
Removed hosts entry: 127.0.0.1 antiworm2008.com
Removed hosts entry: 127.0.0.1 www.antiworm2008.com
Removed hosts entry: 127.0.0.1 antiworm2008.com
Removed hosts entry: 127.0.0.1 www.antiworm2008.com
Removed hosts entry: 127.0.0.1 www.antiwurm2008.com
Removed hosts entry: 127.0.0.1 antiwurm2008.com
Removed hosts entry: 127.0.0.1 antrocity.com
Removed hosts entry: 127.0.0.1 anyofus.com
Removed hosts entry: 127.0.0.1 www.anyofus.com
Removed hosts entry: 127.0.0.1 anysn.seproger.com
Removed hosts entry: 127.0.0.1 www.anysn.seproger.com
Removed hosts entry: 127.0.0.1 anything4health.com
Removed hosts entry: 127.0.0.1 www.apicpreview.com
Removed hosts entry: 127.0.0.1 apicpreview.com
Removed hosts entry: 127.0.0.1 www.appealcircuit.com
Removed hosts entry: 127.0.0.1 appealcircuit.com
Removed hosts entry: 127.0.0.1 approvedlinks.com
Removed hosts entry: 127.0.0.1 www.approvedlinks.com
Removed hosts entry: 127.0.0.1 apps.deskwizz.com
Removed hosts entry: 127.0.0.1 apps.webservicehost.com
Removed hosts entry: 127.0.0.1 aprotectedpage.com
Removed hosts entry: 127.0.0.1 www.aprotectedpage.com
Removed hosts entry: 127.0.0.1 apsua.com
Removed hosts entry: 127.0.0.1 www.archivioadulti.com
Removed hosts entry: 127.0.0.1 archivioadulti.com
Removed hosts entry: 127.0.0.1 archiviosex.net
Removed hosts entry: 127.0.0.1 www.archiviosex.net
Removed hosts entry: 127.0.0.1 aregay.com
Removed hosts entry: 127.0.0.1 www.ares.click-new-download.com
Removed hosts entry: 127.0.0.1 ares.click-new-download.com
Removed hosts entry: 127.0.0.1 www.ares-freebie.com
Removed hosts entry: 127.0.0.1 ares-freebie.com
Removed hosts entry: 127.0.0.1 www.arespro2007.com
Removed hosts entry: 127.0.0.1 arespro2007.com
Removed hosts entry: 127.0.0.1 www.aresultra.com
Removed hosts entry: 127.0.0.1 aresultra.com
Removed hosts entry: 127.0.0.1 ares-usa.com
Removed hosts entry: 127.0.0.1 www.ares-usa.com
Removed hosts entry: 127.0.0.1 arheo.com
Removed hosts entry: 127.0.0.1 arizonaweb.org
Removed hosts entry: 127.0.0.1 armitageinn.com
Removed hosts entry: 127.0.0.1 www.arquivojpgs.smtp.ru
Removed hosts entry: 127.0.0.1 artachnid.com
Removed hosts entry: 127.0.0.1 art-func.com
Removed hosts entry: 127.0.0.1 art-xxx.com
Removed hosts entry: 127.0.0.1 www.asafebrowser.com
Removed hosts entry: 127.0.0.1 asafebrowser.com
Removed hosts entry: 127.0.0.1 www.asafetyalways.com
Removed hosts entry: 127.0.0.1 asafetyalways.com
Removed hosts entry: 127.0.0.1 www.asafetynotice.com
Removed hosts entry: 127.0.0.1 asafetynotice.com
Removed hosts entry: 127.0.0.1 www.asafetypage.com
Removed hosts entry: 127.0.0.1 asafetypage.com
Removed hosts entry: 127.0.0.1 asdbiz.biz
Removed hosts entry: 127.0.0.1 www.asdbiz.biz
Removed hosts entry: 127.0.0.1 www.asdeykuddq.com
Removed hosts entry: 127.0.0.1 asdeykuddq.com
Removed hosts entry: 127.0.0.1 www.asecurebar.com
Removed hosts entry: 127.0.0.1 asecurebar.com
Removed hosts entry: 127.0.0.1 asecureboard.com
Removed hosts entry: 127.0.0.1 www.asecureboard.com
Removed hosts entry: 127.0.0.1 www.asecurevalue.com
Removed hosts entry: 127.0.0.1 asecurevalue.com
Removed hosts entry: 127.0.0.1 www.asecurityissue.com
Removed hosts entry: 127.0.0.1 asecurityissue.com
Removed hosts entry: 127.0.0.1 asecuritynotice.com
Removed hosts entry: 127.0.0.1 www.asecuritynotice.com
Removed hosts entry: 127.0.0.1 www.asecuritypaper.com
Removed hosts entry: 127.0.0.1 asecuritypaper.com
Removed hosts entry: 127.0.0.1 www.asecuritystuff.com
Removed hosts entry: 127.0.0.1 asecuritystuff.com
Removed hosts entry: 127.0.0.1 asiankingkong.com
Removed hosts entry: 127.0.0.1 asianpornmag.com
Removed hosts entry: 127.0.0.1 www.asianpornmag.com
Removed hosts entry: 127.0.0.1 www.asiantoolbar.com
Removed hosts entry: 127.0.0.1 asiantoolbar.com
Removed hosts entry: 127.0.0.1 www.asidseiupc.com
Removed hosts entry: 127.0.0.1 asidseiupc.com
Removed hosts entry: 127.0.0.1 ass-gals.com
Removed hosts entry: 127.0.0.1 www.assureprotection.com
Removed hosts entry: 127.0.0.1 assureprotection.com
Removed hosts entry: 127.0.0.1 asta-killer.com
Removed hosts entry: 127.0.0.1 ataprogram.com
Removed hosts entry: 127.0.0.1 www.ataprogram.com
Removed hosts entry: 127.0.0.1 athenrye.com
Removed hosts entry: 127.0.0.1 atotalsafety.com
Removed hosts entry: 127.0.0.1 www.atotalsafety.com
Removed hosts entry: 127.0.0.1 www.atrueprotection.com
Removed hosts entry: 127.0.0.1 atrueprotection.com
Removed hosts entry: 127.0.0.1 www.atruesecurity.com
Removed hosts entry: 127.0.0.1 atruesecurity.com
Removed hosts entry: 127.0.0.1 www.attackware.com
Removed hosts entry: 127.0.0.1 attackware.com
Removed hosts entry: 127.0.0.1 www.attrezzi.biz
Removed hosts entry: 127.0.0.1 attrezzi.biz
Removed hosts entry: 127.0.0.1 www.aucunsvirus.com
Removed hosts entry: 127.0.0.1 aucunsvirus.com
Removed hosts entry: 127.0.0.1 www.aulde.net
Removed hosts entry: 127.0.0.1 aulde.net
Removed hosts entry: 127.0.0.1 www.autobargains.org
Removed hosts entry: 127.0.0.1 autobargains.org
Removed hosts entry: 127.0.0.1 www.autobargainsnetwork.com
Removed hosts entry: 127.0.0.1 autobargainsnetwork.com
Removed hosts entry: 127.0.0.1 autocontext.begun.ru
Removed hosts entry: 127.0.0.1 www.autocontext.begun.ru
Removed hosts entry: 127.0.0.1 autoescrowpay.com
Removed hosts entry: 127.0.0.1 www.avadvance.com
Removed hosts entry: 127.0.0.1 avadvance.com
Removed hosts entry: 127.0.0.1 www.avast.free-software-center.com
Removed hosts entry: 127.0.0.1 avast.free-software-center.com
Removed hosts entry: 127.0.0.1 www.avast-2007.com
Removed hosts entry: 127.0.0.1 avast-2007.com
Removed hosts entry: 127.0.0.1 avast-downloads.com
Removed hosts entry: 127.0.0.1 www.avast-downloads.com
Removed hosts entry: 127.0.0.1 www.avast-hq.com
Removed hosts entry: 127.0.0.1 avast-hq.com
Removed hosts entry: 127.0.0.1 www.avforce.com
Removed hosts entry: 127.0.0.1 avforce.com
Removed hosts entry: 127.0.0.1 www.avg.grab-it-today.net
Removed hosts entry: 127.0.0.1 avg.grab-it-today.net
Removed hosts entry: 127.0.0.1 www.avg.softwarecenterz.com
Removed hosts entry: 127.0.0.1 avg.softwarecenterz.com
Removed hosts entry: 127.0.0.1 www.avg-secure.com
Removed hosts entry: 127.0.0.1 avg-secure.com
Removed hosts entry: 127.0.0.1 avian-ads.com
Removed hosts entry: 127.0.0.1 www.avideoaxaccess.com
Removed hosts entry: 127.0.0.1 avideoaxaccess.com
Removed hosts entry: 127.0.0.1 avideosurfer.com
Removed hosts entry: 127.0.0.1 www.avideosurfer.com
Removed hosts entry: 127.0.0.1 www.aviewersoft.com
Removed hosts entry: 127.0.0.1 aviewersoft.com
Removed hosts entry: 127.0.0.1 www.avpcheckupdate.com
Removed hosts entry: 127.0.0.1 avpcheckupdate.com
Removed hosts entry: 127.0.0.1 avsmanufacture.com
Removed hosts entry: 127.0.0.1 www.avsmanufacture.com
Removed hosts entry: 127.0.0.1 www.avsystemcare.com
Removed hosts entry: 127.0.0.1 avsystemcare.com
Removed hosts entry: 127.0.0.1 www.avxizaaqada.biz
Removed hosts entry: 127.0.0.1 avxizaaqada.biz
Removed hosts entry: 127.0.0.1 www.avxiz-anjpn.biz
Removed hosts entry: 127.0.0.1 avxiz-anjpn.biz
Removed hosts entry: 127.0.0.1 avxizueorn.biz
Removed hosts entry: 127.0.0.1 www.avxizueorn.biz
Removed hosts entry: 127.0.0.1 www.avxiz-ueorn.biz
Removed hosts entry: 127.0.0.1 avxiz-ueorn.biz
Removed hosts entry: 127.0.0.1 www.avxiz-vtvcp.biz
Removed hosts entry: 127.0.0.1 avxiz-vtvcp.biz
Removed hosts entry: 127.0.0.1 www.avxiz-ygco.biz
Removed hosts entry: 127.0.0.1 avxiz-ygco.biz
Removed hosts entry: 127.0.0.1 www.avxiz-zqav.biz
Removed hosts entry: 127.0.0.1 avxiz-zqav.biz
Removed hosts entry: 127.0.0.1 awarenesstech.com
Removed hosts entry: 127.0.0.1 www.awarenesstech.com
Removed hosts entry: 127.0.0.1 www.awarninglist.com
Removed hosts entry: 127.0.0.1 awarninglist.com
Removed hosts entry: 127.0.0.1 awbeta.net-nucleus.com
Removed hosts entry: 127.0.0.1 www.awesomehomepage.com
Removed hosts entry: 127.0.0.1 awesomehomepage.com
Removed hosts entry: 127.0.0.1 awmcash.biz
Removed hosts entry: 127.0.0.1 awmdabest.com
Removed hosts entry: 127.0.0.1 www.axemediasoftware.com
Removed hosts entry: 127.0.0.1 axemediasoftware.com
Removed hosts entry: 127.0.0.1 www.aximageobject.com
Removed hosts entry: 127.0.0.1 aximageobject.com
Removed hosts entry: 127.0.0.1 www.axmediaproject.com
Removed hosts entry: 127.0.0.1 axmediaproject.com
Removed hosts entry: 127.0.0.1 www.axmediasoftware.com
Removed hosts entry: 127.0.0.1 axmediasoftware.com
Removed hosts entry: 127.0.0.1 www.axmediasolutions.com
Removed hosts entry: 127.0.0.1 axmediasolutions.com
Removed hosts entry: 127.0.0.1 www.axobjectpage.com
Removed hosts entry: 127.0.0.1 axobjectpage.com
Removed hosts entry: 127.0.0.1 www.axobjectsource.com
Removed hosts entry: 127.0.0.1 axobjectsource.com
Removed hosts entry: 127.0.0.1 www.axsoftwaretool.com
Removed hosts entry: 127.0.0.1 axsoftwaretool.com
Removed hosts entry: 127.0.0.1 www.axvideoproject.com
Removed hosts entry: 127.0.0.1 axvideoproject.com
Removed hosts entry: 127.0.0.1 www.axvideosetup.com
Removed hosts entry: 127.0.0.1 axvideosetup.com
Removed hosts entry: 127.0.0.1 ayakawamura.com
Removed hosts entry: 127.0.0.1 ayb.dns-look-up.com
Removed hosts entry: 127.0.0.1 ayb.netbios-wait.com
Removed hosts entry: 127.0.0.1 ayumitaniguchi.com
Removed hosts entry: 127.0.0.1 azebar.com
Removed hosts entry: 127.0.0.1 www.azureusclub.com
Removed hosts entry: 127.0.0.1 azureusclub.com
Removed hosts entry: 127.0.0.1 www.azureus-freebie.com
Removed hosts entry: 127.0.0.1 azureus-freebie.com
Removed hosts entry: 127.0.0.1 b.casalemedia.com
Removed hosts entry: 127.0.0.1 b122.mcboo.com
Removed hosts entry: 127.0.0.1 www.babe.k-lined.com
Removed hosts entry: 127.0.0.1 babe.k-lined.com
Removed hosts entry: 127.0.0.1 www.babenet.com
Removed hosts entry: 127.0.0.1 babenet.com
Removed hosts entry: 127.0.0.1 www.babespornmag.com
Removed hosts entry: 127.0.0.1 babespornmag.com
Removed hosts entry: 127.0.0.1 backstripgirls.com
Removed hosts entry: 127.0.0.1 www.backstripgirls.com
Removed hosts entry: 127.0.0.1 backup.mabou.org
Removed hosts entry: 127.0.0.1 balotierra.com
Removed hosts entry: 127.0.0.1 www.balotierra.com
Removed hosts entry: 127.0.0.1 bannedhost.net
Removed hosts entry: 127.0.0.1 barbudafarms.com
Removed hosts entry: 127.0.0.1 www.bardownload.com
Removed hosts entry: 127.0.0.1 bardownload.com
Removed hosts entry: 127.0.0.1 barnandfence.com
Removed hosts entry: 127.0.0.1 batsearch.com
Removed hosts entry: 127.0.0.1 baygraphicsllc.com
Removed hosts entry: 127.0.0.1 bbbsearch.com
Removed hosts entry: 127.0.0.1 bb-search.com
Removed hosts entry: 127.0.0.1 bcnproduction.com
Removed hosts entry: 127.0.0.1 www.bcnproduction.com
Removed hosts entry: 127.0.0.1 bdsmlibrary.net
Removed hosts entry: 127.0.0.1 www.bdsmpornmag.com
Removed hosts entry: 127.0.0.1 bdsmpornmag.com
Removed hosts entry: 127.0.0.1 www.bearshare.click-new-download.com
Removed hosts entry: 127.0.0.1 bearshare.click-new-download.com
Removed hosts entry: 127.0.0.1 www.bearshare.download-me.info
Removed hosts entry: 127.0.0.1 bearshare.download-me.info
Removed hosts entry: 127.0.0.1 www.bearshare.mp3-muzic.com
Removed hosts entry: 127.0.0.1 bearshare.mp3-muzic.com
Removed hosts entry: 127.0.0.1 www.bearshare-download.org
Removed hosts entry: 127.0.0.1 bearshare-download.org
Removed hosts entry: 127.0.0.1 www.bearshare-downloads.net
Removed hosts entry: 127.0.0.1 bearshare-downloads.net
Removed hosts entry: 127.0.0.1 www.bearsharelive.co.uk
Removed hosts entry: 127.0.0.1 www.bearshare-music-downloads.com
Removed hosts entry: 127.0.0.1 bearshare-music-downloads.com
Removed hosts entry: 127.0.0.1 www.bearsharepro2007.com
Removed hosts entry: 127.0.0.1 bearsharepro2007.com
Removed hosts entry: 127.0.0.1 bearshare-usa.com
Removed hosts entry: 127.0.0.1 www.bearshare-usa.com
Removed hosts entry: 127.0.0.1 bedhome.com
Removed hosts entry: 127.0.0.1 bediadance.com
Removed hosts entry: 127.0.0.1 www.beebappyy.biz
Removed hosts entry: 127.0.0.1 beebappyy.biz
Removed hosts entry: 127.0.0.1 www.begin2search.com
Removed hosts entry: 127.0.0.1 begin2search.com
Removed hosts entry: 127.0.0.1 bellabasketsfl.com
Removed hosts entry: 127.0.0.1 bernaolatwin.com
Removed hosts entry: 127.0.0.1 www.beruijindegunhadesun.com
Removed hosts entry: 127.0.0.1 beruijindegunhadesun.com
Removed hosts entry: 127.0.0.1 best3xclips.com
Removed hosts entry: 127.0.0.1 www.best3xclips.com
Removed hosts entry: 127.0.0.1 bestadults.com
Removed hosts entry: 127.0.0.1 www.bestadults.com
Removed hosts entry: 127.0.0.1 best-counter.com
Removed hosts entry: 127.0.0.1 bestcrawler.com
Removed hosts entry: 127.0.0.1 bestdailyvids.com
Removed hosts entry: 127.0.0.1 www.bestdailyvids.com
Removed hosts entry: 127.0.0.1 www.bestfuckvids.com
Removed hosts entry: 127.0.0.1 bestfuckvids.com
Removed hosts entry: 127.0.0.1 best-hardpics.com
Removed hosts entry: 127.0.0.1 bestmanage.org
Removed hosts entry: 127.0.0.1 www.bestmanage.org
Removed hosts entry: 127.0.0.1 www.bestmanage0.org
Removed hosts entry: 127.0.0.1 bestmanage0.org
Removed hosts entry: 127.0.0.1 bestmanage1.org
Removed hosts entry: 127.0.0.1 www.bestmanage1.org
Removed hosts entry: 127.0.0.1 www.bestmanage2.org
Removed hosts entry: 127.0.0.1 bestmanage2.org
Removed hosts entry: 127.0.0.1 www.bestmanage3.org
Removed hosts entry: 127.0.0.1 bestmanage3.org
Removed hosts entry: 127.0.0.1 www.bestmanage4.org
Removed hosts entry: 127.0.0.1 bestmanage4.org
Removed hosts entry: 127.0.0.1 www.bestmanage5.org
Removed hosts entry: 127.0.0.1 bestmanage5.org
Removed hosts entry: 127.0.0.1 www.bestmanage6.org
Removed hosts entry: 127.0.0.1 bestmanage6.org
Removed hosts entry: 127.0.0.1 www.bestmanage7.org
Removed hosts entry: 127.0.0.1 bestmanage7.org
Removed hosts entry: 127.0.0.1 www.bestmanage8.org
Removed hosts entry: 127.0.0.1 bestmanage8.org
Removed hosts entry: 127.0.0.1 www.bestmanage9.org
Removed hosts entry: 127.0.0.1 bestmanage9.org
Removed hosts entry: 127.0.0.1 www.bestoffersnetworks.com
Removed hosts entry: 127.0.0.1 bestoffersnetworks.com
Removed hosts entry: 127.0.0.1 bestporngate.com
Removed hosts entry: 127.0.0.1 www.bestsafetyguide.net
Removed hosts entry: 127.0.0.1 bestsafetyguide.net
Removed hosts entry: 127.0.0.1 www.bestsearch.cc
Removed hosts entry: 127.0.0.1 bestsearch.cc
Removed hosts entry: 127.0.0.1 www.best-targeted-traffic.com
Removed hosts entry: 127.0.0.1 best-targeted-traffic.com
Removed hosts entry: 127.0.0.1 bestweblinks.com
Removed hosts entry: 127.0.0.1 best-winning-casino.com
Removed hosts entry: 127.0.0.1 www.bestworldgirls-for-u.net
Removed hosts entry: 127.0.0.1 bestworldgirls-for-u.net
Removed hosts entry: 127.0.0.1 www.bestxclips.com
Removed hosts entry: 127.0.0.1 bestxclips.com
Removed hosts entry: 127.0.0.1 bestxporno.com
Removed hosts entry: 127.0.0.1 www.bestxxxmpegs.com
Removed hosts entry: 127.0.0.1 bestxxxmpegs.com
Removed hosts entry: 127.0.0.1 bettersearch.biz
Removed hosts entry: 127.0.0.1 www.bettersearch.biz
Removed hosts entry: 127.0.0.1 bgoogle.it
Removed hosts entry: 127.0.0.1 www.bgoogle.it
Removed hosts entry: 127.0.0.1 bigtrafficnetwork.com
Removed hosts entry: 127.0.0.1 www.bigtrafficnetwork.com
Removed hosts entry: 127.0.0.1 www.bigwww.com
Removed hosts entry: 127.0.0.1 bigwww.com
Removed hosts entry: 127.0.0.1 bin.errorprotector.com
Removed hosts entry: 127.0.0.1 bins.media-motor.net
Removed hosts entry: 127.0.0.1 bins2.media-motor.net
Removed hosts entry: 127.0.0.1 bis.180solutions.com
Removed hosts entry: 127.0.0.1 bitchesonline.net
Removed hosts entry: 127.0.0.1 www.bitcomet-freebie.com
Removed hosts entry: 127.0.0.1 bitcomet-freebie.com
Removed hosts entry: 127.0.0.1 www.bittorrent.click-new-download.com
Removed hosts entry: 127.0.0.1 bittorrent.click-new-download.com
Removed hosts entry: 127.0.0.1 biz.biz
Removed hosts entry: 127.0.0.1 bkvcompany.com
Removed hosts entry: 127.0.0.1 www.bkvcompany.com
Removed hosts entry: 127.0.0.1 www.blackblues00.com
Removed hosts entry: 127.0.0.1 blackblues00.com
Removed hosts entry: 127.0.0.1 www.blackcodec.net
Removed hosts entry: 127.0.0.1 blackcodec.net
Removed hosts entry: 127.0.0.1 blackhawksoftware.com
Removed hosts entry: 127.0.0.1 www.blackhawksoftware.com
Removed hosts entry: 127.0.0.1 blackjack-free.net
Removed hosts entry: 127.0.0.1 blazefind.com
Removed hosts entry: 127.0.0.1 blondetgp.com
Removed hosts entry: 127.0.0.1 www.blue-elefant.com
Removed hosts entry: 127.0.0.1 blue-elefant.com
Removed hosts entry: 127.0.0.1 www.bm.theaimonline.com
Removed hosts entry: 127.0.0.1 bm.theaimonline.com
Removed hosts entry: 127.0.0.1 www.bnmgate.com
Removed hosts entry: 127.0.0.1 bnmgate.com
Removed hosts entry: 127.0.0.1 bodaciousbabette.com
Removed hosts entry: 127.0.0.1 www.bonzi.com
Removed hosts entry: 127.0.0.1 bonzi.com
Removed hosts entry: 127.0.0.1 boobdoll.com
Removed hosts entry: 127.0.0.1 boobsandtits.com
Removed hosts entry: 127.0.0.1 boobsclub.com
Removed hosts entry: 127.0.0.1 www.bookedspace.com
Removed hosts entry: 127.0.0.1 bookedspace.com
Removed hosts entry: 127.0.0.1 boredlife.com
Removed hosts entry: 127.0.0.1 bowlofogumbo.com
Removed hosts entry: 127.0.0.1 www.bpfq02.com
Removed hosts entry: 127.0.0.1 bpfq02.com
Removed hosts entry: 127.0.0.1 www.bqgate.com
Removed hosts entry: 127.0.0.1 bqgate.com
Removed hosts entry: 127.0.0.1 br.errorsafe.com
Removed hosts entry: 127.0.0.1 br.winantivirus.com
Removed hosts entry: 127.0.0.1 br.winfixer.com
Removed hosts entry: 127.0.0.1 bradcoem.org
Removed hosts entry: 127.0.0.1 www.braincodec.com
Removed hosts entry: 127.0.0.1 braincodec.com
Removed hosts entry: 127.0.0.1 brandiyoung.com
Removed hosts entry: 127.0.0.1 bravesentry.com
Removed hosts entry: 127.0.0.1 www.bravesentry.com
Removed hosts entry: 127.0.0.1 breenten.biz
Removed hosts entry: 127.0.0.1 www.breenten.biz
Removed hosts entry: 127.0.0.1 brodbfm.net
Removed hosts entry: 127.0.0.1 www.brodbfm.net
Removed hosts entry: 127.0.0.1 brookeburn.com
Removed hosts entry: 127.0.0.1 www.browserwise.com
Removed hosts entry: 127.0.0.1 browserwise.com
Removed hosts entry: 127.0.0.1 bsa.safetydownload.com
Removed hosts entry: 127.0.0.1 bsplaycodec.com
Removed hosts entry: 127.0.0.1 www.bsplaycodec.com
Removed hosts entry: 127.0.0.1 bucps.com
Removed hosts entry: 127.0.0.1 buldog-stats.com
Removed hosts entry: 127.0.0.1 www.bullseye-network.com
Removed hosts entry: 127.0.0.1 bullseye-network.com
Removed hosts entry: 127.0.0.1 burgerkingbigscreen.com
Removed hosts entry: 127.0.0.1 www.burningsite.com
Removed hosts entry: 127.0.0.1 burningsite.com
Removed hosts entry: 127.0.0.1 www.burnsrecyclinginc.com
Removed hosts entry: 127.0.0.1 burnsrecyclinginc.com
Removed hosts entry: 127.0.0.1 buscards.net
Removed hosts entry: 127.0.0.1 bustyrussell.com
Removed hosts entry: 127.0.0.1 www.busysearch.net
Removed hosts entry: 127.0.0.1 busysearch.net
Removed hosts entry: 127.0.0.1 buttejazz.org
Removed hosts entry: 127.0.0.1 buyselldomain.net
Removed hosts entry: 127.0.0.1 www.buytraff.biz
Removed hosts entry: 127.0.0.1 buytraff.biz
Removed hosts entry: 127.0.0.1 www.bvdtechinque.com
Removed hosts entry: 127.0.0.1 bvdtechinque.com
Removed hosts entry: 127.0.0.1 c.enhance.com
Removed hosts entry: 127.0.0.1 www.c.enhance.com
Removed hosts entry: 127.0.0.1 c.goclick.com
Removed hosts entry: 127.0.0.1 www.c4tdownload.com
Removed hosts entry: 127.0.0.1 c4tdownload.com
Removed hosts entry: 127.0.0.1 cache.surfaccuracy.com
Removed hosts entry: 127.0.0.1 www.cache.surfaccuracy.com
Removed hosts entry: 127.0.0.1 cache.ysbweb.com
Removed hosts entry: 127.0.0.1 www.cadesfinjeriokas.com
Removed hosts entry: 127.0.0.1 cadesfinjeriokas.com
Removed hosts entry: 127.0.0.1 calcioturris.com
Removed hosts entry: 127.0.0.1 calendaralerts.net
Removed hosts entry: 127.0.0.1 www.calendaralerts.net
Removed hosts entry: 127.0.0.1 callinghome.biz
Removed hosts entry: 127.0.0.1 www.callinghome.biz
Removed hosts entry: 127.0.0.1 www.cameouk.co.uk
Removed hosts entry: 127.0.0.1 cameup.com
Removed hosts entry: 127.0.0.1 camouflageclothingonline.net
Removed hosts entry: 127.0.0.1 www.camouflageclothingonline.net
Removed hosts entry: 127.0.0.1 campaigns.outerinfo.net
Removed hosts entry: 127.0.0.1 camup.net
Removed hosts entry: 127.0.0.1 canberracricketcoaching.com
Removed hosts entry: 127.0.0.1 candycantaloupes.com
Removed hosts entry: 127.0.0.1 www.canidetect.org
Removed hosts entry: 127.0.0.1 canidetect.org
Removed hosts entry: 127.0.0.1 cantfind.com
Removed hosts entry: 127.0.0.1 www.cantfind.com
Removed hosts entry: 127.0.0.1 careers.dulcineasystems.net
Removed hosts entry: 127.0.0.1 carsands.com
Removed hosts entry: 127.0.0.1 carsrentals.net
Removed hosts entry: 127.0.0.1 www.casalemedia.com
Removed hosts entry: 127.0.0.1 casalemedia.com
Removed hosts entry: 127.0.0.1 www.cashdeluxe.net
Removed hosts entry: 127.0.0.1 cashdeluxe.net
Removed hosts entry: 127.0.0.1 cashengines.com
Removed hosts entry: 127.0.0.1 www.cashengines.com
Removed hosts entry: 127.0.0.1 cashsearch.biz
Removed hosts entry: 127.0.0.1 www.cashsurfers.com
Removed hosts entry: 127.0.0.1 cashsurfers.com
Removed hosts entry: 127.0.0.1 www.cashunlim.com
Removed hosts entry: 127.0.0.1 cashunlim.com
Removed hosts entry: 127.0.0.1 casino.com.free.game.pogo.gratisdownloads.nl
Removed hosts entry: 127.0.0.1 casino2win.net
Removed hosts entry: 127.0.0.1 casino-gambling-1.net
Removed hosts entry: 127.0.0.1 casino-gambling-2.net
Removed hosts entry: 127.0.0.1 casinomidas.net
Removed hosts entry: 127.0.0.1 casinonline.net
Removed hosts entry: 127.0.0.1 casino-onlines.net
Removed hosts entry: 127.0.0.1 castingsamateur.com
Removed hosts entry: 127.0.0.1 www.castingsamateur.com
Removed hosts entry: 127.0.0.1 catallogue.com
Removed hosts entry: 127.0.0.1 categories.mygeek.com
Removed hosts entry: 127.0.0.1 cc.panet.org
Removed hosts entry: 127.0.0.1 www.ccecaedbebfcaf.com
Removed hosts entry: 127.0.0.1 ccecaedbebfcaf.com
Removed hosts entry: 127.0.0.1 cclebali.org
Removed hosts entry: 127.0.0.1 www.cdcopysite.com
Removed hosts entry: 127.0.0.1 cdcopysite.com
Removed hosts entry: 127.0.0.1 www.cdegate.com
Removed hosts entry: 127.0.0.1 cdegate.com
Removed hosts entry: 127.0.0.1 cdn.drivecleaner.com
Removed hosts entry: 127.0.0.1 cdn.errorsafe.com
Removed hosts entry: 127.0.0.1 cdn.movies-etc.com
Removed hosts entry: 127.0.0.1 cdn.winsoftware.com
Removed hosts entry: 127.0.0.1 cdn2.movies-etc.com
Removed hosts entry: 127.0.0.1 ceewawires.org
Removed hosts entry: 127.0.0.1 certumgroup.com
Removed hosts entry: 127.0.0.1 www.check.jupitersatellites.biz
Removed hosts entry: 127.0.0.1 check.jupitersatellites.biz
Removed hosts entry: 127.0.0.1 www.checkin100.com
Removed hosts entry: 127.0.0.1 checkin100.com
Removed hosts entry: 127.0.0.1 checkssecurity.com
Removed hosts entry: 127.0.0.1 www.checkssecurity.com
Removed hosts entry: 127.0.0.1 chelancatering.com
Removed hosts entry: 127.0.0.1 www.chenshijituan.com
Removed hosts entry: 127.0.0.1 chenshijituan.com
Removed hosts entry: 127.0.0.1 childrenvilla.com
Removed hosts entry: 127.0.0.1 www.chilly3xvids.com
Removed hosts entry: 127.0.0.1 chilly3xvids.com
Removed hosts entry: 127.0.0.1 www.chillymovs.com
Removed hosts entry: 127.0.0.1 chillymovs.com
Removed hosts entry: 127.0.0.1 chips-4-free.com
Removed hosts entry: 127.0.0.1 chrisswasey.com
Removed hosts entry: 127.0.0.1 chriswallace.net
Removed hosts entry: 127.0.0.1 www.cia-trjn.myvnc.com
Removed hosts entry: 127.0.0.1 cia-trjn.myvnc.com
Removed hosts entry: 127.0.0.1 www.cinemadownload.com
Removed hosts entry: 127.0.0.1 cinemadownload.com
Removed hosts entry: 127.0.0.1 ckick4thumbs.com
Removed hosts entry: 127.0.0.1 cl55.biz
Removed hosts entry: 127.0.0.1 clackamasliteraryreview.com
Removed hosts entry: 127.0.0.1 www.clckm.com
Removed hosts entry: 127.0.0.1 clckm.com
Removed hosts entry: 127.0.0.1 www.cleancodec.com
Removed hosts entry: 127.0.0.1 cleancodec.com
Removed hosts entry: 127.0.0.1 www.cleansoftwares.com
Removed hosts entry: 127.0.0.1 cleansoftwares.com
Removed hosts entry: 127.0.0.1 clearsearch.cc
Removed hosts entry: 127.0.0.1 clearsearch.net
Removed hosts entry: 127.0.0.1 clickaire.com
Removed hosts entry: 127.0.0.1 www.click-codec.com
Removed hosts entry: 127.0.0.1 click-codec.com
Removed hosts entry: 127.0.0.1 www.clickhere4search.com
Removed hosts entry: 127.0.0.1 clickhere4search.com
Removed hosts entry: 127.0.0.1 www.click-new-download.com
Removed hosts entry: 127.0.0.1 click-new-download.com
Removed hosts entry: 127.0.0.1 click-now.net
Removed hosts entry: 127.0.0.1 clickspring.net
Removed hosts entry: 127.0.0.1 www.clickspring.net
Removed hosts entry: 127.0.0.1 www.click-to-download.com
Removed hosts entry: 127.0.0.1 click-to-download.com
Removed hosts entry: 127.0.0.1 www.clicktomakeasearch.com
Removed hosts entry: 127.0.0.1 clicktomakeasearch.com
Removed hosts entry: 127.0.0.1 clickyestoenter.net
Removed hosts entry: 127.0.0.1 client.exeupdate.com
Removed hosts entry: 127.0.0.1 client.myadultexplorer.com
Removed hosts entry: 127.0.0.1 www.cliks.org
Removed hosts entry: 127.0.0.1 cliks.org
Removed hosts entry: 127.0.0.1 clipsfestival.com
Removed hosts entry: 127.0.0.1 www.clipsfestival.com
Removed hosts entry: 127.0.0.1 www.clipsreality.com
Removed hosts entry: 127.0.0.1 clipsreality.com
Removed hosts entry: 127.0.0.1 clrsch.com
Removed hosts entry: 127.0.0.1 www.clubxxxvideo.com
Removed hosts entry: 127.0.0.1 clubxxxvideo.com
Removed hosts entry: 127.0.0.1 cmtapestry.com
Removed hosts entry: 127.0.0.1 www.cnetadd.com
Removed hosts entry: 127.0.0.1 cnetadd.com
Removed hosts entry: 127.0.0.1 www.cnomy.com
Removed hosts entry: 127.0.0.1 cnomy.com
Removed hosts entry: 127.0.0.1 cnzz.com
Removed hosts entry: 127.0.0.1 www.cnzz.com
Removed hosts entry: 127.0.0.1 code.ignphrases.com
Removed hosts entry: 127.0.0.1 codec.ninoa.com
Removed hosts entry: 127.0.0.1 codecbsplay.com
Removed hosts entry: 127.0.0.1 www.codecbsplay.com
Removed hosts entry: 127.0.0.1 codecdvd.net
Removed hosts entry: 127.0.0.1 www.codecdvd.net
Removed hosts entry: 127.0.0.1 www.codecdvi.com
Removed hosts entry: 127.0.0.1 codecdvi.com
Removed hosts entry: 127.0
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 11 Apr 2008 19:48    Oggetto: Rispondi citando

Come hai potuto vedere, Norman ha eliminato un pò di roba;

prova a vedere se Spybot ti segnala ancora quel dialer;

adesso fai la scansione con Systemscan e posta il log generato come
indicato quì
Top
Profilo Invia messaggio privato
mattia
Mortale adepto
Mortale adepto


Registrato: 31/07/07 15:07
Messaggi: 34

MessaggioInviato: 11 Apr 2008 21:04    Oggetto: Rispondi citando

Si, ho notato che ha eliminato un bel po' di cose!!
Ora spybot non mi segnala più il dialer ma un altro problema cioè "drivecleaner2006".
Ecco il log ti system scan: [URL="http://www.freefilehosting.net/files/3f6lb"]reportSS.txt[/URL]
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 11 Apr 2008 22:25    Oggetto: Rispondi citando

Nel log non c'è traccia di drivecleaner, tranne nel file hosts, ma sicuramente si tratta di una impostazione di Spybot e non ci sono problemi; puoi sempre controllare;

al limite puoi disattivare il TTimer oppure disinstallando e reinstallando Spybot;

posta un log di Hijackthis aggiornato;

installati un firewal

collegati a Kaspersky online scanner
Quando sta scaricando i file necessari, disattiva momentaneamente l'antivirus. Non appena inizia la scansione del PC disconnettiti da internet.
Alla fine carica il risultato su www.freefilehosting.net, riportando quì il link che ti viene assegnato come indicato quì
Top
Profilo Invia messaggio privato
mattia
Mortale adepto
Mortale adepto


Registrato: 31/07/07 15:07
Messaggi: 34

MessaggioInviato: 12 Apr 2008 13:22    Oggetto: Rispondi citando

Allora, ecco tutto:

Kaspersky: [URL="http://www.freefilehosting.net/files/3f7m3"]Kapersky.html[/URL]

mentre per il log di HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13.13.47, on 12/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\VEXPLITE\MONLITE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\VEXPLITE\viritsvc.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Programmi\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Programmi\internet explorer\iexplore.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmi\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = silv-mi-proxy.eu.corp.arrow.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.1.1;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\VEXPLITE\MONLITE.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?f063cfb8e05e48d493383af303d84d67
O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?f063cfb8e05e48d493383af303d84d67
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1163597914468
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Programmi\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas www.tgsoft.it - C:\VEXPLITE\viritsvc.exe

--
End of file - 8886 bytes

Spero che ora sia tutto a posto...ho installato il firewall! Smile
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 12 Apr 2008 18:51    Oggetto: Rispondi citando

Scusate l'intromissione, ma è meglio cancellare anche i seguenti files:
Citazione:
"2008-04-11 15:00:00 C:\WINDOWS\Tasks\BE24A32D88435B69.job"
- c:\docume~1\admini~1\datiap~1\objbib\About2drive.exe
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 12 Apr 2008 19:00    Oggetto: Rispondi citando

Scarica The Avenger (Nuova versione)
Scompattalo in una sua cartella in c:\
Avvialo e clicca su OK
all'interno del box bianco
Inserisci queste righe: (aggiungo anche quelle indicate da Bdoriano)
Citazione:
files to delete:
C:\Documents and Settings\Administrator\Dati applicazioni\Sun\Java\Deployment\cache\6.0\50\5861d0f2-2148349e
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EJ2BQD23\lc1009[1].htm
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\WTABCDEZ\us1009[1].anr
C:\WINDOWS\Tasks\BE24A32D88435B69.job
c:\docume~1\admini~1\datiap~1\objbib\About2drive.exe

Clicca su Execute
Il pc dovrebbe riavviarsi, se così non fosse, riavvialo tu.
Attenzione a non lasciare interlinee inutili ad esempio:
Citazione:
files to delete:

xxxxxxxxxxx

Al termine dell'operazione, si dovrebbe aprire il blocco note con il risultato, altrimenti lo trovi su C:\Avenger.txt
Top
Profilo Invia messaggio privato
mattia
Mortale adepto
Mortale adepto


Registrato: 31/07/07 15:07
Messaggi: 34

MessaggioInviato: 13 Apr 2008 02:47    Oggetto: Rispondi citando

Mi spiace, ho provato più volte ad eseguire il programma ma mi dà sempre errore nonostante non lasci spazi tra le righe e copi esattamente il contenuto. non so il perchè!
Ti posto comunque il log anche se credo che sia inutile, ma amgari capisci dove sbaglio. L'errore che mi segnala quando lancio il programma è lo stesso riportato nel log

Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Apr 13 02:28:52 2008

02:28:52: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Apr 13 02:31:08 2008

02:31:08: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Apr 13 02:31:15 2008

02:31:15: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Apr 13 02:32:03 2008

02:32:03: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Apr 13 02:32:09 2008

02:32:09: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Apr 13 02:32:37 2008

02:32:37: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Apr 13 02:32:57 2008

02:32:57: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Apr 13 02:34:50 2008

02:34:50: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Apr 13 02:34:58 2008

02:34:58: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Sun Apr 13 02:36:29 2008

02:36:29: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 13 Apr 2008 12:25    Oggetto: Rispondi citando

E' strano perchè dovrebbe funzionare...

Prova con Systemscan;

avvialo e clicca su Removal Script;

nel box inserisci lo script;

clicca su proceed with removal.
Top
Profilo Invia messaggio privato
mattia
Mortale adepto
Mortale adepto


Registrato: 31/07/07 15:07
Messaggi: 34

MessaggioInviato: 13 Apr 2008 12:47    Oggetto: Rispondi citando

Con Systemscan ce l'ho fatta!
ecco il log

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\fftbmkqd

*******************

Script file located at: \??\C:\dfqwbvmi.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\Documents and Settings\Administrator\Dati applicazioni\Sun\Java\Deployment\cache\6.0\50\5861d0f2-2148349e deleted successfully.


File C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EJ2BQD23\lc1009[1].htm not found!
Deletion of file C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EJ2BQD23\lc1009[1].htm failed!

Could not process line:
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\EJ2BQD23\lc1009[1].htm
Status: 0xc0000034



File C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\WTABCDEZ\us1009[1].anr not found!
Deletion of file C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\WTABCDEZ\us1009[1].anr failed!

Could not process line:
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\WTABCDEZ\us1009[1].anr
Status: 0xc0000034

File C:\WINDOWS\Tasks\BE24A32D88435B69.job deleted successfully.


File c:\docume~1\admini~1\datiap~1\objbib\About2drive.exe not found!
Deletion of file c:\docume~1\admini~1\datiap~1\objbib\About2drive.exe failed!

Could not process line:
c:\docume~1\admini~1\datiap~1\objbib\About2drive.exe
Status: 0xc0000034

Program C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\WTABCDEZ\sys91287[1].exe successfully set up to run once on reboot.

Completed script processing.

*******************

Finished! Terminate.

e log aggiornato di hjt
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12.45.34, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
C:\Programmi\Sunbelt Software\Personal Firewall\kpf4ss.exe
c:\Programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\VEXPLITE\viritsvc.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Programmi\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Programmi\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe
C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\VEXPLITE\MONLITE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmi\Windows Live\Messenger\usnsvc.exe
C:\Programmi\internet explorer\iexplore.exe
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Programmi\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = silv-mi-proxy.eu.corp.arrow.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.1.1;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] C:\VEXPLITE\MONLITE.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?f063cfb8e05e48d493383af303d84d67
O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?f063cfb8e05e48d493383af303d84d67
O8 - Extra context menu item: Invia a &Bluetooth - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Inserisci &blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmi\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1163597914468
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Programmi\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programmi\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Programmi\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas www.tgsoft.it - C:\VEXPLITE\viritsvc.exe

--
End of file - 9173 bytes
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 13 Apr 2008 20:23    Oggetto: Rispondi citando

Bene, ora dovresti essere a posto;

utilizza CCleaner; Avvialo e clicca su opzioni->Avanzate, e togli la spunta da "elimina file solo se più vecchi di 48 ore"
Utilizza l'opzione Pulizia e poi clicca su Analizza; alla fine clicca su Avvia Pulizia. Fai la stessa cosa con l'opzione Trova problemi; eliminerà una serie di chiavi di registro inutili;

inoltre deframmenta il disco; per farlo anzichè l'utilità di sistema prova
Auslogics disc defrag che è superiore...
Top
Profilo Invia messaggio privato
mattia
Mortale adepto
Mortale adepto


Registrato: 31/07/07 15:07
Messaggi: 34

MessaggioInviato: 13 Apr 2008 20:45    Oggetto: Rispondi citando

OK! ho già scaricato il programma e fatto la deframmentazione!
Grazie per la disponibilità e la pazienza! Very Happy
Buona serata
Top
Profilo Invia messaggio privato
Sante62
Dio maturo
Dio maturo


Registrato: 27/06/07 17:55
Messaggi: 3477
Residenza: Floridia

MessaggioInviato: 13 Apr 2008 22:37    Oggetto: Rispondi

Ciao
Top
Profilo Invia messaggio privato
Mostra prima i messaggi di:   
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus Tutti i fusi orari sono GMT + 2 ore
Pagina 1 di 1

 
Vai a:  
Non puoi inserire nuovi argomenti
Non puoi rispondere a nessun argomento
Non puoi modificare i tuoi messaggi
Non puoi cancellare i tuoi messaggi
Non puoi votare nei sondaggi