| 
                 
                
                
                 
                
		 
	
		| Precedente :: Successivo   | 
	 
	
	
		| Autore | 
		Messaggio | 
	 
	
		andrea1975 Dio maturo
  
  
  Registrato: 07/12/06 18:58 Messaggi: 4052
 
  | 
		
			
				 Inviato: 27 Set 2013 21:01    Oggetto: Pc lento con strani effetti e pubblicità a go-go, Help! | 
				     | 
			 
			
				
  | 
			 
			
				Ciao.
 
una mia amica ha un problema con il suo pc che è lento, si aprono finestre di pubblicità a casaccio e ogni tanto si apre una finesta di pubblicità che si sovrappone alla pagina aperta (con l'opzione skip in basso a destra) e molto spesso si impalla sia internet explorer che il pc in generale.
 
Sempre nelle pagine internet si aprono finestre di pubblicità anche su singole parole (blu con doppia sottolineatura) che diventano link anche che non lo sono e la finestra manda a (public8media.com)
 
Altro problema alle volte all'accensione sembra che si avvii normalmente carica la scritta con la marca del computer ma poi lo schermo resta grigio con delle righe che sembrano spostarsi.
 
 
Ha fatto la scansione antivirus con Avast e non ha rilevato nessun virus o malware.
 
Il sistema operativo è vista.
 
 
Posto qui il log di HijackThis, scusate se lo posto per intero ma non ricordo dove si condivideva il file.  
 
 
Logfile of Trend Micro HijackThis v2.0.5
 
Scan saved at 19.40.28, on 27/09/2013
 
Platform: Windows Vista SP2 (WinNT 6.00.1906)
 
MSIE: Internet Explorer v9.00 (9.00.8112.16506)
 
 
 
Boot mode: Normal
 
 
Running processes:
 
C:\Windows\system32\Dwm.exe
 
C:\Windows\Explorer.EXE
 
C:\Program Files\Windows Defender\MSASCui.exe
 
C:\Windows\system32\taskeng.exe
 
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
 
C:\Windows\System32\hkcmd.exe
 
C:\Windows\System32\igfxpers.exe
 
C:\Windows\system32\igfxsrvc.exe
 
C:\Windows\ehome\ehtray.exe
 
C:\Program Files\Windows Media Player\wmpnscfg.exe
 
C:\Program Files\Microsoft Works\WkCalRem.exe
 
C:\Windows\ehome\ehmsas.exe
 
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
 
C:\Users\Public\Documents\AppData\PoApp\PService.exe
 
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
 
C:\Windows\system32\wbem\unsecapp.exe
 
C:\Program Files\Internet Explorer\iexplore.exe
 
C:\Program Files\Internet Explorer\iexplore.exe
 
C:\program files\plus-hd-2.2\plus-hd-2.2-bg.exe
 
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_175_ActiveX.exe
 
C:\Program Files\Internet Explorer\iexplore.exe
 
C:\Users\marta\Desktop\HijackThis\HijackThis.exe
 
C:\Windows\system32\DllHost.exe
 
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=84&bd=Presario&pf=cndt
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.it/
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=84&bd=Presario&pf=cndt
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=nv2&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyDyCyD0FyCzy0D0DyB0DyBtN0D0Tzu0CyEyCzytN1L2XzutBtFtBtFtCtFyDyByBtN1L1Czu1G2XtB&cr=78132891&ir=
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;<local>;*.local
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
 
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
 
O1 - Hosts: ::1 localhost
 
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 
O2 - BHO: CrossriderApp0033036 - {11111111-1111-1111-1111-110311301136} - C:\Program Files\Plus-HD-2.2\Plus-HD-2.2-bho.dll
 
O2 - BHO: Secured eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSecu.dll
 
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
 
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
 
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_16\bin\ssv.dll
 
O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (file missing)
 
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
 
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.6.0_16\bin\jp2ssv.dll
 
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll
 
O3 - Toolbar: Secured eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSecu.dll
 
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
 
O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
 
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
 
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
 
O4 - HKLM\..\Run: [TQ566808] "E:\Setup.exe"
 
O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe
 
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
 
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
 
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
 
O4 - HKLM\..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe
 
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
 
O4 - HKLM\..\RunOnce: [aswAhAScr.dll] "C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe" "C:\Program Files\Alwil Software\Avast5\AhAScr.dll"
 
O4 - HKLM\..\RunOnce: [aswasOutExt.dll] "C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe" "C:\Program Files\Alwil Software\Avast5\asOutExt.dll"
 
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
 
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
 
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\marta\AppData\Local\Akamai\netsession_win.exe"
 
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 
O4 - HKCU\..\Run: [Eraser] K:\winPenPack\Bin\Eraser\eraser.exe -hide
 
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
 
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
 
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
 
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
 
O4 - Startup: wkcalrem.LNK = C:\Program Files\Microsoft Works\WkCalRem.exe
 
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 
O8 - Extra context menu item: Add to AMV/AVI Video Converter... - C:\Program Files\Media Player Utilities 4.25\AMVConverter\grab.html
 
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
 
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
 
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
 
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} (20-20 3D Viewer for IKEA) - http://kitchenplanner.ikea.com/IT/Core/Player/2020PlayerAX_IKEA_Win32.cab
 
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} (DownloaderActiveX Control) - http://c6.community.virgilio.it/download/DownloaderActiveX.cab
 
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.fueps.com/gp/images/common/games/PopCapGames/popcaploader_v10_it.cab
 
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{302960E9-3C0B-47F4-A0A4-C245B0FAF888}: NameServer = 8.8.8.8,8.8.4.4
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{80EC53E5-E8E7-4BE6-AA36-52D752B675FE}: NameServer = 8.8.8.8,8.8.4.4
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{958BA84C-7DBB-4B78-92E6-363A90E977F7}: NameServer = 8.8.8.8,8.8.4.4
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC8CBC0F-435A-4724-9518-71690FEA6ABA}: NameServer = 8.8.8.8,8.8.4.4
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1B4D561-E020-490B-9922-C3BD2D57E662}: NameServer = 8.8.8.8,8.8.4.4
 
O17 - HKLM\System\CS1\Services\Tcpip\..\{302960E9-3C0B-47F4-A0A4-C245B0FAF888}: NameServer = 8.8.8.8,8.8.4.4
 
O17 - HKLM\System\CS2\Services\Tcpip\..\{302960E9-3C0B-47F4-A0A4-C245B0FAF888}: NameServer = 8.8.8.8,8.8.4.4
 
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
 
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
 
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
 
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\Alwil Software\Avast5\afwServ.exe
 
O23 - Service:  Servizio Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
 
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
 
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files\WildTangent Games\App\GamesAppIntegrationService.exe
 
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
 
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
 
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
 
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
 
O23 - Service: Pos Service (PowerOffer Service) - PowerOfferService - C:\Users\marta\AppData\Local\PosService\Pos.exe
 
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
 
O23 - Service: Serv Updater (ServUpdater) - ServiceUpd - C:\Users\marta\AppData\Local\ServUpdater\ServiceUpd.exe
 
O23 - Service: Software Upd (SoftwareUpd) - SoftwareUpdService - C:\Users\marta\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe
 
 
--
 
End of file - 11230 bytes
 
 
Mi potete dare una mano?
 
Grazie
 
Andrea | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		R16 Dio maturo
  
  
  Registrato: 07/03/08 22:58 Messaggi: 10129
 
  | 
		
			
				 Inviato: 27 Set 2013 21:30    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Ciao.
 
Scarica Adwcleaner sul desktop:
 
link
 
Chiudi tutti i browser, (è importante IE,Firefox Chrome ecc...)
 
Clicca sul pulsante "Scan".
 
Finita la scansione clicca su "Clean"
 
Conferma con OK le varie finestre che ti compariranno.
 
Il pc si riavvierà, e uscirà il log con le eliminazioni.
 
Postalo qui.
 
 
Poi:
 
scarica Junkware Removal Tool sul desktop.
 
link
 
Disattiva temporaneamente l'antivirus per evitare potenziali conflitti.
 
Doppio click su JRT
 
Lo strumento si aprirà e avvierà la scansione del sistema.
 
Devi avere pazienza in quanto questo tool può richiedere del tempo per completare la scansione .
 
Al termine, un log (JRT.txt) viene salvato sul desktop e si aprirà automaticamente.
 
Postalo qui.
 
 
Per ultimo:
 
Fai questa scansione con OTL. 
 
http://forum.zeusnews.com/viewtopic.php?t=51382
 
 
Per postare i log:
 
Collegati ad internet e vai alla pagina WikiSend:  
 
link 
 
Clicca sul bottone "Sfoglia" 
 
Seleziona il file appena salvato 
 
Clicca su Upload file 
 
Dopo qualche secondo, vieni spostato su una nuova pagina con il link in diversi formati: 
 
Download Link / Forum Link 
 
Seleziona Forum Link, copialo e incollalo in un nuovo messaggio per il forum. | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		andrea1975 Dio maturo
  
  
  Registrato: 07/12/06 18:58 Messaggi: 4052
 
  | 
		
			
				 Inviato: 28 Set 2013 10:52    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Ciao grazie,
 
 
inizio a postare il primo log.
 
 
Questo è quello di Adwcleaner
 
 log.txt]AdwCleaner[R0] log.txt
 
 
non appena riesce a scaricare e fare le altre "scansioni" posterò anche gli altri.
 
 
Andrea | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		R16 Dio maturo
  
  
  Registrato: 07/03/08 22:58 Messaggi: 10129
 
  | 
		
			
				 Inviato: 28 Set 2013 13:59    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				 	  | Citazione: | 	 		  Questo è quello di Adwcleaner
 
log.txt]AdwCleaner[R0] log.txt | 	  
 
Quello è il log delle infezioni che ha trovato.
 
Per eliminarle devi premere il pulsante "Clean". | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		andrea1975 Dio maturo
  
  
  Registrato: 07/12/06 18:58 Messaggi: 4052
 
  | 
		
			
				 Inviato: 28 Set 2013 14:10    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				ah, chiedo scusa non lo sapevo  
 
appena riesco mi faccio mandare quello giusto e lo posto.
 
Grazie | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		andrea1975 Dio maturo
  
  
  Registrato: 07/12/06 18:58 Messaggi: 4052
 
  | 
		 | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		R16 Dio maturo
  
  
  Registrato: 07/03/08 22:58 Messaggi: 10129
 
  | 
		
			
				 Inviato: 03 Ott 2013 17:58    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Ciao.
 
Avvia OTL.
 
 
Sotto "Custom Scans\Fixes" copia-incolla questo codice:
 
 
 	  | Codice: | 	 		  :OTL
 
SRV - File not found [Auto | Stopped] -- C:\Users\marta\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe -- (SoftwareUpd)
 
SRV - [2012/04/03 19.59.46 | 000,169,472 | ---- | M] (PowerOfferService) [Auto | Stopped] -- C:\Users\marta\AppData\Local\PosService\Pos.exe -- (PowerOffer Service)
 
SRV - [2011/12/16 18.44.48 | 000,156,160 | ---- | M] (ServiceUpd) [Auto | Stopped] -- C:\Users\marta\AppData\Local\ServUpdater\ServiceUpd.exe -- (ServUpdater)
 
SRV - [2010/10/12 19.59.12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local
 
[2013/05/01 16.41.07 | 000,000,000 | ---D | M] (Speed Analysis 2) -- C:\Users\marta\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
 
[2013/06/30 10.44.04 | 000,233,016 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc3@hdvidcodec.com.xpi
 
[2013/04/08 19.11.52 | 000,216,492 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc@hdvc.com.xpi
 
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
 
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
 
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)
 
O4 - HKLM..\Run: [TQ566808] "E:\Setup.exe" File not found
 
O4 - HKCU..\Run: [Eraser] K:\winPenPack\Bin\Eraser\eraser.exe -hide File not found
 
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
 
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/IT/Core/Player/2020PlayerAX_IKEA_Win32.cab (20-20 3D Viewer for IKEA)
 
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
 
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
 
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} http://c6.community.virgilio.it/download/DownloaderActiveX.cab (DownloaderActiveX Control)
 
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 10.13.2)
 
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.fueps.com/gp/images/common/games/PopCapGames/popcaploader_v10_it.cab (Reg Error: Key error.)
 
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
 
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell - "" = AutoRun
 
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell\AutoRun\command - "" = F:\AutoRun.exe
 
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell - "" = AutoRun
 
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
 
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell - "" = AutoRun
 
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
 
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\AutoRun\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
 
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\open\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
 
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell - "" = AutoRun
 
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell\AutoRun\command - "" = F:\TicToc.exe
 
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell - "" = AutoRun
 
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell\AutoRun\command - "" = E:\ShelExec.exe index.htm
 
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell - "" = AutoRun
 
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell\AutoRun\command - "" = G:\Setup.exe
 
[2012/06/17 17.56.09 | 000,715,038 | ---- | C] () -- C:\Users\marta\AppData\Local\unins000.exe
 
[2012/06/17 17.56.09 | 000,004,003 | ---- | C] () -- C:\Users\marta\AppData\Local\unins000.dat
 
[2009/10/27 05.01.41 | 000,027,820 | ---- | C] () -- C:\Users\marta\AppData\Local\slot1.mm1
 
[2009/05/10 10.57.27 | 000,286,440 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_nav.dat
 
[2009/05/10 10.57.27 | 000,003,205 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek.dat
 
[2009/05/10 10.57.27 | 000,000,328 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_navps.dat
 
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:BF89B7E7
 
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:E51234A9
 
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:E119EB0E
 
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:0E22C5DB
 
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:700B9342
 
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:9E76E7F3
 
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:123A86B5
 
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0EC7A545
 
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:1B7E2022
 
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:EDC744FB
 
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E7B4296D
 
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:80F63EC3
 
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:32A82570
 
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:C72A744C
 
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:147A3409
 
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:737160C1
 
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:0F38B460
 
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:EA10407C
 
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:6017A808
 
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:FED25C29
 
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:7FCB9D0D
 
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:F84B8DB5
 
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:6444B424
 
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:5BC73C48
 
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:162E02F7
 
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5FA4CB99
 
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:1F96ED45
 
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:870649A4
 
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:68EF6203
 
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:55818279
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:DD04902E
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C22674B6
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:BDF08FAF
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A02025CE
 
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:50636E35
 
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4F96D8E6
 
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E80802C7
 
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:2B1EA607
 
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:1B9E79B3
 
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F1DEA771
 
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:E91ADC66
 
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:842B0AED
 
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:40D8F125
 
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:98DFF516
 
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:0ED4AC2F
 
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:BB3CECA4
 
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:8401B6D5
 
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:EEB25EAE
 
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:BD9F7E4E
 
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:8247A199
 
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:BD36345D
 
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:69AF9D20
 
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:9C012695
 
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:592D7272
 
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:4FE42FFC
 
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:C07A6A6B
 
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:569CEE83
 
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:3D36932D
 
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:59C113EC
 
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:5E9B629B
 
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:1A4BF204
 
 
:Files
 
C:\Users\marta\AppData\Local\SoftwareUpdater
 
C:\Users\marta\AppData\Local\PosService
 
C:\Users\marta\AppData\Local\ServUpdater
 
C:\Users\Public\Documents\AppData\PoApp
 
ipconfig /flushdns /c
 
 
:reg
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
 
""=""%1" %*" 
 
 
:commands
 
[purity]
 
[emptytemp]
 
[Emptyjava]
 
[RESETHOSTS]
 
[EMPTYFLASH]
 
[start explorer]
 
[Reboot] | 	  
 
 
Clicca sul pulsante RUN FIX.
 
Lascia fare la scansione senza interferire.
 
Posta il log. | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		andrea1975 Dio maturo
  
  
  Registrato: 07/12/06 18:58 Messaggi: 4052
 
  | 
		 | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		R16 Dio maturo
  
  
  Registrato: 07/03/08 22:58 Messaggi: 10129
 
  | 
		
			
				 Inviato: 04 Ott 2013 17:36    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				 	  | Citazione: | 	 		  | spero di aver fatto giusto. | 	  
 
Non ha funzionato.
 
Rifai una scansione con OTL configurandolo con questi parametri:
 
 
Apri OTL.
 
Metti la spunta su SCAN ALL USERS.
 
 
Sotto output, metti la spunta : minimal output
 
 
Clicca sulla freccettina di File Age e seleziona 60 Days
 
 
Metti la spunta a LOP Check e  Purity Check.
 
 
Clicca su RUN SCAN
 
 
Lascia fare la scansione senza interferire.
 
Finita la scansione posta il log. (ne rilascerà 1 solo OTL.txt) | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		andrea1975 Dio maturo
  
  
  Registrato: 07/12/06 18:58 Messaggi: 4052
 
  | 
		
			
				 Inviato: 06 Ott 2013 11:54    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				opsss sorry     
 
 
ecco il log che mi appena inviato la mia amica
 
 
OTL.Txt
 
 
Grazie ancora
 
Andrea | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		R16 Dio maturo
  
  
  Registrato: 07/03/08 22:58 Messaggi: 10129
 
  | 
		
			
				 Inviato: 06 Ott 2013 13:29    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				Ciao .
 
Segui attentamente queste indicazioni:
 
 
Avvia OTL.
 
 
Sotto "Custom Scans\Fixes" copia-incolla questo codice: (NON copiare la parola Codice:
 
 
 
 	  | Codice: | 	 		  :OTL
 
SRV - (PowerOffer Service) -- C:\Users\marta\AppData\Local\PosService\Pos.exe (PowerOfferService)
 
SRV - (ServUpdater) -- C:\Users\marta\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)
 
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
 
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
 
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
 
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
 
IE - HKU\S-1-5-21-2492967055-2021645066-3165184103-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local
 
[2013/05/01 16.41.07 | 000,000,000 | ---D | M] (Speed Analysis 2) -- C:\Users\marta\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
 
[2013/06/30 10.44.04 | 000,233,016 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc3@hdvidcodec.com.xpi
 
[2013/04/08 19.11.52 | 000,216,492 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc@hdvc.com.xpi
 
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
 
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)
 
O4 - HKLM..\Run: [TQ566808] "E:\Setup.exe" File not found
 
O4 - HKU\S-1-5-21-2492967055-2021645066-3165184103-1000..\Run: [Eraser] K:\winPenPack\Bin\Eraser\eraser.exe -hide File not found
 
O4 - HKU\S-1-5-21-2492967055-2021645066-3165184103-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
 
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/IT/Core/Player/2020PlayerAX_IKEA_Win32.cab (20-20 3D Viewer for IKEA)
 
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
 
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
 
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} http://c6.community.virgilio.it/download/DownloaderActiveX.cab (DownloaderActiveX Control)
 
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 10.13.2)
 
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.fueps.com/gp/images/common/games/PopCapGames/popcaploader_v10_it.cab (Reg Error: Key error.)
 
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
 
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell - "" = AutoRun
 
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell\AutoRun\command - "" = F:\AutoRun.exe
 
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell - "" = AutoRun
 
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
 
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell - "" = AutoRun
 
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
 
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\AutoRun\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
 
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\open\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
 
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell - "" = AutoRun
 
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell\AutoRun\command - "" = F:\TicToc.exe
 
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell - "" = AutoRun
 
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell\AutoRun\command - "" = E:\ShelExec.exe index.htm
 
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell - "" = AutoRun
 
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell\AutoRun\command - "" = G:\Setup.exe
 
[2009/05/10 10.57.27 | 000,286,440 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_nav.dat
 
[2009/05/10 10.57.27 | 000,003,205 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek.dat
 
[2009/05/10 10.57.27 | 000,000,328 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_navps.dat
 
[2009/01/23 06.09.14 | 000,000,088 | ---- | C] () -- C:\Users\marta\AppData\Local\lptaeae.bat
 
[2010/08/19 20.35.40 | 000,000,000 | -HSD | M] -- C:\Users\marta\AppData\Roaming\.#
 
[2011/12/16 20.53.13 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\.minecraft
 
[2012/10/13 23.01.21 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\4Free
 
[2010/06/17 10.18.42 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\7Wonders
 
[2009/06/19 11.28.38 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Abakt
 
[2009/10/18 16.11.07 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Activision
 
[2009/06/27 16.24.51 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Alawar
 
[2013/08/24 21.23.10 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\AlawarEntertainment
 
[2009/06/19 14.00.35 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Anabel
 
[2012/06/24 09.26.31 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Anarchy
 
[2009/09/03 19.08.01 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Artogon
 
[2009/02/07 09.00.05 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\AVG7
 
[2009/10/18 12.17.27 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Awem
 
[2010/09/18 16.41.11 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Babylonia
 
[2011/06/25 11.52.24 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Friday's games
 
[2012/07/01 10.36.18 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Frogwares
 
[2010/09/01 07.38.34 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Fugazo
 
[2009/04/18 15.20.34 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Gaijin Ent
 
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:BF89B7E7
 
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:E51234A9
 
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:E119EB0E
 
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:0E22C5DB
 
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:700B9342
 
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:9E76E7F3
 
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:123A86B5
 
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0EC7A545
 
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:1B7E2022
 
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:EDC744FB
 
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E7B4296D
 
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:80F63EC3
 
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:32A82570
 
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:C72A744C
 
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:147A3409
 
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:737160C1
 
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:0F38B460
 
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:EA10407C
 
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:6017A808
 
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:FED25C29
 
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:7FCB9D0D
 
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:F84B8DB5
 
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:6444B424
 
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:5BC73C48
 
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:162E02F7
 
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5FA4CB99
 
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:1F96ED45
 
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:870649A4
 
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:68EF6203
 
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:55818279
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:DD04902E
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C22674B6
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:BDF08FAF
 
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A02025CE
 
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:50636E35
 
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4F96D8E6
 
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E80802C7
 
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:2B1EA607
 
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:1B9E79B3
 
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F1DEA771
 
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:E91ADC66
 
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:842B0AED
 
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:40D8F125
 
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:98DFF516
 
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:0ED4AC2F
 
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:BB3CECA4
 
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:8401B6D5
 
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:EEB25EAE
 
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:BD9F7E4E
 
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:8247A199
 
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:BD36345D
 
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:69AF9D20
 
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:9C012695
 
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:592D7272
 
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:4FE42FFC
 
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:C07A6A6B
 
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:569CEE83
 
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:3D36932D
 
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:59C113EC
 
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:5E9B629B
 
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:1A4BF204
 
 
:Files
 
C:\Users\marta\AppData\Local\PosService
 
C:\Users\marta\AppData\Local\ServUpdater
 
C:\Users\Public\Documents\AppData\PoApp
 
ipconfig /flushdns /c
 
 
:reg
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
 
""=""%1" %*" 
 
 
:commands
 
[purity]
 
[emptytemp]
 
[Emptyjava]
 
[RESETHOSTS]
 
[EMPTYFLASH]
 
[start explorer]
 
[Reboot] | 	  
 
 
Clicca sul pulsante RUN FIX.
 
Lascia fare la scansione senza interferire.
 
Posta il log. | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		andrea1975 Dio maturo
  
  
  Registrato: 07/12/06 18:58 Messaggi: 4052
 
  | 
		
			
				 Inviato: 08 Ott 2013 18:27    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				ciao fatto la scansione con otl e questo è il log:
 
 
OTL.Txt 81013.txt
 
 
però non sono sicuro che abbia funzionato...
 
 
ho fatto lo stamp delle impostazioni di otl, sono giuste?
 
 
 
 
 
Uploaded with ImageShack.us
 
 
O è da rifare con le configurazioni del post precedente?
 
 
grazie per la pazienza... | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		R16 Dio maturo
  
  
  Registrato: 07/03/08 22:58 Messaggi: 10129
 
  | 
		
			
				 Inviato: 08 Ott 2013 18:55    Oggetto:  | 
				     | 
			 
			
				
  | 
			 
			
				 	  | Citazione: | 	 		  | ho fatto lo stamp delle impostazioni di otl, sono giuste? | 	  
 
No non sono giuste.
 
Metti la spunta in SCAN ALL USERS
 
 
Riprova a copiare-incollare lo script sotto Custom Scans\Fixes
 
Poi clicca RUN FIX (NON RUN SCAN)
 
 
Se non funziona prova in Modalità provvisoria. | 
			 
		  | 
	 
	
		| Top | 
		 | 
	 
	
		  | 
	 
	
		 | 
	 
 
  
	 
	    
	   | 
	
Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento Non puoi modificare i tuoi messaggi Non puoi cancellare i tuoi messaggi Non puoi votare nei sondaggi
  | 
   
 
  
 
		 |