Indice del forum Olimpo Informatico
I Forum di Zeus News
Leggi la newsletter gratuita - Attiva il Menu compatto
 
 FAQFAQ   CercaCerca   Lista utentiLista utenti   GruppiGruppi   RegistratiRegistrati 
 ProfiloProfilo   Messaggi privatiMessaggi privati   Log inLog in 

    Newsletter RSS Facebook Twitter Contatti Ricerca
Pc lento con strani effetti e pubblicità a go-go, Help!
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus
Precedente :: Successivo  
Autore Messaggio
andrea1975
Dio maturo
Dio maturo


Registrato: 07/12/06 18:58
Messaggi: 4052

MessaggioInviato: 27 Set 2013 21:01    Oggetto: Pc lento con strani effetti e pubblicità a go-go, Help! Rispondi citando

Ciao.
una mia amica ha un problema con il suo pc che è lento, si aprono finestre di pubblicità a casaccio e ogni tanto si apre una finesta di pubblicità che si sovrappone alla pagina aperta (con l'opzione skip in basso a destra) e molto spesso si impalla sia internet explorer che il pc in generale.
Sempre nelle pagine internet si aprono finestre di pubblicità anche su singole parole (blu con doppia sottolineatura) che diventano link anche che non lo sono e la finestra manda a (public8media.com)
Altro problema alle volte all'accensione sembra che si avvii normalmente carica la scritta con la marca del computer ma poi lo schermo resta grigio con delle righe che sembrano spostarsi.

Ha fatto la scansione antivirus con Avast e non ha rilevato nessun virus o malware.
Il sistema operativo è vista.

Posto qui il log di HijackThis, scusate se lo posto per intero ma non ricordo dove si condivideva il file. Very Happy

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 19.40.28, on 27/09/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16506)


Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft Works\WkCalRem.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Users\Public\Documents\AppData\PoApp\PService.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\program files\plus-hd-2.2\plus-hd-2.2-bg.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_175_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\marta\Desktop\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=84&bd=Presario&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=84&bd=Presario&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=nv2&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyDyCyD0FyCzy0D0DyB0DyBtN0D0Tzu0CyEyCzytN1L2XzutBtFtBtFtCtFyDyByBtN1L1Czu1G2XtB&cr=78132891&ir=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;<local>;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CrossriderApp0033036 - {11111111-1111-1111-1111-110311301136} - C:\Program Files\Plus-HD-2.2\Plus-HD-2.2-bho.dll
O2 - BHO: Secured eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSecu.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_16\bin\ssv.dll
O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (file missing)
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.6.0_16\bin\jp2ssv.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll
O3 - Toolbar: Secured eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSecu.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [TQ566808] "E:\Setup.exe"
O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\RunOnce: [aswAhAScr.dll] "C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe" "C:\Program Files\Alwil Software\Avast5\AhAScr.dll"
O4 - HKLM\..\RunOnce: [aswasOutExt.dll] "C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe" "C:\Program Files\Alwil Software\Avast5\asOutExt.dll"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\marta\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Eraser] K:\winPenPack\Bin\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O4 - Startup: wkcalrem.LNK = C:\Program Files\Microsoft Works\WkCalRem.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Add to AMV/AVI Video Converter... - C:\Program Files\Media Player Utilities 4.25\AMVConverter\grab.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} (20-20 3D Viewer for IKEA) - http://kitchenplanner.ikea.com/IT/Core/Player/2020PlayerAX_IKEA_Win32.cab
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} (DownloaderActiveX Control) - http://c6.community.virgilio.it/download/DownloaderActiveX.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.fueps.com/gp/images/common/games/PopCapGames/popcaploader_v10_it.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{302960E9-3C0B-47F4-A0A4-C245B0FAF888}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{80EC53E5-E8E7-4BE6-AA36-52D752B675FE}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{958BA84C-7DBB-4B78-92E6-363A90E977F7}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC8CBC0F-435A-4724-9518-71690FEA6ABA}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1B4D561-E020-490B-9922-C3BD2D57E662}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{302960E9-3C0B-47F4-A0A4-C245B0FAF888}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{302960E9-3C0B-47F4-A0A4-C245B0FAF888}: NameServer = 8.8.8.8,8.8.4.4
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\Alwil Software\Avast5\afwServ.exe
O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Pos Service (PowerOffer Service) - PowerOfferService - C:\Users\marta\AppData\Local\PosService\Pos.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Serv Updater (ServUpdater) - ServiceUpd - C:\Users\marta\AppData\Local\ServUpdater\ServiceUpd.exe
O23 - Service: Software Upd (SoftwareUpd) - SoftwareUpdService - C:\Users\marta\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe

--
End of file - 11230 bytes

Mi potete dare una mano?
Grazie
Andrea
Top
Profilo Invia messaggio privato
R16
Dio maturo
Dio maturo


Registrato: 07/03/08 22:58
Messaggi: 10129

MessaggioInviato: 27 Set 2013 21:30    Oggetto: Rispondi citando

Ciao.
Scarica Adwcleaner sul desktop:
link
Chiudi tutti i browser, (è importante IE,Firefox Chrome ecc...)
Clicca sul pulsante "Scan".
Finita la scansione clicca su "Clean"
Conferma con OK le varie finestre che ti compariranno.
Il pc si riavvierà, e uscirà il log con le eliminazioni.
Postalo qui.

Poi:
scarica Junkware Removal Tool sul desktop.
link
Disattiva temporaneamente l'antivirus per evitare potenziali conflitti.
Doppio click su JRT
Lo strumento si aprirà e avvierà la scansione del sistema.
Devi avere pazienza in quanto questo tool può richiedere del tempo per completare la scansione .
Al termine, un log (JRT.txt) viene salvato sul desktop e si aprirà automaticamente.
Postalo qui.

Per ultimo:
Fai questa scansione con OTL.
http://forum.zeusnews.com/viewtopic.php?t=51382

Per postare i log:
Collegati ad internet e vai alla pagina WikiSend:
link
Clicca sul bottone "Sfoglia"
Seleziona il file appena salvato
Clicca su Upload file
Dopo qualche secondo, vieni spostato su una nuova pagina con il link in diversi formati:
Download Link / Forum Link
Seleziona Forum Link, copialo e incollalo in un nuovo messaggio per il forum.
Top
Profilo Invia messaggio privato
andrea1975
Dio maturo
Dio maturo


Registrato: 07/12/06 18:58
Messaggi: 4052

MessaggioInviato: 28 Set 2013 10:52    Oggetto: Rispondi citando

Ciao grazie,

inizio a postare il primo log.

Questo è quello di Adwcleaner
log.txt]AdwCleaner[R0] log.txt

non appena riesce a scaricare e fare le altre "scansioni" posterò anche gli altri.

Andrea
Top
Profilo Invia messaggio privato
R16
Dio maturo
Dio maturo


Registrato: 07/03/08 22:58
Messaggi: 10129

MessaggioInviato: 28 Set 2013 13:59    Oggetto: Rispondi citando

Citazione:
Questo è quello di Adwcleaner
log.txt]AdwCleaner[R0] log.txt

Quello è il log delle infezioni che ha trovato.
Per eliminarle devi premere il pulsante "Clean".
Top
Profilo Invia messaggio privato
andrea1975
Dio maturo
Dio maturo


Registrato: 07/12/06 18:58
Messaggi: 4052

MessaggioInviato: 28 Set 2013 14:10    Oggetto: Rispondi citando

ah, chiedo scusa non lo sapevo Wink
appena riesco mi faccio mandare quello giusto e lo posto.
Grazie
Top
Profilo Invia messaggio privato
andrea1975
Dio maturo
Dio maturo


Registrato: 07/12/06 18:58
Messaggi: 4052

MessaggioInviato: 03 Ott 2013 12:01    Oggetto: Rispondi citando

Ciao
ecco i log:

1) logo adwcleaner

AdwCleaner riavvio.txt


2 ) logo jrt

JRT log.txt

3) OTL - di questo ha creato due log uno OTL e l'altro extras:

OTL.Txt log.txt

Extras.Txt log.txt

spero di aver fatto tutto giusto Smile

Grazie Andrea
Top
Profilo Invia messaggio privato
R16
Dio maturo
Dio maturo


Registrato: 07/03/08 22:58
Messaggi: 10129

MessaggioInviato: 03 Ott 2013 17:58    Oggetto: Rispondi citando

Ciao.
Avvia OTL.

Sotto "Custom Scans\Fixes" copia-incolla questo codice:

Codice:
:OTL
SRV - File not found [Auto | Stopped] -- C:\Users\marta\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe -- (SoftwareUpd)
SRV - [2012/04/03 19.59.46 | 000,169,472 | ---- | M] (PowerOfferService) [Auto | Stopped] -- C:\Users\marta\AppData\Local\PosService\Pos.exe -- (PowerOffer Service)
SRV - [2011/12/16 18.44.48 | 000,156,160 | ---- | M] (ServiceUpd) [Auto | Stopped] -- C:\Users\marta\AppData\Local\ServUpdater\ServiceUpd.exe -- (ServUpdater)
SRV - [2010/10/12 19.59.12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local
[2013/05/01 16.41.07 | 000,000,000 | ---D | M] (Speed Analysis 2) -- C:\Users\marta\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
[2013/06/30 10.44.04 | 000,233,016 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc3@hdvidcodec.com.xpi
[2013/04/08 19.11.52 | 000,216,492 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc@hdvc.com.xpi
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)
O4 - HKLM..\Run: [TQ566808] "E:\Setup.exe" File not found
O4 - HKCU..\Run: [Eraser] K:\winPenPack\Bin\Eraser\eraser.exe -hide File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/IT/Core/Player/2020PlayerAX_IKEA_Win32.cab (20-20 3D Viewer for IKEA)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} http://c6.community.virgilio.it/download/DownloaderActiveX.cab (DownloaderActiveX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 10.13.2)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.fueps.com/gp/images/common/games/PopCapGames/popcaploader_v10_it.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell - "" = AutoRun
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\AutoRun\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\open\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell\AutoRun\command - "" = F:\TicToc.exe
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell\AutoRun\command - "" = E:\ShelExec.exe index.htm
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell\AutoRun\command - "" = G:\Setup.exe
[2012/06/17 17.56.09 | 000,715,038 | ---- | C] () -- C:\Users\marta\AppData\Local\unins000.exe
[2012/06/17 17.56.09 | 000,004,003 | ---- | C] () -- C:\Users\marta\AppData\Local\unins000.dat
[2009/10/27 05.01.41 | 000,027,820 | ---- | C] () -- C:\Users\marta\AppData\Local\slot1.mm1
[2009/05/10 10.57.27 | 000,286,440 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_nav.dat
[2009/05/10 10.57.27 | 000,003,205 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek.dat
[2009/05/10 10.57.27 | 000,000,328 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_navps.dat
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:BF89B7E7
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:E51234A9
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:E119EB0E
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:0E22C5DB
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:700B9342
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:9E76E7F3
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:123A86B5
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0EC7A545
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:1B7E2022
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:EDC744FB
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E7B4296D
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:80F63EC3
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:32A82570
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:C72A744C
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:147A3409
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:0F38B460
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:EA10407C
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:FED25C29
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:7FCB9D0D
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:F84B8DB5
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:6444B424
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:5BC73C48
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:162E02F7
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5FA4CB99
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:1F96ED45
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:870649A4
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:68EF6203
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:55818279
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:DD04902E
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C22674B6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:BDF08FAF
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:50636E35
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4F96D8E6
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E80802C7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:2B1EA607
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:1B9E79B3
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F1DEA771
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:E91ADC66
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:842B0AED
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:40D8F125
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:98DFF516
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:0ED4AC2F
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:BB3CECA4
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:8401B6D5
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:EEB25EAE
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:BD9F7E4E
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:8247A199
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:BD36345D
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:69AF9D20
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:9C012695
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:592D7272
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:4FE42FFC
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:C07A6A6B
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:569CEE83
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:3D36932D
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:59C113EC
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:1A4BF204

:Files
C:\Users\marta\AppData\Local\SoftwareUpdater
C:\Users\marta\AppData\Local\PosService
C:\Users\marta\AppData\Local\ServUpdater
C:\Users\Public\Documents\AppData\PoApp
ipconfig /flushdns /c

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"

:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot]


Clicca sul pulsante RUN FIX.
Lascia fare la scansione senza interferire.
Posta il log.
Top
Profilo Invia messaggio privato
andrea1975
Dio maturo
Dio maturo


Registrato: 07/12/06 18:58
Messaggi: 4052

MessaggioInviato: 04 Ott 2013 10:39    Oggetto: Rispondi citando

Ciao,

10032013_231648 otl log.txt

spero di aver fatto giusto. Very Happy
Grazie per l'attenzione
andrea
Top
Profilo Invia messaggio privato
R16
Dio maturo
Dio maturo


Registrato: 07/03/08 22:58
Messaggi: 10129

MessaggioInviato: 04 Ott 2013 17:36    Oggetto: Rispondi citando

Citazione:
spero di aver fatto giusto.

Non ha funzionato.
Rifai una scansione con OTL configurandolo con questi parametri:

Apri OTL.
Metti la spunta su SCAN ALL USERS.

Sotto output, metti la spunta : minimal output

Clicca sulla freccettina di File Age e seleziona 60 Days

Metti la spunta a LOP Check e Purity Check.

Clicca su RUN SCAN

Lascia fare la scansione senza interferire.
Finita la scansione posta il log. (ne rilascerà 1 solo OTL.txt)
Top
Profilo Invia messaggio privato
andrea1975
Dio maturo
Dio maturo


Registrato: 07/12/06 18:58
Messaggi: 4052

MessaggioInviato: 06 Ott 2013 11:54    Oggetto: Rispondi citando

opsss sorry Embarassed

ecco il log che mi appena inviato la mia amica

OTL.Txt

Grazie ancora
Andrea
Top
Profilo Invia messaggio privato
R16
Dio maturo
Dio maturo


Registrato: 07/03/08 22:58
Messaggi: 10129

MessaggioInviato: 06 Ott 2013 13:29    Oggetto: Rispondi citando

Ciao .
Segui attentamente queste indicazioni:

Avvia OTL.

Sotto "Custom Scans\Fixes" copia-incolla questo codice: (NON copiare la parola Codice:


Codice:
:OTL
SRV - (PowerOffer Service) -- C:\Users\marta\AppData\Local\PosService\Pos.exe (PowerOfferService)
SRV - (ServUpdater) -- C:\Users\marta\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-21-2492967055-2021645066-3165184103-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local
[2013/05/01 16.41.07 | 000,000,000 | ---D | M] (Speed Analysis 2) -- C:\Users\marta\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
[2013/06/30 10.44.04 | 000,233,016 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc3@hdvidcodec.com.xpi
[2013/04/08 19.11.52 | 000,216,492 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc@hdvc.com.xpi
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)
O4 - HKLM..\Run: [TQ566808] "E:\Setup.exe" File not found
O4 - HKU\S-1-5-21-2492967055-2021645066-3165184103-1000..\Run: [Eraser] K:\winPenPack\Bin\Eraser\eraser.exe -hide File not found
O4 - HKU\S-1-5-21-2492967055-2021645066-3165184103-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/IT/Core/Player/2020PlayerAX_IKEA_Win32.cab (20-20 3D Viewer for IKEA)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} http://c6.community.virgilio.it/download/DownloaderActiveX.cab (DownloaderActiveX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 10.13.2)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.fueps.com/gp/images/common/games/PopCapGames/popcaploader_v10_it.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell - "" = AutoRun
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\AutoRun\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\open\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell\AutoRun\command - "" = F:\TicToc.exe
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell\AutoRun\command - "" = E:\ShelExec.exe index.htm
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell\AutoRun\command - "" = G:\Setup.exe
[2009/05/10 10.57.27 | 000,286,440 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_nav.dat
[2009/05/10 10.57.27 | 000,003,205 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek.dat
[2009/05/10 10.57.27 | 000,000,328 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_navps.dat
[2009/01/23 06.09.14 | 000,000,088 | ---- | C] () -- C:\Users\marta\AppData\Local\lptaeae.bat
[2010/08/19 20.35.40 | 000,000,000 | -HSD | M] -- C:\Users\marta\AppData\Roaming\.#
[2011/12/16 20.53.13 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\.minecraft
[2012/10/13 23.01.21 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\4Free
[2010/06/17 10.18.42 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\7Wonders
[2009/06/19 11.28.38 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Abakt
[2009/10/18 16.11.07 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Activision
[2009/06/27 16.24.51 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Alawar
[2013/08/24 21.23.10 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\AlawarEntertainment
[2009/06/19 14.00.35 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Anabel
[2012/06/24 09.26.31 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Anarchy
[2009/09/03 19.08.01 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Artogon
[2009/02/07 09.00.05 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\AVG7
[2009/10/18 12.17.27 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Awem
[2010/09/18 16.41.11 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Babylonia
[2011/06/25 11.52.24 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Friday's games
[2012/07/01 10.36.18 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Frogwares
[2010/09/01 07.38.34 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Fugazo
[2009/04/18 15.20.34 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Gaijin Ent
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:BF89B7E7
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:E51234A9
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:E119EB0E
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:0E22C5DB
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:700B9342
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:9E76E7F3
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:123A86B5
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0EC7A545
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:1B7E2022
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:EDC744FB
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E7B4296D
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:80F63EC3
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:32A82570
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:C72A744C
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:147A3409
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:0F38B460
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:EA10407C
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:FED25C29
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:7FCB9D0D
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:F84B8DB5
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:6444B424
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:5BC73C48
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:162E02F7
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5FA4CB99
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:1F96ED45
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:870649A4
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:68EF6203
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:55818279
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:DD04902E
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C22674B6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:BDF08FAF
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:50636E35
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4F96D8E6
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E80802C7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:2B1EA607
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:1B9E79B3
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F1DEA771
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:E91ADC66
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:842B0AED
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:40D8F125
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:98DFF516
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:0ED4AC2F
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:BB3CECA4
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:8401B6D5
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:EEB25EAE
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:BD9F7E4E
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:8247A199
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:BD36345D
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:69AF9D20
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:9C012695
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:592D7272
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:4FE42FFC
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:C07A6A6B
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:569CEE83
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:3D36932D
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:59C113EC
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:1A4BF204

:Files
C:\Users\marta\AppData\Local\PosService
C:\Users\marta\AppData\Local\ServUpdater
C:\Users\Public\Documents\AppData\PoApp
ipconfig /flushdns /c

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"

:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot]


Clicca sul pulsante RUN FIX.
Lascia fare la scansione senza interferire.
Posta il log.
Top
Profilo Invia messaggio privato
andrea1975
Dio maturo
Dio maturo


Registrato: 07/12/06 18:58
Messaggi: 4052

MessaggioInviato: 08 Ott 2013 18:27    Oggetto: Rispondi citando

ciao fatto la scansione con otl e questo è il log:

OTL.Txt 81013.txt

però non sono sicuro che abbia funzionato...

ho fatto lo stamp delle impostazioni di otl, sono giuste?



Uploaded with ImageShack.us

O è da rifare con le configurazioni del post precedente?

grazie per la pazienza...
Top
Profilo Invia messaggio privato
R16
Dio maturo
Dio maturo


Registrato: 07/03/08 22:58
Messaggi: 10129

MessaggioInviato: 08 Ott 2013 18:55    Oggetto: Rispondi

Citazione:
ho fatto lo stamp delle impostazioni di otl, sono giuste?

No non sono giuste.
Metti la spunta in SCAN ALL USERS

Riprova a copiare-incollare lo script sotto Custom Scans\Fixes
Poi clicca RUN FIX (NON RUN SCAN)

Se non funziona prova in Modalità provvisoria.
Top
Profilo Invia messaggio privato
Mostra prima i messaggi di:   
Nuovo argomento   Rispondi    Indice del forum -> Pronto Soccorso Virus Tutti i fusi orari sono GMT + 2 ore
Pagina 1 di 1

 
Vai a:  
Non puoi inserire nuovi argomenti
Non puoi rispondere a nessun argomento
Non puoi modificare i tuoi messaggi
Non puoi cancellare i tuoi messaggi
Non puoi votare nei sondaggi