Precedente :: Successivo |
Autore |
Messaggio |
andrea1975 Dio maturo


Registrato: 07/12/06 18:58 Messaggi: 4052
|
Inviato: 27 Set 2013 21:01 Oggetto: Pc lento con strani effetti e pubblicità a go-go, Help! |
|
|
Ciao.
una mia amica ha un problema con il suo pc che è lento, si aprono finestre di pubblicità a casaccio e ogni tanto si apre una finesta di pubblicità che si sovrappone alla pagina aperta (con l'opzione skip in basso a destra) e molto spesso si impalla sia internet explorer che il pc in generale.
Sempre nelle pagine internet si aprono finestre di pubblicità anche su singole parole (blu con doppia sottolineatura) che diventano link anche che non lo sono e la finestra manda a (public8media.com)
Altro problema alle volte all'accensione sembra che si avvii normalmente carica la scritta con la marca del computer ma poi lo schermo resta grigio con delle righe che sembrano spostarsi.
Ha fatto la scansione antivirus con Avast e non ha rilevato nessun virus o malware.
Il sistema operativo è vista.
Posto qui il log di HijackThis, scusate se lo posto per intero ma non ricordo dove si condivideva il file.
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 19.40.28, on 27/09/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16506)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft Works\WkCalRem.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Users\Public\Documents\AppData\PoApp\PService.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\program files\plus-hd-2.2\plus-hd-2.2-bg.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_175_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\marta\Desktop\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=84&bd=Presario&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=84&bd=Presario&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=nv2&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyDyCyD0FyCzy0D0DyB0DyBtN0D0Tzu0CyEyCzytN1L2XzutBtFtBtFtCtFyDyByBtN1L1Czu1G2XtB&cr=78132891&ir=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=SnapdoSoftonic&dpid=SnapdoSoftonic&co=IT&userid=25fef674-4dcf-4d5e-9589-97bec86e46c0&searchtype=ds&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;<local>;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CrossriderApp0033036 - {11111111-1111-1111-1111-110311301136} - C:\Program Files\Plus-HD-2.2\Plus-HD-2.2-bho.dll
O2 - BHO: Secured eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSecu.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_16\bin\ssv.dll
O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (file missing)
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.6.0_16\bin\jp2ssv.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll
O3 - Toolbar: Secured eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSecu.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [TQ566808] "E:\Setup.exe"
O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\RunOnce: [aswAhAScr.dll] "C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe" "C:\Program Files\Alwil Software\Avast5\AhAScr.dll"
O4 - HKLM\..\RunOnce: [aswasOutExt.dll] "C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe" "C:\Program Files\Alwil Software\Avast5\asOutExt.dll"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\marta\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Eraser] K:\winPenPack\Bin\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O4 - Startup: wkcalrem.LNK = C:\Program Files\Microsoft Works\WkCalRem.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Add to AMV/AVI Video Converter... - C:\Program Files\Media Player Utilities 4.25\AMVConverter\grab.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} (20-20 3D Viewer for IKEA) - http://kitchenplanner.ikea.com/IT/Core/Player/2020PlayerAX_IKEA_Win32.cab
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} (DownloaderActiveX Control) - http://c6.community.virgilio.it/download/DownloaderActiveX.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.fueps.com/gp/images/common/games/PopCapGames/popcaploader_v10_it.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{302960E9-3C0B-47F4-A0A4-C245B0FAF888}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{80EC53E5-E8E7-4BE6-AA36-52D752B675FE}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{958BA84C-7DBB-4B78-92E6-363A90E977F7}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC8CBC0F-435A-4724-9518-71690FEA6ABA}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1B4D561-E020-490B-9922-C3BD2D57E662}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{302960E9-3C0B-47F4-A0A4-C245B0FAF888}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{302960E9-3C0B-47F4-A0A4-C245B0FAF888}: NameServer = 8.8.8.8,8.8.4.4
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\Alwil Software\Avast5\afwServ.exe
O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Pos Service (PowerOffer Service) - PowerOfferService - C:\Users\marta\AppData\Local\PosService\Pos.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Serv Updater (ServUpdater) - ServiceUpd - C:\Users\marta\AppData\Local\ServUpdater\ServiceUpd.exe
O23 - Service: Software Upd (SoftwareUpd) - SoftwareUpdService - C:\Users\marta\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe
--
End of file - 11230 bytes
Mi potete dare una mano?
Grazie
Andrea |
|
Top |
|
 |
R16 Dio maturo


Registrato: 07/03/08 22:58 Messaggi: 10129
|
Inviato: 27 Set 2013 21:30 Oggetto: |
|
|
Ciao.
Scarica Adwcleaner sul desktop:
link
Chiudi tutti i browser, (è importante IE,Firefox Chrome ecc...)
Clicca sul pulsante "Scan".
Finita la scansione clicca su "Clean"
Conferma con OK le varie finestre che ti compariranno.
Il pc si riavvierà, e uscirà il log con le eliminazioni.
Postalo qui.
Poi:
scarica Junkware Removal Tool sul desktop.
link
Disattiva temporaneamente l'antivirus per evitare potenziali conflitti.
Doppio click su JRT
Lo strumento si aprirà e avvierà la scansione del sistema.
Devi avere pazienza in quanto questo tool può richiedere del tempo per completare la scansione .
Al termine, un log (JRT.txt) viene salvato sul desktop e si aprirà automaticamente.
Postalo qui.
Per ultimo:
Fai questa scansione con OTL.
http://forum.zeusnews.com/viewtopic.php?t=51382
Per postare i log:
Collegati ad internet e vai alla pagina WikiSend:
link
Clicca sul bottone "Sfoglia"
Seleziona il file appena salvato
Clicca su Upload file
Dopo qualche secondo, vieni spostato su una nuova pagina con il link in diversi formati:
Download Link / Forum Link
Seleziona Forum Link, copialo e incollalo in un nuovo messaggio per il forum. |
|
Top |
|
 |
andrea1975 Dio maturo


Registrato: 07/12/06 18:58 Messaggi: 4052
|
Inviato: 28 Set 2013 10:52 Oggetto: |
|
|
Ciao grazie,
inizio a postare il primo log.
Questo è quello di Adwcleaner
log.txt]AdwCleaner[R0] log.txt
non appena riesce a scaricare e fare le altre "scansioni" posterò anche gli altri.
Andrea |
|
Top |
|
 |
R16 Dio maturo


Registrato: 07/03/08 22:58 Messaggi: 10129
|
Inviato: 28 Set 2013 13:59 Oggetto: |
|
|
Citazione: | Questo è quello di Adwcleaner
log.txt]AdwCleaner[R0] log.txt |
Quello è il log delle infezioni che ha trovato.
Per eliminarle devi premere il pulsante "Clean". |
|
Top |
|
 |
andrea1975 Dio maturo


Registrato: 07/12/06 18:58 Messaggi: 4052
|
Inviato: 28 Set 2013 14:10 Oggetto: |
|
|
ah, chiedo scusa non lo sapevo
appena riesco mi faccio mandare quello giusto e lo posto.
Grazie |
|
Top |
|
 |
andrea1975 Dio maturo


Registrato: 07/12/06 18:58 Messaggi: 4052
|
|
Top |
|
 |
R16 Dio maturo


Registrato: 07/03/08 22:58 Messaggi: 10129
|
Inviato: 03 Ott 2013 17:58 Oggetto: |
|
|
Ciao.
Avvia OTL.
Sotto "Custom Scans\Fixes" copia-incolla questo codice:
Codice: | :OTL
SRV - File not found [Auto | Stopped] -- C:\Users\marta\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe -- (SoftwareUpd)
SRV - [2012/04/03 19.59.46 | 000,169,472 | ---- | M] (PowerOfferService) [Auto | Stopped] -- C:\Users\marta\AppData\Local\PosService\Pos.exe -- (PowerOffer Service)
SRV - [2011/12/16 18.44.48 | 000,156,160 | ---- | M] (ServiceUpd) [Auto | Stopped] -- C:\Users\marta\AppData\Local\ServUpdater\ServiceUpd.exe -- (ServUpdater)
SRV - [2010/10/12 19.59.12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local
[2013/05/01 16.41.07 | 000,000,000 | ---D | M] (Speed Analysis 2) -- C:\Users\marta\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
[2013/06/30 10.44.04 | 000,233,016 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc3@hdvidcodec.com.xpi
[2013/04/08 19.11.52 | 000,216,492 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc@hdvc.com.xpi
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)
O4 - HKLM..\Run: [TQ566808] "E:\Setup.exe" File not found
O4 - HKCU..\Run: [Eraser] K:\winPenPack\Bin\Eraser\eraser.exe -hide File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/IT/Core/Player/2020PlayerAX_IKEA_Win32.cab (20-20 3D Viewer for IKEA)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} http://c6.community.virgilio.it/download/DownloaderActiveX.cab (DownloaderActiveX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 10.13.2)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.fueps.com/gp/images/common/games/PopCapGames/popcaploader_v10_it.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell - "" = AutoRun
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\AutoRun\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\open\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell\AutoRun\command - "" = F:\TicToc.exe
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell\AutoRun\command - "" = E:\ShelExec.exe index.htm
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell\AutoRun\command - "" = G:\Setup.exe
[2012/06/17 17.56.09 | 000,715,038 | ---- | C] () -- C:\Users\marta\AppData\Local\unins000.exe
[2012/06/17 17.56.09 | 000,004,003 | ---- | C] () -- C:\Users\marta\AppData\Local\unins000.dat
[2009/10/27 05.01.41 | 000,027,820 | ---- | C] () -- C:\Users\marta\AppData\Local\slot1.mm1
[2009/05/10 10.57.27 | 000,286,440 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_nav.dat
[2009/05/10 10.57.27 | 000,003,205 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek.dat
[2009/05/10 10.57.27 | 000,000,328 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_navps.dat
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:BF89B7E7
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:E51234A9
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:E119EB0E
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:0E22C5DB
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:700B9342
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:9E76E7F3
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:123A86B5
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0EC7A545
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:1B7E2022
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:EDC744FB
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E7B4296D
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:80F63EC3
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:32A82570
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:C72A744C
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:147A3409
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:0F38B460
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:EA10407C
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:FED25C29
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:7FCB9D0D
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:F84B8DB5
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:6444B424
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:5BC73C48
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:162E02F7
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5FA4CB99
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:1F96ED45
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:870649A4
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:68EF6203
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:55818279
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:DD04902E
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C22674B6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:BDF08FAF
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:50636E35
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4F96D8E6
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E80802C7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:2B1EA607
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:1B9E79B3
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F1DEA771
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:E91ADC66
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:842B0AED
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:40D8F125
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:98DFF516
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:0ED4AC2F
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:BB3CECA4
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:8401B6D5
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:EEB25EAE
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:BD9F7E4E
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:8247A199
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:BD36345D
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:69AF9D20
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:9C012695
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:592D7272
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:4FE42FFC
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:C07A6A6B
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:569CEE83
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:3D36932D
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:59C113EC
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:1A4BF204
:Files
C:\Users\marta\AppData\Local\SoftwareUpdater
C:\Users\marta\AppData\Local\PosService
C:\Users\marta\AppData\Local\ServUpdater
C:\Users\Public\Documents\AppData\PoApp
ipconfig /flushdns /c
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot] |
Clicca sul pulsante RUN FIX.
Lascia fare la scansione senza interferire.
Posta il log. |
|
Top |
|
 |
andrea1975 Dio maturo


Registrato: 07/12/06 18:58 Messaggi: 4052
|
|
Top |
|
 |
R16 Dio maturo


Registrato: 07/03/08 22:58 Messaggi: 10129
|
Inviato: 04 Ott 2013 17:36 Oggetto: |
|
|
Citazione: | spero di aver fatto giusto. |
Non ha funzionato.
Rifai una scansione con OTL configurandolo con questi parametri:
Apri OTL.
Metti la spunta su SCAN ALL USERS.
Sotto output, metti la spunta : minimal output
Clicca sulla freccettina di File Age e seleziona 60 Days
Metti la spunta a LOP Check e Purity Check.
Clicca su RUN SCAN
Lascia fare la scansione senza interferire.
Finita la scansione posta il log. (ne rilascerà 1 solo OTL.txt) |
|
Top |
|
 |
andrea1975 Dio maturo


Registrato: 07/12/06 18:58 Messaggi: 4052
|
Inviato: 06 Ott 2013 11:54 Oggetto: |
|
|
opsss sorry
ecco il log che mi appena inviato la mia amica
OTL.Txt
Grazie ancora
Andrea |
|
Top |
|
 |
R16 Dio maturo


Registrato: 07/03/08 22:58 Messaggi: 10129
|
Inviato: 06 Ott 2013 13:29 Oggetto: |
|
|
Ciao .
Segui attentamente queste indicazioni:
Avvia OTL.
Sotto "Custom Scans\Fixes" copia-incolla questo codice: (NON copiare la parola Codice:
Codice: | :OTL
SRV - (PowerOffer Service) -- C:\Users\marta\AppData\Local\PosService\Pos.exe (PowerOfferService)
SRV - (ServUpdater) -- C:\Users\marta\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-21-2492967055-2021645066-3165184103-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local
[2013/05/01 16.41.07 | 000,000,000 | ---D | M] (Speed Analysis 2) -- C:\Users\marta\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
[2013/06/30 10.44.04 | 000,233,016 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc3@hdvidcodec.com.xpi
[2013/04/08 19.11.52 | 000,216,492 | ---- | M] () (No name found) -- C:\Users\marta\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc@hdvc.com.xpi
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)
O4 - HKLM..\Run: [TQ566808] "E:\Setup.exe" File not found
O4 - HKU\S-1-5-21-2492967055-2021645066-3165184103-1000..\Run: [Eraser] K:\winPenPack\Bin\Eraser\eraser.exe -hide File not found
O4 - HKU\S-1-5-21-2492967055-2021645066-3165184103-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/IT/Core/Player/2020PlayerAX_IKEA_Win32.cab (20-20 3D Viewer for IKEA)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} http://c6.community.virgilio.it/download/DownloaderActiveX.cab (DownloaderActiveX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 10.13.2)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.fueps.com/gp/images/common/games/PopCapGames/popcaploader_v10_it.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{351c32f0-c9f9-11e2-8a68-00218565f69d}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell - "" = AutoRun
O33 - MountPoints2\{351c3312-c9f9-11e2-8a68-001e101fe5e1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{466bcaa2-3a22-11e2-a207-00218565f69d}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\AutoRun\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
O33 - MountPoints2\{60119891-0a51-11de-9f48-00218565f69d}\Shell\open\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\svsys.exe
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{6ccb5dbf-2c03-11e1-9999-00218565f69d}\Shell\AutoRun\command - "" = F:\TicToc.exe
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a3f8b5c8-7d1d-11dd-8213-806e6f6e6963}\Shell\AutoRun\command - "" = E:\ShelExec.exe index.htm
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell - "" = AutoRun
O33 - MountPoints2\{d5b42040-6462-11e2-b9ed-00218565f69d}\Shell\AutoRun\command - "" = G:\Setup.exe
[2009/05/10 10.57.27 | 000,286,440 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_nav.dat
[2009/05/10 10.57.27 | 000,003,205 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek.dat
[2009/05/10 10.57.27 | 000,000,328 | ---- | C] () -- C:\Users\marta\AppData\Local\sigek_navps.dat
[2009/01/23 06.09.14 | 000,000,088 | ---- | C] () -- C:\Users\marta\AppData\Local\lptaeae.bat
[2010/08/19 20.35.40 | 000,000,000 | -HSD | M] -- C:\Users\marta\AppData\Roaming\.#
[2011/12/16 20.53.13 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\.minecraft
[2012/10/13 23.01.21 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\4Free
[2010/06/17 10.18.42 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\7Wonders
[2009/06/19 11.28.38 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Abakt
[2009/10/18 16.11.07 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Activision
[2009/06/27 16.24.51 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Alawar
[2013/08/24 21.23.10 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\AlawarEntertainment
[2009/06/19 14.00.35 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Anabel
[2012/06/24 09.26.31 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Anarchy
[2009/09/03 19.08.01 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Artogon
[2009/02/07 09.00.05 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\AVG7
[2009/10/18 12.17.27 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Awem
[2010/09/18 16.41.11 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Babylonia
[2011/06/25 11.52.24 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Friday's games
[2012/07/01 10.36.18 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Frogwares
[2010/09/01 07.38.34 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Fugazo
[2009/04/18 15.20.34 | 000,000,000 | ---D | M] -- C:\Users\marta\AppData\Roaming\Gaijin Ent
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:BF89B7E7
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:E51234A9
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:E119EB0E
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:0E22C5DB
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:700B9342
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:9E76E7F3
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:123A86B5
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0EC7A545
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:1B7E2022
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:EDC744FB
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:E7B4296D
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:80F63EC3
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:32A82570
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:C72A744C
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:147A3409
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:0F38B460
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:EA10407C
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:FED25C29
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:7FCB9D0D
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:F84B8DB5
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:6444B424
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:5BC73C48
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:162E02F7
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5FA4CB99
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:1F96ED45
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:870649A4
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:68EF6203
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:55818279
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:DD04902E
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C22674B6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:BDF08FAF
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:50636E35
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4F96D8E6
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E80802C7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:2B1EA607
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:1B9E79B3
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F1DEA771
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:E91ADC66
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:842B0AED
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:40D8F125
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:98DFF516
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:0ED4AC2F
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:BB3CECA4
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:8401B6D5
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:EEB25EAE
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:BD9F7E4E
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:8247A199
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:BD36345D
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:69AF9D20
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:9C012695
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:592D7272
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:4FE42FFC
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:C07A6A6B
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:569CEE83
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:3D36932D
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:59C113EC
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:1A4BF204
:Files
C:\Users\marta\AppData\Local\PosService
C:\Users\marta\AppData\Local\ServUpdater
C:\Users\Public\Documents\AppData\PoApp
ipconfig /flushdns /c
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot] |
Clicca sul pulsante RUN FIX.
Lascia fare la scansione senza interferire.
Posta il log. |
|
Top |
|
 |
andrea1975 Dio maturo


Registrato: 07/12/06 18:58 Messaggi: 4052
|
Inviato: 08 Ott 2013 18:27 Oggetto: |
|
|
ciao fatto la scansione con otl e questo è il log:
OTL.Txt 81013.txt
però non sono sicuro che abbia funzionato...
ho fatto lo stamp delle impostazioni di otl, sono giuste?
Uploaded with ImageShack.us
O è da rifare con le configurazioni del post precedente?
grazie per la pazienza... |
|
Top |
|
 |
R16 Dio maturo


Registrato: 07/03/08 22:58 Messaggi: 10129
|
Inviato: 08 Ott 2013 18:55 Oggetto: |
|
|
Citazione: | ho fatto lo stamp delle impostazioni di otl, sono giuste? |
No non sono giuste.
Metti la spunta in SCAN ALL USERS
Riprova a copiare-incollare lo script sotto Custom Scans\Fixes
Poi clicca RUN FIX (NON RUN SCAN)
Se non funziona prova in Modalità provvisoria. |
|
Top |
|
 |
|
|
Non puoi inserire nuovi argomenti Non puoi rispondere a nessun argomento Non puoi modificare i tuoi messaggi Non puoi cancellare i tuoi messaggi Non puoi votare nei sondaggi
|
|