Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

controllo log Opzioni
shapiro
Inviato: Tuesday, October 02, 2012 11:42:13 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
Commenta:
adesso scarica questo file direttamente nella pennetta con la quale hai fatto la scansione e premi il pulsante FIX

A fine scansione Il tool creerà un log sulla flashdrive dal nome Fixlog.txt


devi copiarmi il contenuto del file = > Fixlog.txt non puo' esserci scritto come dici quello l'ho preparato io e te lo ho fatto scaricare nella pennetta
arcere84
Inviato: Tuesday, October 02, 2012 12:08:34 PM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
scusami se insisto ma cliccando su questo file che mi hai postato ieri alle 21.51 mi esce la schermata di wikisend hai la possibilità di collegarti con TEAM VIVER?
shapiro
Inviato: Tuesday, October 02, 2012 12:52:43 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
fai una cosa riesegui l'operazione

scarica questo file direttamente nella pennetta con la quale hai fatto la scansione e premi FIX

lascia lavorare il tool e appena finito posta il log che trovi nella pennetta col nome Fixlog.txt

devi copiarlo non aprirlo....capito??
arcere84
Inviato: Tuesday, October 02, 2012 2:01:55 PM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
niente non funziona forse sono io che non capisco un c......o e sbaglio ad eseguire la procedura ???
shapiro
Inviato: Tuesday, October 02, 2012 5:04:17 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
ma e' facile....quando scarichi il file invece di metterlo sul desktop scegli l'unita' dove risiede la pennetta (sara' F oppure G o altro) poi premi il pulsante FIX e quando ha finito nella stessa pennetta troverai il file Fixlog.txt che devi allegare ( o copiare) nel forum
arcere84
Inviato: Tuesday, October 02, 2012 6:34:10 PM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
forse ho trovato (spero)
però mi dice

no fixilist.txt found the fixlist.txt should be made and saved in te same directory the tool is located

cosa devo fare?
r16
Inviato: Tuesday, October 02, 2012 6:55:20 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Commenta:
cosa devo fare?

Tagliamo la testa al toro:


Scarica OTL, e salvalo sul desktop:

http://oldtimer.geekstogo.com/OTL.com

Clicca sull'icona di OTL che trovi sul tuo desktop .

Metti la spunta su SCAN ALL USERS.

Sotto output, metti la spunta : minimal output

Clicca sulla freccettina di File Age e seleziona 60 Days

Metti la spunta a LOP Check e Purity Check.

Clicca su [b]RUN SCAN[/b]

Lascia fare la scansione senza interferire.

Al termine della scansione trovi 2 log sul desktop. OTL.txt ed Extras.txt, salvali e caricali su Wikisend, per postarli sul forum.

Per caricare i log fai così:

Collegati ad internet e vai alla pagina WikiSend:
http://www.wikisend.com/
Clicca sul bottone "Sfoglia"
Seleziona il file appena salvato
Clicca su Upload file
Dopo qualche secondo, vieni spostato su una nuova pagina con il link in diversi formati:
Download Link / Forum Link
Seleziona Forum Link, copialo e incollalo in un nuovo messaggio per il forum.
arcere84
Inviato: Tuesday, October 02, 2012 7:18:24 PM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
ecco fatto spero di aver fatto giusto questa volta


[Extras.Txt
URL=http://wikisend.com/download/413276/OTL.Txt]OTL.Txt[/URL]
r16
Inviato: Tuesday, October 02, 2012 7:29:05 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Avvia OTL.

Sotto "Custom Scans\Fixes" copia-incolla questo codice: (non copiare la parola Code)

Code:
:Processes
:Services

:OTL
[2012/08/14 09:28:04 | 000,000,000 | ---D | C] -- C:\Users\Luciano\AppData\Roaming\OpenCandy

:Files
C:\Users\Luciano\AppData\Roaming\xsecva
C:\ProgramData\sqj.pad
C:\ProgramData\avaj.pad
C:\ProgramData\ras_0oed.pad
C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}
C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\L
C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\U
C:\Windows\assembly\Desktop.ini
ipconfig /flushdns /c

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"

:commands
[purity]
[emptytemp]
[CLEARALLRESTOREPOINTS]


Clicca sul pulsante RUN FIX.
Lascia fare la scansione senza interferire.
Posta il log.
arcere84
Inviato: Tuesday, October 02, 2012 10:35:01 PM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
ecco il log

All processes killed
========== PROCESSES ==========
========== SERVICES/DRIVERS ==========
========== OTL ==========
C:\Users\Luciano\AppData\Roaming\OpenCandy\E9A6E5A221CC483390D2F57F9E7C26CB folder moved successfully.
C:\Users\Luciano\AppData\Roaming\OpenCandy folder moved successfully.
========== FILES ==========
C:\Users\Luciano\AppData\Roaming\xsecva folder moved successfully.
C:\ProgramData\sqj.pad moved successfully.
C:\ProgramData\avaj.pad moved successfully.
C:\ProgramData\ras_0oed.pad moved successfully.
C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\U folder moved successfully.
C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\L folder moved successfully.
C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240} folder moved successfully.
File\Folder C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\L not found.
File\Folder C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\U not found.
C:\Windows\assembly\Desktop.ini moved successfully.
< ipconfig /flushdns /c >
Configurazione IP di Windows
Cache del resolver DNS svuotata.
C:\Users\Luciano\Desktop\cmd.bat deleted successfully.
C:\Users\Luciano\Desktop\cmd.txt deleted successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Luciano
->Temp folder emptied: 768062 bytes
->Temporary Internet Files folder emptied: 14887103 bytes
->Java cache emptied: 187273 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 537 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 28644 bytes
RecycleBin emptied: 1388734 bytes

Total Files Cleaned = 17,00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.70.1 log created on 10022012_222649

Files\Folders moved on Reboot...
C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ASD5OXQN\adsCA4IXG6A.htm moved successfully.
C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ASD5OXQN\adsCA7NNYZ0.htm moved successfully.
C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8F3FB8WW\adsCADFGIYW.htm moved successfully.
C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8F3FB8WW\aiutamici_it[1].htm moved successfully.
C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8F3FB8WW\metro[2].htm moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
arcere84
Inviato: Wednesday, October 03, 2012 2:05:43 PM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
per r16 scusa se ti rompo ieri sera ti ho postato il log puoi dare un'occhiata grazie
r16
Inviato: Wednesday, October 03, 2012 6:21:23 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Esegui una nuova scansione con OTL.
Posta il log con le solite modalità. (Wikisend)
Dimmi anche quali problemi riscontri.
arcere84
Inviato: Wednesday, October 03, 2012 7:01:25 PM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
per r16
ecco questo è quello che ho trovato spero di aver fatto giusto

OTL.Txt
r16
Inviato: Wednesday, October 03, 2012 7:19:28 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Scarica Adwcleaner sul desktop:
http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner
Avvialo e clicca sul pulsante search.
Finita la scansione, elimina il log che rilascia sul desktop, e clicca su "Delete".
Conferma con OK le varie finestre che ti compariranno.
Il pc si riavvierà, e uscirà il log con le eliminazioni.
Postalo qui.

Non mi hai detto se e quali problemi riscontri.
arcere84
Inviato: Wednesday, October 03, 2012 7:27:46 PM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
adesso il PC mi sembra vada bene avevo preso il virus della polizia postale e lo ho eliminato in modalita provv. e volevo che mi controllaste il log per vedere se lo avevo eliminato
arcere84
Inviato: Wednesday, October 03, 2012 7:34:01 PM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
# AdwCleaner v2.003 - Logfile created 10/03/2012 at 19:29:38
# Updated 23/09/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (32 bits)
# User : Luciano - LUCIANO-PC
# Boot Mode : Normal
# Running from : C:\Users\Luciano\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : Web Assistant Updater

***** [Files / Folders] *****

File Deleted : C:\user.js
Folder Deleted : C:\Program Files\ChatZum Toolbar
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\Web Assistant
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Users\Luciano\AppData\Local\Conduit
Folder Deleted : C:\Users\Luciano\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Folder Deleted : C:\Users\Luciano\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Luciano\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Luciano\AppData\LocalLow\searchquband
Folder Deleted : C:\Users\Luciano\AppData\Roaming\OfferBox

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\searchqutoolbar
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E1368B44-60A8-470F-9537-C1BC2390C8E3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Offerbox
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1561552
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2851640
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3106777
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\NEW_CORRECT_incredibar_install_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\NEW_CORRECT_incredibar_install_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E1368B44-60A8-470F-9537-C1BC2390C8E3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Key Deleted : HKLM\Software\Offerbox
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\Software\Web Assistant
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Google Chrome v22.0.1229.79

ecco il log

File : C:\Users\Luciano\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.24] : search_url = "hxxp://mystart.incredibar.com/mb165/?loc=IB_DS&search={searchTerms}&a=6R8vhKNrZW&i=26",
Deleted [l.264] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?ctid=CT2851640&SearchSource=48" ]
Deleted [l.266] : homepage = "hxxp://search.conduit.com/?ctid=CT2851640&SearchSource=48",

*************************

AdwCleaner[R1].txt - [11788 octets] - [03/10/2012 19:28:34]
AdwCleaner[S1].txt - [11803 octets] - [03/10/2012 19:29:38]

########## EOF - C:\AdwCleaner[S1].txt - [11864 octets] ##########
shapiro
Inviato: Wednesday, October 03, 2012 7:59:11 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
Commenta:
adesso il PC mi sembra vada bene avevo preso il virus della polizia postale e lo ho eliminato in modalita provv. e volevo che mi controllaste il log per vedere se lo avevo eliminato


no non lo avevi eliminato, le infezioni erano riportate nell'operazione che ti ho postato e che non sei riuscito a portare a termine e dopo la scansione con otl r16 te l'ha fatta eliminare, ma non puoi dire che l'avevi eliminata.....
r16
Inviato: Wednesday, October 03, 2012 9:37:10 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
shapiro ha scritto:

no non lo avevi eliminato,

Sì, il virus non poteva essere stato eliminato, visto che i log (tutti e 2) lo riportavano bello e pimpante.
Inoltre come detto, era anche "accompagnato" dal rootkit Zero Access.


@ arcere84:
Comunque:
Apri OTL e clicca su Cleanup.
Si disistallerà OTL.
Se ti chiede il riavvio : acconsenti.

Dai una pulita (registro compreso)con CCleaner http://www.aiutamici.com/software?ID=11223

Provvedi a svuotare del suo contenuto la cartella Prefetch :
clicca su Risorse del Computer
clicca su Disco locale C:
cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella)

SVUOTA IL CESTINO

Disattiva il ripristino configurazione di sistema:
http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121

Riavvia il pc.

Riattiva il ripristino configurazione di sistema
arcere84
Inviato: Thursday, October 04, 2012 12:20:07 AM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
scusami r16 io ho win 7 non riesco a trovare per disattivare il ripristino la spiegazione che mi hai dato è quella per xp
arcere84
Inviato: Thursday, October 04, 2012 9:28:04 AM

Rank: AiutAmico

Iscritto dal : 1/1/2012
Posts: 166
trovato e fatto ho disattivato il ripristino e riavviato il pc e riattivato il ripristino
se abbiamo finito vi volevo ringraziare titti e due (r16 e shapiro)per avermi aiutato e sopratutto per la pazienza che avete avuto con il sottoscritto.
Luciano
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.