|
Rank: AiutAmico
Iscritto dal : 8/24/2008 Posts: 4,164
|
Commenta:adesso scarica questo file direttamente nella pennetta con la quale hai fatto la scansione e premi il pulsante FIX
A fine scansione Il tool creerà un log sulla flashdrive dal nome Fixlog.txt
devi copiarmi il contenuto del file = > Fixlog.txt non puo' esserci scritto come dici quello l'ho preparato io e te lo ho fatto scaricare nella pennetta
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
scusami se insisto ma cliccando su questo file che mi hai postato ieri alle 21.51 mi esce la schermata di wikisend hai la possibilità di collegarti con TEAM VIVER?
|
|
Rank: AiutAmico
Iscritto dal : 8/24/2008 Posts: 4,164
|
fai una cosa riesegui l'operazione scarica questo file direttamente nella pennetta con la quale hai fatto la scansione e premi FIXlascia lavorare il tool e appena finito posta il log che trovi nella pennetta col nome Fixlog.txt devi copiarlo non aprirlo....capito??
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
niente non funziona forse sono io che non capisco un c......o e sbaglio ad eseguire la procedura ???
|
|
Rank: AiutAmico
Iscritto dal : 8/24/2008 Posts: 4,164
|
ma e' facile....quando scarichi il file invece di metterlo sul desktop scegli l'unita' dove risiede la pennetta (sara' F oppure G o altro) poi premi il pulsante FIX e quando ha finito nella stessa pennetta troverai il file Fixlog.txt che devi allegare ( o copiare) nel forum
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
forse ho trovato (spero) però mi dice
no fixilist.txt found the fixlist.txt should be made and saved in te same directory the tool is located
cosa devo fare?
|
|
Rank: AiutAmico
Iscritto dal : 8/7/2007 Posts: 11,016
|
Tagliamo la testa al toro: Scarica OTL, e salvalo sul desktop: http://oldtimer.geekstogo.com/OTL.comClicca sull'icona di OTL che trovi sul tuo desktop . Metti la spunta su SCAN ALL USERS. Sotto output, metti la spunta : minimal outputClicca sulla freccettina di File Age e seleziona 60 Days Metti la spunta a LOP Check e Purity Check. Clicca su [b ]RUN SCAN[/b] Lascia fare la scansione senza interferire. Al termine della scansione trovi 2 log sul desktop. OTL.txt ed Extras.txt, salvali e caricali su Wikisend, per postarli sul forum. Per caricare i log fai così:Collegati ad internet e vai alla pagina WikiSend: http://www.wikisend.com/ Clicca sul bottone " Sfoglia" Seleziona il file appena salvato Clicca su Upload file Dopo qualche secondo, vieni spostato su una nuova pagina con il link in diversi formati: Download Link / Forum Link Seleziona Forum Link, copialo e incollalo in un nuovo messaggio per il forum.
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
ecco fatto spero di aver fatto giusto questa volta [ Extras.TxtURL=http://wikisend.com/download/413276/OTL.Txt]OTL.Txt[/URL]
|
|
Rank: AiutAmico
Iscritto dal : 8/7/2007 Posts: 11,016
|
Avvia OTL. Sotto " Custom Scans\Fixes" copia-incolla questo codice: (non copiare la parola Code) Code::Processes :Services
:OTL [2012/08/14 09:28:04 | 000,000,000 | ---D | C] -- C:\Users\Luciano\AppData\Roaming\OpenCandy
:Files C:\Users\Luciano\AppData\Roaming\xsecva C:\ProgramData\sqj.pad C:\ProgramData\avaj.pad C:\ProgramData\ras_0oed.pad C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240} C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\L C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\U C:\Windows\assembly\Desktop.ini ipconfig /flushdns /c
:reg [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command] ""=""%1" %*"
:commands [purity] [emptytemp] [CLEARALLRESTOREPOINTS] Clicca sul pulsante RUN FIX. Lascia fare la scansione senza interferire. Posta il log.
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
ecco il log
All processes killed ========== PROCESSES ========== ========== SERVICES/DRIVERS ========== ========== OTL ========== C:\Users\Luciano\AppData\Roaming\OpenCandy\E9A6E5A221CC483390D2F57F9E7C26CB folder moved successfully. C:\Users\Luciano\AppData\Roaming\OpenCandy folder moved successfully. ========== FILES ========== C:\Users\Luciano\AppData\Roaming\xsecva folder moved successfully. C:\ProgramData\sqj.pad moved successfully. C:\ProgramData\avaj.pad moved successfully. C:\ProgramData\ras_0oed.pad moved successfully. C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\U folder moved successfully. C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\L folder moved successfully. C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240} folder moved successfully. File\Folder C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\L not found. File\Folder C:\Users\Luciano\AppData\Local\{df7a1774-2aa9-82a2-a75e-12ec8cfbe240}\U not found. C:\Windows\assembly\Desktop.ini moved successfully. < ipconfig /flushdns /c > Configurazione IP di Windows Cache del resolver DNS svuotata. C:\Users\Luciano\Desktop\cmd.bat deleted successfully. C:\Users\Luciano\Desktop\cmd.txt deleted successfully. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Luciano ->Temp folder emptied: 768062 bytes ->Temporary Internet Files folder emptied: 14887103 bytes ->Java cache emptied: 187273 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 537 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 28644 bytes RecycleBin emptied: 1388734 bytes Total Files Cleaned = 17,00 mb Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.70.1 log created on 10022012_222649
Files\Folders moved on Reboot... C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ASD5OXQN\adsCA4IXG6A.htm moved successfully. C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ASD5OXQN\adsCA7NNYZ0.htm moved successfully. C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8F3FB8WW\adsCADFGIYW.htm moved successfully. C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8F3FB8WW\aiutamici_it[1].htm moved successfully. C:\Users\Luciano\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8F3FB8WW\metro[2].htm moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
per r16 scusa se ti rompo ieri sera ti ho postato il log puoi dare un'occhiata grazie
|
|
Rank: AiutAmico
Iscritto dal : 8/7/2007 Posts: 11,016
|
Ciao. Esegui una nuova scansione con OTL. Posta il log con le solite modalità. (Wikisend) Dimmi anche quali problemi riscontri.
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
per r16 ecco questo è quello che ho trovato spero di aver fatto giusto OTL.Txt
|
|
Rank: AiutAmico
Iscritto dal : 8/7/2007 Posts: 11,016
|
Scarica Adwcleaner sul desktop: http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleanerAvvialo e clicca sul pulsante search. Finita la scansione, elimina il log che rilascia sul desktop, e clicca su " Delete". Conferma con OK le varie finestre che ti compariranno. Il pc si riavvierà, e uscirà il log con le eliminazioni. Postalo qui. Non mi hai detto se e quali problemi riscontri.
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
adesso il PC mi sembra vada bene avevo preso il virus della polizia postale e lo ho eliminato in modalita provv. e volevo che mi controllaste il log per vedere se lo avevo eliminato
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
# AdwCleaner v2.003 - Logfile created 10/03/2012 at 19:29:38 # Updated 23/09/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (32 bits) # User : Luciano - LUCIANO-PC # Boot Mode : Normal # Running from : C:\Users\Luciano\Desktop\adwcleaner.exe # Option [Delete]
***** [Services] *****
Stopped & Deleted : Web Assistant Updater
***** [Files / Folders] *****
File Deleted : C:\user.js Folder Deleted : C:\Program Files\ChatZum Toolbar Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\Web Assistant Folder Deleted : C:\ProgramData\Ask Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\boost_interprocess Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\Users\Luciano\AppData\Local\Conduit Folder Deleted : C:\Users\Luciano\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Folder Deleted : C:\Users\Luciano\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Luciano\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\Luciano\AppData\LocalLow\searchquband Folder Deleted : C:\Users\Luciano\AppData\Roaming\OfferBox
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Software\searchqutoolbar Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\DataMngr Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\Iminent Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E1368B44-60A8-470F-9537-C1BC2390C8E3} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Offerbox Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1 Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1561552 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2851640 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3106777 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : HKLM\Software\Iminent Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\NEW_CORRECT_incredibar_install_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\NEW_CORRECT_incredibar_install_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E1368B44-60A8-470F-9537-C1BC2390C8E3} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Key Deleted : HKLM\Software\Offerbox Key Deleted : HKLM\Software\Tarma Installer Key Deleted : HKLM\Software\Web Assistant Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
-\\ Google Chrome v22.0.1229.79
ecco il log
File : C:\Users\Luciano\AppData\Local\Google\Chrome\User Data\Default\Preferences
Deleted [l.24] : search_url = "hxxp://mystart.incredibar.com/mb165/?loc=IB_DS&search={searchTerms}&a=6R8vhKNrZW&i=26", Deleted [l.264] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?ctid=CT2851640&SearchSource=48" ] Deleted [l.266] : homepage = "hxxp://search.conduit.com/?ctid=CT2851640&SearchSource=48",
*************************
AdwCleaner[R1].txt - [11788 octets] - [03/10/2012 19:28:34] AdwCleaner[S1].txt - [11803 octets] - [03/10/2012 19:29:38]
########## EOF - C:\AdwCleaner[S1].txt - [11864 octets] ##########
|
|
Rank: AiutAmico
Iscritto dal : 8/24/2008 Posts: 4,164
|
Commenta:adesso il PC mi sembra vada bene avevo preso il virus della polizia postale e lo ho eliminato in modalita provv. e volevo che mi controllaste il log per vedere se lo avevo eliminato no non lo avevi eliminato, le infezioni erano riportate nell'operazione che ti ho postato e che non sei riuscito a portare a termine e dopo la scansione con otl r16 te l'ha fatta eliminare, ma non puoi dire che l'avevi eliminata.....
|
|
Rank: AiutAmico
Iscritto dal : 8/7/2007 Posts: 11,016
|
shapiro ha scritto: no non lo avevi eliminato,
Sì, il virus non poteva essere stato eliminato, visto che i log (tutti e 2) lo riportavano bello e pimpante. Inoltre come detto, era anche "accompagnato" dal rootkit Zero Access. @ arcere84: Comunque: Apri OTL e clicca su Cleanup. Si disistallerà OTL. Se ti chiede il riavvio : acconsenti. Dai una pulita ( registro compreso)con CCleaner http://www.aiutamici.com/software?ID=11223Provvedi a svuotare del suo contenuto la cartella Prefetch : clicca su Risorse del Computer clicca su Disco locale C: cerca, all’interno delle cartelle che saranno visualizzate la cartella Windows, aprila ed, al suo interno, cerca la cartella Prefetch, la apri ed elimina tutte le voci conservate al suo interno ( non eliminare la cartella) SVUOTA IL CESTINODisattiva il ripristino configurazione di sistema: http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121Riavvia il pc. Riattiva il ripristino configurazione di sistema
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
scusami r16 io ho win 7 non riesco a trovare per disattivare il ripristino la spiegazione che mi hai dato è quella per xp
|
|
Rank: AiutAmico
Iscritto dal : 1/1/2012 Posts: 166
|
trovato e fatto ho disattivato il ripristino e riavviato il pc e riattivato il ripristino se abbiamo finito vi volevo ringraziare titti e due (r16 e shapiro)per avermi aiutato e sopratutto per la pazienza che avete avuto con il sottoscritto. Luciano
|
|
Guest |