PDA

View Full Version : Problemi con emule: sarà un virus??


swarm
28-10-2005, 16:04
Salve a tutti

da circa tre giorni ho notato in improvviso e sensibile peggioramento nelle prestazioni di emule: scarico a 18kb/s di media (prima andavo a oltre 90kb/s di media), ho frequenti disconnessioni dai server, a volte la rete Kad mi dice firewalled.

Ho notato la comparsa sul taskmanager del processo mspmsosv.exe, quindi vi posto il log file HijackThis :Logfile of HijackThis v1.99.1
Scan saved at 16.49.51, on 28/10/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\Explorer.EXE
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
G:\eMule0.45b\emule.exe
C:\Documents and Settings\Daniela1\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://it.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: @msdxmLC.dll,-1@1040,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [eMuleAutoStart] G:\eMule0.45b\emule.exe -AutoStart
O4 - HKCU\..\RunOnce: [MPlayer2_FixUp] C:\WINNT\inf\unregmp2.exe /Fixups
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://it.msn.com
O14 - IERESET.INF: MS_START_PAGE_URL=http://it.msn.com
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/1120173.exe
O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://www.supersesso.org/adulti.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe

ho un router firewall netgear dg834it e avast antivirus.

che sarà mai?

Stereogab
28-10-2005, 16:23
fixa queste:
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/1120173.exe
O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://www.supersesso.org/adulti.exe

quel processo si dovrebbe riferire a windows media player

andorra24
28-10-2005, 16:24
Fixa:
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://it.msn.com
O14 - IERESET.INF: MS_START_PAGE_URL=http://it.msn.com
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/1120173.exe
O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://www.supersesso.org/adulti.exe

Fai una scansione con ewido: http://download.ewido.net/ewido-setup.exe

wgator
28-10-2005, 17:08
Ciao,

avviso ai curiosoni: non cliccate su quel link (supersesso ecc.) rischiate di beccarvi parecchie schifezze solo aprendo la pagina iniziale :p

swarm
28-10-2005, 17:41
ciao ragazzi

grazie a tutti per le risposte....

scusate l'ignoranza: fixa=cancellare? se sì come, col regedit?

PS: mai cliccato su quei link, sto postando dal pc-serverino emule, usato solo per scaricare e navigare saltuariamente...

PS2: per completezza, posto il log di HijackThis in modalità provvisoria:


Logfile of HijackThis v1.99.1
Scan saved at 17.14.00, on 28/10/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\userinit.exe
C:\WINNT\Explorer.EXE
C:\Documents and Settings\Daniela1\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://it.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: @msdxmLC.dll,-1@1040,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [eMuleAutoStart] G:\eMule0.45b\emule.exe -AutoStart
O4 - HKCU\..\RunOnce: [MPlayer2_FixUp] C:\WINNT\inf\unregmp2.exe /Fixups
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://it.msn.com
O14 - IERESET.INF: MS_START_PAGE_URL=http://it.msn.com
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/1120173.exe
O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FC} - http://www.supersesso.org/adulti.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe

provvedo alla scansione con ewido...

a presto!

andorra24
28-10-2005, 17:44
Fixare cioe correggere. Devi mettere la spunta nella casellina accanto alle voci che ti sono state indicate sopra e poi premi ''fix checked'' dopo aver chiuso tutte le finestre aperte, soprattutto il browser.

swarm
28-10-2005, 18:23
grazie per il suggerimento :)

ecco la nuova scansione con Hijack, dopo il fixaggio e il riavvio del sistema (emule è chiuso)


Logfile of HijackThis v1.99.1
Scan saved at 19.17.02, on 28/10/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\Explorer.EXE
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
C:\WINNT\system32\mobsync.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Documents and Settings\Daniela1\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://it.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: @msdxmLC.dll,-1@1040,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Servizio amministrativo di Gestione disco logico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe

se i problemi nn si eliminano, che faccio, provo a cercare spyware?

andorra24
28-10-2005, 18:26
Il log e' pulito. Hai fatto la scansione con ewido?

matteo1
28-10-2005, 18:29
per sicurezza darei una passata con questo:
mcafee scanner (http://dl.codecpack.nl/m/mcafee_20051027.exe)

wgator
28-10-2005, 18:29
Ciao,

ora sembrerebbe tutto a posto :)

EDIT
Andorra e Matteo: scusate, non avevo fatto il "refresh"

swarm
28-10-2005, 18:58
ho appena terminato una scansione con avast! all'avvio, ma nn m'ha trovato niente a parte alcuni errori, nel tentativo di scansire dei file nella directory di Programmi/Javasoft/JRE/1.3.1/lib, dicendomi che è impossibilitato ad agire-file zip danneggiato... :confused:

vado con ewido e mcafee e vi fo' sapere

swarm
28-10-2005, 19:20
effettuata scansione completa con ewido

..... 55 file infetti :D

Risultati scansione:

HKLM\SOFTWARE\Classes\MediaAccX.Installer -> Spyware.WinAd : Pulito con Backup
HKLM\SOFTWARE\Classes\MediaAccX.Installer\CLSID -> Spyware.WinAd : Pulito con Backup
HKU\S-1-5-21-515967899-920026266-1060284298-1000\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@2o7[2].txt -> Spyware.Cookie.2o7 : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@ads.pointroll[1].txt -> Spyware.Cookie.Pointroll : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@adtech[2].txt -> Spyware.Cookie.Adtech : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@advertising[1].txt -> Spyware.Cookie.Advertising : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@as-eu.falkag[2].txt -> Spyware.Cookie.Falkag : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@atdmt[2].txt -> Spyware.Cookie.Atdmt : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@bfast[2].txt -> Spyware.Cookie.Bfast : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@ehg-ati.hitbox[2].txt -> Spyware.Cookie.Hitbox : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@ehg-esa.hitbox[1].txt -> Spyware.Cookie.Hitbox : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@ehg-philipsvheusen.hitbox[1].txt -> Spyware.Cookie.Hitbox : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@ehg-skinstore.hitbox[1].txt -> Spyware.Cookie.Hitbox : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@ehg-yooxspa.hitbox[1].txt -> Spyware.Cookie.Hitbox : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@fastclick[1].txt -> Spyware.Cookie.Fastclick : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@findwhat[1].txt -> Spyware.Cookie.Findwhat : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@hitbox[1].txt -> Spyware.Cookie.Hitbox : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@ilead.itrack[2].txt -> Spyware.Cookie.Itrack : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@overture[1].txt -> Spyware.Cookie.Overture : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@perf.overture[1].txt -> Spyware.Cookie.Overture : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@qksrv[2].txt -> Spyware.Cookie.Qksrv : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@sel.as-eu.falkag[1].txt -> Spyware.Cookie.Falkag : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@servedby.advertising[2].txt -> Spyware.Cookie.Advertising : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@server.iad.liveperson[2].txt -> Spyware.Cookie.Liveperson : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@stat.onestat[2].txt -> Spyware.Cookie.Onestat : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@statcounter[2].txt -> Spyware.Cookie.Statcounter : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@statse.webtrendslive[2].txt -> Spyware.Cookie.Webtrendslive : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@test.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@web4.realtracker[2].txt -> Spyware.Cookie.Realtracker : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@weborama[1].txt -> Spyware.Cookie.Weborama : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@www.smartadserver[2].txt -> Spyware.Cookie.Smartadserver : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@xxxtoolbar[1].txt -> Spyware.Cookie.Xxxtoolbar : Pulito con Backup
C:\Documents and Settings\Daniela1\Cookies\daniela1@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Pulito con Backup
C:\WINNT\Cookies\daniela1@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Pulito con Backup
C:\WINNT\Cookies\daniela1@adtech[2].txt -> Spyware.Cookie.Adtech : Pulito con Backup
C:\WINNT\Cookies\daniela1@as1.falkag[1].txt -> Spyware.Cookie.Falkag : Pulito con Backup
C:\WINNT\Cookies\daniela1@atdmt[1].txt -> Spyware.Cookie.Atdmt : Pulito con Backup
C:\WINNT\Cookies\daniela1@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Pulito con Backup
C:\WINNT\Cookies\daniela1@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Pulito con Backup
C:\WINNT\Cookies\daniela1@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Pulito con Backup
C:\WINNT\Cookies\daniela1@ilead.itrack[2].txt -> Spyware.Cookie.Itrack : Pulito con Backup
C:\WINNT\Cookies\daniela1@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Pulito con Backup
C:\WINNT\Cookies\daniela1@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Pulito con Backup
C:\WINNT\Cookies\daniela1@statcounter[2].txt -> Spyware.Cookie.Statcounter : Pulito con Backup
C:\WINNT\Cookies\daniela1@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Pulito con Backup
C:\WINNT\Cookies\daniela1@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Pulito con Backup
C:\WINNT\Cookies\daniela1@weborama[1].txt -> Spyware.Cookie.Weborama : Pulito con Backup
C:\WINNT\Cookies\daniela1@www.smartadserver[1].txt -> Spyware.Cookie.Smartadserver : Pulito con Backup


serve anche mcafee??

andorra24
28-10-2005, 19:37
Gia' che ci sei una scansione antivirus non ti fa male.

teuz84
28-10-2005, 19:59
fra le scansioni online questo secondo me è uno dei migliori anche io ha avast ma certe voltr bitdefender trova sempre qualcosa in più...
http://www.bitdefender.com/scan8/ie.html

matteo1
28-10-2005, 20:24
vivamente consigliato ccleaner:
http://www.ccleaner.com/ccdownload.asp

swarm
28-10-2005, 22:36
ho fatto la scansione con avast e con ewido, ma il problema permane (ora anche scaricando file da internet noto lentezza.... mah)

cmq ora vado con ccleaner e poi mcafee (semmai anche bitdefender)

grazie a tutti :)