|
|
|
![]() |
|
Strumenti |
![]() |
#1 |
Messaggi: n/a
|
dialer del cazzo!
aiutatemi da settimane mi si apre sto dialer maledetto!!!
|
![]() |
![]() |
#2 |
Senior Member
Iscritto dal: Jun 2003
Città: "Mantua me genuit" Trattative concluse: 1 fracco!!! Devianze: MacTard iMac 27" i5 2,8Ghz 4GB IPHONE 5 32GB Black Iscritto dal: Nov 2002
Messaggi: 4426
|
Ke dialer è prima di tutto???
Vai in Start/Pannello di controllo/Installazione applicazioni e controlla se è possibile di disinstallarlo da lì. Scaricati spybot s&d, adaware6 e a2 e fai 1 scansione del sistema. Controlla in msconfig , nel registro (HKLM/Software/Microsoft/Windows/CurrentVersion/Run, RunOnce, RunOnceEx), nei temporanei, in Windows/System32 e nei Preferiti, se trovi ancora tracce del dialer in questione. Ciao. |
![]() |
![]() |
![]() |
#3 | |
Senior Member
Iscritto dal: Jun 2001
Città: Lazio
Messaggi: 5935
|
Quote:
E' un caso senza speranza, gli avevo fatto togliere delle voci con il solito programmino e sembrava aver risolto..erano voci di siti per giochi e un dialer e il loader ora lo ha ripreso.......SE NON STA ATTENTO c'è poco da fare........ ![]() Ciao
__________________
HP Gaming 16 I7 10750H, nVidia GTX1650TI 4Gbyte DDR6, 16Gbyte di Ram, SSD INTEL 500Gbyte, Amplificatore Denon PMA-510AE, Diffusori Q Acoustics 3020i |
|
![]() |
![]() |
![]() |
#4 | |
Messaggi: n/a
|
Quote:
non vado su nessun sito stranooooooooooooooooo questo è il dialer malefico! ![]() |
|
![]() |
![]() |
#5 |
Messaggi: n/a
|
uppppette!
|
![]() |
![]() |
#6 | |
Senior Member
Iscritto dal: Jun 2001
Città: Lazio
Messaggi: 5935
|
Quote:
Ciao
__________________
HP Gaming 16 I7 10750H, nVidia GTX1650TI 4Gbyte DDR6, 16Gbyte di Ram, SSD INTEL 500Gbyte, Amplificatore Denon PMA-510AE, Diffusori Q Acoustics 3020i |
|
![]() |
![]() |
![]() |
#7 | |
Messaggi: n/a
|
Quote:
|
|
![]() |
![]() |
#8 | |
Senior Member
Iscritto dal: Jun 2001
Città: Lazio
Messaggi: 5935
|
Quote:
Comunque se hai problemi riposta il log di quel tool. Ciao
__________________
HP Gaming 16 I7 10750H, nVidia GTX1650TI 4Gbyte DDR6, 16Gbyte di Ram, SSD INTEL 500Gbyte, Amplificatore Denon PMA-510AE, Diffusori Q Acoustics 3020i |
|
![]() |
![]() |
![]() |
#9 | |
Messaggi: n/a
|
Quote:
|
|
![]() |
![]() |
#10 |
Messaggi: n/a
|
ecco le img
![]() ![]() fateme sape! ho usato tutto adware e spyboot |
![]() |
![]() |
#11 |
Senior Member
Iscritto dal: Jun 2003
Città: "Mantua me genuit" Trattative concluse: 1 fracco!!! Devianze: MacTard iMac 27" i5 2,8Ghz 4GB IPHONE 5 32GB Black Iscritto dal: Nov 2002
Messaggi: 4426
|
Cavoli!!!! ...ma nn puoi usare il tasto "save log", aprire poi il file di testo e fare 1 copia ed incolla qui????
![]() Ultima modifica di MrOZ : 09-02-2004 alle 19:00. |
![]() |
![]() |
![]() |
#12 |
Senior Member
Iscritto dal: Sep 2003
Messaggi: 988
|
Recentemente ho scoperto
bazooka adware scanner ed e' piu' efficace di lavasoft non rimuove i file in automatico, ma rimanda a una pagina web dove e' spiegato come farlo manualmente passo passo ![]() Poi io uso peerguardian
__________________
IMBROCCHIAMOLA! |
![]() |
![]() |
![]() |
#13 | |
Messaggi: n/a
|
Quote:
domani li riposto ![]() |
|
![]() |
![]() |
#14 | |
Messaggi: n/a
|
Quote:
Logfile of HijackThis v1.97.7 Scan saved at 15.37.05, on 10/02/04 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\SDMAN.EXE C:\PROGRAMMI\FILE COMUNI\EPSON\EBAPI\SAGENT2.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\RPCSS.EXE C:\WINDOWS\TASKMON.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\SYSTEM\IGFXTRAY.EXE C:\WINDOWS\SYSTEM\HKCMD.EXE C:\SABRE\APPS\ATS\SSSCLNT.EXE C:\WINDOWS\LOADQM.EXE C:\PROGRAMMI\NORTON ANTIVIRUS\NAVAPW32.EXE C:\WINDOWS\SYSTEM\DDHELP.EXE C:\WINDOWS\SYSTEM\STIMON.EXE C:\WINDOWS\SYSTEM\E_S10IC2.EXE C:\PROGRAMMI\MSN MESSENGER\MSNMSGR.EXE C:\WINDOWS\SABSERV.EXE C:\SABRE\APPS\OADP\OADP.EXE C:\PROGRAMMI\WINFAX\WFXCTL32.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\PROGRAMMI\STOPDIALERS\STOPDIALER.EXE C:\PROGRAMMI\OUTLOOK EXPRESS\MSIMN.EXE C:\WINDOWS\SYSTEM\PSTORES.EXE C:\DOCUMENTI\FABIO\COMPUTER\HTML2\HTML2POP3.EXE C:\PROGRAMMI\POPUPKILLERTRACKSERASER\POPUPKILLERTRAY.EXE C:\PROGRAMMI\ICQLITE\ICQLITE.EXE C:\SABRE\SV.EXE C:\WINDOWS\MDBCSAPI.EXE C:\WINDOWS\SYSTEM\WSASRV.EXE C:\SABRE\SBTIMER.EXE C:\PROGRAMMI\WINFAX\WFXMOD32.EXE C:\PROGRAMMI\WINZIP\WINZIP32.EXE C:\WINDOWS\TEMP\HIJACKTHIS.EXE R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://in.webcounter.cc/--/?cwvag (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://in.webcounter.cc/---/?cwvag (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://in.webcounter.cc/--/?cwvag (obfuscated) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://in.webcounter.cc/-/?cwvag about:blank (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://in.webcounter.cc/-/?cwvag (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://in.webcounter.cc/--/?cwvag (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://in.webcounter.cc/---/?cwvag (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://in.webcounter.cc/--/?cwvag (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://in.webcounter.cc/-/?cwvag about:blank (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://in.webcounter.cc/--/?cwvag (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://in.webcounter.cc/--/?cwvag (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://in.webcounter.cc/--/?cwvag (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://in.webcounter.cc/---/?cwvag (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://in.webcounter.cc/--/?cwvag (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://in.webcounter.cc/--/?cwvag (obfuscated) O1 - Hosts: 193.125.201.50 ie.search.msn.com O1 - Hosts: 193.125.201.50 sitefinder.verisign.com O2 - BHO: (no name) - {A09790E7-DD00-4A83-B632-5B563423CFBB} - C:\PROGRAMMI\POPUPKILLERTRACKSERASER\POPUPKILLERIEDLL.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\SYSTEM\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\SYSTEM\hkcmd.exe O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [Sabre Site Services] C:\SABRE\Apps\ATS\SSSClnt.EXE O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET O4 - HKLM\..\Run: [Internat Conf] \bootconf.exe O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe O4 - HKLM\..\Run: [Soundmx] \soundmx.exe O4 - HKLM\..\Run: [Control] rundll32.exe C:\WINDOWS\SYSTEM\ctrlpan.dll,Restore ControlPanel O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\SYSTEM\E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O5 "LPT1:" /M "Stylus C42" O4 - HKLM\..\Run: [IST Service] C:\Programmi\ISTsvc\istsvc.exe O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [SDApp] C:\WINDOWS\SDMan.EXE O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAMMI\MSN MESSENGER\MSNMSGR.EXE" /background O4 - HKCU\..\RunOnce: [ICQ Lite] C:\PROGRAMMI\ICQLITE\ICQLITE.EXE -trayboot O4 - Startup: Server Sabre.lnk = C:\WINDOWS\sabserv.exe O4 - Startup: Sabre Printing Module.lnk = C:\SABRE\Apps\OADP\Oadp.exe O4 - Startup: Controller.LNK = C:\Programmi\WinFax\WFXCTL32.EXE O4 - Startup: Microsoft Office.lnk = C:\WINDOWS\Application Data\Microsoft\Installer\{00030410-78E1-11D2-B60F-006097C998E7}\misc.exe O4 - Startup: C6 Client.LNK = C:\TinMessenger\TinMessenger.exe O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmsearch.html O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmcache.html O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmsimilar.html O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmbacklinks.html O9 - Extra button: ICQ Lite (HKLM) O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM) O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) - http://toolbar.google.com/data/it/de.../GoogleNav.cab O16 - DPF: myEXTRA! Italian Support - https://directaccess.sabre.it/mcs/co...Viewers_It.cab O16 - DPF: myEXTRA! Terminal Feature Support - https://directaccess.sabre.it/mcs/co...erFeatures.cab O16 - DPF: myEXTRA! 3270 Terminal (SSL) - https://directaccess.sabre.it/mcs/co...inalSecure.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab O16 - DPF: {9b935470-ad4a-11d5-b63e-00c04faedb18} (Oracle JInitiator 1.1.8.16) - O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...reShowdown.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {91413D86-9F27-402C-B5E3-DEBDD122C3B2} - http://content.netvenda.com/sites/ga.../it/games3.cab O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = dns2.interbusiness.it O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 151.99.125.2,151.99.250.2 O19 - User stylesheet: C:\WINDOWS\Web\tips.ini O19 - User stylesheet: C:\WINDOWS\hh.htt (HKLM) |
|
![]() |
![]() |
#15 |
Messaggi: n/a
|
up
|
![]() |
![]() |
#16 |
Senior Member
Iscritto dal: Jun 2003
Città: "Mantua me genuit" Trattative concluse: 1 fracco!!! Devianze: MacTard iMac 27" i5 2,8Ghz 4GB IPHONE 5 32GB Black Iscritto dal: Nov 2002
Messaggi: 4426
|
Scaricati CWShredder... lancialo, poi riavvia, rifai 1 nuova scansione con Hijackthis e poi riposta 1 nuovo log qui.
|
![]() |
![]() |
![]() |
#18 | |
Senior Member
Iscritto dal: Jun 2003
Città: "Mantua me genuit" Trattative concluse: 1 fracco!!! Devianze: MacTard iMac 27" i5 2,8Ghz 4GB IPHONE 5 32GB Black Iscritto dal: Nov 2002
Messaggi: 4426
|
Quote:
![]() ![]() ...deve essere superpreparato (oltre ke superdotato ![]() ![]() ![]() ![]() |
|
![]() |
![]() |
![]() |
#19 |
Messaggi: n/a
|
dai aiutatemi!
|
![]() |
![]() |
#20 | |
Senior Member
Iscritto dal: Jun 2003
Città: "Mantua me genuit" Trattative concluse: 1 fracco!!! Devianze: MacTard iMac 27" i5 2,8Ghz 4GB IPHONE 5 32GB Black Iscritto dal: Nov 2002
Messaggi: 4426
|
Quote:
|
|
![]() |
![]() |
![]() |
Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 07:17.