|
|||||||
|
|
|
![]() |
|
|
Strumenti |
|
|
#1 |
|
Senior Member
Iscritto dal: Dec 2001
Città: Napoli
Messaggi: 3249
|
Spyware : le ho provate tutte :(
Allora raga, ci risiamo con sti spyware del biiiiiiiiiiiiiiiiip!
Ho provato per cercare di eliminarlo : AdAware, Spybot, CWShredder ma nada...... nn ne vuole sapere di andar via... la pagina che mi compare, correlata da pop up è questa : ![]() questi invece sono i risultati di HijackThis v1.97.7 : Logfile of HijackThis v1.97.7 Scan saved at 17.14.24, on 07/10/04 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\WINDOWS\helpw.exe C:\Programmi\Messenger Plus! 3\MsgPlus.exe C:\WINDOWS\sysly32.exe C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\system32\cisvc.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe C:\WINDOWS\system32\apikp.exe C:\WINDOWS\System32\devldr32.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Gianlu\Desktop\AntiSpyware\Hijackthis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Tin.it R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {D7AC1511-463F-7B9F-50A1-66F823A5FA17} - C:\WINDOWS\ipee32.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [helpw] "helpw.exe" O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\Messenger Plus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [sysly32.exe] C:\WINDOWS\sysly32.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O9 - Extra button: Umail (HKCU) O14 - IERESET.INF: START_PAGE_URL=http://www.virgilio.it/free O15 - Trusted Zone: *.05p.com O15 - Trusted Zone: *.blazefind.com O15 - Trusted Zone: *.clickspring.net O15 - Trusted Zone: *.flingstone.com O15 - Trusted Zone: *.mt-download.com O15 - Trusted Zone: *.my-internet.info O15 - Trusted Zone: *.scoobidoo.com O15 - Trusted Zone: *.searchbarcash.com O15 - Trusted Zone: *.searchmiracle.com O15 - Trusted Zone: *.slotch.com O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole...rcadeRdxIE.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{EA84403B-DE45-4529-9C81-17A349D238E9}: NameServer = 212.216.112.112,212.216.172.62
__________________
Codice:
Concluso con[OK BAD]: ercagno,Claudio, Antopx, Lunaticgate, Deuced, Nicola5154,nEA[x2], Lupino.86, ironfrank, Marxio, luke10, Sniper86, alexis1980, Andrea16v[x3], Red_Rose, mitsuhashi1, antanio, Rinos, flavix25, geolite30, cianuro, spzerosp, GoldFinder, Zagor4, Mercurius00, Leland Gaunt, Iron10, tyco74, Clatit, PaPuAsja, onka, jing13, _19Fabio85_, Murakami, raizen89, dinigio63, ncerozz, rtype, Isotattico, vinz86, valdisteadsl, battalion75 |
|
|
|
|
|
#2 |
|
Senior Member
Iscritto dal: Nov 2003
Città: Mordor
Messaggi: 336
|
Spunta e fixa
*************************************************** R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti O15 - Trusted Zone: *.05p.com O15 - Trusted Zone: *.blazefind.com O15 - Trusted Zone: *.clickspring.net O15 - Trusted Zone: *.flingstone.com O15 - Trusted Zone: *.mt-download.com O15 - Trusted Zone: *.my-internet.info O15 - Trusted Zone: *.scoobidoo.com O15 - Trusted Zone: *.searchbarcash.com O15 - Trusted Zone: *.searchmiracle.com O15 - Trusted Zone: *.slotch.com O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab ************************************************** Pieno di schifezze, eh??? Fammi sapere! Ciao |
|
|
|
|
|
#3 |
|
Senior Member
Iscritto dal: Dec 2001
Città: Napoli
Messaggi: 3249
|
nn è il mio pc
cmq si...... pieno di monnezza appena posso provo e vedo se va!
__________________
Codice:
Concluso con[OK BAD]: ercagno,Claudio, Antopx, Lunaticgate, Deuced, Nicola5154,nEA[x2], Lupino.86, ironfrank, Marxio, luke10, Sniper86, alexis1980, Andrea16v[x3], Red_Rose, mitsuhashi1, antanio, Rinos, flavix25, geolite30, cianuro, spzerosp, GoldFinder, Zagor4, Mercurius00, Leland Gaunt, Iron10, tyco74, Clatit, PaPuAsja, onka, jing13, _19Fabio85_, Murakami, raizen89, dinigio63, ncerozz, rtype, Isotattico, vinz86, valdisteadsl, battalion75 |
|
|
|
|
|
#4 |
|
Senior Member
Iscritto dal: Dec 2001
Città: Napoli
Messaggi: 3249
|
pc incriminato
sono sul pc incriminato, ho appena eliminato le cose ke mi hai detto, ma gli R1 e R0 ricompaiono dopo ke eseguo IE
riecco il log : Logfile of HijackThis v1.97.7 Scan saved at 20.37.04, on 07/10/04 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\WINDOWS\helpw.exe C:\Programmi\Messenger Plus! 3\MsgPlus.exe C:\WINDOWS\sysly32.exe C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\system32\cisvc.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe C:\WINDOWS\System32\devldr32.exe C:\WINDOWS\system32\apikp.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Gianlu\Desktop\AntiSpyware\Hijackthis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll O2 - BHO: (no name) - {D7AC1511-463F-7B9F-50A1-66F823A5FA17} - C:\WINDOWS\ipee32.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [helpw] "helpw.exe" O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\Messenger Plus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [sysly32.exe] C:\WINDOWS\sysly32.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O8 - Extra context menu item: &Google Search - res://c:\programmi\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: Collegamenti a ritroso - res://c:\programmi\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Pagine simili - res://c:\programmi\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Versione cache della pagina - res://c:\programmi\google\GoogleToolbar2.dll/cmcache.html O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O9 - Extra button: Umail (HKCU) O14 - IERESET.INF: START_PAGE_URL=http://www.virgilio.it/free O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole...rcadeRdxIE.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{EA84403B-DE45-4529-9C81-17A349D238E9}: NameServer = 212.216.112.112,212.216.172.62
__________________
Codice:
Concluso con[OK BAD]: ercagno,Claudio, Antopx, Lunaticgate, Deuced, Nicola5154,nEA[x2], Lupino.86, ironfrank, Marxio, luke10, Sniper86, alexis1980, Andrea16v[x3], Red_Rose, mitsuhashi1, antanio, Rinos, flavix25, geolite30, cianuro, spzerosp, GoldFinder, Zagor4, Mercurius00, Leland Gaunt, Iron10, tyco74, Clatit, PaPuAsja, onka, jing13, _19Fabio85_, Murakami, raizen89, dinigio63, ncerozz, rtype, Isotattico, vinz86, valdisteadsl, battalion75 |
|
|
|
|
|
#5 |
|
Senior Member
Iscritto dal: Nov 2003
Città: Mordor
Messaggi: 336
|
Fai così.
Fai passare CWShredder, Ad-aware e SpyBot aggiornati. Poi fai girare ancora HiJackThis (scaricati l'utlima versione) e postami il log. Fammi sapere Ciao |
|
|
|
|
|
#6 |
|
Senior Member
Iscritto dal: Aug 2004
Messaggi: 19355
|
http://forum.hwupgrade.it/showthread...hreadid=784740
Avevo aperto una discussione in merito, ma l'hanno letta in pochi.
__________________
"Le statistiche sono come le donne lascive: se riesci a metterci le mani sopra, puoi farci quello che ti pare" Walt Michaels |
|
|
|
|
|
#7 |
|
Senior Member
Iscritto dal: Nov 2002
Città: Lago maggiore
Messaggi: 981
|
Quello che hai preso è abuot blank... C'è un topic in rilievo a riguardo. Buona fortuna
__________________
L'uomo comune cerca la certezza negli occhi di chi gli sta di fronte e chiama questo fiducia in se. Il Guerriero cerca di essere senza macchia ai propri occhi e chiama questo umiltà. |
|
|
|
|
|
#8 |
|
Senior Member
Iscritto dal: May 2001
Messaggi: 1740
|
ciao
allora la prima cosa che devi fare è scaricarti l'ultimo hijackthis... la tua versione è vecchia poi riavvia in provvisoria assicurati che la vis dei files nascosti e di sistema sia attiva fai fare una pulizia ad Aboutbuster poi se vuoi fai altre passate con i software che preferisci per sicurezza potresti anche svuotare le cartelle temporanee di sistema e di IE riavvia in modalità normale e posta un log di hijackthis nuovo ciauz
__________________
www.tweakness.net - Trucchi per il PC DECALOGO ANTISPY - GUIDA A HIJACKTHIS - GUIDA AI SERVIZI DI WIN XP - CONSIGLI ANTIVIRUS PER BART'S PE - SP2 SLIPSTREAMING - FAQ WINDOWS XPSP2 - I SERVIZI DOPO SP2 - XP SP2 UNATTENDED - GUIDA A nLite |
|
|
|
|
|
#9 |
|
Senior Member
Iscritto dal: Dec 2001
Città: Napoli
Messaggi: 3249
|
allora
porcaccia la miseriaccia...
ecco il log di AboutBuster : Scanned at: 15.53.04 on: 08/10/04 -- Scan 1 --------------------------- about:Buster Version 3.0 Reference List : 15 ADS not scanned System(FAT) Removed 7 Random Key Entries Deleted 2 Service Keys Successfully! Removed! : C:\WINDOWS\yufqkl.dat Removed! : C:\WINDOWS\jcmnhd.dat Removed! : C:\WINDOWS\crxp.dll Removed! : C:\WINDOWS\System32\sdkwf.dll Error Removing! : C:\WINDOWS\System32\apikp.exe Removed! : C:\WINDOWS\System32\msyy.dll Removed! : C:\WINDOWS\System32\ntda32.exe Removed! : C:\WINDOWS\System32\d3hw.dll Attempted Clean Of Temp folder. Removed Uninstall Key (HSA) Removed Uninstall Key (SE) Removed Uninstall Key (SW) Pages Reset... Done! -- Scan 2 --------------------------- about:Buster Version 3.0 Reference List : 15 ADS not scanned System(FAT) Removed 6 Random Key Entries Removed! : C:\WINDOWS\yufqkl.dat Removed! : C:\WINDOWS\System32\apikp.exe Attempted Clean Of Temp folder. Removed Uninstall Key (HSA) Removed Uninstall Key (SE) Removed Uninstall Key (SW) Pages Reset... Done! Ecco l'altro log di HijackThis : Logfile of HijackThis v1.97.7 Scan saved at 15.58.08, on 08/10/04 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\cisvc.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\WINDOWS\helpw.exe C:\Programmi\Messenger Plus! 3\MsgPlus.exe C:\WINDOWS\sysly32.exe C:\WINDOWS\System32\devldr32.exe C:\WINDOWS\DigitalSound.exe C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\yufqkl.dat C:\Programmi\Messenger\msmsgs.exe C:\Documents and Settings\Gianlu\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll O2 - BHO: (no name) - {D7AC1511-463F-7B9F-50A1-66F823A5FA17} - C:\WINDOWS\ipee32.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [helpw] "helpw.exe" O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\Messenger Plus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [sysly32.exe] C:\WINDOWS\sysly32.exe O4 - HKLM\..\Run: [DigiD] "C:\WINDOWS\DigitalSound.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmi\Messenger Plus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background O8 - Extra context menu item: &Google Search - res://c:\programmi\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: Collegamenti a ritroso - res://c:\programmi\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Pagine simili - res://c:\programmi\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Versione cache della pagina - res://c:\programmi\google\GoogleToolbar2.dll/cmcache.html O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O9 - Extra button: Umail (HKCU) O14 - IERESET.INF: START_PAGE_URL=http://www.virgilio.it/free O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole...rcadeRdxIE.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{EA84403B-DE45-4529-9C81-17A349D238E9}: NameServer = 212.216.112.112,212.216.172.62 l'aboutbuster fa il suo lavoro... ma al riavvio di explorer siamo punto e a capo
__________________
Codice:
Concluso con[OK BAD]: ercagno,Claudio, Antopx, Lunaticgate, Deuced, Nicola5154,nEA[x2], Lupino.86, ironfrank, Marxio, luke10, Sniper86, alexis1980, Andrea16v[x3], Red_Rose, mitsuhashi1, antanio, Rinos, flavix25, geolite30, cianuro, spzerosp, GoldFinder, Zagor4, Mercurius00, Leland Gaunt, Iron10, tyco74, Clatit, PaPuAsja, onka, jing13, _19Fabio85_, Murakami, raizen89, dinigio63, ncerozz, rtype, Isotattico, vinz86, valdisteadsl, battalion75 |
|
|
|
|
|
#10 | |
|
Senior Member
Iscritto dal: Nov 2002
Città: Lago maggiore
Messaggi: 981
|
Re: allora
Quote:
C'è un 3d apposito in rilievo. ciao
__________________
L'uomo comune cerca la certezza negli occhi di chi gli sta di fronte e chiama questo fiducia in se. Il Guerriero cerca di essere senza macchia ai propri occhi e chiama questo umiltà. |
|
|
|
|
|
|
#11 | |
|
Senior Member
Iscritto dal: Dec 2001
Città: Napoli
Messaggi: 3249
|
Re: Re: allora
Quote:
mo mi finisco di leggere il 3d in rilievo.
__________________
Codice:
Concluso con[OK BAD]: ercagno,Claudio, Antopx, Lunaticgate, Deuced, Nicola5154,nEA[x2], Lupino.86, ironfrank, Marxio, luke10, Sniper86, alexis1980, Andrea16v[x3], Red_Rose, mitsuhashi1, antanio, Rinos, flavix25, geolite30, cianuro, spzerosp, GoldFinder, Zagor4, Mercurius00, Leland Gaunt, Iron10, tyco74, Clatit, PaPuAsja, onka, jing13, _19Fabio85_, Murakami, raizen89, dinigio63, ncerozz, rtype, Isotattico, vinz86, valdisteadsl, battalion75 |
|
|
|
|
|
|
#12 | |
|
Senior Member
Iscritto dal: Nov 2002
Città: Lago maggiore
Messaggi: 981
|
Re: Re: Re: allora
Quote:
Ultimo consiglio... Se navighi in acque non sicure, una un'altro browser tipo "Opera" che non è soggetto ad attacchi come explorer. Ciao
__________________
L'uomo comune cerca la certezza negli occhi di chi gli sta di fronte e chiama questo fiducia in se. Il Guerriero cerca di essere senza macchia ai propri occhi e chiama questo umiltà. |
|
|
|
|
|
|
#13 |
|
Senior Member
Iscritto dal: Nov 2003
Città: Mordor
Messaggi: 336
|
Fixa:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekhww.dll/sp.html#29126 O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab Fammi sapere Ciao |
|
|
|
|
|
#14 |
|
Senior Member
Iscritto dal: May 2001
Messaggi: 1740
|
franklin da dove hai avviato about buster?
da modalità provvisoria? non hai aggiornato hijackthis... è difficile aiutarti così... ciao
__________________
www.tweakness.net - Trucchi per il PC DECALOGO ANTISPY - GUIDA A HIJACKTHIS - GUIDA AI SERVIZI DI WIN XP - CONSIGLI ANTIVIRUS PER BART'S PE - SP2 SLIPSTREAMING - FAQ WINDOWS XPSP2 - I SERVIZI DOPO SP2 - XP SP2 UNATTENDED - GUIDA A nLite |
|
|
|
|
|
#15 | |
|
Senior Member
Iscritto dal: Dec 2001
Città: Napoli
Messaggi: 3249
|
Quote:
Ho aggiornato hijackthis, ma qual è the last version ?!
__________________
Codice:
Concluso con[OK BAD]: ercagno,Claudio, Antopx, Lunaticgate, Deuced, Nicola5154,nEA[x2], Lupino.86, ironfrank, Marxio, luke10, Sniper86, alexis1980, Andrea16v[x3], Red_Rose, mitsuhashi1, antanio, Rinos, flavix25, geolite30, cianuro, spzerosp, GoldFinder, Zagor4, Mercurius00, Leland Gaunt, Iron10, tyco74, Clatit, PaPuAsja, onka, jing13, _19Fabio85_, Murakami, raizen89, dinigio63, ncerozz, rtype, Isotattico, vinz86, valdisteadsl, battalion75 |
|
|
|
|
|
|
#16 |
|
Senior Member
Iscritto dal: May 2001
Messaggi: 1740
|
__________________
www.tweakness.net - Trucchi per il PC DECALOGO ANTISPY - GUIDA A HIJACKTHIS - GUIDA AI SERVIZI DI WIN XP - CONSIGLI ANTIVIRUS PER BART'S PE - SP2 SLIPSTREAMING - FAQ WINDOWS XPSP2 - I SERVIZI DOPO SP2 - XP SP2 UNATTENDED - GUIDA A nLite |
|
|
|
|
|
#17 |
|
Senior Member
Iscritto dal: Dec 2001
Città: Napoli
Messaggi: 3249
|
....
che rimane lo skermo nero e nn entra in windows
__________________
Codice:
Concluso con[OK BAD]: ercagno,Claudio, Antopx, Lunaticgate, Deuced, Nicola5154,nEA[x2], Lupino.86, ironfrank, Marxio, luke10, Sniper86, alexis1980, Andrea16v[x3], Red_Rose, mitsuhashi1, antanio, Rinos, flavix25, geolite30, cianuro, spzerosp, GoldFinder, Zagor4, Mercurius00, Leland Gaunt, Iron10, tyco74, Clatit, PaPuAsja, onka, jing13, _19Fabio85_, Murakami, raizen89, dinigio63, ncerozz, rtype, Isotattico, vinz86, valdisteadsl, battalion75 |
|
|
|
|
|
#18 |
|
Senior Member
Iscritto dal: May 2001
Messaggi: 1740
|
ma l'HD macina?
non è che sta effettuando un check disk in background?
__________________
www.tweakness.net - Trucchi per il PC DECALOGO ANTISPY - GUIDA A HIJACKTHIS - GUIDA AI SERVIZI DI WIN XP - CONSIGLI ANTIVIRUS PER BART'S PE - SP2 SLIPSTREAMING - FAQ WINDOWS XPSP2 - I SERVIZI DOPO SP2 - XP SP2 UNATTENDED - GUIDA A nLite |
|
|
|
|
| Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 13:19.




















