PDA

Visualizza la versione completa : Come eliminare Claro?


 
tanogabo
31-08-2012, 12:45
Salve, da alcuni giorni il browser Firefox resetta automaticamente la home page a: isearch.claro-search.com
Credo che si tratti di un virus legato a Firefox ma sia AVG che Malwarebytes non rilevano nulla di anomalo.
Qualcuno mi puņ aiutare?

Grazie
Gaetano

menatwork
31-08-2012, 13:11
scarica adwcleaner (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner) clicca su ''delete'' e posta il log che rilascia

fai anche una scansione con hijackthis e posta anche il suo log

tanogabo
31-08-2012, 18:25
# AdwCleaner v2.000 - Logfile created 08/31/2012 at 18:20:47
# Updated 30/08/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : user - USER-PC
# Boot Mode : Normal
# Running from : C:\Users\user\Downloads\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\ProgramData\Browser Manager
Folder Deleted : C:\ProgramData\boost_interprocess

***** [Registry] *****

Data Deleted : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\browse~1\22565~1.25\{16cdf~1\browse~1. dll
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Settings\{E601996F-E400-41CA-804B-CD6373A7EEE2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Settings\{EB5CEE80-030A-4ED8-8E20-454E9C68380F}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKU\S-1-5-21-2288913306-1939202801-1310200859-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKU\S-1-5-21-2288913306-1939202801-1310200859-1009\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421


-\\ Mozilla Firefox v15.0 (it)

-\\ Google Chrome v21.0.1180.89

*************************

AdwCleaner[S1].txt - [22941 octets] - [31/08/2012 18:12:40]
AdwCleaner[R1].txt - [1838 octets] - [31/08/2012 18:20:10]
AdwCleaner[S2].txt - [1769 octets] - [31/08/2012 18:20:47]

########## EOF - C:\AdwCleaner[S2].txt - [1829 octets] ##########

menatwork
31-08-2012, 18:27
posta anche un log di hijackthis per un controllo

tanogabo
31-08-2012, 18:30
# AdwCleaner v2.000 - Logfile created 08/31/2012 at 18:30:01
# Updated 30/08/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : user - USER-PC
# Boot Mode : Normal
# Running from : C:\Users\user\Downloads\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\ProgramData\boost_interprocess
Folder Found : C:\ProgramData\Browser Manager

***** [Registry] *****

Data Found : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\browse~1\22565~1.25\{16cdf~1\browse~1. dll
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Settings\{E601996F-E400-41CA-804B-CD6373A7EEE2}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Settings\{EB5CEE80-030A-4ED8-8E20-454E9C68380F}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKU\S-1-5-21-2288913306-1939202801-1310200859-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKU\S-1-5-21-2288913306-1939202801-1310200859-1009\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v15.0 (it)

-\\ Google Chrome v21.0.1180.89

*************************

AdwCleaner[S1].txt - [22941 octets] - [31/08/2012 18:12:40]
AdwCleaner[R1].txt - [1838 octets] - [31/08/2012 18:20:10]
AdwCleaner[S2].txt - [1896 octets] - [31/08/2012 18:20:47]
AdwCleaner[R2].txt - [1831 octets] - [31/08/2012 18:30:01]

########## EOF - C:\AdwCleaner[R2].txt - [1891 octets] ##########

menatwork
31-08-2012, 18:39
non quello lo hai gia' postato hijackthis lo scarichi da qui (http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php#) mettilo nella directory C dove avrai preparato una cartella con il suo nome. Lanci l'eseguibile e clicchi su " do a system scan and save a log" alla fine salvi questo file con estensione *.TXT e lo alleghi ad un post sul forum.

tanogabo
31-08-2012, 21:51
Ho riprovato ma forse non ho capito bene come procedere.
Forse mi conviene cancellare Firefox, visto che gli altri browser sono immuni da questo difetto.
Grazie

Loading