Pagina 1 di 4 1 2 3 ... ultimoultimo
Visualizzazione dei risultati da 1 a 10 su 34
  1. #1

    AIUTO!!sempre la stramaledetta variante di Win32dialer RUtrojan

    Ciao a tutti!!!
    Ho un problema: ogni giorno il mio antivirus NOD32 mi segnala un file infetto e lo mette in quarantena...io li elimino dalla quarantena ma ogni giorno è sempre la stessa storia!!! Ho provato a fare una scansione con Ad-aware e con spybot ma niente..
    Premesso che nn sono molto "pratica" vi incollo cosa c'è nel Trheat log dell'antivirus:


    Time Module Object Name Threat Action User Information
    13/05/2007 22.44.53 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\sazzcb.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    11/05/2007 21.18.16 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\uozeva.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
    10/05/2007 21.16.29 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\hvbnha.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\svchost.exe. The file was moved to quarantine. You may close this window.
    09/05/2007 20.51.32 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\y€zvfa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    08/05/2007 20.43.07 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\hmsueb.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    07/05/2007 20.27.40 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\sqpseb.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    06/05/2007 20.06.47 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\etvebb.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\svchost.exe. The file was moved to quarantine. You may close this window.
    05/05/2007 20.33.05 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\rgxioa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\svchost.exe. The file was moved to quarantine. You may close this window.
    03/05/2007 18.42.56 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\ficqaa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
    02/05/2007 11.42.06 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\kgkhca.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\svchost.exe. The file was moved to quarantine. You may close this window.
    01/05/2007 11.36.57 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\cbozda.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
    30/04/2007 11.29.13 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\€fzcja.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
    29/04/2007 11.01.42 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\zzdzda.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
    28/04/2007 10.46.35 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\kpcraa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
    27/04/2007 9.46.34 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\kfoqaa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    26/04/2007 9.33.38 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\hzvraa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
    24/04/2007 23.18.12 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\s€a€pa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    23/04/2007 23.08.09 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\qugknb.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    22/04/2007 23.04.23 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\aflkgb.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    21/04/2007 22.33.44 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\€nbwfa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
    20/04/2007 22.04.19 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\lz€pta.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    19/04/2007 21.50.53 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\zxjexa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    18/04/2007 21.14.03 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\zts€hb.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    17/04/2007 20.44.26 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\zslnoa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.
    16/04/2007 20.29.14 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\nfchoa.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\svchost.exe. The file was moved to quarantine. You may close this window.
    15/04/2007 20.46.38 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\zmbzcb.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\svchost.exe. The file was moved to quarantine. You may close this window.
    14/04/2007 19.34.28 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\sfslca.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\winlogon.exe. The file was moved to quarantine. You may close this window.
    13/04/2007 19.24.58 AMON file C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\zjyjca.exe a variant of Win32/Dialer.RU trojan quarantined - deleted HAL-9001\S1lv1@ Event occurred on a new file created by the application: C:\windows\system32\services.exe. The file was moved to quarantine. You may close this window.

    Se per favore qualcuno può dirmi cosa devo fare!!!
    é un bel pò che vado avanti così....
    grazie
    ciao

  2. #2
    Utente di HTML.it L'avatar di OYS
    Registrato dal
    Apr 2006
    Messaggi
    3,142
    È un virus molto difficile da togliere, se fai una ricarca sul forum vedi una discussione simile alla tua.

    Fai una scansione con HijackThis e posta il log.

    Fai una scansione con systemscan.
    Una volta eseguita la scansione portati in C:\suspectfile e carica il file report.txt su www.sendmefile.com oppure su www.savefile.com e scrivi il link per poterlo scaricare.

  3. #3
    Originariamente inviato da OYS
    È un virus molto difficile da togliere, se fai una ricarca sul forum vedi una discussione simile alla tua.

    Fai una scansione con HijackThis e posta il log.

    Fai una scansione con systemscan.
    Una volta eseguita la scansione portati in C:\suspectfile e carica il file report.txt su www.sendmefile.com oppure su www.savefile.com e scrivi il link per poterlo scaricare.
    Ti ringrazio!!!
    Ci provo e speriamo di nn vederlo più!
    ciaooo

  4. #4
    Fatto lo scan con Hijack!
    Ecco il log:

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 13.45.55, on 14/05/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
    C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Programmi\Eset\nod32krn.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ufdsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SYSTEM32\ATIPTAXX.EXE
    C:\WINDOWS\AGRSMMSG.exe
    C:\Programmi\necmfk\necmfk.exe
    C:\Programmi\Apoint2K\Apoint.exe
    C:\Programmi\DAEMON Tools\daemon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Programmi\Eset\nod32kui.exe
    C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
    C:\Programmi\Apoint2K\Apntex.exe
    C:\Programmi\File comuni\Real\Update_OB\realsched.exe
    C:\windows\system32\winlogon.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE
    C:\Programmi\WIDCOMM\Software Bluetooth\BTTray.exe
    C:\Programmi\Kaspersky Lab\Kaspersky Security Suite\Kaspersky Anti-Hacker\KAVPF.exe
    C:\Programmi\LG PC Suite\LG PC Sync\LGSyncManager.exe
    C:\PROGRA~1\WIDCOMM\SOFTWA~1\BTSTAC~1.EXE
    C:\Programmi\MSN Messenger\usnsvc.exe
    C:\Programmi\Internet Explorer\IEXPLORE.EXE
    C:\Programmi\MSN Messenger\msnmsgr.exe
    C:\Documents and Settings\S1lv1@\Desktop\HiJackThis_v2.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.d ll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
    O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Programmi\Canon\Easy-WebPrint\EWPBrowseLoader.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Encarta Web Companion Oggetto helper - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
    O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
    O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programmi\Macrogaming\SweetIMBarForIE\toolbar.d ll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmi\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\WINDOWS\SYSTEM32\ATIPTAXX.EXE
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [NECMFK] C:\Programmi\necmfk\necmfk.exe
    O4 - HKLM\..\Run: [Apoint] C:\Programmi\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmi\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\Aethra\ADSL EB1070 USB\CnxTrApp.dll",AppEntry -REG "Aethra\ADSL EB1070 USB"
    O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programmi\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
    O4 - HKLM\..\Run: [SweetIM] C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [modcbttw] "c:\windows\system32\modcbttw.exe"
    O4 - HKLM\..\Run: [€dzxfa.exe] C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\€dzxfa.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [E06IXLRD_1099561] "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE" -m
    O4 - HKCU\..\Run: [SweetIM] C:\Programmi\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: BTTray.lnk = ?
    O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Programmi\Kaspersky Lab\Kaspersky Security Suite\Kaspersky Anti-Hacker\KAVPF.exe
    O4 - Global Startup: LG SyncManager.lnk = C:\Programmi\LG PC Suite\LG PC Sync\LGSyncManager.exe
    O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
    O8 - Extra context menu item: Anteprima Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Stampa ad alta velocità Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
    O8 - Extra context menu item: Stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Software Bluetooth\btsendto_ie.htm
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programmi\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programmi\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{1C08680B-EB8E-4BB9-9DAB-8CCE37A6C5F7}: NameServer = 212.216.172.62 151.99.125.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{A6682044-8BCA-4A71-B2F3-A5FBC398F5B1}: NameServer = 212.216.112.112,212.216.172.62
    O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe
    O23 - Service: UFD Command Service (UFDSVC) - Generic - C:\WINDOWS\system32\ufdsvc.exe

    Che faccio ora???

  5. #5
    Utente di HTML.it L'avatar di OYS
    Registrato dal
    Apr 2006
    Messaggi
    3,142
    Questo è tuo? È hijackhtis rinominato?:


    C:\Programmi\necmfk\necmfk.exe


    Se non lo conosci eliminalo.





    Premi fix checked dopo aver selezionato questi:


    O4 - HKLM\..\Run: [modcbttw] "c:\windows\system32\modcbttw.exe"

    O4 - HKLM\..\Run: [€dzxfa.exe] C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\€dzxfa.exe


    Fai la scansione con systemscan.

  6. #6
    Originariamente inviato da OYS
    Questo è tuo? È hijackhtis rinominato?:


    C:\Programmi\necmfk\necmfk.exe


    Se non lo conosci eliminalo.





    Premi fix checked dopo aver selezionato questi:


    O4 - HKLM\..\Run: [modcbttw] "c:\windows\system32\modcbttw.exe"

    O4 - HKLM\..\Run: [€dzxfa.exe] C:\DOCUME~1\S1lv1@\IMPOST~1\Temp\€dzxfa.exe

    Fai la scansione con systemscan.

    SCUSAMI, lo so che sono un tantino impedita..ma come lo elimino C:\Programmi\necmfk\necmfk.exe...cioè dove lo trovo?
    Ok invece per fix checked...ora provvedo e faccio la scansione

  7. #7
    Utente di HTML.it L'avatar di OYS
    Registrato dal
    Apr 2006
    Messaggi
    3,142
    Originariamente inviato da maya1980sdm
    SCUSAMI, lo so che sono un tantino impedita..ma come lo elimino C:\Programmi\necmfk\necmfk.exe...cioè dove lo trovo?
    start-->risorse del computer--> C: (Disco locale)-->Programmi--> elimina la cartella necmfk.


    P.S. Se utilizzi una tastiera wireless (senza fili), allora non eliminarlo, perchè è probabilmente legata ad essa.

  8. #8
    Purtroppo nn me lo fa eliminare; accesso negato!!! mi dice questo:

    "Controllare che il disco nn sia pieno o protetto da scrittura e che il file nn sia attualmente in uso."
    Ah, ho un portatile cmq!
    Solo che ora deo andare...e nn ho ancora fatto la scansione!
    Riprenderò nel pomeriggio...posso inserirti tra i miei contatti msn???

  9. #9
    Utente di HTML.it L'avatar di OYS
    Registrato dal
    Apr 2006
    Messaggi
    3,142
    Si puoi inserirmi tra i miei contatti msn. Per adesso non lo eliminare, fai la scansione con systemscan, e poi ti dirò cosa fare.

  10. #10
    Originariamente inviato da OYS
    Si puoi inserirmi tra i miei contatti msn. Per adesso non lo eliminare, fai la scansione con systemscan, e poi ti dirò cosa fare.


    Grazie della pazienza!!!
    Ti ho inserito tra i miei contatti, solo che adesso devo lasciare tutto....ma posso fare la scansione nel pomeriggio, intorno alle 16.
    Se ti trovo connesso su msn magari ci sentiamo lì...Cmq ti tengo aggiornato!!!
    grazie mille ancora

    ciaoooo

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved.