Pagina 1 di 3 1 2 3 ultimoultimo
Visualizzazione dei risultati da 1 a 10 su 28
  1. #1

    instant access-internet connection

    Salve a tutti, da un po' di giorni mi è comparsa una connessione internet denominata "internet connection" con numero da comporre 000 che si sostituisce alla mia connessione predefinita. Penso di essere affetto da instant accesso visto che ogni tanto compare sul desktop un collegamento ad "instant access". Ho letto anche altre discussioni a riguardo ma le soluzioni riportate non hanno prodotto risultati soddisfacenti, visto che continua a comparire. Ho prima incollato in avenger i codici riportati in questa discussione: http://forum.html.it/forum/showthrea...readid=1169080 ma non è successo niente, successivamente quelli riportati in quest'altra discussione: http://forum.html.it/forum/showthrea...readid=1168334 . Al che, al riavvio del pc, è apparso questo log di avenger:

    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Service s\ofrvaptr

    *******************

    Script file located at: \??\C:\etdtgqbh.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:



    Could not open file C:\Program Files\PestPatrol\PPControl.exe for deletion
    Deletion of file C:\Program Files\PestPatrol\PPControl.exe failed!

    Could not process line:
    C:\Program Files\PestPatrol\PPControl.exe
    Status: 0xc000003a



    File C:\WINDOWS\system32\DrvMon.exe not found!
    Deletion of file C:\WINDOWS\system32\DrvMon.exe failed!

    Could not process line:
    C:\WINDOWS\system32\DrvMon.exe
    Status: 0xc0000034



    Could not open file C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe for deletion
    Deletion of file C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe failed!

    Could not process line:
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    Status: 0xc000003a



    Could not open file C:\Program Files\CA\eTrust Antivirus\realmon.exe for deletion
    Deletion of file C:\Program Files\CA\eTrust Antivirus\realmon.exe failed!

    Could not process line:
    C:\Program Files\CA\eTrust Antivirus\realmon.exe
    Status: 0xc000003a



    Could not open file C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe for deletion
    Deletion of file C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe failed!

    Could not process line:
    C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    Status: 0xc000003a



    Could not open file C:\WINDOWS\system32\dla\tfswctrl.exe for deletion
    Deletion of file C:\WINDOWS\system32\dla\tfswctrl.exe failed!

    Could not process line:
    C:\WINDOWS\system32\dla\tfswctrl.exe
    Status: 0xc000003a



    Could not open file C:\Program Files\PestPatrol\bak\PPControl.exe for move operation
    File move operation C:\Program Files\PestPatrol\bak\PPControl.exe|C:\Program Files\PestPatrol\PPControl.exe failed!

    Could not process line:
    C:\Program Files\PestPatrol\bak\PPControl.exe|C:\Program Files\PestPatrol\PPControl.exe
    Status: 0xc000003a



    File C:\WINDOWS\system32\bak\DrvMon.exe not found!
    File move operation C:\WINDOWS\system32\bak\DrvMon.exe|C:\WINDOWS\syst em32\DrvMon.exe failed!

    Could not process line:
    C:\WINDOWS\system32\bak\DrvMon.exe|C:\WINDOWS\syst em32\DrvMon.exe
    Status: 0xc0000034



    Could not open file C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe for move operation
    File move operation C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe|C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe failed!

    Could not process line:
    C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe|C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    Status: 0xc000003a



    Could not open file C:\Program Files\CA\eTrust Antivirus\bak\realmon.exe for move operation
    File move operation C:\Program Files\CA\eTrust Antivirus\bak\realmon.exe|C:\Program Files\CA\eTrust Antivirus\realmon.exe failed!

    Could not process line:
    C:\Program Files\CA\eTrust Antivirus\bak\realmon.exe|C:\Program Files\CA\eTrust Antivirus\realmon.exe
    Status: 0xc000003a



    Could not open file C:\Program Files\TOSHIBA\E-KEY\bak\CeEKey.exe for move operation
    File move operation C:\Program Files\TOSHIBA\E-KEY\bak\CeEKey.exe|C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe failed!

    Could not process line:
    C:\Program Files\TOSHIBA\E-KEY\bak\CeEKey.exe|C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    Status: 0xc000003a



    Could not open file C:\WINDOWS\system32\dla\bak\tfswctrl.exe for move operation
    File move operation C:\WINDOWS\system32\dla\bak\tfswctrl.exe|C:\WINDOW S\system32\dla\tfswctrl.exe failed!

    Could not process line:
    C:\WINDOWS\system32\dla\bak\tfswctrl.exe|C:\WINDOW S\system32\dla\tfswctrl.exe
    Status: 0xc000003a


    Completed script processing.





    cosa devo fare???

  2. #2
    Comunque sia, vi posto il log di HiJackThis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14.26.13, on 03/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
    C:\Programmi\File comuni\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
    C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\NVIDIA\NetworkAccessManager\bin\nSvcIp.exe
    C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.e xe
    C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
    C:\Programmi\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
    C:\Programmi\File comuni\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
    C:\Programmi\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Programmi\File comuni\Teleca Shared\Generic.exe
    C:\Programmi\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
    C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Internet Explorer\iexplore.exe
    C:\Programmi\Windows Media Player\wmplayer.exe
    C:\Programmi\MSN Messenger\msnmsgr.exe
    C:\Programmi\MSN Messenger\usnsvc.exe
    C:\Programmi\WinRAR\WinRAR.exe
    C:\DOCUME~1\Admin\IMPOST~1\Temp\Rar$EX00.016\Hijac kThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Encarta Web Companion Oggetto helper - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programmi\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe "
    O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Programmi\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [E06IXLRD_7451750] "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE" -m
    O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
    O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
    O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
    O4 - Global Startup: Avvio rapido HP Photosmart Premier.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: BTTray.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Programmi\IncrediMail\bin\resources\WebMenuImg. htm
    O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.it
    O15 - Trusted Zone: *.whataboutadog.com
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://doriangray90.spaces.live.com/...d/MsnPUpld.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/.../GAME_UNO1.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1180812086703
    O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/ca...ail/DASAct.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {F5BC716E-2650-4B08-9235-C110CF95017F} (Connessione Tiscali) - http://selfcare.tiscali.it:8585/scri...oneTiscali.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7BFD39DC-BCCE-41D3-A17B-476243A32327}: NameServer = 213.205.32.70 213.205.36.70
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSvcHst.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Programmi\Norton AntiVirus\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\NVIDIA\NetworkAccessManager\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - Unknown owner - C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.e xe
    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Admin/IMPOST~1/Temp/msohtml1/01/clip_image001.jpg

    --
    End of file - 12253 bytes


    *******************

    Finished! Terminate.

  3. #3
    Utente bannato
    Registrato dal
    Jun 2007
    Messaggi
    3,899
    scarica findwaf, fai la scansione ed alla fine posta il log.

  4. #4
    e quello di winaf


    Find AWF report by noahdfear ©2006
    Version 1.40



    bak folders found
    ~~~~~~~~~~~

    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\ITUNES\BAK

    14/09/2007 10.00 267.064 iTunesHelper.exe
    1 File 267.064 byte
    2 Directory 47.992.041.472 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\QUICKT~1\BAK

    29/06/2007 06.24 286.720 QTTask.exe
    1 File 286.720 byte
    2 Directory 47.992.041.472 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\WINDOWS\SYSTEM32\BAK

    09/07/2001 11.50 155.648 NeroCheck.exe
    1 File 155.648 byte
    2 Directory 47.992.037.376 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\CYBERL~1\POWERDVD\BAK

    31/10/2003 20.42 32.768 PDVDServ.exe
    1 File 32.768 byte
    2 Directory 47.992.037.376 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\FILECO~1\SYMANT~1\BAK

    0 File 0 byte
    2 Directory 47.992.037.376 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\HP\HPCORE~1\BAK

    12/05/2004 15.18 241.664 hpcmpmgr.exe
    1 File 241.664 byte
    6 Directory 47.992.037.376 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\MIF408~1\MICROS~1\BAK

    04/06/2005 11.06 301.776 EDICT.EXE
    1 File 301.776 byte
    2 Directory 47.992.037.376 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\FILECO~1\REAL\UPDATE~1\BAK

    05/09/2007 18.00 185.632 realsched.exe
    1 File 185.632 byte
    2 Directory 47.992.037.376 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\JAVA\JRE16~1.0_0\BIN\BAK

    14/03/2007 03.43 83.608 jusched.exe
    1 File 83.608 byte
    2 Directory 47.992.037.376 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\SONYER~1\MOBILE2\APPLIC~1\BAK

    0 File 0 byte
    2 Directory 47.992.037.376 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\WINDOWS\BRICOP~1\VISTAI~1\ROCKET~1\BAK

    19/03/2007 00.05 630.784 RocketDock.exe
    1 File 630.784 byte
    2 Directory 47.992.037.376 byte disponibili


    Duplicate files of bak directory contents
    ~~~~~~~~~~~~~~~~~~~~~~~

    27664 3 Oct 2007 "C:\Programmi\iTunes\iTunesHelper.exe"
    267064 14 Sep 2007 "C:\Programmi\iTunes\bak\iTunesHelper.exe"
    102400 24 Sep 2007 "C:\WINDOWS\Installer\{7FF9CD9C-6E0C-4462-9670-F424DCB32DAF}\iTunesIco.exe"
    116024 14 Sep 2007 "C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 7.4.2.4\iTunesSetupAdmin.exe"
    27664 3 Oct 2007 "C:\Programmi\QuickTime\QTTask.exe"
    28672 5 Apr 2005 "C:\WINDOWS\system32\qttask.exe"
    286720 29 Jun 2007 "C:\Programmi\QuickTime\bak\QTTask.exe"
    27664 3 Oct 2007 "C:\WINDOWS\system32\NeroCheck.exe"
    155648 9 Jul 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
    27664 3 Oct 2007 "C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe"
    32768 31 Oct 2003 "C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ. exe"
    27664 3 Oct 2007 "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
    241664 12 May 2004 "C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe"
    575 27 Sep 2007 "C:\Programmi\HP\hpcoretech\data\EvntData-140079833.xml"
    324 2 Oct 2007 "C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml"
    27664 3 Oct 2007 "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE"
    301776 4 Jun 2005 "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\bak\EDICT.EXE"
    27664 3 Oct 2007 "C:\Programmi\File comuni\Real\Update_OB\realsched.exe"
    185632 5 Sep 2007 "C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe"
    27664 3 Oct 2007 "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe "
    83608 14 Mar 2007 "C:\Programmi\Java\jre1.6.0_01\bin\bak\jusched.exe "
    27664 3 Oct 2007 "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
    630784 19 Mar 2007 "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\bak\RocketDock.exe"


    end of report

  5. #5
    Utente bannato
    Registrato dal
    Jun 2007
    Messaggi
    3,899
    con avenger inserisci questo script:

    Files to delete:
    C:\Programmi\iTunes\iTunesHelper.exe
    C:\WINDOWS\Installer\{7FF9CD9C-6E0C-4462-9670-F424DCB32DAF}\iTunesIco.exe
    116024 14 Sep 2007 "C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 7.4.2.4\iTunesSetupAdmin.exe
    C:\WINDOWS\system32\qttask.exe
    C:\WINDOWS\system32\NeroCheck.exe
    C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
    C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
    C:\Programmi\HP\hpcoretech\data\EvntData-140079833.xml
    C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE
    C:\Programmi\File comuni\Real\Update_OB\realsched.exe
    C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe

    Files to move:
    C:\Programmi\iTunes\iTunesHelper.exe | C:\Programmi\iTunes
    C:\Programmi\QuickTime\bak\QTTask.exe | C:\Programmi\QuickTime\QTTask.exe
    C:\WINDOWS\system32\bak\NeroCheck.exe | C:\WINDOWS\system32
    C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ.exe | C:\Programmi\CyberLink\PowerDVD
    C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe | C:\Programmi\HP\hpcoretech
    C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml | C:\Programmi\HP\hpcoretech\data
    C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\bak\EDICT.EXE | Microsoft Encarta Enciclopedia DVD - 2006
    C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe | C:\Programmi\File comuni\Real\Update_OB
    C:\Programmi\Java\jre1.6.0_01\bin\bak\jusched.exe | C:\Programmi\Java\jre1.6.0_01\bin
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\bak\RocketDock.exe | C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock


    poi posta il log...

  6. #6
    questo è il log di avenger che è comparso al riavvio...o vuoi quello di findawf??

    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Service s\jmykejlh

    *******************

    Script file located at: \??\C:\WINDOWS\qmeuqicn.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    File C:\Programmi\iTunes\iTunesHelper.exe deleted successfully.
    File C:\WINDOWS\Installer\{7FF9CD9C-6E0C-4462-9670-F424DCB32DAF}\iTunesIco.exe deleted successfully.


    Could not open file 116024 14 Sep 2007 "C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 7.4.2.4\iTunesSetupAdmin.exe for deletion
    Deletion of file 116024 14 Sep 2007 "C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 7.4.2.4\iTunesSetupAdmin.exe failed!

    Could not process line:
    116024 14 Sep 2007 "C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 7.4.2.4\iTunesSetupAdmin.exe
    Status: 0xc000003a

    File C:\WINDOWS\system32\qttask.exe deleted successfully.
    File C:\WINDOWS\system32\NeroCheck.exe deleted successfully.
    File C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe deleted successfully.
    File C:\Programmi\HP\hpcoretech\hpcmpmgr.exe deleted successfully.
    File C:\Programmi\HP\hpcoretech\data\EvntData-140079833.xml deleted successfully.
    File C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE deleted successfully.
    File C:\Programmi\File comuni\Real\Update_OB\realsched.exe deleted successfully.
    File C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe deleted successfully.
    File C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe deleted successfully.


    File C:\Programmi\iTunes\iTunesHelper.exe not found!
    File move operation C:\Programmi\iTunes\iTunesHelper.exe|C:\Programmi\ iTunes failed!

    Could not process line:
    C:\Programmi\iTunes\iTunesHelper.exe|C:\Programmi\ iTunes
    Status: 0xc0000034

    File move operation C:\Programmi\QuickTime\bak\QTTask.exe|C:\Programmi \QuickTime\QTTask.exe completed successfully.


    Could not move file C:\WINDOWS\system32\bak\NeroCheck.exe
    File move operation C:\WINDOWS\system32\bak\NeroCheck.exe|C:\WINDOWS\s ystem32 failed!

    Could not process line:
    C:\WINDOWS\system32\bak\NeroCheck.exe|C:\WINDOWS\s ystem32
    Status: 0xc0000022



    Could not move file C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ.exe
    File move operation C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ.exe|C :\Programmi\CyberLink\PowerDVD failed!

    Could not process line:
    C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ.exe|C :\Programmi\CyberLink\PowerDVD
    Status: 0xc0000022



    Could not move file C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe
    File move operation C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe|C:\Pro grammi\HP\hpcoretech failed!

    Could not process line:
    C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe|C:\Pro grammi\HP\hpcoretech
    Status: 0xc0000022



    Could not move file C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml
    File move operation C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml|C:\Programmi\HP\hpcoretech\data failed!

    Could not process line:
    C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml|C:\Programmi\HP\hpcoretech\data
    Status: 0xc0000022


    Error: file move operations must be within volumes.
    File move operation C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\bak\EDICT.EXE|Microsoft Encarta Enciclopedia DVD - 2006 failed!

    Could not process line:
    C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\bak\EDICT.EXE|Microsoft Encarta Enciclopedia DVD - 2006
    Status: 0xc000003e



    Could not move file C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe
    File move operation C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe|C:\Program mi\File comuni\Real\Update_OB failed!

    Could not process line:
    C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe|C:\Program mi\File comuni\Real\Update_OB
    Status: 0xc0000022



    Could not move file C:\Programmi\Java\jre1.6.0_01\bin\bak\jusched.exe
    File move operation C:\Programmi\Java\jre1.6.0_01\bin\bak\jusched.exe| C:\Programmi\Java\jre1.6.0_01\bin failed!

    Could not process line:
    C:\Programmi\Java\jre1.6.0_01\bin\bak\jusched.exe| C:\Programmi\Java\jre1.6.0_01\bin
    Status: 0xc0000022



    Could not move file C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\bak\RocketDock.exe
    File move operation C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\bak\RocketDock.exe|C:\WINDOWS\BricoPa cks\Vista Inspirat 2\RocketDock failed!

    Could not process line:
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\bak\RocketDock.exe|C:\WINDOWS\BricoPa cks\Vista Inspirat 2\RocketDock
    Status: 0xc0000022


    Completed script processing.

    *******************

    Finished! Terminate.

  7. #7
    Utente bannato
    Registrato dal
    Jun 2007
    Messaggi
    3,899
    posta anche quello nuovo di findawf...come va?

  8. #8
    Find AWF report by noahdfear ©2006
    Version 1.40



    bak folders found
    ~~~~~~~~~~~

    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\ITUNES\BAK

    14/09/2007 10.00 267.064 iTunesHelper.exe
    1 File 267.064 byte
    2 Directory 47.993.864.192 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\QUICKT~1\BAK

    0 File 0 byte
    2 Directory 47.993.864.192 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\WINDOWS\SYSTEM32\BAK

    09/07/2001 11.50 155.648 NeroCheck.exe
    1 File 155.648 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\CYBERL~1\POWERDVD\BAK

    31/10/2003 20.42 32.768 PDVDServ.exe
    1 File 32.768 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\FILECO~1\SYMANT~1\BAK

    0 File 0 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\HP\HPCORE~1\BAK

    12/05/2004 15.18 241.664 hpcmpmgr.exe
    1 File 241.664 byte
    6 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\MIF408~1\MICROS~1\BAK

    04/06/2005 11.06 301.776 EDICT.EXE
    1 File 301.776 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\FILECO~1\REAL\UPDATE~1\BAK

    05/09/2007 18.00 185.632 realsched.exe
    1 File 185.632 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\JAVA\JRE16~1.0_0\BIN\BAK

    14/03/2007 03.43 83.608 jusched.exe
    1 File 83.608 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\SONYER~1\MOBILE2\APPLIC~1\BAK

    0 File 0 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\WINDOWS\BRICOP~1\VISTAI~1\ROCKET~1\BAK

    19/03/2007 00.05 630.784 RocketDock.exe
    1 File 630.784 byte
    2 Directory 47.993.860.096 byte disponibili


    Duplicate files of bak directory contents
    ~~~~~~~~~~~~~~~~~~~~~~~

    267064 14 Sep 2007 "C:\Programmi\iTunes\bak\iTunesHelper.exe"
    116024 14 Sep 2007 "C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 7.4.2.4\iTunesSetupAdmin.exe"
    155648 9 Jul 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
    32768 31 Oct 2003 "C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ. exe"
    241664 12 May 2004 "C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe"
    324 2 Oct 2007 "C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml"
    301776 4 Jun 2005 "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\bak\EDICT.EXE"
    185632 5 Sep 2007 "C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe"
    83608 14 Mar 2007 "C:\Programmi\Java\jre1.6.0_01\bin\bak\jusched.exe "
    630784 19 Mar 2007 "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\bak\RocketDock.exe"


    end of report



    ecco...cmq va, grazie

  9. #9
    Utente bannato
    Registrato dal
    Jun 2007
    Messaggi
    3,899
    inserisci ancora questo script:

    Files to delete:
    C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 7.4.2.4\iTunesSetupAdmin.exe

    Files to move:
    C:\Programmi\iTunes\bak\iTunesHelper.exe | C:\Programmi\iTunes
    C:\WINDOWS\system32\bak\NeroCheck.exe | C:\WINDOWS\system32
    C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ.exe | C:\Programmi\CyberLink\PowerDVD
    C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe | C:\Programmi\HP\hpcoretech
    C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml | C:\Programmi\HP\hpcoretech\bak\data
    C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\bak\EDICT.EXE | C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006
    C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe | C:\Programmi\File comuni\Real\Update_OB
    C:\Programmi\Java\jre1.6.0_01\bin\bak\jusched.exe | C:\Programmi\Java\jre1.6.0_01\bin
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\bak\RocketDock.exe | C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock


    posta entrambi i logs. come va?

  10. #10
    Originariamente inviato da artificial_boy
    Find AWF report by noahdfear ©2006
    Version 1.40



    bak folders found
    ~~~~~~~~~~~

    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\ITUNES\BAK

    14/09/2007 10.00 267.064 iTunesHelper.exe
    1 File 267.064 byte
    2 Directory 47.993.864.192 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\QUICKT~1\BAK

    0 File 0 byte
    2 Directory 47.993.864.192 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\WINDOWS\SYSTEM32\BAK

    09/07/2001 11.50 155.648 NeroCheck.exe
    1 File 155.648 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\CYBERL~1\POWERDVD\BAK

    31/10/2003 20.42 32.768 PDVDServ.exe
    1 File 32.768 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\FILECO~1\SYMANT~1\BAK

    0 File 0 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\HP\HPCORE~1\BAK

    12/05/2004 15.18 241.664 hpcmpmgr.exe
    1 File 241.664 byte
    6 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\MIF408~1\MICROS~1\BAK

    04/06/2005 11.06 301.776 EDICT.EXE
    1 File 301.776 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\FILECO~1\REAL\UPDATE~1\BAK

    05/09/2007 18.00 185.632 realsched.exe
    1 File 185.632 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\JAVA\JRE16~1.0_0\BIN\BAK

    14/03/2007 03.43 83.608 jusched.exe
    1 File 83.608 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\PROGRA~1\SONYER~1\MOBILE2\APPLIC~1\BAK

    0 File 0 byte
    2 Directory 47.993.860.096 byte disponibili
    Il volume nell'unit… C non ha etichetta.
    Numero di serie del volume: 9084-9925

    Directory di C:\WINDOWS\BRICOP~1\VISTAI~1\ROCKET~1\BAK

    19/03/2007 00.05 630.784 RocketDock.exe
    1 File 630.784 byte
    2 Directory 47.993.860.096 byte disponibili


    Duplicate files of bak directory contents
    ~~~~~~~~~~~~~~~~~~~~~~~

    267064 14 Sep 2007 "C:\Programmi\iTunes\bak\iTunesHelper.exe"
    116024 14 Sep 2007 "C:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 7.4.2.4\iTunesSetupAdmin.exe"
    155648 9 Jul 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
    32768 31 Oct 2003 "C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ. exe"
    241664 12 May 2004 "C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe"
    324 2 Oct 2007 "C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml"
    301776 4 Jun 2005 "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\bak\EDICT.EXE"
    185632 5 Sep 2007 "C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe"
    83608 14 Mar 2007 "C:\Programmi\Java\jre1.6.0_01\bin\bak\jusched.exe "
    630784 19 Mar 2007 "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\bak\RocketDock.exe"


    end of report



    ecco...cmq va, grazie
    @ste
    ma dico io,una ricerca su instant access e come fare la rimozione,la leggi ste?sbagli sempre i pezzi,perche vai di fretta.vai un po con calma.gli hai fatto fare un macello,non si capisce niente.

    lo script giusto e':


    files to delete:
    C:\Programmi\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\NeroCheck.exe
    C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
    C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
    C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml
    C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE
    C:\Programmi\File comuni\Real\Update_OB\realsched.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe

    files to move:
    C:\Programmi\iTunes\bak\iTunesHelper.exe | C:\Programmi\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\bak\NeroCheck.exe | C:\WINDOWS\system32\NeroCheck.exe
    C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ.exe | C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe C:\Programmi\HP\hpcoretech\bak\hpcmpmgr.exe | C:\Programmi\HP\hpcoretech\hpcmpmgr.exe
    C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml | C:\Programmi\HP\hpcoretech\bak\data\EvntData-814375110.xml
    C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\bak\EDICT.EXE | C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE
    C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe | C:\Programmi\File comuni\Real\Update_OB\realsched.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\bak\RocketDock.exe | C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe




    usa questo nell'box bianco ed esegui i comandi,sempre postando il log,poi sei a posto.

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2026 vBulletin Solutions, Inc. All rights reserved.