Valutazione 4.87/ 5 (100.00%) 5838 voti

Condividi:        

pagine pubblicitarie che si aprono da sole

Come rimuovere virus e spyware? Le carte di credito sono davvero sicure in rete? È possibile navigare anonimi? Con quali programmi tutelare la propria privacy? Come proteggere i file importanti? Se volete una risposta a queste e altre domande questo è il luogo giusto!

Moderatori: kadosh, Luke57

Re: pagine pubblicitarie che si aprono da sole

Postdi turbinoz » 24/03/13 17:01

turbinoz
Utente Junior
 
Post: 10
Iscritto il: 23/03/13 13:18

Sponsor
 

Re: pagine pubblicitarie che si aprono da sole

Postdi Luke57 » 24/03/13 23:59

Ciao, il report di tdsskiller penso che sia incompleto...mentre otl.txt pesa 20 mb, decisamente troppi per un file di testo, riprova a inserirlo in maniera corretta.
Luke57
Moderatore
 
Post: 6410
Iscritto il: 11/08/05 19:10

Re: pagine pubblicitarie che si aprono da sole

Postdi turbinoz » 25/03/13 10:23

ecco il file otl che dovrebbe pesare 120 kb circa
http://wikisend.com/download/657932/OTL.Txt

tdsskiller ho fatto tutti i passaggi che mi hai detto magari non ho capito bene io, prova a rispiegarmelo grazie mille e scusa ancora...
turbinoz
Utente Junior
 
Post: 10
Iscritto il: 23/03/13 13:18

Re: pagine pubblicitarie che si aprono da sole

Postdi Luke57 » 26/03/13 12:47

Ciao, apri otl.exe, al suo interno copia e incolla il seguente script:


:OTL
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0D5C1D47-9D42-4E87-A878-B6BEF7E04AFB}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{23E5BEE8-47FB-4EC4-B13C-8A128B0E9EE7}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{29057C00-8D9B-4F50-9F8F-A052CD9980DF}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{90C565B8-0A94-4B93-8EA7-F6ECBD309221}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9ABA0099-324C-44AF-A037-D6B176DB287D}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DAADBC02-A868-46F6-945D-9131BF8157C9}: NameServer = 176.31.229.24,176.31.229.25


premi runfix; al riavvio posta il report, poi
scarica adwcleaner
http://general-changelog-team.fr/fr/dow ... adwcleaner
clicca su ''delete'' e posta il log

Inoltre scarica• Malwarebytes Anti-Malware
http://download.cnet.com/Malwarebytes-A ... tag=button
dopo averlo installato è necessario aggiornarlo e solo dopo eseguire la scansione completa del sistema, è altresì richiesto eliminare tutti gli oggetti identificati e salvare il log della scansione (il file di log da allegare per il controllo si trova nel Tab "File di log").Il file di log va preso solamente dopo aver eliminato gli oggetti (metti il segno di spunta alle infezioni rilevate da malwarebytes e premi rimuovi elementi selezionati.).
Riassumendo, esegui le scansioni e allega i due log a un post
Luke57
Moderatore
 
Post: 6410
Iscritto il: 11/08/05 19:10

Re: pagine pubblicitarie che si aprono da sole

Postdi turbinoz » 26/03/13 13:30

ecco il report do OTL dopo aver inserito lo script che mi hai postato :
========== OTL ==========
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0D5C1D47-9D42-4E87-A878-B6BEF7E04AFB}\\NameServer| /E : value set successfully!
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{23E5BEE8-47FB-4EC4-B13C-8A128B0E9EE7}\\NameServer| /E : value set successfully!
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{29057C00-8D9B-4F50-9F8F-A052CD9980DF}\\NameServer| /E : value set successfully!
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90C565B8-0A94-4B93-8EA7-F6ECBD309221}\\NameServer| /E : value set successfully!
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9ABA0099-324C-44AF-A037-D6B176DB287D}\\NameServer| /E : value set successfully!
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DAADBC02-A868-46F6-945D-9131BF8157C9}\\NameServer| /E : value set successfully!

OTL by OldTimer - Version 3.2.69.0 log created on 03262013_125812





ti allego anche il report che mi ha dato adwcleaner:

# AdwCleaner v2.115 - Logfile creato il 26/03/2013 alle 13:01:12
# Aggiornamento 17/03/2013 by Xplode
# Sistema Operativo : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Utente : antonio - PC-ANTONIO
# Modalità Avvio : Modalità Normale
# Eseguito da : C:\Users\antonio\Downloads\adwcleaner.exe
# Opzioni [Elimina]


***** [Servizi] *****


***** [File / Cartelle] *****

Cartella Eliminato : C:\Program Files\adawaretb
Cartella Eliminato : C:\Program Files\Optimizer Pro
Cartella Eliminato : C:\ProgramData\~0
Cartella Eliminato : C:\ProgramData\blekko toolbars
Cartella Eliminato : C:\ProgramData\boost_interprocess
Cartella Eliminato : C:\ProgramData\Tarma Installer
Cartella Eliminato : C:\Users\antonio\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Cartella Eliminato : C:\Users\antonio\AppData\Local\OpenCandy
Cartella Eliminato : C:\Users\antonio\AppData\Local\PackageAware
Cartella Eliminato : C:\Users\antonio\AppData\Local\PutLockerDownloader
Cartella Eliminato : C:\Users\antonio\AppData\LocalLow\adawaretb
Cartella Eliminato : C:\Users\antonio\AppData\LocalLow\incredibar.com
Cartella Eliminato : C:\Users\antonio\AppData\LocalLow\ShopperReports3
Cartella Eliminato : C:\Users\antonio\AppData\Roaming\freeTVRadio
Cartella Eliminato : C:\Users\antonio\AppData\Roaming\Mozilla\Firefox\Profiles\f59l1ye0.default\adawaretb
Cartella Eliminato : C:\Users\antonio\AppData\Roaming\Mozilla\Firefox\Profiles\f59l1ye0.default\Conduit
Cartella Eliminato : C:\Users\antonio\AppData\Roaming\Mozilla\Firefox\Profiles\f59l1ye0.default\extensions\engine@conduit.com
Cartella Eliminato : C:\Users\antonio\AppData\Roaming\Mozilla\Firefox\Profiles\f59l1ye0.default\jetpack
Cartella Eliminato : C:\Users\antonio\AppData\Roaming\Mozilla\Firefox\Profiles\f59l1ye0.default\SweetPacksToolbarData
Cartella Eliminato : C:\Users\antonio\AppData\Roaming\OpenCandy
Cartella Eliminato : C:\Users\antonio\AppData\Roaming\yourfiledownloader
Cartella Eliminato : C:\Windows\Installer\{2C8574B5-6935-4FCE-860E-F4E8602378FF}
Cartella Eliminato : C:\Windows\Installer\{38470B46-9BF1-40AE-A588-F6AD6D1C2D42}
File Eliminato : C:\Program Files\Mozilla FireFox\searchplugins\Search_Results.xml
File Eliminato : C:\user.js
File Eliminato : C:\Users\antonio\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cjpglkicenollcignonpgiafdgfeehoj_0.localstorage
File Eliminato : C:\Users\antonio\AppData\Roaming\Mozilla\Firefox\Profiles\f59l1ye0.default\searchplugins\MyStart Search.xml
File Eliminato : C:\Users\antonio\AppData\Roaming\Mozilla\Firefox\Profiles\f59l1ye0.default\searchplugins\Search_Results.xml
File Eliminato : C:\Users\antonio\AppData\Roaming\Mozilla\Firefox\Profiles\f59l1ye0.default\searchplugins\SweetIm.xml

***** [Registro] *****

Chiave Eliminata : HKCU\Software\1ClickDownload
Chiave Eliminata : HKCU\Software\APN PIP
Chiave Eliminata : HKCU\Software\AppDataLow\Software\Crossrider
Chiave Eliminata : HKCU\Software\AppDataLow\Software\ShopperReports3
Chiave Eliminata : HKCU\Software\freeTVRadio
Chiave Eliminata : HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Chiave Eliminata : HKCU\Software\IM
Chiave Eliminata : HKCU\Software\ImInstaller
Chiave Eliminata : HKCU\Software\InstallCore
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}
Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ShopperReportsSA
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Chiave Eliminata : HKCU\Software\Softonic
Chiave Eliminata : HKCU\Software\YourFileDownloader
Chiave Eliminata : HKLM\Software\Babylon
Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{1973277F-87B0-4EA3-9ED2-470A91D284CF}
Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Chiave Eliminata : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Chiave Eliminata : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{453DB0C5-F41C-4D97-8DD6-CC72ECD5F699}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{4AFC07D0-59BB-46B8-B097-1A46E88EEF71}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{6511CE4C-4722-40D0-AD3D-4AFA2F50978A}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{9BEC9B38-BF39-4899-806E-A1C5DFEB60A2}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{AEBF09E2-0C15-43C8-99BF-928C645D98A0}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{B86D82BF-D39F-439A-A07C-43EDDC6F6EA6}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{DA6305B9-0869-4235-8C1D-533A65E639E5}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{E6961C59-CFCE-4CCD-B794-BC78DB98413A}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Chiave Eliminata : HKLM\SOFTWARE\Classes\Prod.cap
Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Chiave Eliminata : HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Chiave Eliminata : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Chiave Eliminata : HKLM\Software\IB Updater
Chiave Eliminata : HKLM\Software\Iminent
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Chiave Eliminata : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Chiave Eliminata : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Chiave Eliminata : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Chiave Eliminata : HKLM\Software\PIP
Chiave Eliminata : HKLM\Software\YourFileDownloader
Valore Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Valore Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Valore Eliminata : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Browser Internet] *****

-\\ Internet Explorer v9.0.8112.16470

Eliminata : [HKCU\Software\Microsoft\Internet Explorer\Main - Backup.Old.Start Page]

-\\ Mozilla Firefox v19.0.2 (it)

File : C:\Users\antonio\AppData\Roaming\Mozilla\Firefox\Profiles\f59l1ye0.default\prefs.js

C:\Users\antonio\AppData\Roaming\Mozilla\Firefox\Profiles\f59l1ye0.default\user.js ... Eliminato !

Eliminata : user_pref("CT2405727.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Eliminata : user_pref("CT2405727.CTID", "CT2405727");
Eliminata : user_pref("CT2405727.CurrentServerDate", "18-4-2010");
Eliminata : user_pref("CT2405727.DialogsAlignMode", "LTR");
Eliminata : user_pref("CT2405727.EMailNotifierPollDate", "Sun Apr 18 2010 20:40:28 GMT+0200 (ora legale Europa o[...]
Eliminata : user_pref("CT2405727.ExternalComponentPollDate129078516974368471", "Sun Apr 18 2010 20:07:01 GMT+020[...]
Eliminata : user_pref("CT2405727.FirstServerDate", "18-4-2010");
Eliminata : user_pref("CT2405727.FirstTime", true);
Eliminata : user_pref("CT2405727.FirstTimeFF3", true);
Eliminata : user_pref("CT2405727.GroupingServerCheckInterval", 1440);
Eliminata : user_pref("CT2405727.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Eliminata : user_pref("CT2405727.Initialize", true);
Eliminata : user_pref("CT2405727.InitializeCommonPrefs", true);
Eliminata : user_pref("CT2405727.InstalledDate", "Sun Apr 18 2010 20:07:17 GMT+0200 (ora legale Europa occidenta[...]
Eliminata : user_pref("CT2405727.InvalidateCache", false);
Eliminata : user_pref("CT2405727.IsGrouping", false);
Eliminata : user_pref("CT2405727.IsMulticommunity", false);
Eliminata : user_pref("CT2405727.IsOpenThankYouPage", true);
Eliminata : user_pref("CT2405727.IsOpenUninstallPage", true);
Eliminata : user_pref("CT2405727.LanguagePackLastCheckTime", "Sun Apr 18 2010 20:07:56 GMT+0200 (ora legale Euro[...]
Eliminata : user_pref("CT2405727.LanguagePackReloadIntervalMM", 1440);
Eliminata : user_pref("CT2405727.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Eliminata : user_pref("CT2405727.LastLogin_2.5.8.6", "Sun Apr 18 2010 20:07:31 GMT+0200 (ora legale Europa occid[...]
Eliminata : user_pref("CT2405727.LatestVersion", "2.1.0.18");
Eliminata : user_pref("CT2405727.Locale", "en");
Eliminata : user_pref("CT2405727.LoginCache", 4);
Eliminata : user_pref("CT2405727.MCDetectTooltipHeight", "83");
Eliminata : user_pref("CT2405727.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Eliminata : user_pref("CT2405727.MCDetectTooltipWidth", "295");
Eliminata : user_pref("CT2405727.RadioIsPodcast", false);
Eliminata : user_pref("CT2405727.RadioLastCheckTime", "Sun Apr 18 2010 20:07:03 GMT+0200 (ora legale Europa occi[...]
Eliminata : user_pref("CT2405727.RadioLastUpdateIPServer", "3");
Eliminata : user_pref("CT2405727.RadioLastUpdateServer", "3");
Eliminata : user_pref("CT2405727.RadioMediaID", "9962");
Eliminata : user_pref("CT2405727.RadioMediaType", "Media Player");
Eliminata : user_pref("CT2405727.RadioMenuSelectedID", "EBRadioMenu_CT24057279962");
Eliminata : user_pref("CT2405727.RadioStationName", "California%20Rock");
Eliminata : user_pref("CT2405727.RadioStationURL", "hxxp://feedlive.net/california.asx");
Eliminata : user_pref("CT2405727.SHRINK_TOOLBAR", 1);
Eliminata : user_pref("CT2405727.SavedHomepage", "resource:/browserconfig.properties");
Eliminata : user_pref("CT2405727.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Eliminata : user_pref("CT2405727.SearchFromAddressBarIsInit", true);
Eliminata : user_pref("CT2405727.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT240[...]
Eliminata : user_pref("CT2405727.SearchInNewTabEnabled", true);
Eliminata : user_pref("CT2405727.SearchInNewTabIntervalMM", 1440);
Eliminata : user_pref("CT2405727.SearchInNewTabLastCheckTime", "Sun Apr 18 2010 20:07:32 GMT+0200 (ora legale Eu[...]
Eliminata : user_pref("CT2405727.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Eliminata : user_pref("CT2405727.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Eliminata : user_pref("CT2405727.SettingsCheckIntervalMin", 120);
Eliminata : user_pref("CT2405727.SettingsLastCheckTime", "Sun Apr 18 2010 20:07:02 GMT+0200 (ora legale Europa o[...]
Eliminata : user_pref("CT2405727.SettingsLastUpdate", "1271264598");
Eliminata : user_pref("CT2405727.ThirdPartyComponentsInterval", 504);
Eliminata : user_pref("CT2405727.ThirdPartyComponentsLastCheck", "Sun Apr 18 2010 20:07:01 GMT+0200 (ora legale [...]
Eliminata : user_pref("CT2405727.ThirdPartyComponentsLastUpdate", "1271264598");
Eliminata : user_pref("CT2405727.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Eliminata : user_pref("CT2405727.UserID", "UN31327435109279755");
Eliminata : user_pref("CT2405727.ValidationData_Toolbar", 2);
Eliminata : user_pref("CT2405727.WeatherNetwork", "");
Eliminata : user_pref("CT2405727.WeatherPollDate", "Sun Apr 18 2010 20:40:27 GMT+0200 (ora legale Europa occiden[...]
Eliminata : user_pref("CT2405727.WeatherUnit", "C");
Eliminata : user_pref("CT2405727.alertChannelId", "800210");
Eliminata : user_pref("CT2405727.clientLogIsEnabled", false);
Eliminata : user_pref("CT2405727.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Eliminata : user_pref("CT2405727.components.1000034", true);
Eliminata : user_pref("CT2405727.myStuffEnabled", true);
Eliminata : user_pref("CT2405727.myStuffPublihserMinWidth", 400);
Eliminata : user_pref("CT2405727.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Eliminata : user_pref("CT2405727.myStuffServiceIntervalMM", 1440);
Eliminata : user_pref("CT2405727.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Eliminata : user_pref("CT2405727.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Eliminata : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "www.igoogle.it");
Eliminata : user_pref("CommunityToolbar.ToolbarsList", "www.igoogle.it");
Eliminata : user_pref("CommunityToolbar.ToolbarsList2", "www.igoogle.it");
Eliminata : user_pref("CommunityToolbar.alert.alertInfoInterval", 60);
Eliminata : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Apr 18 2010 20:07:01 GMT+0200 (ora l[...]
Eliminata : user_pref("CommunityToolbar.alert.clientsServerUrl", "www.igoogle.it");
Eliminata : user_pref("CommunityToolbar.alert.locale", "www.igoogle.it");
Eliminata : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Eliminata : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun Apr 18 2010 20:07:01 GMT+0200 (ora legal[...]
Eliminata : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1234796400");
Eliminata : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Eliminata : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Eliminata : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Eliminata : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Eliminata : user_pref("CommunityToolbar.alert.userId", "{d29cbe64-dd91-4511-afca-f84a1e1674b3}");
Eliminata : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2405727");
Eliminata : user_pref("browser.babylon.HPOnNewTab", "www.igoogle.it");
Eliminata : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb201?a=6R8Q8B61D7&i=26");
Eliminata : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Eliminata : user_pref("extensions.BabylonToolbar_i.babExt", "");
Eliminata : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=112555&tt=2912_3");
Eliminata : user_pref("extensions.BabylonToolbar_i.hardId", "b488b3530000000000000009dd509397");
Eliminata : user_pref("extensions.BabylonToolbar_i.id", "b488b3530000000000000009dd509397");
Eliminata : user_pref("extensions.BabylonToolbar_i.instlDay", "15539");
Eliminata : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Eliminata : user_pref("extensions.BabylonToolbar_i.newTab", false);
Eliminata : user_pref("extensions.BabylonToolbar_i.newTabUrl", "www.igoogle.it");
Eliminata : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Eliminata : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Eliminata : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Eliminata : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Eliminata : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Eliminata : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Eliminata : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1722:10:06");
Eliminata : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Eliminata : user_pref("extensions.enabledAddons", "DivXWebPlayer%40divx.com:2.0.2.039,newtaburl%40sogame.cat:2.2[...]
Eliminata : user_pref("extensions.engine@conduit.com.install-event-fired", true);
Eliminata : user_pref("extensions.incredibar.actvtyRptTime", "1364030352977");
Eliminata : user_pref("extensions.incredibar.admin", false);
Eliminata : user_pref("extensions.incredibar.aflt", "orgnl");
Eliminata : user_pref("extensions.incredibar.afterInstallRpt", "sent");
Eliminata : user_pref("extensions.incredibar.cntry", "IT");
Eliminata : user_pref("extensions.incredibar.dfltLng", "EN");
Eliminata : user_pref("extensions.incredibar.dfltSrch", false);
Eliminata : user_pref("extensions.incredibar.dfltlng", "EN");
Eliminata : user_pref("extensions.incredibar.dfltsrch", "false");
Eliminata : user_pref("extensions.incredibar.did", "10643");
Eliminata : user_pref("extensions.incredibar.envrmnt", "production");
Eliminata : user_pref("extensions.incredibar.excTlbr", false);
Eliminata : user_pref("extensions.incredibar.hdrMd5", "B2C8EC3EF65DB204B01A585F0D096124");
Eliminata : user_pref("extensions.incredibar.hmpg", false);
Eliminata : user_pref("extensions.incredibar.hrdid", "b488b3530000000000000009dd509397");
Eliminata : user_pref("extensions.incredibar.id", "b488b3530000000000000009dd509397");
Eliminata : user_pref("extensions.incredibar.installerproductid", "26");
Eliminata : user_pref("extensions.incredibar.instlDay", "15707");
Eliminata : user_pref("extensions.incredibar.instlRef", "");
Eliminata : user_pref("extensions.incredibar.instlday", "15707");
Eliminata : user_pref("extensions.incredibar.instlref", "");
Eliminata : user_pref("extensions.incredibar.isDcmntCmplt", true);
Eliminata : user_pref("extensions.incredibar.isdcmntcmplt", "false");
Eliminata : user_pref("extensions.incredibar.keywordurl", "");
Eliminata : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1421:12:34");
Eliminata : user_pref("extensions.incredibar.mntrvrsn", "1.2.0");
Eliminata : user_pref("extensions.incredibar.newTab", false);
Eliminata : user_pref("extensions.incredibar.newtab", "false");
Eliminata : user_pref("extensions.incredibar.newtaburl", "");
Eliminata : user_pref("extensions.incredibar.noFFXTlbr", false);
Eliminata : user_pref("extensions.incredibar.ppd", "6666660837");
Eliminata : user_pref("extensions.incredibar.prdct", "incredibar");
Eliminata : user_pref("extensions.incredibar.productid", "26");
Eliminata : user_pref("extensions.incredibar.prtnrId", "Incredibar");
Eliminata : user_pref("extensions.incredibar.prtnrid", "Incredibar");
Eliminata : user_pref("extensions.incredibar.sg", "none");
Eliminata : user_pref("extensions.incredibar.smplGrp", "none");
Eliminata : user_pref("extensions.incredibar.smplgrp", "none");
Eliminata : user_pref("extensions.incredibar.srch", "");
Eliminata : user_pref("extensions.incredibar.srchprvdr", "");
Eliminata : user_pref("extensions.incredibar.tlbrId", "base");
Eliminata : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8Q8B61D7&loc=IB_T[...]
Eliminata : user_pref("extensions.incredibar.tlbrid", "base");
Eliminata : user_pref("extensions.incredibar.tlbrsrchurl", "hxxp://mystart.Incredibar.com/?a=6R8Q8B61D7&loc=IB_T[...]
Eliminata : user_pref("extensions.incredibar.upn2", "6R8Q8B61D7");
Eliminata : user_pref("extensions.incredibar.upn2n", "92825679279904157");
Eliminata : user_pref("extensions.incredibar.vrsn", "1.5.11.14");
Eliminata : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1421:12:34");
Eliminata : user_pref("extensions.incredibar.vrsni", "1.5.11.14");
Eliminata : user_pref("extensions.incredibar.vrsnts", "1.5.11.1421:12:34");
Eliminata : user_pref("extensions.incredibar_i.aflt", "orgnl");
Eliminata : user_pref("extensions.incredibar_i.dfltLng", "");
Eliminata : user_pref("extensions.incredibar_i.did", "10643");
Eliminata : user_pref("extensions.incredibar_i.excTlbr", false);
Eliminata : user_pref("extensions.incredibar_i.id", "b488b3530000000000000009dd509397");
Eliminata : user_pref("extensions.incredibar_i.installerproductid", "26");
Eliminata : user_pref("extensions.incredibar_i.instlDay", "15707");
Eliminata : user_pref("extensions.incredibar_i.instlRef", "");
Eliminata : user_pref("extensions.incredibar_i.ms_url_id", "");
Eliminata : user_pref("extensions.incredibar_i.newTab", false);
Eliminata : user_pref("extensions.incredibar_i.ppd", "6666660837");
Eliminata : user_pref("extensions.incredibar_i.prdct", "incredibar");
Eliminata : user_pref("extensions.incredibar_i.productid", "26");
Eliminata : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Eliminata : user_pref("extensions.incredibar_i.smplGrp", "none");
Eliminata : user_pref("extensions.incredibar_i.tlbrId", "base");
Eliminata : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8Q8B61D7&loc=IB[...]
Eliminata : user_pref("extensions.incredibar_i.upn2", "6R8Q8B61D7");
Eliminata : user_pref("extensions.incredibar_i.upn2n", "92825679279904157");
Eliminata : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
Eliminata : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1421:12:34");
Eliminata : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");
Eliminata : user_pref("extensions.searchya.aflt", "foxtab");
Eliminata : user_pref("extensions.searchya.autoRvrt", false);
Eliminata : user_pref("extensions.searchya.cntry", "www.igoogle.it");
Eliminata : user_pref("extensions.searchya.dfltLng", "");
Eliminata : user_pref("extensions.searchya.dfltSrch", true);
Eliminata : user_pref("extensions.searchya.dnsErr", true);
Eliminata : user_pref("extensions.searchya.envrmnt", "production");
Eliminata : user_pref("extensions.searchya.excTlbr", false);
Eliminata : user_pref("extensions.searchya.hdrMd5", "www.igoogle.it");
Eliminata : user_pref("extensions.searchya.hmpg", true);
Eliminata : user_pref("extensions.searchya.hmpgUrl", "hxxp://www.searchya.com/?s=0&a=foxtab&chnl=ft-100&cd=2Xzuy[...]
Eliminata : user_pref("extensions.searchya.id", "00235A945C28B353");
Eliminata : user_pref("extensions.searchya.instlDay", "15552");
Eliminata : user_pref("extensions.searchya.instlRef", "ft-100");
Eliminata : user_pref("extensions.searchya.isdcmntcmplt", true);
Eliminata : user_pref("extensions.searchya.lastVrsnTs", "www.igoogle.it");
Eliminata : user_pref("extensions.searchya.mntrvrsn", "1.3.0");
Eliminata : user_pref("extensions.searchya.newTab", false);
Eliminata : user_pref("extensions.searchya.newTabUrl", "hxxp://www.searchya.com/?s=2&a=foxtab&chnl=ft-100&cd=2Xz[...]
Eliminata : user_pref("extensions.searchya.prdct", "searchya");
Eliminata : user_pref("extensions.searchya.propectorlck", 82325622);
Eliminata : user_pref("extensions.searchya.prtnrId", "searchya");
Eliminata : user_pref("extensions.searchya.sg", "www.igoogle.it");
Eliminata : user_pref("extensions.searchya.smplGrp", "www.igoogle.it");
Eliminata : user_pref("extensions.searchya.srchPrvdr", "Search");
Eliminata : user_pref("extensions.searchya.tlbrId", "base");
Eliminata : user_pref("extensions.searchya.tlbrSrchUrl", "hxxp://www.searchya.com/?s=3&a=foxtab&chnl=ft-100&cd=2[...]
Eliminata : user_pref("extensions.searchya.vrsn", "1.5.25.0");
Eliminata : user_pref("extensions.searchya.vrsnTs", "www.igoogle.it");
Eliminata : user_pref("extensions.searchya.vrsni", "1.5.25.0");
Eliminata : user_pref("extensions.searchya_i.newTab", true);
Eliminata : user_pref("extensions.searchya_i.smplGrp", "none");
Eliminata : user_pref("extensions.searchya_i.vrsnTs", "1.5.25.018:50:55");
Eliminata : user_pref("keyword.URL", "hxxp://mystart.incredibar.com/mb201/?loc=IB_DS&a=6R8Q8B61D7&&i=26&search="[...]
Eliminata : user_pref("sweetim.toolbar.RevertDialog.enable", "false");
Eliminata : user_pref("sweetim.toolbar.UserSelectedSaveSettings", "true");
Eliminata : user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "1364030372605");
Eliminata : user_pref("sweetim.toolbar.Visibility.enable", "true");
Eliminata : user_pref("sweetim.toolbar.Visibility.intervaldays", "7");
Eliminata : user_pref("sweetim.toolbar.cargo", "3.1010000.00000");
Eliminata : user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true");
Eliminata : user_pref("sweetim.toolbar.cda.HideOveride.enable", "true");
Eliminata : user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true");
Eliminata : user_pref("sweetim.toolbar.cda.returnValue", "hide");
Eliminata : user_pref("sweetim.toolbar.dialogs.0.enable", "true");
Eliminata : user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-h[...]
Eliminata : user_pref("sweetim.toolbar.dialogs.0.height", "335");
Eliminata : user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog");
Eliminata : user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;");
Eliminata : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.asp?la[...]
Eliminata : user_pref("sweetim.toolbar.dialogs.0.width", "761");
Eliminata : user_pref("sweetim.toolbar.dialogs.1.enable", "true");
Eliminata : user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-h[...]
Eliminata : user_pref("sweetim.toolbar.dialogs.1.height", "300");
Eliminata : user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog");
Eliminata : user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog");
Eliminata : user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html"[...]
Eliminata : user_pref("sweetim.toolbar.dialogs.1.width", "500");
Eliminata : user_pref("sweetim.toolbar.dialogs.2.enable", "true");
Eliminata : user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handl[...]
Eliminata : user_pref("sweetim.toolbar.dialogs.2.height", "150");
Eliminata : user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove");
Eliminata : user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog");
Eliminata : user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp");
Eliminata : user_pref("sweetim.toolbar.dialogs.2.width", "530");
Eliminata : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.goog[...]
Eliminata : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
Eliminata : user_pref("sweetim.toolbar.keywordUrlGuard.enable", "false");
Eliminata : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
Eliminata : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
Eliminata : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
Eliminata : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
Eliminata : user_pref("sweetim.toolbar.mode.debug", "false");
Eliminata : user_pref("sweetim.toolbar.newtab.created", "false");
Eliminata : user_pref("sweetim.toolbar.newtab.enable", "true");
Eliminata : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Eliminata : user_pref("sweetim.toolbar.rc.url", "hxxp://www.sweetim.com/simffbar/rc.html?toolbar_version=$ITEM_V[...]
Eliminata : user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true");
Eliminata : user_pref("sweetim.toolbar.scripts.0.callback", "simVerification");
Eliminata : user_pref("sweetim.toolbar.scripts.0.domain-blacklist", "");
Eliminata : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*");
Eliminata : user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb");
Eliminata : user_pref("sweetim.toolbar.scripts.0.enable", "false");
Eliminata : user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb");
Eliminata : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js");
Eliminata : user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "true");
Eliminata : user_pref("sweetim.toolbar.scripts.1.callback", "simVerification");
Eliminata : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Eliminata : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(www.|apps.)?facebook\\.com.*");
Eliminata : user_pref("sweetim.toolbar.scripts.1.elementid", "id_script_sim_fb");
Eliminata : user_pref("sweetim.toolbar.scripts.1.enable", "false");
Eliminata : user_pref("sweetim.toolbar.scripts.1.id", "id_script_fb_hxxpS");
Eliminata : user_pref("sweetim.toolbar.scripts.1.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js");
Eliminata : user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "false");
Eliminata : user_pref("sweetim.toolbar.scripts.2.callback", "");
Eliminata : user_pref("sweetim.toolbar.scripts.2.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..[...]
Eliminata : user_pref("sweetim.toolbar.scripts.2.domain-whitelist", "");
Eliminata : user_pref("sweetim.toolbar.scripts.2.elementid", "id_predict_include_script");
Eliminata : user_pref("sweetim.toolbar.scripts.2.enable", "false");
Eliminata : user_pref("sweetim.toolbar.scripts.2.id", "id_script_prad");
Eliminata : user_pref("sweetim.toolbar.scripts.2.url", "hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?[...]
Eliminata : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engin[...]
Eliminata : user_pref("sweetim.toolbar.search.history.capacity", "10");
Eliminata : user_pref("sweetim.toolbar.searchguard.enable", "false");
Eliminata : user_pref("sweetim.toolbar.searchguard.initialized_by_rc", "true");
Eliminata : user_pref("sweetim.toolbar.simapp_id", "{61E23362-529E-11E2-9842-98146E0209AC}");
Eliminata : user_pref("sweetim.toolbar.version", "1.9.0.0");
Eliminata : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=too[...]
Eliminata : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...]

-\\ Google Chrome v25.0.1364.172

File : C:\Users\antonio\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File Pulito.

*************************

AdwCleaner[S1].txt - [35493 octets] - [26/03/2013 13:01:12]

########## EOF - C:\AdwCleaner[S1].txt - [35554 octets] ##########
turbinoz
Utente Junior
 
Post: 10
Iscritto il: 23/03/13 13:18

Re: pagine pubblicitarie che si aprono da sole

Postdi turbinoz » 26/03/13 16:48

ti allego il log di malwarebytes dopo aver fatto la scansione completa:

Malwarebytes Anti-Malware (Prova) 1.65.1.1000
http://www.malwarebytes.org

Versione database: v2012.11.02.09

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19328
antonio :: PC-ANTONIO [amministratore]

Protezione: Attivata

02/11/2012 18.25.57
mbam-log-2012-11-02 (18-25-57).txt

Tipo di scansione: Scansione veloce
Opzioni di scansione attive: Memoria | Esecuzione automatica | Registro | File di sistema | Euristica/Extra | Euristica/Shuriken | PUP | PUM
Opzioni di scansione disattivate: P2P
Elementi esaminati: 226698
Tempo impiegato: 8 minuti, 42 secondi

Processi rilevati in memoria: 0
(non sono stati rilevati elementi nocivi)

Moduli di memoria rilevati: 0
(non sono stati rilevati elementi nocivi)

Chiavi di registro rilevate: 62
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{25927741-5E5B-4D27-8D8B-9188FE64373F} (PUP.SearchYa) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25927741-5E5B-4D27-8D8B-9188FE64373F} (PUP.SearchYa) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{33AA308B-B565-4376-AC66-59EE9B6AD13E} (PUP.SearchYa) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{33AA308B-B565-4376-AC66-59EE9B6AD13E} (PUP.SearchYa) -> Nessuna azione intrapresa.
HKCR\AppID\{0D82ACD6-A652-4496-A298-2BDE705F4227} (Adware.ClickPotato) -> Spostato in quarantena ed eliminato con successo.
HKCR\AppID\{7025E484-D4B0-441a-9F0B-69063BD679CE} (Adware.ClickPotato) -> Spostato in quarantena ed eliminato con successo.
HKCR\AppID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D} (Adware.ClickPotato) -> Spostato in quarantena ed eliminato con successo.
HKCR\AppID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306} (Adware.ClickPotato) -> Spostato in quarantena ed eliminato con successo.
HKCR\CLSID\{396CFC12-932D-496b-A0A8-5D7201E105E1} (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\TypeLib\{573F4ABB-A1A2-44ED-9BA9-A8DAD40AAC46} (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\Interface\{71E02280-5212-45C3-B174-4D5A35DA254F} (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.MozillaNvgtnTrpr.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.MozillaNvgtnTrpr (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\CLSID\{74C22317-5B90-471f-9AD2-FEC049870A16} (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.Scopes.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.Scopes (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\Typelib\{ACC62306-9A63-4864-BD2F-C8825D2D7EA6} (Adware.ClickPotato) -> Spostato in quarantena ed eliminato con successo.
HKCR\Interface\{21BA420E-161C-413A-B21E-4E42AE1F4226} (Adware.ClickPotato) -> Spostato in quarantena ed eliminato con successo.
HKCR\Typelib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2} (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB} (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\Typelib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF} (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5428486-50A0-4A02-9D20-520B59A9F9B2} (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5428486-50A0-4A02-9D20-520B59A9F9B3} (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89F88394-3828-4d03-A0CF-8203604C3DA6} (Adware.Hotbar) -> Spostato in quarantena ed eliminato con successo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4233F04-1789-483c-A137-731E8F113DD5} (Adware.Hotbar) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.AsyncReporter (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.AsyncReporter.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.Dwnldr (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.Dwnldr.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.HbAx (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.HbAx.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.HbGuru (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.HbGuru.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.HbInfoBand (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.HbInfoBand.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.IEButton (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.IEButton.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.IEButtonA (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.IEButtonA.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.MozillaPSExecuter (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.MozillaPSExecuter.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.ReportData (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.ReportData.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.Reporter (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.Reporter.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.RprtCtrl (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.RprtCtrl.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.Stock (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.Stock.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.TriggerImmidiate (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.TriggerImmidiate.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.TriggerImmidiateOrRandomTS (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.TriggerImmidiateOrRandomTS.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.TriggerOnceInDay (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\ShopperReports.TriggerOnceInDay.1 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKCR\AppID\BRNstIE.DLL (Adware.ClickPotato) -> Spostato in quarantena ed eliminato con successo.
HKCR\AppID\CmndFF.DLL (Adware.ClickPotato) -> Spostato in quarantena ed eliminato con successo.
HKCR\AppID\mozillaps.dll (Adware.ClickPotato) -> Spostato in quarantena ed eliminato con successo.
HKCR\AppID\Pltfrm.DLL (Adware.ClickPotato) -> Spostato in quarantena ed eliminato con successo.
HKCU\SOFTWARE\fcn (Rogue.Residue) -> Spostato in quarantena ed eliminato con successo.
HKCU\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
HKLM\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.

Valori di registro rilevati: 5
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} (Adware.Zango) -> Dati: -> Spostato in quarantena ed eliminato con successo.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} (Adware.Zango) -> Dati: a·¸+߬H»à¼À:›; -> Spostato in quarantena ed eliminato con successo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform|ShopperReports 3.2.7.0 (Adware.HotBar) -> Dati: -> Spostato in quarantena ed eliminato con successo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform|SRS_IT_E8790670BD76595232A995 (Malware.Trace) -> Dati: -> Spostato in quarantena ed eliminato con successo.
HKLM\SOFTWARE\Mozilla\Firefox\extensions|ShopperReports@ShopperReports.com (ShopperReports) -> Dati: C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions -> Spostato in quarantena ed eliminato con successo.

Voci rilevate nei dati di registro: 0
(non sono stati rilevati elementi nocivi)

Cartelle rilevate: 11
C:\Users\antonio\AppData\Roaming\ShopperReports3 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0 (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions\chrome (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions\chrome\content (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions\components (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShopperReports (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.

File rilevati: 13
C:\Program Files\ShopperReports3\bin\3.2.7.0\CmndFF.dll (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Users\Public\Desktop\MP3 Downloader.lnk (Rogue.Link) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\LaunchHelp.dll (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\link.ico (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions\chrome.manifest (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions\install.rdf (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions\chrome\content\infopane.js (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions\chrome\content\InfoPane.xul (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.dll (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\Program Files\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.xpt (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShopperReports\About Us.lnk (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShopperReports\Customer Support.lnk (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShopperReports\ShopperReports Uninstall Instructions.lnk (Adware.ShopperReports) -> Spostato in quarantena ed eliminato con successo.

(fine)
turbinoz
Utente Junior
 
Post: 10
Iscritto il: 23/03/13 13:18

Re: pagine pubblicitarie che si aprono da sole

Postdi kyiv » 27/03/13 09:37

guarda che hai fatto una scansione veloce, e non completa,
ed elimina tutte le ''minacce'' trovate ;)
kyiv
Utente Junior
 
Post: 87
Iscritto il: 24/01/13 10:51

Re: pagine pubblicitarie che si aprono da sole

Postdi turbinoz » 27/03/13 17:57

Malwarebytes Anti-Malware 1.70.0.1100
http://www.malwarebytes.org

Versione database: v2013.03.26.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
antonio :: PC-ANTONIO [amministratore]

26/03/2013 13.40.37
mbam-log-2013-03-26 (13-40-37).txt

Tipo di scansione: Scansione completa (C:\|D:\|E:\|F:\|)
Opzioni di scansione attive: Memoria | Esecuzione automatica | Registro | File di sistema | Euristica/Extra | Euristica/Shuriken | PUP | PUM
Opzioni di scansione disattivate: P2P
Elementi esaminati: 431548
Tempo impiegato: 2 ore, 30 minuti, 7 secondi

Processi rilevati in memoria: 0
(non sono stati rilevati elementi nocivi)

Moduli di memoria rilevati: 0
(non sono stati rilevati elementi nocivi)

Chiavi di registro rilevate: 0
(non sono stati rilevati elementi nocivi)

Valori di registro rilevati: 0
(non sono stati rilevati elementi nocivi)

Voci rilevate nei dati di registro: 0
(non sono stati rilevati elementi nocivi)

Cartelle rilevate: 0
(non sono stati rilevati elementi nocivi)

File rilevati: 2
C:\Program Files\Common Files\Adobe\Adobe PCD\amtlib.dll (PUP.RiskwareTool.CK) -> Spostato in quarantena ed eliminato con successo.
C:\ProwIRC\Script\Dlls\nHTMLn_2.95.dll (Trojan.Agent) -> Spostato in quarantena ed eliminato con successo.

(fine)
turbinoz
Utente Junior
 
Post: 10
Iscritto il: 23/03/13 13:18

Re: pagine pubblicitarie che si aprono da sole

Postdi Luke57 » 28/03/13 11:12

Ciao, ok, hai sempre problemi?
Luke57
Moderatore
 
Post: 6410
Iscritto il: 11/08/05 19:10

Re: pagine pubblicitarie che si aprono da sole

Postdi turbinoz » 28/03/13 12:05

ciao sinceramente sembra di no per adesso.....grazie di tutto......se mi succede di nuovo vi contatto.....grazie mille ancora!
turbinoz
Utente Junior
 
Post: 10
Iscritto il: 23/03/13 13:18

Re: pagine pubblicitarie che si aprono da sole

Postdi Fabio92D » 30/03/13 12:10

Ciao. Da quando ho scaricato Opera (da softonic) questo browser ha iniziato ad aprirsi da solo e mostrando pagine pubblicitarie. Dopo che l'ho disinstallato, tale problema è comparso su internet explorer. Adesso ho riscaricato Opera e presenta lo stesso problema di prima. Ho usato hijackthis e, seguendo l'analizzatore automatico del log, ho fixato i file che sembravano essere "strani" ma non è cambiato niente. Ecco il log di Hijackthis appena fatto:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:55:41, on 30/03/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16521)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Public\Documents\Application\CurrentFile\ssadp.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Guard BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: (no name) - !{472734EA-242A-422B-ADF8-83D1E48CC825} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
O4 - HKLM\..\Run: [ROC_ROC_NT] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SsroService] C:\Users\Public\Documents\Application\CurrentFile\ssadl.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Mario\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [EPSON SX218 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGDE.EXE /FU "C:\Windows\TEMP\E_S2B0A.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: &AOL Toolbar Cerca - C:\ProgramData\AOL\ieToolbar\resources\it-IT\local\search.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/i ... ction2.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A6CC4C4-4135-4A11-B0EA-79731BE8FAAA}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{0A6CC4C4-4135-4A11-B0EA-79731BE8FAAA}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{0A6CC4C4-4135-4A11-B0EA-79731BE8FAAA}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira Pianificatore (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files (x86)\Dassault Systemes\B17\intel_a\code\bin\CATSysDemon.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EPSON V5 Service4(04) (EPSON_EB_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Servizio di Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpSC - SoftwareUpdService - C:\Users\Mario\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Serv Updater (ServUpdater) - ServiceUpd - C:\Users\Mario\AppData\Local\ServUpdater\ServiceUpd.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Ssro Service (SsroService) - SsroService - C:\Users\Mario\AppData\Local\ServiceManager\ssro.exe
O23 - Service: Ssupd Service (SsupdService) - SsupdService - C:\Users\Mario\AppData\Local\ssupd\ssupd.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 15519 bytes
Fabio92D
Newbie
 
Post: 7
Iscritto il: 28/03/13 10:39

Re: pagine pubblicitarie che si aprono da sole

Postdi shel » 30/03/13 18:38

ciao bisognerebbe evitare di scaricare da softonic spesso e volentieri si installano adware ed altre porcherie, ora fai questa scansione


scarica OTL
Metti la spunta su SCAN ALL USERS.
Sotto output spunta minimal output
Clicca sulla freccettina di File Age e seleziona 60 Days
Metti la spunta a LOP Check and Purity Check.
A fine scansione OTL produrrà due file di log (OTL.txt ed Extras.txt)
Allegali con wikisend e posta il link ottenuto
shel
Utente Senior
 
Post: 1292
Iscritto il: 29/08/08 21:56

Re: pagine pubblicitarie che si aprono da sole

Postdi Fabio92D » 02/04/13 14:00

Fabio92D
Newbie
 
Post: 7
Iscritto il: 28/03/13 10:39

Re: pagine pubblicitarie che si aprono da sole

Postdi shel » 03/04/13 10:20

apri otl e copia nel box bianco questo codice




Codice: Seleziona tutto
:OTL
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
SRV - (LiveUpSC) -- C:\Users\Mario\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe (SoftwareUpdService)
SRV - (SsupdService) -- C:\Users\Mario\AppData\Local\ssupd\ssupd.exe (SsupdService)
SRV - (SsroService) -- C:\Users\Mario\AppData\Local\ServiceManager\ssro.exe (SsroService)
SRV - (ServUpdater) -- C:\Users\Mario\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{AC286C67-BBE2-4E6D-B1B3-C170CBAB31B4}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1120&query={searchTerms}&invocationType=tb50hpcndtie7-it-it
IE - HKLM\..\SearchScopes\{D5DB4156-F8F3-45C7-8036-3938386B92C0}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1120&query={searchTerms}&invocationType=tb50hpcndtie7-it-it
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-21-718512464-448119397-1643257312-1001\..\SearchScopes\{522D170E-ADAF-431E-8D0C-4794533595BD}: "URL" = http://start.funmoods.com/results.php?f=4&a=nv1&q={searchTerms}
IE - HKU\S-1-5-21-718512464-448119397-1643257312-1001\..\SearchScopes\{AC286C67-BBE2-4E6D-B1B3-C170CBAB31B4}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=433cc300-49ea-11e1-bb4e-002655390f5f&q={searchTerms}
FF - prefs.js..extensions.enabledItems: offerboxffx@offerbox.com:2.1.3128.64
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fbphotozoom@installdaddy.com: C:\Program Files (x86)\fbphotozoom\fbphotozoom15.xpi
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ocr@babylon.com: C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\ocr@babylon.com
[2013/01/30 19:13:10 | 000,224,945 | ---- | M] () (No name found) -- C:\Users\Mario\AppData\Roaming\mozilla\firefox\profiles\yav23nf8.default\extensions\gophoto@gophoto.it.xpi
[2012/06/15 16:33:44 | 000,001,867 | ---- | M] () -- C:\Users\Mario\AppData\Roaming\mozilla\firefox\profiles\yav23nf8.default\searchplugins\findeer.xml
CHR - homepage: http://search.findeer.com
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKU\S-1-5-21-718512464-448119397-1643257312-1001\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKU\S-1-5-21-718512464-448119397-1643257312-1001..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O8:[b]64bit:[/b] - Extra context menu item: &AOL Toolbar Cerca - C:\ProgramData\AOL\ieToolbar\resources\it-IT\local\search.html ()
O8 - Extra context menu item: &AOL Toolbar Cerca - C:\ProgramData\AOL\ieToolbar\resources\it-IT\local\search.html ()
[2013/03/12 23:44:27 | 000,000,000 | ---D | C] -- C:\Users\Mario\AppData\Local\ssupd
[2013/03/12 18:54:48 | 000,000,000 | ---D | C] -- C:\Users\Mario\AppData\Local\SoftwareUpdater
[2010/05/13 19:51:45 | 000,008,212 | ---- | C] () -- C:\Users\Mario\AppData\Roaming\wklnhst.dat
@Alternate Data Stream - 845 bytes -> C:\Users\Mario\Desktop\Letto__IMPORTANTE!!!!.eml:OECustomProperty
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:DFC5A2B2

:Files
ipconfig /flushdns /c

:commands
[Reboot]



clicca su RUN FIX e allega il log che rilascia
shel
Utente Senior
 
Post: 1292
Iscritto il: 29/08/08 21:56

Re: pagine pubblicitarie che si aprono da sole

Postdi Fabio92D » 03/04/13 11:32

http://wikisend.com/download/242008/desktop.ini[url]
http://wikisend.com/download/278686/desktop.ini[/url]
Mi ha dato due file "desktop.ini, spero siano questi
Fabio92D
Newbie
 
Post: 7
Iscritto il: 28/03/13 10:39

Re: pagine pubblicitarie che si aprono da sole

Postdi shel » 03/04/13 11:56

no non sono questi, guarda nella cartella di otl lo trovi in questo percorso

C:\_OTL\MovedFiles\ ggMMaaaa_hhmmss.log
shel
Utente Senior
 
Post: 1292
Iscritto il: 29/08/08 21:56

Re: pagine pubblicitarie che si aprono da sole

Postdi Fabio92D » 03/04/13 12:50

Fabio92D
Newbie
 
Post: 7
Iscritto il: 28/03/13 10:39

Re: pagine pubblicitarie che si aprono da sole

Postdi shel » 03/04/13 16:49

sai dirmi se il problema e' risolto?

apri otl e clicca su cleanup rimuoverai correttamente otl
shel
Utente Senior
 
Post: 1292
Iscritto il: 29/08/08 21:56

Re: pagine pubblicitarie che si aprono da sole

Postdi Fabio92D » 04/04/13 10:37

il problema non si è risolto in quanto Opera mi si è appena aperto da solo con due pagine pubblicitarie. Comunque vorrei aggiungere che nella seconda scansione con OTL, quella dove ho aggiunto quelle scritte che mi hai consigliato, avevo dei browser aperti e non avevo cambiato le impostazioni di OTL ( es: metti la spunta su scann all users) come mi avevi consigliato la prima volta.
Fabio92D
Newbie
 
Post: 7
Iscritto il: 28/03/13 10:39

Re: pagine pubblicitarie che si aprono da sole

Postdi shel » 04/04/13 11:19

rimuovi opera da pannello di controllo

scarica e installa ccleaner
Importante:
In fase d’installazione togli la spunta altrimenti viene installata Yahoo Tollbar.
Avvialo e clicca su:
- Opzioni Avanzate
Togli la spunta da:
- Elimina file solo se più vecchi di 48 ore
Clicca i tasti:
- Pulizia (il primo in alto a Sinistra)
- Analizza ( Pulsante in basso Centrale)
- Avvia Pulizia (Pulsante in basso a Destra)

Correzione errori File di Registro
CCleaner
Clicca i tasti:
- Registro (Secondo tasto in alto a Sinistra)
- Trova Problemi (Pulsante in basso Centrale)
- Ripara selezionati Pulsante in basso a Destra
- alla domanda:
- Vuoi eseguire il Backup delle modifiche del Registro”
- clicca:
- SI


scarica la versione di opera da qui

ora riesegui otl impostato come la prima volta e con tutte le applicazioni chiuse

allega il log di otl.txt
shel
Utente Senior
 
Post: 1292
Iscritto il: 29/08/08 21:56

PrecedenteProssimo

Torna a Sicurezza e Privacy


Topic correlati a "pagine pubblicitarie che si aprono da sole":


Chi c’è in linea

Visitano il forum: Nessuno e 2 ospiti