Condividi:        

Sono stato colpito dall'e1xplorer

Come rimuovere virus e spyware? Le carte di credito sono davvero sicure in rete? È possibile navigare anonimi? Con quali programmi tutelare la propria privacy? Come proteggere i file importanti? Se volete una risposta a queste e altre domande questo è il luogo giusto!

Moderatori: m.paolo, kadosh, Luke57

Sono stato colpito dall'e1xplorer

Postdi Andrea-86 » 08/09/06 16:11

Ciao a tutti sono Andrea e anche io sono stato colpito dal virus e1xplorer che mi sta incasinando il pc cosa posso fare per risolvere i miei problemi ho usato hijackthis ma non vorrei combinare altri guai chi mi può aiutare?
se volete vi posso mandare il resoconto di hijackthis.

P.S.:so che avete già risolto problemi simili ma pur leggendo le soluzioni non ho capito granchè solo per questo sto riaprendo una discussione che avete già affrontato.
Andrea-86
Utente Junior
 
Post: 14
Iscritto il: 08/09/06 15:57

Sponsor
 

Postdi andorra24 » 08/09/06 16:17

SI, posta il log di hijackthis cosi controlliamo.
andorra24
Utente Senior
 
Post: 2742
Iscritto il: 21/05/06 15:44
Località: Palermo

Postdi Andrea-86 » 08/09/06 16:26

Logfile of HijackThis v1.99.1
Scan saved at 17.23.08, on 08/09/06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS1\SYSTEM\KERNEL32.DLL
C:\WINDOWS1\SYSTEM\MSGSRV32.EXE
C:\WINDOWS1\SYSTEM\SPOOL32.EXE
C:\WINDOWS1\SYSTEM\MPREXE.EXE
C:\WINDOWS1\SYSTEM\MSTASK.EXE
C:\PROGRAMMI\MESSENGERPLUS! 3\MSGPLUS.EXE
C:\PROGRAMMI\ANTIVIR PERSONALEDITION CLASSIC\SCHEDM.EXE
C:\WINDOWS1\SYSTEM\mmtask.tsk
C:\WINDOWS1\EXPLORER.EXE
C:\WINDOWS1\SYSTEM\TAPISRV.EXE
C:\WINDOWS1\TASKMON.EXE
C:\WINDOWS1\SYSTEM\SYSTRAY.EXE
C:\PROGRAMMI\MATROX MGA POWERDESK\MGACTRL.EXE
C:\PROGRAMMI\MATROX MGA POWERDESK\COLOR\HGCCTL95.EXE
C:\WINDOWS1\LOADQM.EXE
C:\PROGRAMMI\WINAMP\WINAMPA.EXE
C:\WINDOWS1\SYSTEM\E_S4I0T1.EXE
C:\WINDOWS1\SYSTEM\STIMON.EXE
C:\PROGRAMMI\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE
C:\WINDOWS1\SYSTEM\LVCOMSX.EXE
C:\WINDOWS1\SYSTEM\LVCOMS.EXE
C:\PROGRAMMI\LOGITECH\IMAGESTUDIO\LOGITRAY.EXE
C:\WINDOWS1\TEMP\IUWT2.EXE
C:\PROGRAM FILES\GLOBESPANVIRATA\ADSL\DSLSTAT.EXE
C:\PROGRAM FILES\GLOBESPANVIRATA\ADSL\DSLAGENT.EXE
C:\WINDOWS1\SYSTEM\SPOOLSVC.EXE
C:\PROGRAMMI\ANTIVIR PERSONALEDITION CLASSIC\AVGCTRL.EXE
C:\PROGRAMMI\MATROX MGA POWERDESK\QDESK\MGAQDESK.EXE
C:\PROGRAMMI\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAMMI\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.EXE
C:\PROGRAMMI\HP\DIGITAL IMAGING\BIN\HPQTRA08.EXE
C:\WINDOWS1\SYSTEM\WMIEXE.EXE
C:\WINDOWS1\SYSTEM\PSTORES.EXE
C:\WINDOWS1\SYSTEM\DDHELP.EXE
C:\WINDOWS1\SYSTEM\RNAAPP.EXE
C:\PROGRAMMI\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS1\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.1987324.com?301
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMI\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS1\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS1\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS1\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Matrox Control Center] C:\Programmi\Matrox MGA PowerDesk\mgactrl.exe
O4 - HKLM\..\Run: [Matrox Color Control] C:\Programmi\Matrox MGA PowerDesk\Color\hgcctl95.exe
O4 - HKLM\..\Run: [Matrox Diagnostic] C:\Programmi\Matrox MGA PowerDesk\diag\mgadiag.exe -s
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS1\SYSTEM\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O5 "LPT1:" /M "Stylus C46"
O4 - HKLM\..\Run: [licli] li.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS1\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [zzzHPSETUP] E:\Setup.exe \RESET
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmi\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS1\SYSTEM\LVCOMSX.EXE
O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS1\SYSTEM\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programmi\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programmi\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [funk] funk.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS1\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [IUWT1.EXE] C:\WINDOWS1\TEMP\IUWT1.EXE
O4 - HKLM\..\Run: [bikini] bikini.exe
O4 - HKLM\..\Run: [IUWT2.EXE] C:\WINDOWS1\TEMP\IUWT2.EXE
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\GlobespanVirata\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS1\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Systems] C:\WINDOWS1\SYSTEM\spoolsvc.exe
O4 - HKLM\..\Run: [avgctrl] "C:\Programmi\AntiVir PersonalEdition Classic\avgctrl.exe" /min
O4 - HKLM\..\Run: [SpyHunter] C:\Programmi\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\RunServices: [schedm] "C:\Programmi\AntiVir PersonalEdition Classic\schedm.exe"
O4 - HKCU\..\Run: [Matrox QuickDesk] C:\Programmi\Matrox MGA PowerDesk\QDesk\mgaqdesk.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAMMI\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Encoder Agent.lnk = C:\Programmi\Windows Media Components\Encoder\WMENCAGT.EXE
O4 - Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS1\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS1\web\related.htm
O15 - Trusted Zone: *.aflashcounter.com
O15 - Trusted Zone: http://www.1987324.com
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnme ... loader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZI ... b32846.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://cloudy89italy.spaces.msn.com/Pho ... 10,0,912,0
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
Andrea-86
Utente Junior
 
Post: 14
Iscritto il: 08/09/06 15:57

Postdi andorra24 » 08/09/06 16:46

Apri hijackthis, premi su ''open the misc tools section'', poi premi ''open process manager'', individua le voci indicate sotto e premi ''kill process'' :

C:\WINDOWS1\TEMP\IUWT2.EXE
C:\WINDOWS1\SYSTEM\SPOOLSVC.EXE

Poi vai in basso e premi il tasto back e subito dopo il tasto scan. Metti la spunta nella casellina accanto alle voci indicate sotto e premi ''fix checked'' :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.1987324.com?301
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll (file missing)
O4 - HKLM\..\Run: [licli] li.exe
O4 - HKLM\..\Run: [zzzHPSETUP] E:\Setup.exe \RESET
O4 - HKLM\..\Run: [funk] funk.exe
O4 - HKLM\..\Run: [IUWT1.EXE] C:\WINDOWS1\TEMP\IUWT1.EXE
O4 - HKLM\..\Run: [bikini] bikini.exe
O4 - HKLM\..\Run: [IUWT2.EXE] C:\WINDOWS1\TEMP\IUWT2.EXE
O4 - HKLM\..\Run: [Systems] C:\WINDOWS1\SYSTEM\spoolsvc.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS1\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS1\web\related.htm
O15 - Trusted Zone: *.aflashcounter.com
O15 - Trusted Zone: http://www.1987324.com

Scarica ATF Cleaner da qui:
http://www.atribune.org/ccount/click.php?id=1
(per eliminare file temporanei di windows e IE)
Avvia ATF cleaner, clicca sul menu "main" e poi seleziona la casella "Select All". Adesso clicca sul pulsante "Empty selected" e aspetta il messaggio "Done Cleaning!".

Scarica killbox: http://www.killbox.net/downloads/KillBox.exe
con killbox elimina i seguenti files:
C:\WINDOWS1\TEMP\IUWT2.EXE
C:\WINDOWS1\TEMP\IUWT1.EXE
C:\WINDOWS1\SYSTEM\SPOOLSVC.EXE
C:\WINDOWS1\SYSTEM\funk.exe
C:\WINDOWS1\SYSTEM\bikini.exe
C:\WINDOWS1\SYSTEM\li.exe

Fai una scansione con superantispyware:
http://www.superantispyware.com/downloa ... PYWAREFREE
andorra24
Utente Senior
 
Post: 2742
Iscritto il: 21/05/06 15:44
Località: Palermo

Postdi Andrea-86 » 08/09/06 19:37

Ho fatto tutto quello che mi hai scritto, solo non sono riuscito ad usare killbox in quanto non sono riuscito a trovare quei file che dovevo eliminare (saranno già stati eliminati o semplicemente rinominati e ancora presenti?); la scansione con antispyware è durata 51 minuti ma ha trovato 5 trojan e 48 adware e 2 unknown e poi mi ha chiesto di riavviare, dopo il riavvio al momento non ho problemi da circa mezz'ora a questa parte, che sia tutto finito? Se è così grazie di tutto, mi hai salvato da questo casino.

P.S. Forza Palermo (domenica inizia il mio terzo anno da abbonato curva nord)
Andrea-86
Utente Junior
 
Post: 14
Iscritto il: 08/09/06 15:57

Postdi andorra24 » 08/09/06 20:00

Dovresti essere a posto. Comunque, se vuoi puoi postare un nuovo log per un ultimo controllo.
andorra24
Utente Senior
 
Post: 2742
Iscritto il: 21/05/06 15:44
Località: Palermo

Postdi Andrea-86 » 13/09/06 23:18

Scusa se non ho risposto prima ma volevo essere sicuro che fosse tutto a posto per 3-4 giorni ed è così; sembra veramente essere tutto risolto, per sicurezza ti invio nuovamente il log di hijackthis.
GRAZIE ancora.

P.S.:Ho antivir come antivirus (uno dei pochi che il mio pc regge senza rallentare troppo) com'è come antivirus?

Logfile of HijackThis v1.99.1
Scan saved at 0.13.53, on 14/09/06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS1\SYSTEM\KERNEL32.DLL
C:\WINDOWS1\SYSTEM\MSGSRV32.EXE
C:\WINDOWS1\SYSTEM\MPREXE.EXE
C:\WINDOWS1\SYSTEM\mmtask.tsk
C:\WINDOWS1\SYSTEM\MSTASK.EXE
C:\PROGRAMMI\MESSENGERPLUS! 3\MSGPLUS.EXE
C:\PROGRAMMI\ANTIVIR PERSONALEDITION CLASSIC\SCHEDM.EXE
C:\WINDOWS1\EXPLORER.EXE
C:\WINDOWS1\SYSTEM\RNAAPP.EXE
C:\WINDOWS1\SYSTEM\TAPISRV.EXE
C:\WINDOWS1\TASKMON.EXE
C:\WINDOWS1\SYSTEM\SYSTRAY.EXE
C:\PROGRAMMI\MATROX MGA POWERDESK\MGACTRL.EXE
C:\PROGRAMMI\MATROX MGA POWERDESK\COLOR\HGCCTL95.EXE
C:\WINDOWS1\LOADQM.EXE
C:\PROGRAMMI\WINAMP\WINAMPA.EXE
C:\WINDOWS1\SYSTEM\E_S4I0T1.EXE
C:\WINDOWS1\SYSTEM\STIMON.EXE
C:\PROGRAMMI\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE
C:\WINDOWS1\SYSTEM\LVCOMSX.EXE
C:\WINDOWS1\SYSTEM\LVCOMS.EXE
C:\PROGRAMMI\LOGITECH\IMAGESTUDIO\LOGITRAY.EXE
C:\PROGRAM FILES\GLOBESPANVIRATA\ADSL\DSLSTAT.EXE
C:\WINDOWS1\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\GLOBESPANVIRATA\ADSL\DSLAGENT.EXE
C:\PROGRAMMI\ANTIVIR PERSONALEDITION CLASSIC\AVGCTRL.EXE
C:\PROGRAMMI\MATROX MGA POWERDESK\QDESK\MGAQDESK.EXE
C:\PROGRAMMI\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
C:\PROGRAMMI\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.EXE
C:\PROGRAMMI\HP\DIGITAL IMAGING\BIN\HPQTRA08.EXE
C:\PROGRAMMI\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS1\SYSTEM\WMIEXE.EXE
C:\WINDOWS1\SYSTEM\DDHELP.EXE
C:\PROGRAMMI\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS1\SYSTEM\PSTORES.EXE
C:\WINDOWS1\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMI\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS1\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS1\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS1\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Matrox Control Center] C:\Programmi\Matrox MGA PowerDesk\mgactrl.exe
O4 - HKLM\..\Run: [Matrox Color Control] C:\Programmi\Matrox MGA PowerDesk\Color\hgcctl95.exe
O4 - HKLM\..\Run: [Matrox Diagnostic] C:\Programmi\Matrox MGA PowerDesk\diag\mgadiag.exe -s
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\winampa.exe
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS1\SYSTEM\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O5 "LPT1:" /M "Stylus C46"
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS1\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmi\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS1\SYSTEM\LVCOMSX.EXE
O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS1\SYSTEM\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Programmi\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Programmi\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS1\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\GlobespanVirata\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS1\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [avgctrl] "C:\Programmi\AntiVir PersonalEdition Classic\avgctrl.exe" /min
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\RunServices: [schedm] "C:\Programmi\AntiVir PersonalEdition Classic\schedm.exe"
O4 - HKCU\..\Run: [Matrox QuickDesk] C:\Programmi\Matrox MGA PowerDesk\QDesk\mgaqdesk.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programmi\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAMMI\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAMMI\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Encoder Agent.lnk = C:\Programmi\Windows Media Components\Encoder\WMENCAGT.EXE
O4 - Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnme ... loader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZI ... b32846.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://cloudy89italy.spaces.msn.com/Pho ... 10,0,912,0
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O20 - Winlogon Notify: SASWinLogon - C:\PROGRAMMI\SUPERANTISPYWARE\SASWINLO.DLL
Andrea-86
Utente Junior
 
Post: 14
Iscritto il: 08/09/06 15:57

Postdi andorra24 » 13/09/06 23:25

Ciao, il log e' pulito. Antivir va benissimo come antivirus. ;)
andorra24
Utente Senior
 
Post: 2742
Iscritto il: 21/05/06 15:44
Località: Palermo


Torna a Sicurezza e Privacy


Topic correlati a "Sono stato colpito dall'e1xplorer":


Chi c’è in linea

Visitano il forum: Nessuno e 23 ospiti

cron