s13.tempx.cc

gnagnela

Nuovo Utente
21 Gen 2005
12
0
0
mi son beccato questo "coso" ke mi reindirizza a s13.tempx.cc...
inutile dire ke non riesco a fare nulla o quasi per eliminarlo con i soliti mezzi (spybot, adware, ecc).
COME POSSO FARE X ELIMINARLO????' :incazz:
 

seth74

Nuovo Utente
2 Mar 2005
3
0
0
ciao ho lo stesso tuo problema sei riuscito a risolverlo???
te ne sarei veramente grato!
grazie
seth :incazz:
 

seth74

Nuovo Utente
2 Mar 2005
3
0
0
si ho provato entrambi e sto usando ad-aware e spy-bot ma non servono a nulla i problemi si ripresentano!
non si riesce a toglierli neanche andando direttamente nei file di registro;
è diventato un tormento!!
aiutoooooo :incazz:
 

gnagnela

Nuovo Utente
21 Gen 2005
12
0
0
si', ho provato....

si, ho provato con tutto (ad-aware, hijackthis,spybot..,stinger, ecc.) ma NULLA!!!! Il bastardissimo si ripresenta! Per ora ho dribblato il problema installando Mozilla e collegandomi con quello (altrimenti non potrei scrivere su questo forum!)
BASTARDO!!!!!!!!!!!!1
 

gnagnela

Nuovo Utente
21 Gen 2005
12
0
0
Ciao Web! ti posto il log! spero tu possa aiutarmi!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ANGELA~2\IMPOST~1\Temp\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ANGELA~2\IMPOST~1\Temp\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {C52C6423-4DBC-4F6A-93FF-02521199E84F} - C:\WINDOWS\System32\ohapkc.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Client Access Service] "C:\Programmi\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "C:\Programmi\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "C:\Programmi\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Programmi\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programmi\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmi\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [PromemoriaAT] C:\PROGRA~1\LATUAA~1\PromemATf.exe
O4 - HKLM\..\Run: [PostATlst] C:\PROGRA~1\LATUAA~1\PostATlstf.exe
O4 - HKLM\..\Run: [PromemoriaATf] C:\PROGRA~1\LATUAA~1\PromemATf.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F61C5A0-5317-46AC-B33C-30C0F3CA96BA}: NameServer = 213.140.2.43,213.140.2.49
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Programmi\HP\hpcoretech\comp\hpuiprot.dll
O18 - Filter: text/html - {65DCE7F0-6CEC-4A4D-BF3F-80E1CFC612B0} - C:\WINDOWS\System32\ohapkc.dll
O18 - Filter: text/plain - {65DCE7F0-6CEC-4A4D-BF3F-80E1CFC612B0} - C:\WINDOWS\System32\ohapkc.dll
O23 - Service: Comando remoto Client Access Express - IBM Corporation - C:\WINDOWS\CWBRXD.EXE
 

seth74

Nuovo Utente
2 Mar 2005
3
0
0
ciao, ho fatto come hai detto, ti posto il LOG
grazie!!!!!!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {F665BAC8-B1EF-4274-A126-72A7156F7CDD} - C:\WINDOWS\SYSTEM\GJEFN.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - Startup: Collegamento a ORARIO.xls.lnk.disabled
O4 - User Startup: Collegamento a ORARIO.xls.lnk.disabled
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.pcw.it
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = anasnet.it
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 126.1.8.15,126.1.8.16
O18 - Filter: text/html - {0E24D25F-3E14-4F2D-8C6C-287A2C1557EB} - C:\WINDOWS\SYSTEM\GJEFN.DLL
O18 - Filter: text/plain - {0E24D25F-3E14-4F2D-8C6C-287A2C1557EB} - C:\WINDOWS\SYSTEM\GJEFN.DLL