Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

impossibile disinstallare qvo6 e altri

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » mer ott 02, 2013 4:41 pm

ciao a tutti. mi sono accorta che installando alcuni programmi da softonic mi restano nel pc dei tool che non riesco a togliere. ho fatto la scansione con avira ma il risultato è uguale. vi allego scansione di hijackthis potete aiutarmi? grazie

ogfile of Trend Micro HijackThis v2.0.5
Scan saved at 16:44:36, on 02/10/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16490)

FIREFOX: 24.0 (it)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
F:\HijackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1380631594
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1380631594
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Avira SearchFree Toolbar plus Web Protection BHO - {41564952-412D-5637-00A7-7A786E7484D7} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - (no file)
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Pianificatore (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Servizio di aggiornamento Ask (APNMCP) - APN LLC. - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Remote Connections Service (FlexService) - BitMicro Software Corporation - C:\Program Files (x86)\RapidBIT\cisvc.exe
O23 - Service: Servizio Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8292 bytes
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am

Re: impossibile disinstallare qvo6 e altri

Messaggioda GERONIMO* » gio ott 03, 2013 12:26 pm

fixa queste voci
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1380631594
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1380631594

poi segui questa guida va bene pure per qv06 cambia solo il nome [^]
http://www.windoctor.it/sicurezza/guide ... te-v9-com/
Avatar utente
GERONIMO*
Bronze Member
Bronze Member
 
Messaggi: 931
Iscritto il: lun apr 23, 2012 11:30 pm

Re: impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » ven ott 04, 2013 10:21 am

grazie geronimo, metto in pratica i suggerimenti e poi ti saprò dire. ancora mille grazie
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am


Re: impossibile disinstallare qvo6 e altri

Messaggioda GERONIMO* » ven ott 04, 2013 2:27 pm

prego
fai sapere [;)]
per curiosità mi dici installando quale programma hai beccato qvo6 ? [sh]
Avatar utente
GERONIMO*
Bronze Member
Bronze Member
 
Messaggi: 931
Iscritto il: lun apr 23, 2012 11:30 pm

Re: impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » ven ott 04, 2013 8:13 pm

buonasera geronimo, ho eguito tutto quanto indicato nella guida e per qvo6 ho risolto, solo non so da dove è uscito DO SEARCH che non riesco a togliere, Bing e start Search.
per quanto riguarda qvo6 non saprei che programma era, sono solo sicura che avevo scaricato da softonic e poi l'ho tolto perché non era interessante, ma è successo tempo fa.
se faccio una scansione con combofix pensi possa risolvere? grazie sei molto gentile
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am

Re: impossibile disinstallare qvo6 e altri

Messaggioda GERONIMO* » ven ott 04, 2013 8:36 pm

ok fuori uno [rotfl] [:)]
peccato mannaggia volevo studiarli e farci le guide [bleh]

no,facciamola con OTL [sh]

Scarica OTL by OldTimer sul Desktop
http://www.windoctor.it/download/otl/
Chiudi tutti i programmi aperti Metti il segno di spunta su Scan All Users
Clicca su Run Scan
Attendere la fine della scansione, OTL lascierà due file di log (OTL.txt ed Extras.txt),
allegali sul forum
caricali da qui,perché sono lunghi
http://wikisend.com
Immagine
Avatar utente
GERONIMO*
Bronze Member
Bronze Member
 
Messaggi: 931
Iscritto il: lun apr 23, 2012 11:30 pm

Re: impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » sab ott 05, 2013 11:37 am

ciao geronimo, fatto tutto ma porta pazienza,essendo alquanto imbranata, come funziona l'invio con wikisend?
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am

Re: impossibile disinstallare qvo6 e altri

Messaggioda GERONIMO* » sab ott 05, 2013 12:37 pm

devi fliccare su Scegli file
selezioni otl
poi apri
upload file
poi
in Forum link:
selezioni il link e lo incolli qui
stessa cosa per Extras
Avatar utente
GERONIMO*
Bronze Member
Bronze Member
 
Messaggi: 931
Iscritto il: lun apr 23, 2012 11:30 pm

Re: impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » sab ott 05, 2013 1:15 pm

http://wikisend.com/download/999742/OTL.Txt[MEMO]Extras.Txt

spero di aver capito. grazie
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am

Re: impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » sab ott 05, 2013 1:21 pm

OTL.Txt[/MEMO[MEMO]OTL.Txt

ho rifatto tutto perché credo di aver sbagliato, scusami ancora
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am

Re: impossibile disinstallare qvo6 e altri

Messaggioda GERONIMO* » sab ott 05, 2013 2:01 pm

[^]
AZZ..sei piena
non te ne sei persa una [:D]

ora
Apri OTL
e copia/incolla tutto questo Script che vedi sotto nella finestra Custom Scans/Fixes
clicca su RUN FIX
Lascia finire la scansione
Riavvia il pc quando richiesto cliccando su Ok

Codice: Seleziona tutto
:OTL
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dosearches.com/?utm_source=b&utm_medium=slbnew&utm_campaign=eXQ&utm_content=hp&from=slbnew&uid=MaxtorX6L250R0_L51S0V2G&ts=1380727034
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dosearches.com/?utm_source=b&utm_medium=slbnew&utm_campaign=eXQ&utm_content=hp&from=slbnew&uid=MaxtorX6L250R0_L51S0V2G&ts=1380727034
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.qvo6.com/web/?utm_source=b&utm_medium=nsb3&utm_campaign=eXQ&utm_content=ds&from=nsb3&uid=MaxtorX6L250R0_L51S0V2G&ts=1380631594&type=default&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qvo6.com/web/?utm_source=b&utm_medium=nsb3&utm_campaign=eXQ&utm_content=ds&from=nsb3&uid=MaxtorX6L250R0_L51S0V2G&ts=1380631594&type=default&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-21-3167258803-1722963852-1982512013-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.iminent.com/?appId=0BF0B8A7-1EF3-46B8-BC63-36D9BBAA8D7B
IE - HKU\S-1-5-21-3167258803-1722963852-1982512013-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3167258803-1722963852-1982512013-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.searchplusnetwork.com/?sp=st3&q={searchTerms}
IE - HKU\S-1-5-21-3167258803-1722963852-1982512013-1000\..\SearchScopes\{1A2E0D00-110C-4428-ADFB-FAC9E03B5EE2}: "URL" = http://searchou.com/?q={searchTerms}&id=586244d2000000000000002618b8cea3&r=558
IE - HKU\S-1-5-21-3167258803-1722963852-1982512013-1000\..\SearchScopes\{20AB4037-35C3-48E9-841F-B7CA94D64F91}: "URL" = http://start.funmoods.com/results.php?f=4&a=nv1&q={searchTerms}
IE - HKU\S-1-5-21-3167258803-1722963852-1982512013-1000\..\SearchScopes\{628B9780-A6FD-457F-B4EB-36C591423DE8}: "URL" = http://search.softonic.com/MOY00010/tb_v1?q={searchTerms}&SearchSource=4&cc=&r=196
[2013/10/03 10:34:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Extensions
[2013/10/04 17:31:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\2m95z44t.default-1348950681792\extensions
[2013/05/01 18:01:55 | 000,040,492 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\2m95z44t.default-1348950681792\extensions\about-addons-memory@tn123.org.xpi
[2013/09/30 23:08:31 | 000,743,106 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\2m95z44t.default-1348950681792\extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
[2012/10/28 14:24:20 | 000,060,290 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\2m95z44t.default-1348950681792\extensions\translator@zoli.bod.xpi
[2013/10/04 14:57:51 | 000,150,994 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\2m95z44t.default-1348950681792\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
[2013/09/17 16:58:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013/10/02 17:17:14 | 000,000,845 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\dosearches.xml
CHR - Extension: Docs = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0\
O2 - BHO: (iminent Helper Object) - {112BA211-334C-4A90-90EC-2AD1CDAB287C} - C:\Program Files (x86)\IminentToolbar\1.8.25.0\bh\iminent.dll File not found
O3 - HKLM\..\Toolbar: (Iminent Toolbar) - {1FAFD711-ABF9-4F6A-8130-5166C7371427} - C:\Program Files (x86)\IminentToolbar\1.8.25.0\iminentTlbr.dll File not found
O3 - HKLM\..\Toolbar: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
@Alternate Data Stream - 215 bytes -> C:\ProgramData\TEMP:DB76C881
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:87A3A233
@Alternate Data Stream - 161 bytes -> C:\ProgramData\TEMP:ED0B32CA
@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:DD6F157A
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:79BFF8A4
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:4D551822
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:8029E75F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:D026A5A4
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:86B7FDDB
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:5453E5AF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F5D01D7C
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:A6F30843
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:661DFA1C
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:BEACE4C8
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:012BC84F
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:474022C7
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:57B2B96C
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:DBC3D477
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:1A15E356
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:8E5EA40F
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:B6D84F71
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:95079543
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:3595B780
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:AD7183FA
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:774C075A
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:774A0E14
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:A58B27C9
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:12D2EB9C

:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{FF7FB506-AEBA-4EFB-9A67-7E9148D2056C}" =-

:Files
ipconfig /flushdns /c

:commands
[purity]
[emptytemp]
[Emptyjava]
[EMPTYFLASH]
[start explorer]
[Reboot]


Esempio
Immagine

Immagine

Immagine

Immagine
Avatar utente
GERONIMO*
Bronze Member
Bronze Member
 
Messaggi: 931
Iscritto il: lun apr 23, 2012 11:30 pm

Re: impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » sab ott 05, 2013 3:54 pm

fatto tutto.ti mando il risultato finale, però risulta ancora sia bing che DO SEARCHES quando apro una nuova finestra, accidenti a me

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomizeSearch| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-3167258803-1722963852-1982512013-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_USERS\S-1-5-21-3167258803-1722963852-1982512013-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3167258803-1722963852-1982512013-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-3167258803-1722963852-1982512013-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1A2E0D00-110C-4428-ADFB-FAC9E03B5EE2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A2E0D00-110C-4428-ADFB-FAC9E03B5EE2}\ not found.
Registry key HKEY_USERS\S-1-5-21-3167258803-1722963852-1982512013-1000\Software\Microsoft\Internet Explorer\SearchScopes\{20AB4037-35C3-48E9-841F-B7CA94D64F91}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20AB4037-35C3-48E9-841F-B7CA94D64F91}\ not found.
Registry key HKEY_USERS\S-1-5-21-3167258803-1722963852-1982512013-1000\Software\Microsoft\Internet Explorer\SearchScopes\{628B9780-A6FD-457F-B4EB-36C591423DE8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{628B9780-A6FD-457F-B4EB-36C591423DE8}\ not found.
C:\Users\User\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully.
C:\Users\User\AppData\Roaming\mozilla\Extensions folder moved successfully.
C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\2m95z44t.default-1348950681792\extensions folder moved successfully.
File C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\2m95z44t.default-1348950681792\extensions\about-addons-memory@tn123.org.xpi not found.
File C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\2m95z44t.default-1348950681792\extensions\toolbar_AVIRA-V7@apn.ask.com.xpi not found.
File C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\2m95z44t.default-1348950681792\extensions\translator@zoli.bod.xpi not found.
File C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\2m95z44t.default-1348950681792\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi not found.
C:\Program Files (x86)\mozilla firefox\extensions\{5ddeb737-082c-48fb-8c06-aa4b38d61e5f}\defaults\preferences folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{5ddeb737-082c-48fb-8c06-aa4b38d61e5f}\defaults folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{5ddeb737-082c-48fb-8c06-aa4b38d61e5f}\chrome\skin folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{5ddeb737-082c-48fb-8c06-aa4b38d61e5f}\chrome\locale\en-US folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{5ddeb737-082c-48fb-8c06-aa4b38d61e5f}\chrome\locale folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{5ddeb737-082c-48fb-8c06-aa4b38d61e5f}\chrome\content folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{5ddeb737-082c-48fb-8c06-aa4b38d61e5f}\chrome folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions\{5ddeb737-082c-48fb-8c06-aa4b38d61e5f} folder moved successfully.
C:\Program Files (x86)\mozilla firefox\extensions folder moved successfully.
C:\Program Files (x86)\mozilla firefox\searchplugins\dosearches.xml moved successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\__MACOSX folder moved successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 folder moved successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkhojieggfgllhllcegoffdcnmdeojgb\2.0_0 folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{112BA211-334C-4A90-90EC-2AD1CDAB287C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{112BA211-334C-4A90-90EC-2AD1CDAB287C}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{1FAFD711-ABF9-4F6A-8130-5166C7371427} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1FAFD711-ABF9-4F6A-8130-5166C7371427}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{41564952-412D-5637-00A7-7A786E7484D7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
ADS C:\ProgramData\TEMP:DB76C881 deleted successfully.
ADS C:\ProgramData\TEMP:87A3A233 deleted successfully.
ADS C:\ProgramData\TEMP:ED0B32CA deleted successfully.
ADS C:\ProgramData\TEMP:DD6F157A deleted successfully.
ADS C:\ProgramData\TEMP:79BFF8A4 deleted successfully.
ADS C:\ProgramData\TEMP:4D551822 deleted successfully.
ADS C:\ProgramData\TEMP:8029E75F deleted successfully.
ADS C:\ProgramData\TEMP:D026A5A4 deleted successfully.
ADS C:\ProgramData\TEMP:86B7FDDB deleted successfully.
ADS C:\ProgramData\TEMP:5453E5AF deleted successfully.
ADS C:\ProgramData\TEMP:F5D01D7C deleted successfully.
ADS C:\ProgramData\TEMP:A6F30843 deleted successfully.
ADS C:\ProgramData\TEMP:661DFA1C deleted successfully.
ADS C:\ProgramData\TEMP:BEACE4C8 deleted successfully.
ADS C:\ProgramData\TEMP:012BC84F deleted successfully.
ADS C:\ProgramData\TEMP:474022C7 deleted successfully.
ADS C:\ProgramData\TEMP:57B2B96C deleted successfully.
ADS C:\ProgramData\TEMP:DBC3D477 deleted successfully.
ADS C:\ProgramData\TEMP:1A15E356 deleted successfully.
ADS C:\ProgramData\TEMP:8E5EA40F deleted successfully.
ADS C:\ProgramData\TEMP:B6D84F71 deleted successfully.
ADS C:\ProgramData\TEMP:95079543 deleted successfully.
ADS C:\ProgramData\TEMP:3595B780 deleted successfully.
ADS C:\ProgramData\TEMP:AD7183FA deleted successfully.
ADS C:\ProgramData\TEMP:774C075A deleted successfully.
ADS C:\ProgramData\TEMP:774A0E14 deleted successfully.
ADS C:\ProgramData\TEMP:A58B27C9 deleted successfully.
ADS C:\ProgramData\TEMP:12D2EB9C deleted successfully.
File EY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] not found.
File rity] not found.
File ptytemp] not found.
File ptyjava] not found.
File PTYFLASH] not found.
File art explorer] not found.
File boot] not found.

OTL by OldTimer - Version 3.2.69.0 log created on 10052013_164359

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am

Re: impossibile disinstallare qvo6 e altri

Messaggioda GERONIMO* » sab ott 05, 2013 4:22 pm

ok [^]
ma Bing non è nociva,è il motore di ricerca di microsoft
mi dici DO SEARCHES su quali browser ti esce?
Avatar utente
GERONIMO*
Bronze Member
Bronze Member
 
Messaggi: 931
Iscritto il: lun apr 23, 2012 11:30 pm

Re: impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » sab ott 05, 2013 5:47 pm

lo so che bing noin è nocivo, ma io come motore di ricerca ho messo google e bing non esiste nel menù dei motori. quanto a DO SEARCHES mi esce quando apro una finesta su firefox e anche questo non c'è in nessuna parte. non uso IE, avevo provato google e opera, ma non mi trovo e così sono rimasta a firefox.
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am

Re: impossibile disinstallare qvo6 e altri

Messaggioda GERONIMO* » sab ott 05, 2013 7:45 pm

per bing vedi se lo trovi in programmi e funzionalità,e lo disinstalli o vedi in gestione componenti aggiuntivi
Provider di ricerca,e lo rimuovi

per DO SEARCHES
apri firefox
digita nella barra indirizzi in alto about:config
poi clicca sul pulsante Farò attenzione,prometto
individua la voce browser.newtab.url
tasto destro del mouse su browser.newtab.url e clicca su Modifica
e inserisci il valore di default questo about:newtab e dai OK
se poi vuoi che si apre google metti questo google.com
Avatar utente
GERONIMO*
Bronze Member
Bronze Member
 
Messaggi: 931
Iscritto il: lun apr 23, 2012 11:30 pm

Re: impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » sab ott 05, 2013 10:48 pm

sei molto gentile geronimo, ma non ho rsolto nulla. ho cancellato componenti aggiuntivi da IE ma niente da fare. ricompare sempre bing. invece per firefox scrivo about ecc. ma mi esce alice che dice che l'indirizzo non è valido. a questo punto cosa faccio?
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am

Re: impossibile disinstallare qvo6 e altri

Messaggioda GERONIMO* » dom ott 06, 2013 9:53 am

per bing,non ho capito se ti esce la pagina iniziale bing,o il motore di ricerca

riapri hijackthis se c'è questa voce selezionala e clicca su Fix checked
O3 - Toolbar: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - (no file)


per la pagina iniziale
Opzioni Internet

Sulla scheda Generale
Pagina iniziale
metti http://www.google.it/

per il motore di ricerca bing,non ho capito non si rimuove? se lo selezioni e clicchi Rimuovi?

aggiungi google segui qui come fare
https://support.google.com/websearch/answer/464?hl=it

per firefox avrai sbagliato a scrivere riprova
Immagine
Avatar utente
GERONIMO*
Bronze Member
Bronze Member
 
Messaggi: 931
Iscritto il: lun apr 23, 2012 11:30 pm

Re: impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » dom ott 06, 2013 10:59 am

buona domenica geronimo, grazie ed avevi ragione:sbagliavo a digitare about. allora per il momento mi sembra di avere risolto tutto facendo come mi hai spiegato, solo che su hijackthis non trovo 03ecc. per DO SEARCHERS ho aperto IE e bloccato il sito,fin'ora e tutto OK. spero non doverti disturbare più. a MegaLab ed a te in particolare un grazie enorme siete veramente fantastici [applauso+] [applauso+] [applauso+] [ciao] [ciao]
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am

Re: impossibile disinstallare qvo6 e altri

Messaggioda lollo40 » dom ott 06, 2013 11:00 am

dimenticavo inoltre ho reinstallato FF.ciao
Avatar utente
lollo40
Senior Member
Senior Member
 
Messaggi: 204
Iscritto il: lun mar 26, 2007 1:33 am

Re: impossibile disinstallare qvo6 e altri

Messaggioda GERONIMO* » dom ott 06, 2013 1:01 pm

buona domenica anche a te [;)]
visto? con un po' di pazienza si risolve tutto [:)]
ciao [ciao]
Avatar utente
GERONIMO*
Bronze Member
Bronze Member
 
Messaggi: 931
Iscritto il: lun apr 23, 2012 11:30 pm

Prossimo

Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 47 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising