Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

"value to add was out of range" Opzioni
bettab27
Inviato: Saturday, October 26, 2013 8:37:21 AM
Rank: Member

Iscritto dal : 1/20/2002
Posts: 15
Da un paio di settimane mi appare questa finestra di pop-up all'avvio di Windows: "Protected: value to add was out of range. Parameter name: value" - Mi potete aiutare a risolvere il problema? (con linguaggio semplice.. non sono granché esperta..) Grazie. Anxious
Sponsor
Inviato: Saturday, October 26, 2013 8:37:21 AM

 
miticoalex
Inviato: Saturday, October 26, 2013 12:33:26 PM

Rank: AiutAmico

Iscritto dal : 10/19/2010
Posts: 14,635
Salve! Ultimamente hai installato qualche software prima che si verificava il problema?

In tal caso, potresti iniziare ad eseguire un ripristino configurazione di sistema, riportando il PC ad una data antecedente.

Per XP leggi qui.

Se non risolvi, si potrebbe avviare il PC nella modalità avvio pulito, e verificare se il problema si ripresenta.

Per l'avvio pulito, leggi qui.

Sarebbe stato utile sapere il sistema operativo in uso.



bettab27
Inviato: Sunday, October 27, 2013 8:24:59 AM
Rank: Member

Iscritto dal : 1/20/2002
Posts: 15
Grazie miticoalex, ho seguito i tuoi consigli ma non ho risolto. Ho riprovato il ripristino (che avevo già tentato) e il mio PC dice che non si può rirpistinare a punti precedenti.. (??) poi ho fatto passo passo l'avvio pulito.. niente: la finestra di pop-up in questione permane.. Il mio sistema operativo è XP Home ed. v. 2002 service pack 3, .. e.. sì, avevo appena fatto danni installando nuovi programmini... :-( ..c'è altro che posso tentare?
miticoalex
Inviato: Sunday, October 27, 2013 12:43:36 PM

Rank: AiutAmico

Iscritto dal : 10/19/2010
Posts: 14,635
bettab27 ha scritto:
Ho riprovato il ripristino (che avevo già tentato) e il mio PC dice che non si può rirpistinare a punti precedenti.. (??)


Come temevo: non è andato buon fine.

Per il ripristino prova così:

Avvia il PC, premendo F8, dopodiché scegli con le frecce modalità provvisoria con prompt dei comandi,
al prompt dei comandi digitare %systemroot%\system32\restore\rstrui.exe

Scegli il punto di ripristino precedente. Dovrebbe andar bene.

Inoltre, se non risolvi, scaricati hijackthis da qui, lancialo e copia il log che rilascia qui.

Dopo scaricati malwarebytes da qui, installalo, aggiornalo ed esegui una scansione completa; copia il log che rilascia qui.

Per finire; Scaricati Adwcleaner sul desktop(per comodità)

http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner

Avvialo e clicca su "Scan".
Finita la scansione clicca su Clean.
Conferma con OK le varie finestre che ti compariranno.
Il pc si riavvierà, e salverà il log sul desktop che copierai qui.

Ciao


bettab27
Inviato: Sunday, November 03, 2013 2:09:30 PM
Rank: Member

Iscritto dal : 1/20/2002
Posts: 15
Carissimo miticoalex, (ero via qualche giorno) eccomi qua..
1) Avvia il PC, premendo F8, dopodiché scegli con le frecce modalità provvisoria con prompt dei comandi,
al prompt dei comandi digitare %systemroot%\system32\restore\rstrui.exe

>>>non sono riuscita a farlo

2) scaricati hijackthis da qui, lancialo e copia il log che rilascia qui.
>>>>fatto, ecco il log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9.40.20, on 03/11/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.21357)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2014\avgrsx.exe
C:\Programmi\AVG\AVG2014\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe
C:\Programmi\AVG\AVG2014\avgidsagent.exe
C:\Programmi\AVG\AVG2014\avgwdsvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\Programmi\AVG\AVG2014\avgui.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\Programmi\Java\jre7\bin\jqs.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\AVG\AVG2014\avgnsx.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\AVG\AVG2014\avgemcx.exe
C:\Programmi\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programmi\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=70474&tid=8094&ver=4.9&ts=1381528800000.000009&tguid=70474-8094-1381589695297-68E74A1B712E840C2C677E0C07A1B0F2&st=chrome&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=70474&tid=8094&ver=4.9&ts=1381528800000.000009&tguid=70474-8094-1381589695297-68E74A1B712E840C2C677E0C07A1B0F2&st=chrome&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=70474&tid=8094&ver=4.9&ts=1381528800000.000009&tguid=70474-8094-1381589695297-68E74A1B712E840C2C677E0C07A1B0F2&st=chrome&q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=70474&tid=8094&ver=4.9&ts=1381528800000.000009&tguid=70474-8094-1381589695297-68E74A1B712E840C2C677E0C07A1B0F2&st=chrome&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=70474&tid=8094&ver=4.9&ts=1381528800000.000009&tguid=70474-8094-1381589695297-68E74A1B712E840C2C677E0C07A1B0F2&st=chrome&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=70474&tid=8094&ver=4.9&ts=1381528800000.000009&tguid=70474-8094-1381589695297-68E74A1B712E840C2C677E0C07A1B0F2&st=chrome&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=70474&tid=8094&ver=4.9&ts=1381528800000.000009&tguid=70474-8094-1381589695297-68E74A1B712E840C2C677E0C07A1B0F2&st=chrome&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=70474&tid=8094&ver=4.9&ts=1381528800000.000009&tguid=70474-8094-1381589695297-68E74A1B712E840C2C677E0C07A1B0F2&st=chrome&q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG2012\avgssie.dll (file missing)
O2 - BHO: HomeTab - {47c2cd1b-8f48-4b52-a018-1baefdf41b7d} - C:\Documents and Settings\Bonino\Dati applicazioni\HomeTab\HomeTab.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Programmi\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll
O2 - BHO: DVDVideoSoftTB - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programmi\DVDVideoSoftTB\prxtbDVD2.dll
O2 - BHO: searchgol Helper Object - {8F547BDD-FCD4-48F8-A06F-573D6F404A3C} - C:\Programmi\searchgol\searchgol\1.8.16.19\bh\searchgol.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Programmi\AVG Secure Search\17.0.1.12\AVG Secure Search_toolbar.dll
O2 - BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Programmi\Delta\delta\1.8.24.6\bh\delta.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre7\bin\jp2ssv.dll
O2 - BHO: DVDVideoSoft.WebPageAdjuster - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Programmi\File comuni\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programmi\DVDVideoSoftTB\prxtbDVD2.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Programmi\AVG Secure Search\17.0.1.12\AVG Secure Search_toolbar.dll
O3 - Toolbar: Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Programmi\Delta\delta\1.8.24.6\deltaTlbr.dll
O3 - Toolbar: searchgol Toolbar - {00078E95-3A4A-4137-8DE7-2824908D1C17} - C:\Programmi\searchgol\searchgol\1.8.16.19\searchgolTlbr.dll
O3 - Toolbar: HomeTab - {47c2cd1b-8f48-4b52-a018-1baefdf41b7d} - C:\Documents and Settings\Bonino\Dati applicazioni\HomeTab\HomeTab.dll
O4 - HKLM\..\Run: [TrayServer] C:\Programmi\MAGIX\Video_deluxe_2008_e-version\TrayServer.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Programmi\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Programmi\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [StartCCC] C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [4Y3Y0C3AUF7W0A4WSOGGAN] C:\Recycle.Bin\B6232F3AD02.exe /q
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [NTRedirect] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\enhancedNT.dll",Run
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Programmi\File comuni\DVDVideoSoft\plugins\freeytmp3downloader.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre7\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre7\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Programmi\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Programmi\File comuni\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O9 - Extra 'Tools' menuitem: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Programmi\File comuni\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Programmi\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG2012\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Programmi\File comuni\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Programmi\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG2014\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmi\Canon\CAL\CALMAIN.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Programmi\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Servizio di Google Update (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Programmi\Java\jre7\bin\jqs.exe
O23 - Service: LiveUpSC - SoftwareUpdService - C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\SoftwareUpdater\SoftwareUpdService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Programmi\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Programmi\Skype\Updater\Updater.exe
O23 - Service: Ssupd Service (SsupdService) - SsupdService - C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\ssupd\ssupd.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 14236 bytes


3) scaricati malwarebytes da qui, installalo, aggiornalo ed esegui una scansione completa; copia il log che rilascia qui.
>>>>> fatto, ecco il log:


Malwarebytes Anti-Malware (Prova) 1.75.0.1300
www.malwarebytes.org

Versione database: v2013.11.03.01

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
Bonino :: BONINO-D0B20D3F [amministratore]

Protezione: Attivata

03/11/2013 10.16.28
MBAM-log-2013-11-03 (11-57-26).txt

Tipo di scansione: Scansione completa (C:\|E:\|)
Opzioni di scansione attive: Memoria | Esecuzione automatica | Registro | File di sistema | Euristica/Extra | Euristica/Shuriken | PUP | PUM
Opzioni di scansione disattivate: P2P
Elementi esaminati: 409899
Tempo impiegato: 1 ore, 39 minuti, 41 secondi

Processi rilevati in memoria: 0
(non sono stati rilevati elementi nocivi)

Moduli di memoria rilevati: 2
C:\Documents and Settings\Bonino\Dati applicazioni\HomeTab\HomeTab.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\enhancedNT.dll (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.

Chiavi di registro rilevate: 88
HKCR\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\delta.deltaHlpr.1 (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\delta.deltaHlpr (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKCR\CLSID\{00078E95-3A4A-4137-8DE7-2824908D1C17} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\searchgol.searchgoldskBnd.1 (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\searchgol.searchgoldskBnd (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00078E95-3A4A-4137-8DE7-2824908D1C17} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00078E95-3A4A-4137-8DE7-2824908D1C17} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\esrv.deltaESrvc.1 (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\esrv.deltaESrvc (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Nessuna azione intrapresa.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Nessuna azione intrapresa.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Nessuna azione intrapresa.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Nessuna azione intrapresa.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Nessuna azione intrapresa.
HKCR\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKCR\delta.deltadskBnd.1 (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKCR\delta.deltadskBnd (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKCR\CLSID\{840A13FF-B464-4782-9C96-AAF3092E55DD} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\TypeLib\{88AF4F6A-C6B7-4229-9275-824E98BF97F9} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\esrv.searchgolESrvc.1 (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\esrv.searchgolESrvc (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\CLSID\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\searchgol.searchgolHlpr.1 (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\searchgol.searchgolHlpr (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\Typelib\{105F25A9-C42F-48A6-998D-0494E8AE336A} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\Interface\{3860D897-7DCD-473C-9744-B21DB133AB20} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\Typelib\{4599D05A-D545-4069-BB42-5895B4EAE05B} (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKCR\Interface\{1231839B-064E-4788-B865-465A1B5266FD} (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70C6E9DE-F30E-4A40-8A6F-9572C2328320} (PUP.FCTPlugin) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} (PUP.Optional.Iminent.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} (PUP.Optional.Iminent.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
HKCR\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\delta.deltaappCore.1 (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\delta.deltaappCore (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKCR\d (PUP.Optional.Delta) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0626df74-01ec-4afa-977e-86f291b4a82f}_is1 (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCR\CLSID\{2623b6f0-f532-46d1-89a2-3ea1be21549d} (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCR\TypeLib\{bd0a73d9-7bf2-4548-9f27-ef3a457d25e3} (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCR\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687} (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCR\wtb.NotificationSource.1 (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCR\wtb.NotificationSource (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCR\CLSID\{47c2cd1b-8f48-4b52-a018-1baefdf41b7d} (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCR\wtb.Band.1 (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCR\wtb.Band (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{47C2CD1B-8F48-4B52-A018-1BAEFDF41B7D} (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{47C2CD1B-8F48-4B52-A018-1BAEFDF41B7D} (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{47C2CD1B-8F48-4B52-A018-1BAEFDF41B7D} (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
HKCR\searchgol.searchgolappCore (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\searchgol.searchgolappCore.1 (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\searchgol (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\DELTA\DELTA (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKCU\Software\ConduitSearchScopes (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
HKCU\Software\DataMngr (PUP.Optional.DataMngr.A) -> Nessuna azione intrapresa.
HKCU\Software\PriceGong (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
HKCU\Software\BabSolution\Redir (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\CROSSRIDER (PUP.Optional.CrossRider.A) -> Nessuna azione intrapresa.
HKCU\SOFTWARE\DELTA\DELTA\IESTRG (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\searchgol (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Delta\delta\Instl (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Google\Chrome\Extensions\aipfmkinhleccnodemkoofnnofpbbpac (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl (PUP.FCTPlugin) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\delta (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\searchgol (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\CLSID\{539F74BF-7E5C-46BD-9D45-35B1A91C9CBD} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\CLSID\{9448AC19-EB62-46D5-B7DA-B059A7DB466A} (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
HKCR\s (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.

Valori di registro rilevati: 11
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{00078E95-3A4A-4137-8DE7-2824908D1C17} (PUP.Optional.SearchGolTB.A) -> Dati: searchgol Toolbar -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Dati: Delta Toolbar -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Dati: -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{00078E95-3A4A-4137-8DE7-2824908D1C17} (PUP.Optional.SearchGolTB.A) -> Dati: -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{47C2CD1B-8F48-4B52-A018-1BAEFDF41B7D} (PUP.Optional.HomeTab.A) -> Dati: -> Nessuna azione intrapresa.
HKCU\SOFTWARE\Delta\Delta|tlbrSrchUrl (PUP.Optional.Delta.A) -> Dati: -> Nessuna azione intrapresa.
HKCU\Software\Crossrider|Verifier (PUP.Optional.CrossRider.A) -> Dati: d35eda84adb90877d5bd760cad73de0d -> Nessuna azione intrapresa.
HKCU\Software\Delta\delta|lastB (PUP.Optional.Delta.A) -> Dati: http://www1.delta-search.com/?babsrc=HP_ss&mntrId=5C28001E8C864ABE&affID=123925&tsp=4983 -> Nessuna azione intrapresa.
HKCU\Software\Delta\delta\iestrg|tlbrsrchurl (PUP.Optional.Delta.A) -> Dati: -> Nessuna azione intrapresa.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run|NTRedirect (PUP.Optional.BabSolution.A) -> Dati: C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\enhancedNT.dll",Run -> Nessuna azione intrapresa.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs|bProtectTabs (PUP.Optional.BrowserProtect.A) -> Dati: http://www.searchgol.com/?babsrc=NT_ss&mntrId=5C28001E8C864ABE&affID=125036&tsp=5033 -> Nessuna azione intrapresa.

Voci rilevate nei dati di registro: 0
(non sono stati rilevati elementi nocivi)

Cartelle rilevate: 42
C:\Documents and Settings\Bonino\Dati applicazioni\SwvUpdater (PUP.Software.Updater) -> Nessuna azione intrapresa.
C:\Programmi\Object (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\chromeaddon (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\content (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\defaults (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\defaults\preferences (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\locale (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\locale\en-US (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\skin (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\Delta (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\Delta\delta (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\SimplyTech\home (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\SimplyTech\Toolbar (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\chrome (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com\chrome (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com\components (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com\plugins (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\CR (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Programmi\Delta\delta\1.8.24.6 (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Programmi\Delta\delta\1.8.24.6\bh (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\OpenCandy (PUP.Optional.OpenCandy) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\OpenCandy\2A59009BA9864844A98CB07E0D09AA72 (PUP.Optional.OpenCandy) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\OpenCandy\61C961080B71420DA8CDA963609D69FB (PUP.Optional.OpenCandy) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\OpenCandy\8BC26A301E2F41E28D5020EE6184103D (PUP.Optional.OpenCandy) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\mt_ffx\Delta (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\mt_ffx\Delta\delta (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\mt_ffx\Delta\delta\1.8.24.6 (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\ct2269050 (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\ct2269050\xpi (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol\1.8.16.19 (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol\1.8.16.19\bh (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\mt_ffx\searchgol (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\mt_ffx\searchgol\searchgol (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\mt_ffx\searchgol\searchgol\1.8.16.19 (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.

File rilevati: 206
C:\Programmi\Delta\delta\1.8.24.6\bh\delta.dll (PUP.Optional.Delta) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol\1.8.16.19\searchgolTlbr.dll (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Programmi\Delta\delta\1.8.24.6\deltasrv.exe (PUP.Optional.Delta) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\SwvUpdater\Updater.exe (PUP.Software.Updater) -> Nessuna azione intrapresa.
C:\Programmi\Delta\delta\1.8.24.6\deltaTlbr.dll (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol\1.8.16.19\searchgolsrv.exe (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol\1.8.16.19\bh\searchgol.dll (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\BabMaint.exe (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\OpenCandy\2A59009BA9864844A98CB07E0D09AA72\SearchGolTB.exe (PUP.Optional.PCFixSpeed.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\Updater.exe (PUP.Optional.Amonetize) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\FVOtNgCk.exe.part (PUP.Optional.OneClickDownloader.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\E9Pk5bZ+.exe.part (PUP.Optional.Somoto) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\tbu19A.exe (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\tbu928.exe (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\tbu929.exe (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\wOyvKkvn.exe.part (PUP.Optional.BundleInstaller.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\X45YAlHD.exe.part (PUP.Optional.Installrex) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\XAmE_QxO.exe.part (PUP.Optional.OneClickDownloader.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\_M+JaA6C.exe.part (PUP.Optional.Somoto) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\OfferBoxSetup.exe (PUP.Optional.OfferBox.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\mPH+29UF.exe.part (PUP.Optional.BundleInstaller.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\3Z1d83QU.exe.part (PUP.Optional.InstalleRex) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\NKDCKDE3.exe.part (PUP.Optional.Installrex) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\rSAg8OUv.exe.part (PUP.Optional.Somoto) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\8EV3a5JA.exe.part (PUP.Optional.Somoto) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\jXgXEn52.exe.part (PUP.Optional.InstalleRex) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus30\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus890\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\busE9\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\4666F3B2-BAB0-7891-8F70-B34A9B506DCC\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\4666F3B2-BAB0-7891-8F70-B34A9B506DCC\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\4666F3B2-BAB0-7891-8F70-B34A9B506DCC\Latest\ccp.exe (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\4666F3B2-BAB0-7891-8F70-B34A9B506DCC\Latest\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\4666F3B2-BAB0-7891-8F70-B34A9B506DCC\Latest\MntrDLLInstall.dll (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\4666F3B2-BAB0-7891-8F70-B34A9B506DCC\Latest\MySgolTB.exe (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\4666F3B2-BAB0-7891-8F70-B34A9B506DCC\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\294737C5-BAB0-7891-B78A-EDC0203CEC60\BabMaint.exe (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\294737C5-BAB0-7891-B78A-EDC0203CEC60\BUSolution.dll (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\294737C5-BAB0-7891-B78A-EDC0203CEC60\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\294737C5-BAB0-7891-B78A-EDC0203CEC60\MntrDLLInstall.dll (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\294737C5-BAB0-7891-B78A-EDC0203CEC60\MyDeltaTB.exe (PUP.Optional.Delta) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus128\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus148\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus16\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus167\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus19\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus1AE\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus2\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus3\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus894\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus895\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus896\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus897\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus898\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus8A4\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus902\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus939\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus9A\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\busBA\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\busBE\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\busCC\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\busD1\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\busD2\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\busF8\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\busFA\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus36\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus390\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus3B\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus3F\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus4C\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus5\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus59\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus88A\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\bus88B\CrxUpdater_d.exe (PUP.Optional.CRX.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temporary Internet Files\Content.IE5\3AYH8B8E\IminentMinibarIE[1].exe (PUP.Optional.Iminent.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temporary Internet Files\Content.IE5\3AYH8B8E\setup__1925[1].exe (PUP.Optional.Amonetize.AS) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temporary Internet Files\Content.IE5\3AYH8B8E\DeltaTB[1].exe (PUP.Optional.DeltaTB) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temporary Internet Files\Content.IE5\AEYUBCLD\HomeTab[1].exe (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temporary Internet Files\Content.IE5\AEYUBCLD\SearchGolTB[1].exe (PUP.Optional.PCFixSpeed.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temporary Internet Files\Content.IE5\AEYUBCLD\MinibarFirefox[1].exe (PUP.Optional.Iminent.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temporary Internet Files\Content.IE5\JHAR1OCB\MinibarChrome[1].exe (PUP.Optional.Iminent.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temporary Internet Files\Content.IE5\N2WY6A5D\iminent[1].msi (PUP.Optional.Iminent) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol\1.8.16.19\uninstall.exe (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\STInst32.exe (Trojan.MSIL) -> Nessuna azione intrapresa.
C:\Programmi\Delta\delta\1.8.24.6\deltaApp.dll (PUP.Optional.Delta) -> Nessuna azione intrapresa.
C:\Programmi\Delta\delta\1.8.24.6\deltaEng.dll (PUP.Optional.Delta) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{A2C0FB43-7E24-4CF6-9C14-67F6DB45DD9E}\RP4\A0000364.exe (Trojan.MSIL) -> Nessuna azione intrapresa.
C:\System Volume Information\_restore{A2C0FB43-7E24-4CF6-9C14-67F6DB45DD9E}\RP4\A0000366.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
E:\Programmi scaricati\Sonic Foundry Sound Forge v6.0 MP3 Plugin Crack\damn_MP3Plugin_kg.exe (Trojan.Agent.CK) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\SwvUpdater\Updater.xml (PUP.Software.Updater) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\SwvUpdater\status.cfg (PUP.Software.Updater) -> Nessuna azione intrapresa.
C:\WINDOWS\Tasks\AmiUpdXp.job (PUP.Software.Updater) -> Nessuna azione intrapresa.
C:\Programmi\Object\status.txt (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\ChromeAddon.pem (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\config.ini (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\status2.txt (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\chromeaddon\._included.js (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\chromeaddon\background.html (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\chromeaddon\included.js (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\chromeaddon\manifest.json (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\build.sh (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\chrome.manifest (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\config_build.sh (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\files (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\install.rdf (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\readme.txt (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\content\.DS_Store (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\content\firefoxOverlay.xul (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\content\installid.js (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\content\overlay.js (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\content\sudoku.js (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\defaults\.DS_Store (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\defaults\preferences\.DS_Store (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\defaults\preferences\._sudoku.js (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\defaults\preferences\sudoku.js (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\locale\.DS_Store (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\locale\en-US\.DS_Store (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\locale\en-US\sudoku.dtd (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\locale\en-US\sudoku.properties (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\Programmi\Object\facetheme\skin\overlay.css (PUP.FCTPlugin) -> Nessuna azione intrapresa.
C:\WINDOWS\Tasks\EPUpdater.job (PUP.Optional.Babylon.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\Delta\sqlite3.dll (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\SimplyTech\home\home.htm (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\SimplyTech\home\jquery-ui-1.10.1.custom.min.js (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\SimplyTech\home\jquiso.js (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\SimplyTech\home\style.css (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\SimplyTech\home\vars.js (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\SimplyTech\Toolbar\settings.dat (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\Microsoft.Win32.TaskScheduler.xml (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\cinshlpr.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\hometab_icon.ico (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\InstallHelper.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\Interop.IWshRuntimeLibrary.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\Microsoft.Win32.TaskScheduler.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\ProtectedSearch.exe (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\ProtectedSearch.ico (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\STInst32.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\STInst32.exe (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\System.Data.SQLite.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\TaskSchedulerCreator.exe (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\TBUpdater.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\ToolbarUninstall.exe (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\unins000.dat (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\unins000.exe (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\chrome\HomeTab.crx (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com\chrome.manifest (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com\install.js (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com\install.rdf (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com\pop.htm (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com\chrome\HomeTab_8094.jar (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com\components\wtb_complete.js (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Programmi\HomeTab\support@HomeTab.com\plugins\npwiddit.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\WINDOWS\Tasks\Protected Search.job (PUP.Optional.ProtectedSearch.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage (PUP.Optional.BrowserDefender.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\HomeTab\HomeTab.dll (PUP.Optional.HomeTab.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\enhancedNT.dll (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\CR\Delta.crx (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\CR\searchgol.crx (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\BUSolution.dll (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\chu.js (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\Delta.ico (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\GUninstaller.exe (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\searchgol.ico (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\SetupParams.ini (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution\Shared\sqlite3.dll (PUP.Optional.BabSolution.A) -> Nessuna azione intrapresa.
C:\Programmi\Delta\delta\1.8.24.6\GUninstaller.exe (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Programmi\Delta\delta\1.8.24.6\uninstall.exe (PUP.Optional.Delta.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\1.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\a.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\b.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\c.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\d.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\e.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\f.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\g.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\h.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\i.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\J.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\k.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\l.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\m.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\n.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\o.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\p.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\q.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\r.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\s.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\t.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\u.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\v.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\w.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\x.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\y.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong\Data\z.xml (PUP.Optional.PriceGong.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\OpenCandy\61C961080B71420DA8CDA963609D69FB\TuneUpUtilities2012_it-IT.exe (PUP.Optional.OpenCandy) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Dati applicazioni\OpenCandy\8BC26A301E2F41E28D5020EE6184103D\Install_BubbleDock.exe (PUP.Optional.OpenCandy) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\ct2269050\CT2269050.xpi (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\ct2269050\ffLogic.exe (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\ct2269050\ieLogic.exe (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\ct2269050\statisticsStub.exe (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\ct2269050\version.txt (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
C:\Documents and Settings\Bonino\Impostazioni locali\Temp\ct2269050\xpi\install.rdf (PUP.Optional.Conduit.A) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol\1.8.16.19\escortShld.dll (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol\1.8.16.19\GUninstaller.exe (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol\1.8.16.19\searchgolApp.dll (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.
C:\Programmi\searchgol\searchgol\1.8.16.19\searchgolEng.dll (PUP.Optional.SearchGolTB.A) -> Nessuna azione intrapresa.

(fine)

4) fatto tutto ma finora la famigerata finestra in oggetto permane..

Per finire; Scaricati Adwcleaner sul desktop(per comodità)
Avvialo e clicca su "Scan".
Finita la scansione clicca su Clean.
Conferma con OK le varie finestre che ti compariranno.
Il pc si riavvierà, e salverà il log sul desktop che copierai qui.

fatto, ecco il log:


# AdwCleaner v3.010 - Report created 03/11/2013 at 12:20:53
# Updated 20/10/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Bonino - BONINO-D0B20D3F
# Running from : C:\Documents and Settings\Bonino\Documenti\Download\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : APNMCP
[#] Service Deleted : vToolbarUpdater17.0.12

***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Dati applicazioni\apn
Folder Deleted : C:\Documents and Settings\All Users\Dati applicazioni\AskPartnerNetwork
Folder Deleted : C:\Documents and Settings\All Users\Dati applicazioni\AVG Secure Search
Folder Deleted : C:\Documents and Settings\All Users\Dati applicazioni\AVG Security Toolbar
Folder Deleted : C:\Documents and Settings\All Users\Dati applicazioni\Babylon
Folder Deleted : C:\Documents and Settings\All Users\Dati applicazioni\ParetoLogic
Folder Deleted : C:\Programmi\AskBarDis
Folder Deleted : C:\Programmi\AskPartnerNetwork
Folder Deleted : C:\Programmi\AVG Secure Search
Folder Deleted : C:\Programmi\Conduit
Folder Deleted : C:\Programmi\Delta
Folder Deleted : C:\Programmi\DVDVideoSoftTB
Folder Deleted : C:\Programmi\HomeTab
Folder Deleted : C:\Programmi\Iminent
Folder Deleted : C:\Programmi\Nosibay
Folder Deleted : C:\Programmi\Object
Folder Deleted : C:\Programmi\searchgol
Folder Deleted : C:\Programmi\Softonic-IT
Folder Deleted : C:\Programmi\File comuni\AVG Secure Search
Folder Deleted : C:\Programmi\File comuni\DVDVideoSoft\TB
Folder Deleted : C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\DVDVideoSoftTB
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\AVG Secure Search
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\AVG Security Toolbar
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\Conduit
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\ConduitEngine
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\DVDVideoSoftTB
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\HomeTab
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\lollipop
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\SimplyTech
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\SoftwareUpdater
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\Softonic-IT
Folder Deleted : C:\DOCUME~1\Bonino\IMPOST~1\Temp\apn
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\AVG Secure Search
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\BabSolution
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Delta
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\DriverCure
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\dvdvideosoftiehelpers
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\freeTVRadio
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\HomeTab
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Nosibay
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\OfferBox
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\OpenCandy
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\ParetoLogic
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\PriceGong
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\searchgol
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\SimplyTech
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\SwvUpdater
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\Solo_562533\Smartbar
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\Smartbar
File Deleted : C:\END
File Deleted : C:\WINDOWS\system32\conduitEngine.tmp
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\Solo_562533\bProtector_extensions.rdf
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\bProtector_extensions.rdf
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\Solo_562533\invalidprefs.js
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\invalidprefs.js
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\Solo_562533\searchplugins\ask-search.xml
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\searchplugins\ask-search.xml
File Deleted : C:\Programmi\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\Solo_562533\searchplugins\dvdvideosofttb-customized-web-search.xml
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\searchplugins\dvdvideosofttb-customized-web-search.xml
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\Solo_562533\searchplugins\searchgol.xml
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\searchplugins\searchgol.xml
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\Solo_562533\searchplugins\Web Search.xml
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\searchplugins\Web Search.xml
File Deleted : C:\Programmi\Mozilla Firefox\searchplugins\Web Search.xml
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\Solo_562533\user.js
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\user.js
File Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage
File Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
File Deleted : C:\WINDOWS\Tasks\AmiUpdXp.job
File Deleted : C:\WINDOWS\Tasks\Browser Updater.job
File Deleted : C:\WINDOWS\Tasks\EPUpdater.job
File Deleted : C:\WINDOWS\Tasks\Protected Search.job

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aipfmkinhleccnodemkoofnnofpbbpac
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NTRedirect]
Key Deleted : HKCU\Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\HomeTab.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore
Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Key Deleted : HKLM\SOFTWARE\Classes\delta.deltadskBnd
Key Deleted : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1
Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaHlpr
Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.deltaESrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.searchgolESrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.searchgolESrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgolappCore
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgolappCore.1
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgoldskBnd
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgoldskBnd.1
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgolHlpr
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgolHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.Band
Key Deleted : HKLM\SOFTWARE\Classes\wtb.Band.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.NotificationSource
Key Deleted : HKLM\SOFTWARE\Classes\wtb.NotificationSource.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl
Key Deleted : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl.1
Key Deleted : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo
Key Deleted : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Babylon.exe
Key Deleted : HKCU\Software\5e55dcd1b33cee47
Key Deleted : HKLM\SOFTWARE\5e55dcd1b33cee47
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2530241
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4277F7CF-0000-46CF-BA49-D624465C4BAB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{88AF4F6A-C6B7-4229-9275-824E98BF97F9}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00078E95-3A4A-4137-8DE7-2824908D1C17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0702A2B6-13AA-4090-9E01-BCDC85DD933F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{539F74BF-7E5C-46BD-9D45-35B1A91C9CBD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{571715D7-3395-4DF0-B43C-784836209E60}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{622FD888-4E91-4D68-84D4-7262FD0811BF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{840A13FF-B464-4782-9C96-AAF3092E55DD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9448AC19-EB62-46D5-B7DA-B059A7DB466A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B0DE3308-5D5A-470D-81B9-634FC078393B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{471B163C-D832-47CF-87B9-70EC803DA402}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E3393495-8103-46A0-8181-270273EDDD60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3860D897-7DCD-473C-9744-B21DB133AB20}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4634804A-F0B0-4A74-A550-FC0EEF8A4362}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4C07EA4F-5F52-4222-B170-4CD9ED33BAEA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C44FEFF4-EF0C-4CF7-83D0-92B4266A32B9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F131923C-381D-4E4C-A472-4A17118FD742}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{105F25A9-C42F-48A6-998D-0494E8AE336A}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{88AF4F6A-C6B7-4229-9275-824E98BF97F9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D2E5FA06-DCC7-46F9-BEFF-BFD06F69B9B2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00078E95-3A4A-4137-8DE7-2824908D1C17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{23AF19F7-1D5B-442C-B14C-3D1081953C94}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00078E95-3A4A-4137-8DE7-2824908D1C17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{471B163C-D832-47CF-87B9-70EC803DA402}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C5CBB76-7379-4490-AA5B-B037C0A36381}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A02F9AEA-1DF7-41B6-9DC4-790E0213C303}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DACB1BD6-5EB4-4E7F-B77B-9DB315A9694C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{814F3B5C-0837-40B2-84EA-6EE8AA5188F8}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{00078E95-3A4A-4137-8DE7-2824908D1C17}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CCC7A320-B3CA-4199-B1A6-9F516DD69829}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CCC7A320-B3CA-4199-B1A6-9F516DD69829}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Programmi\HomeTab\ProtectedSearch.exe]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Programmi\HomeTab\TBUpdater.dll]
Key Deleted : HKCU\Software\AskBarDis
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\Babylon
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\Crossrider
Key Deleted : HKCU\Software\DataMngr
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\DVDVideoSoftTB
Key Deleted : HKCU\Software\freeTVRadio
Key Deleted : HKCU\Software\HomeTab
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\InstalledThirdPartyPrograms
Key Deleted : HKCU\Software\lollipop
Key Deleted : HKCU\Software\Nosibay
Key Deleted : HKCU\Software\Offerbox
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\PriceGong
Key Deleted : HKCU\Software\Searchgol
Key Deleted : HKCU\Software\simplytech
Key Deleted : HKCU\Software\smartbar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\Softonic-IT
Key Deleted : HKCU\Software\AppDataLow\AskBarDis
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\simplytech
Key Deleted : HKLM\Software\AskPartnerNetwork
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Delta
Key Deleted : HKLM\Software\DVDVideoSoftTB
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\InstalledThirdPartyPrograms
Key Deleted : HKLM\Software\Offerbox
Key Deleted : HKLM\Software\ParetoLogic
Key Deleted : HKLM\Software\Searchgol
Key Deleted : HKLM\Software\Softonic-IT
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ask Toolbar_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search-Gol Chrome Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchgol
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDVideoSoftTB Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic-IT Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ask Toolbar_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta Chrome Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\facemoods
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Search-Gol Chrome Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Searchgol
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DVDVideoSoftTB Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Softonic-IT Toolbar
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375

***** [ Browsers ] *****

-\\ Internet Explorer v7.0.6000.21357

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]

-\\ Mozilla Firefox v24.0 (it)

[ File : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\Solo_562533\prefs.js ]

Line Deleted : user_pref("CT2269050.1000082.isDisplayHidden", "true");
Line Deleted : user_pref("CT2269050.1000082.state", "{\"state\":\"stopped\",\"text\":\"Hotmix 108\",\"description\":\"Hotmix 108\",\"url\":\"hxxp://67.202.67.18:8082\"}");
Line Deleted : user_pref("CT2269050.1000234.TWC_TMP_city", "ROMA");
Line Deleted : user_pref("CT2269050.1000234.TWC_TMP_country", "IT");
Line Deleted : user_pref("CT2269050.1000234.TWC_locId", "ROXX0330");
Line Deleted : user_pref("CT2269050.1000234.TWC_location", "Roma, Romania");
Line Deleted : user_pref("CT2269050.1000234.TWC_region", "OT");
Line Deleted : user_pref("CT2269050.1000234.TWC_temp_dis", "c");
Line Deleted : user_pref("CT2269050.1000234.TWC_wind_dis", "kmh");
Line Deleted : user_pref("CT2269050.1000234.weatherData", "{\"icon\":\"20.png\",\"temperature\":\"11°C\",\"temperatureClear\":\"11°C\",\"highTemperature\":\"11°C\",\"lowTemperature\":\"8°C\",\"feelsLike\[...]
Line Deleted : user_pref("CT2269050.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.FirstTime", "true");
Line Deleted : user_pref("CT2269050.FirstTimeFF3", "true");
Line Deleted : user_pref("CT2269050.LoginRevertSettingsEnabled", true);
Line Deleted : user_pref("CT2269050.RevertSettingsEnabled", true);
Line Deleted : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=");
Line Deleted : user_pref("CT2269050.UserID", "UN94856364310450489");
Line Deleted : user_pref("CT2269050.addressBarTakeOverEnabledInHidden", "true");
Line Deleted : user_pref("CT2269050.autoDisableScopes", -1);
Line Deleted : user_pref("CT2269050.browser.search.defaultthis.engineName", true);
Line Deleted : user_pref("CT2269050.countryCode", "IT");
Line Deleted : user_pref("CT2269050.defaultSearch", "true");
Line Deleted : user_pref("CT2269050.enableAlerts", "false");
Line Deleted : user_pref("CT2269050.enableFix404ByUser", "TRUE");
Line Deleted : user_pref("CT2269050.enableSearchFromAddressBar", "true");
Line Deleted : user_pref("CT2269050.firstTimeDialogOpened", "true");
Line Deleted : user_pref("CT2269050.fixPageNotFoundError", "true");
Line Deleted : user_pref("CT2269050.fixPageNotFoundErrorByUser", "true");
Line Deleted : user_pref("CT2269050.fixPageNotFoundErrorInHidden", "true");
Line Deleted : user_pref("CT2269050.fixUrls", true);
Line Deleted : user_pref("CT2269050.fullUserID", "UN94856364310450489.UP.20130623195813");
Line Deleted : user_pref("CT2269050.homepageuserchanged", true);
Line Deleted : user_pref("CT2269050.installId", "ConduitNSISIntegration");
Line Deleted : user_pref("CT2269050.installType", "ConduitNSISIntegration");
Line Deleted : user_pref("CT2269050.isCheckedStartAsHidden", true);
Line Deleted : user_pref("CT2269050.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.isFirstTimeToolbarLoading", "false");
Line Deleted : user_pref("CT2269050.isNewTabEnabled", true);
Line Deleted : user_pref("CT2269050.isPerformedSmartBarTransition", "true");
Line Deleted : user_pref("CT2269050.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT2269050.keyword", true);
Line Deleted : user_pref("CT2269050.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT2269050&octid=CT2269050&SearchSource=15&CUI=UN94856364310450489&SSPV=&Lay=1&UM=false\"}[...]
Line Deleted : user_pref("CT2269050.lastVersion", "10.20.1.508");
Line Deleted : user_pref("CT2269050.migrateAppsAndComponents", true);
Line Deleted : user_pref("CT2269050.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.vodafone.it%2F190%2Ffsms%2Fsend.do\",\"EB_MAIN_FRAME_TITLE\":\"Vodafone\",\"EB_TOOLBAR_S[...]
Line Deleted : user_pref("CT2269050.openThankYouPage", "false");
Line Deleted : user_pref("CT2269050.openUninstallPage", "true");
Line Deleted : user_pref("CT2269050.originalSearchAddressUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&CUI=UN94856364310450489&UM=&q=");
Line Deleted : user_pref("CT2269050.search.searchAppId", "128834881989343895");
Line Deleted : user_pref("CT2269050.search.searchCount", "0");
Line Deleted : user_pref("CT2269050.searchInNewTabEnabledByUser", "true");
Line Deleted : user_pref("CT2269050.searchInNewTabEnabledInHidden", "true");
Line Deleted : user_pref("CT2269050.searchSuggestEnabledByUser", "true");
Line Deleted : user_pref("CT2269050.searchUserMode", "false");
Line Deleted : user_pref("CT2269050.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2269050\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://DVDVideoSoftTB.OurToolbar.com//xpi\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"DVDVideoSoftTB \"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_services_Configuration_lastUpdate", "1380533289845");
Line Deleted : user_pref("CT2269050.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1350054580573");
Line Deleted : user_pref("CT2269050.serviceLayer_services_appsMetadata_lastUpdate", "1350114859125");
Line Deleted : user_pref("CT2269050.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1349167404493");
Line Deleted : user_pref("CT2269050.serviceLayer_services_location_lastUpdate", "1371982281568");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.13.1.89_lastUpdate", "1352793653339");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.13.40.15_lastUpdate", "1358434424972");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.14.42.7_lastUpdate", "1360656507377");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.14.65.43_lastUpdate", "1363888387396");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.15.0.562_lastUpdate", "1364114642453");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.15.2.523_lastUpdate", "1367942439743");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.16.1.521_lastUpdate", "1368513095042");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.16.2.509_lastUpdate", "1371996682292");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.16.4.519_lastUpdate", "1374497523635");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.16.70.505_lastUpdate", "1377255954917");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.19.2.505_lastUpdate", "1378621066886");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.20.0.513_lastUpdate", "1379952968327");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.20.1.508_lastUpdate", "1380568611978");
Line Deleted : user_pref("CT2269050.serviceLayer_services_optimizer_lastUpdate", "1350137671577");
Line Deleted : user_pref("CT2269050.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1349167410692");
Line Deleted : user_pref("CT2269050.serviceLayer_services_searchAPI_lastUpdate", "1380533290146");
Line Deleted : user_pref("CT2269050.serviceLayer_services_serviceMap_lastUpdate", "1380533289435");
Line Deleted : user_pref("CT2269050.serviceLayer_services_toolbarContextMenu_lastUpdate", "1349167410635");
Line Deleted : user_pref("CT2269050.serviceLayer_services_toolbarSettings_lastUpdate", "1380568611812");
Line Deleted : user_pref("CT2269050.serviceLayer_services_translation_lastUpdate", "1380533289338");
Line Deleted : user_pref("CT2269050.settingsINI", true);
Line Deleted : user_pref("CT2269050.shouldFirstTimeDialog", "false");
Line Deleted : user_pref("CT2269050.showToolbarPermission", "false");
Line Deleted : user_pref("CT2269050.smartbar.CTID", "CT2269050");
Line Deleted : user_pref("CT2269050.smartbar.Uninstall", "0");
Line Deleted : user_pref("CT2269050.smartbar.homepage", true);
Line Deleted : user_pref("CT2269050.smartbar.isHidden", true);
Line Deleted : user_pref("CT2269050.smartbar.toolbarName", "DVDVideoSoftTB ");
Line Deleted : user_pref("CT2269050.toolbarBornServerTime", "2-10-2012");
Line Deleted : user_pref("CT2269050.toolbarCurrentServerTime", "30-9-2013");
Line Deleted : user_pref("CT2269050.toolbarLoginClientTime", "Fri Mar 22 2013 08:46:55 GMT+0100 (ora solare Europa occidentale)");
Line Deleted : user_pref("CT2269050_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1380609622405,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("avg.install.installDirPath", "C:\\Documents and Settings\\All Users\\Dati applicazioni\\AVG Secure Search\\10.2.0.3");
Line Deleted : user_pref("avg.install.userHPSettings", "hxxp://start.facemoods.com/?a=grupo");
Line Deleted : user_pref("avg.install.userSPSettings", "Facemoods Search");
Line Deleted : user_pref("browser.search.defaultengine", "Web Search");
Line Deleted : user_pref("browser.search.defaultenginename", "Web Search");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "DVDVideoSoftTB Customized Web Search");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}");
Line Deleted : user_pref("browser.search.order.1", "Web Search");
Line Deleted : user_pref("browser.search.selectedEngine", "Web Search");
Line Deleted : user_pref("extensions.APN_TB.first-previous-keyword-url", "hxxp://search.conduit.com/ResultsExt.aspx?octid=CT2269050&ctid=CT2269050&SearchSource=2&CUI=UN94856364310450489&UM=false&q=");
Line Deleted : user_pref("extensions.crossrider.bic", "140ab6a7a99ed221c6cd15c2c459d637");
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.dfltLng", "it");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.id", "5c287026000000000000001e8c864abe");
Line Deleted : user_pref("extensions.delta.instlDay", "15940");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.24.6");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.24.615:41:58");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.24.6");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=123925&tsp=4983");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");
Line Deleted : user_pref("extensions.engine@conduit.com.install-event-fired", true);
Line Deleted : user_pref("extensions.facemoods._xpiupdate", true);
Line Deleted : user_pref("extensions.facemoods.aflt", "_#grupo");
Line Deleted : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4");
Line Deleted : user_pref("extensions.facemoods.firstRun", false);
Line Deleted : user_pref("extensions.facemoods.first_time", false);
Line Deleted : user_pref("extensions.facemoods.id", "_#560a10f825eb4da68cc7093790a8efc9");
Line Deleted : user_pref("extensions.facemoods.instlDay", "_#15204");
Line Deleted : user_pref("extensions.facemoods.lastActv", "18");
Line Deleted : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");
Line Deleted : user_pref("extensions.facemoods.sid", "_#560a10f825eb4da68cc7093790a8efc9");
Line Deleted : user_pref("extensions.facemoods.uninst", true);
Line Deleted : user_pref("extensions.facemoods.update", "_#v1.4.0");
Line Deleted : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5");
Line Deleted : user_pref("extensions.ffxtlbr@Facemoods.com.install-event-fired", true);
Line Deleted : user_pref("extensions.searchgol.admin", false);
Line Deleted : user_pref("extensions.searchgol.aflt", "babsst");
Line Deleted : user_pref("extensions.searchgol.appId", "{4277F7CF-0000-46CF-BA49-D624465C4BAB}");
Line Deleted : user_pref("extensions.searchgol.autoRvrt", "false");
Line Deleted : user_pref("extensions.searchgol.dfltLng", "it");
Line Deleted : user_pref("extensions.searchgol.excTlbr", false);
Line Deleted : user_pref("extensions.searchgol.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.searchgol.id", "5c287026000000000000001e8c864abe");
Line Deleted : user_pref("extensions.searchgol.instlDay", "15990");
Line Deleted : user_pref("extensions.searchgol.instlRef", "sst");
Line Deleted : user_pref("extensions.searchgol.newTab", false);
Line Deleted : user_pref("extensions.searchgol.prdct", "searchgol");
Line Deleted : user_pref("extensions.searchgol.prtnrId", "searchgol");
Line Deleted : user_pref("extensions.searchgol.rvrt", "false");
Line Deleted : user_pref("extensions.searchgol.smplGrp", "none");
Line Deleted : user_pref("extensions.searchgol.tlbrId", "base");
Line Deleted : user_pref("extensions.searchgol.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.searchgol.vrsn", "1.8.16.19");
Line Deleted : user_pref("extensions.searchgol.vrsnTs", "1.8.16.1916:38:11");
Line Deleted : user_pref("extensions.searchgol.vrsni", "1.8.16.19");
Line Deleted : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=70474&tid=8094&ver=4.9&ts=1381528800000.000009&tguid=70474-8094-1381589695297-68E74A1B712E840C2C677E0C07A1B0F2&st=chrome&q=");
Line Deleted : user_pref("smartbar.machineId", "DFYPLJXDWL+HIFUUAUJO//J+WGXCRECECG7EUSFSESWVL5VK/5S4EE5SQQWXUXMKK9GTCJQOO8LI8MOMU5913W");

[ File : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\prefs.js ]

Line Deleted : user_pref("CT2269050.1000082.isDisplayHidden", "true");
Line Deleted : user_pref("CT2269050.1000082.state", "{\"state\":\"stopped\",\"text\":\"Hotmix 108\",\"description\":\"Hotmix 108\",\"url\":\"hxxp://67.202.67.18:8082\"}");
Line Deleted : user_pref("CT2269050.1000234.TWC_TMP_city", "ROMA");
Line Deleted : user_pref("CT2269050.1000234.TWC_TMP_country", "IT");
Line Deleted : user_pref("CT2269050.1000234.TWC_locId", "ROXX0330");
Line Deleted : user_pref("CT2269050.1000234.TWC_location", "Roma, Romania");
Line Deleted : user_pref("CT2269050.1000234.TWC_region", "OT");
Line Deleted : user_pref("CT2269050.1000234.TWC_temp_dis", "c");
Line Deleted : user_pref("CT2269050.1000234.TWC_wind_dis", "kmh");
Line Deleted : user_pref("CT2269050.1000234.weatherData", "{\"icon\":\"20.png\",\"temperature\":\"11°C\",\"temperatureClear\":\"11°C\",\"highTemperature\":\"11°C\",\"lowTemperature\":\"8°C\",\"feelsLike\[...]
Line Deleted : user_pref("CT2269050.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.FirstTime", "true");
Line Deleted : user_pref("CT2269050.FirstTimeFF3", "true");
Line Deleted : user_pref("CT2269050.LoginRevertSettingsEnabled", true);
Line Deleted : user_pref("CT2269050.RevertSettingsEnabled", true);
Line Deleted : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=");
Line Deleted : user_pref("CT2269050.UserID", "UN94856364310450489");
Line Deleted : user_pref("CT2269050.addressBarTakeOverEnabledInHidden", "true");
Line Deleted : user_pref("CT2269050.autoDisableScopes", -1);
Line Deleted : user_pref("CT2269050.browser.search.defaultthis.engineName", true);
Line Deleted : user_pref("CT2269050.countryCode", "IT");
Line Deleted : user_pref("CT2269050.defaultSearch", "true");
Line Deleted : user_pref("CT2269050.enableAlerts", "false");
Line Deleted : user_pref("CT2269050.enableFix404ByUser", "TRUE");
Line Deleted : user_pref("CT2269050.enableSearchFromAddressBar", "true");
Line Deleted : user_pref("CT2269050.firstTimeDialogOpened", "true");
Line Deleted : user_pref("CT2269050.fixPageNotFoundError", "true");
Line Deleted : user_pref("CT2269050.fixPageNotFoundErrorByUser", "true");
Line Deleted : user_pref("CT2269050.fixPageNotFoundErrorInHidden", "true");
Line Deleted : user_pref("CT2269050.fixUrls", true);
Line Deleted : user_pref("CT2269050.fullUserID", "UN94856364310450489.UP.20130623195813");
Line Deleted : user_pref("CT2269050.homepageuserchanged", true);
Line Deleted : user_pref("CT2269050.installId", "ConduitNSISIntegration");
Line Deleted : user_pref("CT2269050.installType", "ConduitNSISIntegration");
Line Deleted : user_pref("CT2269050.isCheckedStartAsHidden", true);
Line Deleted : user_pref("CT2269050.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.isFirstTimeToolbarLoading", "false");
Line Deleted : user_pref("CT2269050.isNewTabEnabled", true);
Line Deleted : user_pref("CT2269050.isPerformedSmartBarTransition", "true");
Line Deleted : user_pref("CT2269050.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT2269050.keyword", true);
Line Deleted : user_pref("CT2269050.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT2269050&octid=CT2269050&SearchSource=15&CUI=UN94856364310450489&SSPV=&Lay=1&UM=false\"}[...]
Line Deleted : user_pref("CT2269050.lastVersion", "10.20.1.508");
Line Deleted : user_pref("CT2269050.migrateAppsAndComponents", true);
Line Deleted : user_pref("CT2269050.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.vodafone.it%2F190%2Ffsms%2Fsend.do\",\"EB_MAIN_FRAME_TITLE\":\"Vodafone\",\"EB_TOOLBAR_S[...]
Line Deleted : user_pref("CT2269050.openThankYouPage", "false");
Line Deleted : user_pref("CT2269050.openUninstallPage", "true");
Line Deleted : user_pref("CT2269050.originalSearchAddressUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&CUI=UN94856364310450489&UM=&q=");
Line Deleted : user_pref("CT2269050.search.searchAppId", "128834881989343895");
Line Deleted : user_pref("CT2269050.search.searchCount", "0");
Line Deleted : user_pref("CT2269050.searchInNewTabEnabledByUser", "true");
Line Deleted : user_pref("CT2269050.searchInNewTabEnabledInHidden", "true");
Line Deleted : user_pref("CT2269050.searchSuggestEnabledByUser", "true");
Line Deleted : user_pref("CT2269050.searchUserMode", "false");
Line Deleted : user_pref("CT2269050.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2269050\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://DVDVideoSoftTB.OurToolbar.com//xpi\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"DVDVideoSoftTB \"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT2269050.serviceLayer_services_Configuration_lastUpdate", "1380533289845");
Line Deleted : user_pref("CT2269050.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1350054580573");
Line Deleted : user_pref("CT2269050.serviceLayer_services_appsMetadata_lastUpdate", "1350114859125");
Line Deleted : user_pref("CT2269050.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1349167404493");
Line Deleted : user_pref("CT2269050.serviceLayer_services_location_lastUpdate", "1371982281568");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.13.1.89_lastUpdate", "1352793653339");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.13.40.15_lastUpdate", "1358434424972");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.14.42.7_lastUpdate", "1360656507377");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.14.65.43_lastUpdate", "1363888387396");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.15.0.562_lastUpdate", "1364114642453");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.15.2.523_lastUpdate", "1367942439743");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.16.1.521_lastUpdate", "1368513095042");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.16.2.509_lastUpdate", "1371996682292");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.16.4.519_lastUpdate", "1374497523635");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.16.70.505_lastUpdate", "1377255954917");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.19.2.505_lastUpdate", "1378621066886");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.20.0.513_lastUpdate", "1379952968327");
Line Deleted : user_pref("CT2269050.serviceLayer_services_login_10.20.1.508_lastUpdate", "1380568611978");
Line Deleted : user_pref("CT2269050.serviceLayer_services_optimizer_lastUpdate", "1350137671577");
Line Deleted : user_pref("CT2269050.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1349167410692");
Line Deleted : user_pref("CT2269050.serviceLayer_services_searchAPI_lastUpdate", "1380533290146");
Line Deleted : user_pref("CT2269050.serviceLayer_services_serviceMap_lastUpdate", "1380533289435");
Line Deleted : user_pref("CT2269050.serviceLayer_services_toolbarContextMenu_lastUpdate", "1349167410635");
Line Deleted : user_pref("CT2269050.serviceLayer_services_toolbarSettings_lastUpdate", "1380568611812");
Line Deleted : user_pref("CT2269050.serviceLayer_services_translation_lastUpdate", "1380533289338");
Line Deleted : user_pref("CT2269050.settingsINI", true);
Line Deleted : user_pref("CT2269050.shouldFirstTimeDialog", "false");
Line Deleted : user_pref("CT2269050.showToolbarPermission", "false");
Line Deleted : user_pref("CT2269050.smartbar.CTID", "CT2269050");
Line Deleted : user_pref("CT2269050.smartbar.Uninstall", "0");
Line Deleted : user_pref("CT2269050.smartbar.homepage", true);
Line Deleted : user_pref("CT2269050.smartbar.isHidden", true);
Line Deleted : user_pref("CT2269050.smartbar.toolbarName", "DVDVideoSoftTB ");
Line Deleted : user_pref("CT2269050.toolbarBornServerTime", "2-10-2012");
Line Deleted : user_pref("CT2269050.toolbarCurrentServerTime", "30-9-2013");
Line Deleted : user_pref("CT2269050.toolbarLoginClientTime", "Fri Mar 22 2013 08:46:55 GMT+0100 (ora solare Europa occidentale)");
Line Deleted : user_pref("CT2269050_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1380609622405,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("avg.install.installDirPath", "C:\\Documents and Settings\\All Users\\Dati applicazioni\\AVG Secure Search\\10.2.0.3");
Line Deleted : user_pref("avg.install.userHPSettings", "hxxp://start.facemoods.com/?a=grupo");
Line Deleted : user_pref("avg.install.userSPSettings", "Facemoods Search");
Line Deleted : user_pref("browser.search.defaultengine", "Web Search");
Line Deleted : user_pref("browser.search.defaultenginename", "Web Search");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "DVDVideoSoftTB Customized Web Search");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}");
Line Deleted : user_pref("browser.search.order.1", "Web Search");
Line Deleted : user_pref("browser.search.selectedEngine", "Web Search");
Line Deleted : user_pref("extensions.APN_TB.first-previous-keyword-url", "hxxp://search.conduit.com/ResultsExt.aspx?octid=CT2269050&ctid=CT2269050&SearchSource=2&CUI=UN94856364310450489&UM=false&q=");
Line Deleted : user_pref("extensions.crossrider.bic", "140ab6a7a99ed221c6cd15c2c459d637");
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.dfltLng", "it");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.id", "5c287026000000000000001e8c864abe");
Line Deleted : user_pref("extensions.delta.instlDay", "15940");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.24.6");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.24.615:41:58");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.24.6");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=123925&tsp=4983");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");
Line Deleted : user_pref("extensions.engine@conduit.com.install-event-fired", true);
Line Deleted : user_pref("extensions.facemoods._xpiupdate", true);
Line Deleted : user_pref("extensions.facemoods.aflt", "_#grupo");
Line Deleted : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4");
Line Deleted : user_pref("extensions.facemoods.firstRun", false);
Line Deleted : user_pref("extensions.facemoods.first_time", false);
Line Deleted : user_pref("extensions.facemoods.id", "_#560a10f825eb4da68cc7093790a8efc9");
Line Deleted : user_pref("extensions.facemoods.instlDay", "_#15204");
Line Deleted : user_pref("extensions.facemoods.lastActv", "18");
Line Deleted : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");
Line Deleted : user_pref("extensions.facemoods.sid", "_#560a10f825eb4da68cc7093790a8efc9");
Line Deleted : user_pref("extensions.facemoods.uninst", true);
Line Deleted : user_pref("extensions.facemoods.update", "_#v1.4.0");
Line Deleted : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5");
Line Deleted : user_pref("extensions.ffxtlbr@Facemoods.com.install-event-fired", true);
Line Deleted : user_pref("extensions.searchgol.admin", false);
Line Deleted : user_pref("extensions.searchgol.aflt", "babsst");
Line Deleted : user_pref("extensions.searchgol.appId", "{4277F7CF-0000-46CF-BA49-D624465C4BAB}");
Line Deleted : user_pref("extensions.searchgol.autoRvrt", "false");
Line Deleted : user_pref("extensions.searchgol.dfltLng", "it");
Line Deleted : user_pref("extensions.searchgol.excTlbr", false);
Line Deleted : user_pref("extensions.searchgol.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.searchgol.id", "5c287026000000000000001e8c864abe");
Line Deleted : user_pref("extensions.searchgol.instlDay", "15990");
Line Deleted : user_pref("extensions.searchgol.instlRef", "sst");
Line Deleted : user_pref("extensions.searchgol.newTab", false);
Line Deleted : user_pref("extensions.searchgol.prdct", "searchgol");
Line Deleted : user_pref("extensions.searchgol.prtnrId", "searchgol");
Line Deleted : user_pref("extensions.searchgol.rvrt", "false");
Line Deleted : user_pref("extensions.searchgol.smplGrp", "none");
Line Deleted : user_pref("extensions.searchgol.tlbrId", "base");
Line Deleted : user_pref("extensions.searchgol.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.searchgol.vrsn", "1.8.16.19");
Line Deleted : user_pref("extensions.searchgol.vrsnTs", "1.8.16.1916:38:11");
Line Deleted : user_pref("extensions.searchgol.vrsni", "1.8.16.19");
Line Deleted : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=70474&tid=8094&ver=4.9&ts=1381528800000.000009&tguid=70474-8094-1381589695297-68E74A1B712E840C2C677E0C07A1B0F2&st=chrome&q=");
Line Deleted : user_pref("smartbar.machineId", "DFYPLJXDWL+HIFUUAUJO//J+WGXCRECECG7EUSFSESWVL5VK/5S4EE5SQQWXUXMKK9GTCJQOO8LI8MOMU5913W");

-\\ Google Chrome v

[ File : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\preferences ]

Deleted : search_url

*************************

AdwCleaner[R0].txt - [62717 octets] - [03/11/2013 12:19:53]
AdwCleaner[S0].txt - [61646 octets] - [03/11/2013 12:20:53]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [61707 octets] ##########

5) A questo punto la finestra è scomparsa...spero x sempre (ho riavviato 2 volte e non si è ripresentata)
Incrocio le dita e ti ringrazio assai! Betta
bettab27
Inviato: Tuesday, November 05, 2013 12:01:30 PM
Rank: Member

Iscritto dal : 1/20/2002
Posts: 15
Confermo, si è risolto, grazie miticoalex!!!
cbbusto
Inviato: Tuesday, November 05, 2013 2:55:36 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
bettab27 ha scritto:
Confermo, si è risolto, grazie miticoalex!!!


Certo che ne avevi di porcherie, comunque non hai finito, tutto quello che ha trovato Malwarebytes lo devi eliminare, ci sono parecchie chiavi registro e programmi infetti, apri il programma vai su file di log seleziona tutto e clic su rimuovi.
Dal log di HJT ci sono parecchie voci da eliminare e servizi da disattivare, dopo aver rimosso tutte le voci di Malwarebytes rifai una scansione con HJT e posta un nuovo log aggiornato così vediamo cos'è rimasto, poi ti dico cosa rimuovere, hai parecchie infezioni, spyware e dirottatori, avevi un pc veramente messo male. Ciao
bettab27
Inviato: Wednesday, November 06, 2013 9:25:04 PM
Rank: Member

Iscritto dal : 1/20/2002
Posts: 15
Ciao cbbusto! grazie anche a te!.. messa male..? ohi ohi.. Ho seguito il tuo consiglio: ho rifatto una scansione (a dir la verità quella rapida) e rimosso ben 85 porcherie... :-( .. qui a seguire il nuovo log di Hijack
Attendo istruzioni... (e sappi che non sono tanto pratica..) Grazie!!! Betta

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21.18.09, on 06/11/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.21357)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2014\avgrsx.exe
C:\Programmi\AVG\AVG2014\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\AVG\AVG2014\avgidsagent.exe
C:\Programmi\AVG\AVG2014\avgwdsvc.exe
C:\Programmi\Java\jre7\bin\jqs.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\Programmi\AVG\AVG2014\avgui.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Programmi\AVG\AVG2014\avgnsx.exe
C:\Programmi\AVG\AVG2014\avgemcx.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Canon\CAL\CALMAIN.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Mozilla Firefox\plugin-container.exe
C:\Programmi\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: HomeTab - {47c2cd1b-8f48-4b52-a018-1baefdf41b7d} - C:\Documents and Settings\Bonino\Dati applicazioni\HomeTab\HomeTab.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Programmi\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll
O2 - BHO: (no name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre7\bin\jp2ssv.dll
O2 - BHO: (no name) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - (no file)
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: HomeTab - {47c2cd1b-8f48-4b52-a018-1baefdf41b7d} - C:\Documents and Settings\Bonino\Dati applicazioni\HomeTab\HomeTab.dll (file missing)
O4 - HKLM\..\Run: [TrayServer] C:\Programmi\MAGIX\Video_deluxe_2008_e-version\TrayServer.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Programmi\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Programmi\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [StartCCC] C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Programmi\File comuni\DVDVideoSoft\plugins\freeytmp3downloader.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre7\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre7\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Programmi\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Programmi\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG2012\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Programmi\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG2014\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmi\Canon\CAL\CALMAIN.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Programmi\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Servizio di Google Update (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Programmi\Java\jre7\bin\jqs.exe
O23 - Service: LiveUpSC - Unknown owner - C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\SoftwareUpdater\SoftwareUpdService.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Programmi\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Programmi\Skype\Updater\Updater.exe
O23 - Service: Ssupd Service (SsupdService) - SsupdService - C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\ssupd\ssupd.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 10658 bytes


cbbusto
Inviato: Wednesday, November 06, 2013 10:14:40 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Con le eliminazioni delle voci trovate da Malwarebytes, la scansione era meglio farla completa, il log di HJT si è ridotto, alcune voci sono sparite.
Ora fai queste operazioni, segui attentamente non è difficile:

Prima operazione bisogna disattivare il Tea Timer in SpyBot, così:
Apri SpyBot in modalità avanzata (menù modalità - avanzata) poi vai in utilità - resident e togli la spunta a TeaTimer, e riavvia il pc.

Chiudi tutti i programmi e disconnessa lanci HJT e clicca sul secondo pulsante: Do a system scan only, poi metti la spunta alle voci che ti indico e alla fine clic su Fix checked:

R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)

O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)

O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

O2 - BHO: HomeTab - {47c2cd1b-8f48-4b52-a018-1baefdf41b7d} - C:\Documents and Settings\Bonino\Dati applicazioni\HomeTab\HomeTab.dll (file missing)

O2 - BHO: (no name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)

O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)

O2 - BHO: (no name) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - (no file)

O3 - Toolbar: HomeTab - {47c2cd1b-8f48-4b52-a018-1baefdf41b7d} - C:\Documents and Settings\Bonino\Dati applicazioni\HomeTab\HomeTab.dll (file missing)

O4 - HKLM\..\Run: [TrayServer] C:\Programmi\MAGIX\Video_deluxe_2008_e-version\TrayServer.exe

O4 - HKLM\..\Run: [SMSERIAL] C:\Programmi\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RemoteControl] C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe

O4 - HKLM..Run: [PinnacleDriverCheck] C:WINDOWSsystem32\PSDrvCheck.exe

O4 - HKLM\..\Run: [PCLEUSBTip] C:\Programmi\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe

O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /minimized /regrun

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG2012\avgpp.dll (file missing)
N.B.- tutte le voci 04 non toccano i programmi ma disabilitano solo l'avvio automatico, inutile.


Ora ci sono dei servizi da Disabilitare, vai nel Pannello di controllo - Strumenti amministrazione - Servizi e cerca la voce: LiveUpSC \SoftwareUpdService, fai doppio clic sulla voce e poi in Tipo di avvio metti DISABILITATO.
Poi cerca anche questa voce: Ssupd Service (SsupdService) fai doppio clic e in tipo di avvio metti Disabilitato, ok esci.

Poi fai una pulizia con Ccleaner compreso il Registro, per il Registro spunta tutte le voci acconsenti al backup quando richiesto, sempre in Ccleaner vai in Strumenti Ripristino Sistema seleziona tutte le voci tranne l'ultima che non è selezionabile e rimane per sicurezza, poi clic su Rimuovi.
Ccleaner se non è installato lo trovi QUI clic in alto a destra scarica ultima versione.

Poi vai in C:\windows, cerca la cartella Prefetch la apri e cancella tutto il contenuto, non cancellare la cartella.

Così sei a posto, il pc dovrebbe essere anche più veloce, specie in avvio, fai sapere.
Se hai qualche dubbio chiedi pure. Ciao

bettab27
Inviato: Thursday, November 07, 2013 3:45:14 PM
Rank: Member

Iscritto dal : 1/20/2002
Posts: 15
Caro cbbusto, ho seguito alla lettera le tue chiarissime istruzioni: Ho disattivato il Tea Timer in SpyBot e riavviato il pc. Disconnesso e fatto "system scan only" con HiJack, spuntate le voci indicate e alla fine clic su Fix checked.
Idem per: Pannello di controllo - Strumenti amministrazione - Servizi -LiveUpSC \SoftwareUpdService e Ssupd Service (SsupdService) - Disabilitati
Fatto pulizia con Ccleaner, compreso il Registro, ecc...
Poi in C:\windows, cartella Prefetch - cancellato tutto il contenuto.

...Poi presa da senso di colpa per non aver fatto ieri (che non avevo tempo) la scansione completa con Malware.. l'ho fatta
e sono saltati fuori altre 30 porcherie - le ho eliminate e ho rifatto la scansione con Hijack.
Allego qui il nuovo log (in seguito verrò presa da sensi di colpa per aver ancora aprofittato della tua disponibilità...):


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15.25.32, on 07/11/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.21357)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2014\avgrsx.exe
C:\Programmi\AVG\AVG2014\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Programmi\AVG\AVG2014\avgui.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\Programmi\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Programmi\AVG\AVG2014\avgidsagent.exe
C:\Programmi\AVG\AVG2014\avgwdsvc.exe
C:\Programmi\Java\jre7\bin\jqs.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Programmi\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\AVG\AVG2014\avgnsx.exe
C:\Programmi\AVG\AVG2014\avgemcx.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programmi\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Mozilla Firefox\plugin-container.exe
C:\Programmi\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.softonic.com/MOY00621/tb_v1?SearchSource=10&cc=&mi=5c287026000000000000001e8c864abe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=5c287026000000000000001e8c864abe&r=265
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Programmi\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Programmi\Softonic\Softonic\1.8.21.14\bh\Softonic.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Programmi\Softonic\Softonic\1.8.21.14\SoftonicTlbr.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [OpwareSE4] "C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Programmi\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [StartCCC] C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Programmi\File comuni\DVDVideoSoft\plugins\freeytmp3downloader.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre7\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre7\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Programmi\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Programmi\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Programmi\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Programmi\AVG\AVG2014\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmi\Canon\CAL\CALMAIN.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Programmi\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Servizio di Google Update (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Programmi\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Programmi\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Programmi\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Programmi\Skype\Updater\Updater.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 8558 bytes
cbbusto
Inviato: Thursday, November 07, 2013 6:14:05 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Non ti preoccupare, nessun problema, fin che posso aiutare lo faccio volentieri, nei limiti delle mie possibilità.

Vedo che hai fatto tutto alla perfezione, Applause Applause nel log di hjt ci sono delle voci nuove che non vanno bene, si riferiscono tutte a Softonic, mi ero dimenticato di avvisarti, se puoi evita di scaricare dal sito oppure non usare il loro downloader, non installare mai le toolbar.

Chiudi tutti i programmi e disconnessa lanci HJT e clicca sul secondo pulsante: Do a system scan only poi metti la spunta alle voci che ti indico e alla fine clic su Fix checked:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.softonic.com/MOY00621/tb_v1?SearchSource=10&cc=&mi=5c2870260000000 00000001e8c864abe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi= 5c287026000000000000001e8c864abe&r=265

O2 - BHO: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Programmi\Softonic\Softonic\1.8.21.14\bh\Softonic.dll

O3 - Toolbar: Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Programmi\Softonic\Softonic\1.8.21.14\SoftonicTlbr.dll

Potrebbe esserci ancora della spazzatura da eliminare, quindi ti faccio lavorare ancora un po', se te la senti:

Rifai la scansione con ADW,
Scarica Adwcleaner sul desktop:
http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/2-adwcleaner
Avvialo e clicca sul pulsante "Scan” finita la scansione clicca su Clean , conferma con OK le varie finestre che ti compariranno.
Il pc si riavvierà, e uscirà il log col Blocco Note.
Copialo e postalo qui.

Poi aggiungi anche questa, altro buon pulitore:
Software tipo ADW pulisce il pc da toolbar e file spazzatura. Trova anche cartelle vuote.

Fai questa scansione:
Scarica JunkerRemovalTool da qui: http://thisisudax.org/downloads/JRT.exe
Una volta scaricato chiudere tutti i programmi compreso il browser, lancialo cliccando sull’eseguibile.
Appare il prompt dei comandi, premere un tasto per continuare e il programma inizia la scansione, può durare diversi minuti, lascia fare senza toccare nulla anche se sembra fermo, alla fine appare il Blocco Note col log, JRT.txt copialo e postalo qui.

Dopo dovresti essere a posto e col pc sicuramente più veloce, fammi sapere.
Ciao e buon lavoro. Speak to the hand

bettab27
Inviato: Thursday, November 07, 2013 7:31:44 PM
Rank: Member

Iscritto dal : 1/20/2002
Posts: 15
Sei un mito! Dancing ..ho fatto tutto... lanciato HJT- system scan only - spuntate le voci indicate e Fix checked -
Poi.. ecco qui il log di ADWCleaner:


# AdwCleaner v3.011 - Report created 07/11/2013 at 19:10:40
# Updated 03/11/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Bonino - BONINO-D0B20D3F
# Running from : C:\Documents and Settings\Bonino\Documenti\Download\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Programmi\optimizer pro
Folder Deleted : C:\Programmi\Softonic
Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\SimplyTech
Folder Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Softonic
[!] Folder Deleted : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\searchplugins\softonic.xml
File Deleted : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\user.js

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\elchiiiejkobdbblfejjkbphbddgmljf
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\Softonic.dskBnd
Key Deleted : HKLM\SOFTWARE\Classes\Softonic.dskBnd.1
Key Deleted : HKLM\SOFTWARE\Classes\Softonic.SoftonicHlpr
Key Deleted : HKLM\SOFTWARE\Classes\Softonic.SoftonicHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\SoftonicApp.appCore
Key Deleted : HKLM\SOFTWARE\Classes\SoftonicApp.appCore.1
Key Deleted : HKLM\SOFTWARE\Classes\srv.SoftonicSrvc
Key Deleted : HKLM\SOFTWARE\Classes\srv.SoftonicSrvc.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B15F118E-AF21-45E8-A809-29FDD7362565}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DCDBBF03-BC10-457D-911F-EFB0321D22BE}
Key Deleted : HKCU\Software\Babylon
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Softonic

***** [ Browsers ] *****

-\\ Internet Explorer v7.0.6000.21357

Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]

-\\ Mozilla Firefox v25.0 (it)

[ File : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\Solo_562533\prefs.js ]


[ File : C:\Documents and Settings\Bonino\Dati applicazioni\Mozilla\Firefox\Profiles\tzzrc7bs.default\prefs.js ]

Line Deleted : user_pref("extensions.Softonic.admin", false);
Line Deleted : user_pref("extensions.Softonic.aflt", "OC");
Line Deleted : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");
Line Deleted : user_pref("extensions.Softonic.autoRvrt", "false");
Line Deleted : user_pref("extensions.Softonic.dfltLng", "");
Line Deleted : user_pref("extensions.Softonic.dfltSrch", true);
Line Deleted : user_pref("extensions.Softonic.dnsErr", true);
Line Deleted : user_pref("extensions.Softonic.excTlbr", false);
Line Deleted : user_pref("extensions.Softonic.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.Softonic.hmpg", true);
Line Deleted : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=5c287026000000000000001e8c864abe");
Line Deleted : user_pref("extensions.Softonic.id", "5c287026000000000000001e8c864abe");
Line Deleted : user_pref("extensions.Softonic.instlDay", "16016");
Line Deleted : user_pref("extensions.Softonic.instlRef", "MOY00621");
Line Deleted : user_pref("extensions.Softonic.newTab", true);
Line Deleted : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=5c287026000000000000001e8c864abe");
Line Deleted : user_pref("extensions.Softonic.prdct", "Softonic");
Line Deleted : user_pref("extensions.Softonic.prtnrId", "softonic");
Line Deleted : user_pref("extensions.Softonic.rvrt", "false");
Line Deleted : user_pref("extensions.Softonic.smplGrp", "none");
Line Deleted : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
Line Deleted : user_pref("extensions.Softonic.tlbrId", "opencandy2013");
Line Deleted : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=5c287026000000000000001e8c864abe&q=");
Line Deleted : user_pref("extensions.Softonic.vrsn", "1.8.21.14");
Line Deleted : user_pref("extensions.Softonic.vrsnTs", "1.8.21.1412:31:06");
Line Deleted : user_pref("extensions.Softonic.vrsni", "1.8.21.14");

-\\ Google Chrome v

[ File : C:\Documents and Settings\Bonino\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : search_url
Deleted : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [62717 octets] - [03/11/2013 12:19:53]
AdwCleaner[R1].txt - [8738 octets] - [07/11/2013 19:09:18]
AdwCleaner[S0].txt - [61760 octets] - [03/11/2013 12:20:53]
AdwCleaner[S1].txt - [8767 octets] - [07/11/2013 19:10:40]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [8827 octets] ##########

e quello di JRT :

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Microsoft Windows XP x86
Ran by Bonino on 07/11/2013 at 19.16.29,20
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1645522239-1364589140-839522115-1004\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311791112}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411391110}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C4E9B79B-3E27-443D-A178-31CA0EF9DA95}



~~~ Files



~~~ Folders





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 07/11/2013 at 19.23.26,79
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
cbbusto
Inviato: Thursday, November 07, 2013 11:31:48 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
C'era ancora molta robaccia da eliminare, mi raccomando fai molta attenzione quando navighi, ai siti che visiti e soprattutto quando scarichi dei programmi controlla molto bene che non ci siano delle spunte su altri sw che ti propongono cose non richieste, non installare mai le toolbar.
Con tutta la roba che è stata cancellata avrai sicuramente il disco molto frammentato, se non hai già un sw installato, il deframmentatore di XP è molto scarso, ti consiglio QUESTO ottimo. Ciao
bettab27
Inviato: Friday, November 08, 2013 3:18:40 PM
Rank: Member

Iscritto dal : 1/20/2002
Posts: 15
Ciao ccbusto! sto facendo la defrag che mi hai suggerito.. tutta la porcheria credo di averla accumulata cercando e scaricando film e serie (scarico parecchio...) Whistle Quale dei programmi usati questi giorni devo riutilizzare regolarmente? Malwarebytes ad esempio è in prova e scadrà fra 10 gg... C'è qualche programma o antivirus di cui devo dotarmi..? (io uso solo AVG free) Non scarico mai programmi.. ma l'ho fatto una volta recentemente ed è lì che è successo il patatrac (non sono stata abbastanza attenta alle cose non richieste...)... o forse è stata solo la goccia che ha.... Brick wall
cbbusto
Inviato: Friday, November 08, 2013 3:54:20 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
bettab27 ha scritto:
Ciao ccbusto! sto facendo la defrag che mi hai suggerito.. tutta la porcheria credo di averla accumulata cercando e scaricando film e serie (scarico parecchio...) Whistle Quale dei programmi usati questi giorni devo riutilizzare regolarmente? Malwarebytes ad esempio è in prova e scadrà fra 10 gg... C'è qualche programma o antivirus di cui devo dotarmi..? (io uso solo AVG free) Non scarico mai programmi.. ma l'ho fatto una volta recentemente ed è lì che è successo il patatrac (non sono stata abbastanza attenta alle cose non richieste...)... o forse è stata solo la goccia che ha.... Brick wall


Rispondo alle tue domande:
Malwarebytes devi scaricare la vs gratuita-QUI
ogni volta che lo vuoi usare ricordati di aggiornarlo e fai sempre la scansione COMPLETA non veloce, elimina quello che trova, questo non è un programma da usare spesso ma solo quando vedi che il pc ha qualche problema.
Antivirus: hai già AVG e va bene, anche se non è il mio preferito.
Per le pulizie frequenti va bene Ccleaner.
ADWcleaner e Junkware Remove Tool usali saltuariamente.
Come antispyware dovresti avere Windows Defender, controlla in installazione applicazioni nel pannello di controllo, se non c'è lo puoi scaricare sempre da aiutamici QUI, questo ha la protezione in tempo reale.
Non serve altro.
Quando scarichi film o altro è facile incappare in Adware e dirottatori vari, alle volte succede anche in siti sicuri, controllare sempre e non installare mai le toolbar, creano solo intoppi. Ciao
bettab27
Inviato: Friday, November 08, 2013 7:16:44 PM
Rank: Member

Iscritto dal : 1/20/2002
Posts: 15
Grazie grazie grazie.. per sdebitarmi resto a tua disposizione per qualsiasi cosa! (che non sia informatica..) ;-)
cbbusto
Inviato: Friday, November 08, 2013 11:44:16 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
bettab27 ha scritto:
Grazie grazie grazie.. per sdebitarmi resto a tua disposizione per qualsiasi cosa! (che non sia informatica..) ;-)


Troppo buona...uno potrebbe approfittare.... Think Think scherzo naturalmente.
Sono contento che il pc si sia sistemato, se dovesse capitare qualche altro problema, speriamo di no, scrivi pure. Buon fine settimana.
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.