Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Per favore mi controllate questo -log Hijackthis Opzioni
domino
Inviato: Monday, December 14, 2015 5:52:11 PM

Rank: Member

Iscritto dal : 2/13/2004
Posts: 16
Ho installato Win 10 da settimane. Oggi non mi funziona: l'antivirus, l'audio, non si connette a internet via cavo ethernet, devo schiacciare più volte il pulsante perchè esca la finestra dell'avvio e forse altro da verificare.Grazie.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:13:07, on 14/12/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16603)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe
C:\Users\Renato\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\Pmsb.exe
C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
C:\Users\Renato\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE
C:\Program Files (x86)\MyServices\fshoster32.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\APPINTEGRATOR.EXE
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Users\Renato\AppData\Roaming\Telegram Desktop\Telegram.exe
C:\Users\Renato\Desktop\Pulizia computer\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCON/6
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.it/?gfe_rd=cr&ei=W2JvVZqhMamI8QfIgoDgCg&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll
F2 - REG:system.ini: UserInit=
O2 - BHO: Toolbar BHO - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - C:\PROGRA~2\MAPSGA~2\bar\1.bin\39bar.dll
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O2 - BHO: Browsing Protection by F-Secure - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files (x86)\MyServices\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll
O2 - BHO: SafeSearchBHO - {690EF1CF-5775-4CB3-A5B8-85A63FD0262B} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O2 - BHO: Search Assistant BHO - {71c1d63a-c944-428a-a5bd-ba513190e5d2} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O3 - Toolbar: F-Secure Search Toolbar - {B242FC32-2B60-48EA-A8E3-2E280EDBC48F} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure Hoster (45406)] "C:\Program Files (x86)\MyServices\fshoster32.exe" -app -hosterid:1
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [MapsGalaxy AppIntegrator 32-bit] C:\PROGRA~2\MAPSGA~2\bar\1.bin\APPINT~1.EXE
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [MapsGalaxy AppIntegrator 64-bit] C:\PROGRA~2\MAPSGA~2\bar\1.bin\APPINT~2.EXE
O4 - HKLM\..\Run: [MapsGalaxy EPM Support] "C:\PROGRA~2\MAPSGA~2\bar\1.bin\39medint.exe" T8EPMSUP.DLL,S
O4 - HKLM\..\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [PMSpeed] C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE
O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
O4 - HKCU\..\Run: [ABBYY Screenshot Reader Bonus] "C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe" -autorun
O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Renato\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Renato\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Scan Buttons] C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\Pmsb.exe /M=HIDE
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series"
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe (User '?')
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [ABBYY Screenshot Reader Bonus] "C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe" -autorun (User '?')
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [Dropbox Update] "C:\Users\Renato\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c (User '?')
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [OneDrive] "C:\Users\Renato\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background (User '?')
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [Scan Buttons] C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\Pmsb.exe /M=HIDE (User '?')
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User '?')
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User '?')
O4 - HKUS\.DEFAULT\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User 'Default user')
O4 - S-1-5-21-304278504-1489702862-4084318992-1001 Startup: Dropbox.lnk = Renato\AppData\Roaming\Dropbox\bin\Dropbox.exe (User '?')
O4 - Startup: Dropbox.lnk = Renato\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: ImageBrowser EX Agent.lnk = C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Visualizza o nasconde HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

--
End of file - 10833 bytes
Sponsor
Inviato: Monday, December 14, 2015 5:52:11 PM

 
cbbusto
Inviato: Monday, December 14, 2015 7:03:07 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Con win 10 avere problemi non è una novità, comunque hai il pc abbastanza incasinato con parecchia roba inutile in particolare le toolbar, fai queste operazioni:

Chiudi tutti i programmi e disconnesso da internet,
Lancia HijackThis e clicca sul secondo pulsante Do a system scan only
inserisci il segno di spunta nel quadratino davanti alle righe sotto elencate, una volta seleziona clicca il tasto Fix checked per procedere all'eliminazione, comparirà una finestra clicca su SI per accettare e l'operazione è conclusa.

Ti preciso che eliminando le voci 04, i programmi non vengono toccati ma viene solo disattivato l'Avvio automatico, inutile......basterebbe solo l'antivirus.

Ricorda che Hijackthis deve essere avviato da una cartella a lui dedicata meglio sul desktop. Solo così Hijackthis creerà copie di backup di quello che viene eliminato prima di apportare modifiche, così in caso di inconvenienti si possono reinstallare.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCON/6
R3 - URLSearchHook: (no name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll
O2 - BHO: Toolbar BHO - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - C:\PROGRA~2\MAPSGA~2\bar\1.bin\39bar.dll
O3 - Toolbar: F-Secure Search Toolbar - {B242FC32-2B60-48EA-A8E3-2E280EDBC48F} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure Hoster (45406)] "C:\Program Files (x86)\MyServices\fshoster32.exe" -app -hosterid:1
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [MapsGalaxy AppIntegrator 32-bit] C:\PROGRA~2\MAPSGA~2\bar\1.bin\APPINT~1.EXE
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [MapsGalaxy AppIntegrator 64-bit] C:\PROGRA~2\MAPSGA~2\bar\1.bin\APPINT~2.EXE
O4 - HKLM\..\Run: [MapsGalaxy EPM Support] "C:\PROGRA~2\MAPSGA~2\bar\1.bin\39medint.exe" T8EPMSUP.DLL,S
O4 - HKLM\..\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [PMSpeed] C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE
O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
O4 - HKCU\..\Run: [ABBYY Screenshot Reader Bonus] "C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe" -autorun
O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Renato\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Renato\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Scan Buttons] C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\Pmsb.exe /M=HIDE
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series"
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe (User '?')
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [ABBYY Screenshot Reader Bonus] "C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe" -autorun (User '?')
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [Dropbox Update] "C:\Users\Renato\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c (User '?')
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [OneDrive] "C:\Users\Renato\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background (User '?')
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [Scan Buttons] C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\Pmsb.exe /M=HIDE (User '?')
O4 - HKUS\S-1-5-21-304278504-1489702862-4084318992-1001\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User '?')
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User '?')
O4 - HKUS\.DEFAULT\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User 'Default user')
O4 - S-1-5-21-304278504-1489702862-4084318992-1001 Startup: Dropbox.lnk = Renato\AppData\Roaming\Dropbox\bin\Dropbox.exe (User '?')
O4 - Global Startup: ImageBrowser EX Agent.lnk = C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe

Poi fai queste scansioni nell'ordine:

Scarica ed installa MalwareBytes: clicca qui per il download: http://it.malwarebytes.org/
Clicca su: scarica la versione Gratuita alla destra, nella finestra che appare clic su Salva file,
poi per installarlo clic su: mbam-setup.exe, a completamento installazione togliere la spunta alla casella "Attiva la prova gratuita di Malwarebytes Pro" poi clic su fine.
Il programma è già in Italiano.
Nella parte alta cliccare sul menu Opzioni e nella sezione Rilevamento e protezione spuntare la casella Ricerca Rootkit
Prima di fare la scansione AGGIORNALO. (è molto importante)
Poi clic su SCANSIONE verrà fatta la ricerca di elementi nocivi., già selezionata di Default,.
Alla fine appariranno i risultati della ricerca, se ci sono elementi nocivi cliccare su Rimuovi selezionati che verranno messi in quarantena, poi clic su chiudi.
Durante le operazioni ignorare gli annunci che appaiono in basso, riguardano la vs Pro.
Posta il log.

Scarica Adwcleaner sul desktop:
http://dw2.it.uptodown.com/dw/1435411607/a94c018f502a4aea50c76175543cf32ee028bd97/adwcleaner-4-207-multi-win.exe
Per il download cliccare su: Download now
Chiudi tutti i browser (è importante IE,Firefox Chrome ecc...)
Clicca sul pulsante "Scan".
Finita la scansione clicca su "Clean"
Conferma con OK le varie finestre che ti compariranno.
Il pc si riavvierà, e uscirà il log con le eliminazioni.
Postalo qui.
ADW crea un backup dei files e delle impostazioni eliminati, si trova in "C:\AdwCleaner\Quarantine" in modo da consentire l'eventuale ripristino di dati erroneamente cancellati.
Per il ripristino, aprire il programma>Strumenti>Gestione quarantena>Ripristino.

Scarica Junkware Removal Tool sul desktop.
http://junkware-removal-tool.it.uptodown.com/download
Il download dovrebbe partire entro 5 secondi
Disattiva temporaneamente l'antivirus per evitare potenziali conflitti.
Doppio click su JRT
Lo strumento si aprirà e avvierà la scansione del sistema.
Devi avere pazienza in quanto questo tool può richiedere del tempo per completare la scansione .
Al termine, un log (JRT.txt) viene salvato sul desktop e si aprirà automaticamente.
Postalo qui.
Quando hai finito tutto rifai una scansione con HijackThis e posta il nuovo log aggiornato.
Per l'audio non so se con le pulizie si ripristina potrebbe dipendere da altro.
Il cavo Ethernet è collegato bene e non è rovinato, controlla bene gli attacchi.
Fai sapere se i problemi sono risolti o no. Ciao





domino
Inviato: Tuesday, December 15, 2015 2:33:10 PM

Rank: Member

Iscritto dal : 2/13/2004
Posts: 16
Ciao Cbbusto, ti ringrazio per la tua disponibilità.
Non sono riuscito a completare ciò che mi hai detto di fare per il motivo che non si installa -mbam-setup-org-2.2.0.1024.exe- questo scaricato da altro computer in quanto il mio non accede a internet. Mi dice questo..... - impossibile eseguire un file nella cartella temporanea. Installazione anullata. Errore 5: accesso negato -
Per ora ti mando il nuovo hijackthis.log.
Ci sono altre cose che non si possono fare:
- Ripristino configurazione di sistema non funziona correttamente nel sistema in uso
- E' presente un problema che impedisce l'avvio dello strumento di risoluzione dei problemi.
- Impossibile avviare il servizio centro sicurezza PC Windows.




Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 12:40:16, on 15/12/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16603)

FIREFOX: 42.0 (x86 it)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE
C:\Program Files (x86)\MyServices\fshoster32.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\APPINTEGRATOR.EXE
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.exe
C:\Program Files (x86)\FastStone Capture\FSCapture.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Users\Renato\Desktop\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.it/?gfe_rd=cr&ei=W2JvVZqhMamI8QfIgoDgCg&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll
F2 - REG:system.ini: UserInit=
O2 - BHO: Toolbar BHO - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - C:\PROGRA~2\MAPSGA~2\bar\1.bin\39bar.dll
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O2 - BHO: Browsing Protection by F-Secure - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files (x86)\MyServices\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll
O2 - BHO: SafeSearchBHO - {690EF1CF-5775-4CB3-A5B8-85A63FD0262B} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O2 - BHO: Search Assistant BHO - {71c1d63a-c944-428a-a5bd-ba513190e5d2} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O3 - Toolbar: F-Secure Search Toolbar - {B242FC32-2B60-48EA-A8E3-2E280EDBC48F} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure Hoster (45406)] "C:\Program Files (x86)\MyServices\fshoster32.exe" -app -hosterid:1
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [MapsGalaxy AppIntegrator 32-bit] C:\PROGRA~2\MAPSGA~2\bar\1.bin\APPINT~1.EXE
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [MapsGalaxy AppIntegrator 64-bit] C:\PROGRA~2\MAPSGA~2\bar\1.bin\APPINT~2.EXE
O4 - HKLM\..\Run: [MapsGalaxy EPM Support] "C:\PROGRA~2\MAPSGA~2\bar\1.bin\39medint.exe" T8EPMSUP.DLL,S
O4 - HKLM\..\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [PMSpeed] C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User '?')
O4 - HKUS\.DEFAULT\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Visualizza o nasconde HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

--
End of file - 8343 bytes
giza
Inviato: Tuesday, December 15, 2015 3:57:08 PM

Rank: AiutAmico

Iscritto dal : 10/27/2006
Posts: 9,612
ma non hai fixato le voci che ti ha indicato cbusto
giza
Inviato: Tuesday, December 15, 2015 4:00:43 PM

Rank: AiutAmico

Iscritto dal : 10/27/2006
Posts: 9,612
ma non hai fixato le voci che ti ha indicato cbusto
domino
Inviato: Friday, December 18, 2015 12:38:37 PM

Rank: Member

Iscritto dal : 2/13/2004
Posts: 16
Chiedo scusa per il ritardo e sopratutto per la mia ignoranza in materia.
Vi posto i log. che ho ricavato con i tre programmi.
Come sopra detto non funziona internet e altro (sostituito il cavetto del modem).


# AdwCleaner v5.025 - Creato file registro eventi 17/12/2015 in 18:16:41
# Aggiornato 13/12/2015 da Xplode
# Database : 2015-12-13.2 [Locale]
# Sistema operativo : Windows 10 Home (x64)
# Nome utente : Renato - RENATO-HP
# In esecuzione da : C:\Users\Renato\Desktop\adwcleaner_5.025\adwcleaner_5.025.exe
# Opzione : Pulizia
# Supporto : http://toolslib.net/forum

***** [ Servizi ] *****

[-] Servizio Eliminato : MapsGalaxy_39Service
[!] Servizio Non Eliminato : MapsGalaxy_39Service

***** [ Cartelle ] *****

[-] Cartella Eliminato : C:\Program Files\DomaIQ Uninstaller
[-] Cartella Eliminato : C:\Program Files (x86)\Mobogenie
[-] Cartella Eliminato : C:\Program Files (x86)\SearchProtect
[-] Cartella Eliminato : C:\Program Files (x86)\Yahoo!\Companion
[-] Cartella Eliminato : C:\Program Files (x86)\myfree codec
[-] Cartella Eliminato : C:\Program Files (x86)\MapsGalaxy_39
[-] Cartella Eliminato : C:\ProgramData\Babylon
[-] Cartella Eliminato : C:\ProgramData\SweetIM
[-] Cartella Eliminato : C:\ProgramData\Tarma Installer
[-] Cartella Eliminato : C:\ProgramData\Yahoo! Companion
[-] Cartella Eliminato : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner
[-] Cartella Eliminato : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
[-] Cartella Eliminato : C:\Users\Renato\AppData\Local\genienext
[-] Cartella Eliminato : C:\Users\Renato\AppData\Local\lollipop
[-] Cartella Eliminato : C:\Users\Renato\AppData\Local\Mobogenie
[-] Cartella Eliminato : C:\Users\Renato\AppData\Local\MapsGalaxy_39
[-] Cartella Eliminato : C:\Users\Renato\AppData\LocalLow\Delta
[-] Cartella Eliminato : C:\Users\Renato\AppData\LocalLow\HPAppData
[-] Cartella Eliminato : C:\Users\Renato\AppData\LocalLow\MapsGalaxy_39
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\Babylon
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\DriverCure
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\OpenCandy
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\ParetoLogic
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\YourFileDownloader
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\RHEng
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\Yahoo!\Companion
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\MapsGalaxy_39
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HDvidCodec.com
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner
[-] Cartella Eliminato : C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\Smartbar
[-] Cartella Eliminato : C:\Users\Renato\Documents\Mobogenie
[-] Cartella Eliminato : C:\WINDOWS\Installer\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}
[-] Cartella Eliminato : C:\WINDOWS\SysWOW64\ARFC
[-] Cartella Eliminato : C:\WINDOWS\SysWOW64\WNLT

***** [ File ] *****

[-] File Eliminato : C:\END
[-] File Eliminato : C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\invalidprefs.js
[-] File Eliminato : C:\WINDOWS\SysNative\dmwu.exe
[-] File Eliminato : C:\WINDOWS\SysNative\ImhxxpComm.dll

***** [ DLLs ] *****


***** [ Collegamenti ] *****


***** [ Attività pianificate ] *****

[-] Attività Eliminata : YourFile DownloaderUpdate
[-] Attività Eliminata : OpenCandyHelperRunOnce
[-] Attività Eliminata : OpenCandyHelperRunAsStandardUser

***** [ Registry ] *****

[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\escort.DLL
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Prod.cap
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\sim-packages
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.FeedManager
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.FeedManager.1
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.HTMLMenu
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.HTMLMenu.1
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.HTMLPanel
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.HTMLPanel.1
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.MultipleButton
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.MultipleButton.1
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.PseudoTransparentPlugin
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.PseudoTransparentPlugin.1
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.ScriptButton
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.ScriptButton.1
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.SettingsPlugin
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.SettingsPlugin.1
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.ThirdPartyInstaller
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.ThirdPartyInstaller.1
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.ToolbarProtector
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\MapsGalaxy_39.ToolbarProtector.1
[-] Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [MapsGalaxy AppIntegrator 32-bit]
[-] Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [MapsGalaxy AppIntegrator 64-bit]
[-] Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [MapsGalaxy EPM Support]
[-] Chiave Eliminata : HKCU\Software\a08bd9bd34e517
[-] Chiave Eliminata : HKLM\SOFTWARE\a08bd9bd34e517
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{67FCE87F-F3EF-4A3C-87C2-8BD46E68807B}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
[-] Chiave Eliminata : HKCU\Software\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
[-] Chiave Eliminata : HKCU\Software\Classes\CLSID\{26842a09-ffa8-4e2c-ae12-0c80f01c3295}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{B853E835-9F24-4F4B-B55C-E554D15CCCD2}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{1241cebd-9777-4bc6-aae5-2a77e25db246}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{173a5778-34bf-48a2-8a5e-6963ce922fed}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{1e91a655-bb4b-4693-a05e-2edebc4c9d89}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{364ea597-e728-4ce4-bb4a-ed846ef47970}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{3ED5E5EC-0965-4DD3-B7D8-DBC48A1172B9}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{4369f96e-4071-43e7-8fd2-4d8f96918ef3}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{4b7d0b0c-cff3-49c5-9bc3-ffabc031c822}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{4f28fa5f-7d15-4753-b4fc-d548a0f02bfb}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{5e1bdcf6-dd5f-4dd3-8783-b1454aef1830}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{71c1d63a-c944-428a-a5bd-ba513190e5d2}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{9b58a6ce-b337-43d5-9c2f-8c6d92fba094}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{a35ff019-6dbe-4044-b080-6f3fa78a947f}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{c4a25b73-8ef5-4282-9d21-c8920dd577a1}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{cae88e60-cea5-4fcb-b611-54ea6305d8ab}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{db1384d8-1bda-4c8d-a743-e9ca671feb00}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\CLSID\{e045df14-bf1d-405c-a37b-a75c1551ad17}
[!] Chiave Non Eliminata : HKLM\SOFTWARE\Classes\CLSID\{1241cebd-9777-4bc6-aae5-2a77e25db246}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{94952EC4-DB66-3F32-BE4C-F0BB875EA98E}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{05F5414D-DCD6-4EE6-8C46-20A3F1209E0F}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{0D8734DB-7110-4CDB-833F-52BC93865AB2}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{200F1306-1316-473B-90CE-A777144BBDF5}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{269D72FF-8629-4DB6-AB4F-86AA3A92F8A9}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{41AE59EF-88EE-450B-B60A-F153679E6EE8}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{4404078E-2745-4E25-B010-BBC026C0E9C2}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{47A124BA-A6E2-4ED4-AA6F-84FF29E4D7DC}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{4AEF0F25-D761-4EAA-AEB7-9E756C6BF11E}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{4E26AE37-A628-496E-B410-5D432F38BD1A}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{4F55EE37-30D9-45D6-870F-3EEA6CB9BE9F}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{50ADA3A9-20B4-4EE0-8AFA-DE0BCAB94A25}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{6818868a-1b3d-4e35-a561-fa964a96cd3b}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{9193e23b-4182-493f-a38e-682307a7c463}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{0396D01A-1323-4A15-BD0C-1BC7510F46C6}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{15106AE4-6BDF-443E-80B0-3E38B59D26EC}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{64FBF8B6-C770-401A-8B84-F630EDAF4448}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{69D0BAC4-A1B1-45CE-944F-9EEB1479F059}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{8FEEDA9E-8F71-45DF-A797-468226D1D35B}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{A549A4F7-FA70-421C-B0F2-8F6C0B4B85A8}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{BF78452B-F168-4310-9EC0-4B9B66B845F0}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{D833690C-6E56-46C2-A19F-CF5FD81C9C9A}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{E38FA7CB-C053-4B07-84AD-BCA6D2BE4FE7}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{F9B90065-CD7A-4439-B311-B292299182A9}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1e91a655-bb4b-4693-a05e-2edebc4c9d89}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71c1d63a-c944-428a-a5bd-ba513190e5d2}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1e91a655-bb4b-4693-a05e-2edebc4c9d89}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{364ea597-e728-4ce4-bb4a-ed846ef47970}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4b7d0b0c-cff3-49c5-9bc3-ffabc031c822}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{71c1d63a-c944-428a-a5bd-ba513190e5d2}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1e91a655-bb4b-4693-a05e-2edebc4c9d89}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{364ea597-e728-4ce4-bb4a-ed846ef47970}
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{71c1d63a-c944-428a-a5bd-ba513190e5d2}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{173a5778-34bf-48a2-8a5e-6963ce922fed}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3ED5E5EC-0965-4DD3-B7D8-DBC48A1172B9}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4b7d0b0c-cff3-49c5-9bc3-ffabc031c822}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a35ff019-6dbe-4044-b080-6f3fa78a947f}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e045df14-bf1d-405c-a37b-a75c1551ad17}
[-] Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
[-] Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
[-] Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1241cebd-9777-4bc6-aae5-2a77e25db246}
[!] Chiave Non Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1241cebd-9777-4bc6-aae5-2a77e25db246}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6818868a-1b3d-4e35-a561-fa964a96cd3b}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79e57afa-bc05-4636-9457-fbc0abb3576b}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9193e23b-4182-493f-a38e-682307a7c463}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{bf75b5a2-8403-4f70-88a6-488e3bea0d7b}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e1f80eb5-8af4-410d-87c1-4f3e2776822a}
[-] Valore Eliminata : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{26842a09-ffa8-4e2c-ae12-0c80f01c3295}]
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{94952EC4-DB66-3F32-BE4C-F0BB875EA98E}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{05F5414D-DCD6-4EE6-8C46-20A3F1209E0F}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{0D8734DB-7110-4CDB-833F-52BC93865AB2}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{200F1306-1316-473B-90CE-A777144BBDF5}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{269D72FF-8629-4DB6-AB4F-86AA3A92F8A9}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{41AE59EF-88EE-450B-B60A-F153679E6EE8}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{4404078E-2745-4E25-B010-BBC026C0E9C2}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{47A124BA-A6E2-4ED4-AA6F-84FF29E4D7DC}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{4AEF0F25-D761-4EAA-AEB7-9E756C6BF11E}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{4E26AE37-A628-496E-B410-5D432F38BD1A}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{4F55EE37-30D9-45D6-870F-3EEA6CB9BE9F}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{50ADA3A9-20B4-4EE0-8AFA-DE0BCAB94A25}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{6818868a-1b3d-4e35-a561-fa964a96cd3b}
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{9193e23b-4182-493f-a38e-682307a7c463}
[-] Chiave Eliminata : HKCU\Software\Conduit
[-] Chiave Eliminata : HKCU\Software\Delta
[-] Chiave Eliminata : HKCU\Software\filescout
[-] Chiave Eliminata : HKCU\Software\IM
[-] Chiave Eliminata : HKCU\Software\ImInstaller
[-] Chiave Eliminata : HKCU\Software\lollipop
[-] Chiave Eliminata : HKCU\Software\Myfree Codec
[-] Chiave Eliminata : HKCU\Software\Optimizer Pro
[-] Chiave Eliminata : HKCU\Software\ParetoLogic
[-] Chiave Eliminata : HKCU\Software\YourFileDownloader
[-] Chiave Eliminata : HKCU\Software\Yahoo\Companion
[-] Chiave Eliminata : HKCU\Software\Yahoo\YFriendsBar
[-] Chiave Eliminata : HKCU\Software\MapsGalaxy_39
[-] Chiave Eliminata : HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Chiave Eliminata : HKCU\Software\AppDataLow\Software\MapsGalaxy_39
[-] Chiave Eliminata : HKLM\SOFTWARE\Babylon
[-] Chiave Eliminata : HKLM\SOFTWARE\Conduit
[-] Chiave Eliminata : HKLM\SOFTWARE\Myfree Codec
[-] Chiave Eliminata : HKLM\SOFTWARE\ParetoLogic
[-] Chiave Eliminata : HKLM\SOFTWARE\Uniblue
[!] Chiave Non Eliminata : HKLM\SOFTWARE\Uniblue\DriverScanner
[-] Chiave Eliminata : HKLM\SOFTWARE\YourFileDownloader
[-] Chiave Eliminata : HKLM\SOFTWARE\Yahoo\Companion
[-] Chiave Eliminata : HKLM\SOFTWARE\MapsGalaxy_39
[-] Chiave Eliminata : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DomaIQ Uninstaller
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MapsGalaxy_39bar Uninstall Internet Explorer
[!] Chiave Non Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MapsGalaxy_39bar Uninstall Internet Explorer
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Tarma Installer
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\WNLT
[-] Chiave Eliminata : HKU\.DEFAULT\Software\ImInstaller
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Installer\Features\B2FD9C0A5B9838449838816A28001F4B
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Installer\Products\B2FD9C0A5B9838449838816A28001F4B
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8724E58E6C7D00C48A0D4F3345EB2C26
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31BBB0B825EDEF45AB0FE7099C68C81
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B471D8D7319336B4CA89374ED0D7B806
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC30043663AA2CA4DA1DAA9CA5FDCC75
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDC83385E6C239F4C876A77A37DF581D
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D8011310B2622942868A458964FFDC5
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C63F7979DCC2154CB9591969A5CB89D
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DD31E6C1A73B334383DF186676F4D20
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB3204F747B20694B8D49EF92D8DC94B
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C81E33A400B6F814E90C7A3354E2A3A5
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDBF68C5F16790341B7C6FD7C7F8E4FC
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFA531D0F3A71504DA7AC6A11CE33739
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B2FD9C0A5B9838449838816A28001F4B
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632
[-] Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\C6FF2DF84A404F54AAAB66F45950D33C
[-] Chiave Eliminata : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Dati Ripristinato : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] Dati Ripristinato : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs]

***** [ Browser web ] *****

[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.FirstTime", "true");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.FirstTimeFF3", "true");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.UserID", "UN16779164593085113");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.addressBarTakeOverEnabledInHidden", "true");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.appOptions", "{}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.countryCode", "IT");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.defaultSearch", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.enableAlerts", "true");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.enableSearchFromAddressBar", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.firstTimeDialogOpened", "true");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.fixPageNotFoundError", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.fixPageNotFoundErrorByUser", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.fixPageNotFoundErrorInHidden", "true");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.fullUserID", "UN16779164593085113.IN.20140118134422");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.installType", "conduitnsisintegration");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.isCheckedStartAsHidden", true);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.isFirstTimeToolbarLoading", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.lastVersion", "10.23.0.722");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fbasketball.sports.ws%2Fleague%2Fschedule.x\",\"EB_MAIN_FRAME_TITLE\":\"Fantasy%20Basketball%[...]
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.openThankYouPage", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.openUninstallPage", "true");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.revertSettingsEnabled", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.searchInNewTabEnabledByUser", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.searchInNewTabEnabledInHidden", "true");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.searchSuggestEnabledByUser", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.searchUninstallUserMode", "4");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.searchUserMode", "4");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3289075\"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://uTorrentControlv6.OurToolbar.com//xpi\"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentControl_v6 \"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_Configuration_lastUpdate", "1417875011166");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1417021456796");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_appsMetadata_lastUpdate", "1417875011675");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1417021456913");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_login_10.23.0.722_lastUpdate", "1417874899695");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1417021456887");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_searchAPI_lastUpdate", "1417875011315");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_serviceMap_lastUpdate", "1417875010946");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_setupAPI_lastUpdate", "1417021457306");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_toolbarContextMenu_lastUpdate", "1417875011629");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_toolbarSettings_lastUpdate", "1417874899634");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.serviceLayer_services_translation_lastUpdate", "1417875011663");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.settingsINI", true);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.shouldFirstTimeDialog", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.showToolbarPermission", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.smartbar.CTID", "CT3289075");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.smartbar.Uninstall", "0");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.smartbar.toolbarName", "uTorrentControl_v6 ");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.startPage", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.toolbarBornServerTime", "25-11-2014");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.toolbarCurrentServerTime", "6-12-2014");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.toolbarInstallDate", "26-11-2014 18:04:15");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075.toolbarLoginClientTime", "Wed Nov 26 2014 18:04:15 GMT+0100 (ora solare Europa occidentale)");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("CT3289075_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1417874896335,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("browser.newtab.url", "hxxp://www.bing.com/?pc=COSP&ptag=D060215-ABA01A7CCEB2146F8A7F&form=CONMHP&conlogo=CT3330961");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.admin", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.aflt", "babsst");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.autoRvrt", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.dfltLng", "en");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.excTlbr", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.id", "a6e0989f000000000000406186f87ca5");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.instlDay", "15781");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.instlRef", "sst");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.newTab", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.prdct", "delta");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.prtnrId", "delta");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.rvrt", "false");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.smplGrp", "none");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.tlbrId", "base");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.tlbrSrchUrl", "");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.vrsn", "1.8.10.0");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.vrsnTs", "1.8.10.021:39:18");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("extensions.delta.vrsni", "1.8.10.0");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("network.hxxp.request.max-start-delay", 0);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("plugin.state.npconduitfirefoxplugin", 2);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("smartbar.machineId", "41ABM1GFQ+VEQ8YNAXOUAZ/P1TZNBZZZYOQMI2RJ+QIXV/UMRBB9EBDGHHMHSSSGQXNOKH2NJZIZVYMS5HOSLG");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075./9B-0?3GFA7EF", "2B2E2C3D");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075./9B-0?3GFA7EF.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075./9B90E@.3C;7B=?OFB>>RHIQS", "393F352F3E");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075./9B90E@.3C;7B=?OFB>>RHIQS.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.PG_ENABLE", "74727565");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.PG_ENABLE.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.SF_JUST_INSTALLED", "46414C5345");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.SF_JUST_INSTALLED.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.SF_STATUS", "454E41424C4544");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.SF_STATUS.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appStateReportTime", "31343137373838353133333333");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appStateReportTime.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appState_CouponBuddy", "6F6E");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appState_CouponBuddy.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appState_Easytobook", "6F6E");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appState_Easytobook.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appState_Easytobook_targeted", "6F6E");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appState_Easytobook_targeted.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appState_PriceGong", "6F6E");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appState_PriceGong.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appState_WindowShopper", "6F6E");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appState_WindowShopper.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appsConfig.storedInFile", true);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appsDefaultEnabled", "6E756C6C");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_appsDefaultEnabled.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_calledSetupService", "31");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_calledSetupService.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_currentVersion", "312E31332E302E3137");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_currentVersion.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_existingUsersRecoveryDone", "31");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_existingUsersRecoveryDone.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_first_time", "31");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_first_time.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_lastLoginTime", "31343137373838353133363031");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_lastLoginTime.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_localization.storedInFile", true);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_mamEnabled", "74727565");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_mamEnabled.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_migrated_from_ls", "31");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_migrated_from_ls.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_new_welcome_experience", "31");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_new_welcome_experience.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_settings1.13.0.17.storedInFile", true);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_showWelcomeGadget", "66616C7365");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_showWelcomeGadget.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_stamp", "38345F30");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_stamp.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_userBornDate", "4E2F41");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_userBornDate.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_userId", "38393832646664632D323161322D343234302D386235382D663738373165393862353162");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_userId.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_user_approval_interacted", "31");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_user_approval_interacted.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_welcomeDialogMode", "31");
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.CT3289075.mam_gk_welcomeDialogMode.storedInFile", false);
[-] [C:\Users\Renato\AppData\Roaming\Mozilla\Firefox\Profiles\3jm3u8sa.default\prefs.js] [Preference] Eliminata : user_pref("valueApps.storage.mam_gk_userId", "38393832646664632D323161322D343234302D386235382D663738373165393862353162");

*************************

:: Chiavi "Tracing" eliminatas
:: Impostazioni Winsock azzerate

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [64784 byte] ##########







Malwarebytes Anti-Malware
www.malwarebytes.org

Data scansione: 17/12/2015
Ora scansione: 18:56
File di log: hhh.txt
Amministratore: Sì

Versione: 2.2.0.1024
Database malware: v2015.09.22.05
Database rootkit: v2015.09.18.01
Licenza: Gratuito
Protezione da malware: Disattivata
Protezione da siti web nocivi: Disattivata
Auto-protezione: Disattivata

SO: Windows 8
CPU: x64
File system: NTFS
Utente: Renato

Tipo di scansione: Ricerca elementi nocivi
Risultati: Completata
Elementi analizzati: 436346
Tempo impiegato: 26 min, 52 sec

Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Attivata
Euristiche: Attivata
PUP: Attivata
PUM: Attivata

Processi: 0
(Nessun elemento nocivo rilevato)

Moduli: 0
(Nessun elemento nocivo rilevato)

Chiavi di registro: 7
PUP.Optional.MindSpark, HKLM\SOFTWARE\CLASSES\INTERFACE\{B03CD630-51ED-4B15-974C-76472E4624C0}, In quarantena, [6885959dfd8e55e1475f7d6c887a916f],
PUP.Optional.MindSpark, HKLM\SOFTWARE\CLASSES\TypeLib\{E38FA7CB-C053-4B07-84AD-BCA6D2BE4FE7}, In quarantena, [6687260c8cffef47970f1acf9f630df3],
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B03CD630-51ED-4B15-974C-76472E4624C0}, In quarantena, [6687260c8cffef47970f1acf9f630df3],
PUP.Optional.MindSpark, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B03CD630-51ED-4B15-974C-76472E4624C0}, In quarantena, [6687260c8cffef47970f1acf9f630df3],
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TypeLib\{E38FA7CB-C053-4B07-84AD-BCA6D2BE4FE7}, In quarantena, [bd30bc76f794ce688d19df0a13ef20e0],
PUP.Optional.MindSpark, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TypeLib\{E38FA7CB-C053-4B07-84AD-BCA6D2BE4FE7}, In quarantena, [c726939ffc8fa195e4c2c22738ca3cc4],
PUP.Optional.Bundle, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5E36886D-AE94-4901-82A6-A96381B7B4AD}_is1, In quarantena, [bf2e72c0c8c37bbb01312d59ab56b749],

Valori di registro: 0
(Nessun elemento nocivo rilevato)

Dati di registro: 0
(Nessun elemento nocivo rilevato)

Cartelle: 0
(Nessun elemento nocivo rilevato)

File: 9
PUP.Optional.InstallCore, C:\Users\Renato\AppData\Roaming\0F1F1C2Y1H1P1C0I0T\Video to Video Converter Packages\uninstaller.exe, In quarantena, [886567cb74172e086142d208659c768a],
PUP.Optional.MindSpark, C:\Users\Renato\Downloads\MapsGalaxy.exe, In quarantena, [da1345ede6a557dfe20b2d30fd080ef2],
PUP.Optional.OpenCandy, C:\Users\Renato\Downloads\AxCrypt-1.7.3156.0-Setup (1).exe, In quarantena, [915cbd75e6a5132395b6d8c3e0255da3],
PUP.Optional.OpenCandy, C:\Users\Renato\Downloads\AxCrypt-1.7.3156.0-Setup.exe, In quarantena, [7479a58d711abb7bdf6c8417719427d9],
PUP.Optional.Bundle, C:\Windows\Installer\UltraZip\unins000.exe, In quarantena, [bf2e72c0c8c37bbb01312d59ab56b749],
PUP.Optional.MindSpark, C:\Users\Renato\Desktop\HiJackThis\backups\backup-20151215-102913-435.dll, In quarantena, [3ab389a942491224c299981350b538c8],
PUP.Optional.ClickRunSoftware, C:\Users\Renato\Desktop\Per film\VDownloader\VDownloaderInstaller.exe, In quarantena, [7677d260fb906accdaeb87234bba6f91],
PUP.Optional.OpenCandy, C:\Users\Renato\Desktop\Utilità\AxCrypt\AxCrypt-1.7.3156.0-Setup.exe, In quarantena, [0de044ee63285adc2a21b5e6996cfd03],
PUP.Optional.OpenCandy, C:\Users\Renato\Desktop\Utilità\AxCrypt\AxCrypt.zip, In quarantena, [d914072bdfacd165e26974278184c739],

Settori fisici: 0
(Nessun elemento nocivo rilevato)


(end)




Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 19:48:52, on 17/12/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16603)

FIREFOX: 42.0 (x86 it)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE
C:\Program Files (x86)\MyServices\fshoster32.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.exe
C:\Users\Renato\Desktop\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.it/?gfe_rd=cr&ei=W2JvVZqhMamI8QfIgoDgCg&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Browsing Protection by F-Secure - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files (x86)\MyServices\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll
O2 - BHO: SafeSearchBHO - {690EF1CF-5775-4CB3-A5B8-85A63FD0262B} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O3 - Toolbar: F-Secure Search Toolbar - {B242FC32-2B60-48EA-A8E3-2E280EDBC48F} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure Hoster (45406)] "C:\Program Files (x86)\MyServices\fshoster32.exe" -app -hosterid:1
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [PMSpeed] C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User '?')
O4 - HKUS\.DEFAULT\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Visualizza o nasconde HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

--
End of file - 6965 bytes
cbbusto
Inviato: Friday, December 18, 2015 3:52:16 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Allora ADW ha tolto un sacco di robaccia e qualcosa anche malwarebytes, il log non ha grosi problemi però ti consiglio di fixare ed eliminare delle voci in avvio che proprio non servono:
Chiudi tutti i programmi e disconnesso da internet,
Lancia HijackThis e clicca sul secondo pulsante Do a system scan only
inserisci il segno di spunta nel quadratino davanti alle righe sotto elencate, una volta seleziona clicca il tasto Fix checked per procedere all'eliminazione, comparirà una finestra clicca su SI per accettare e l'operazione è conclusa.
Ti preciso che eliminando le voci 04, i programmi non vengono toccati ma viene solo disattivato l'Avvio automatico, inutile......basterebbe solo l'antivirus.

O4 - HKLM\..\Run: [F-Secure Hoster (45406)] "C:\Program Files (x86)\MyServices\fshoster32.exe" -app -hosterid:1
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User '?')
O4 - HKUS\.DEFAULT\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User 'Default user')

Non hai detto come va il pc. Ciao
domino
Inviato: Friday, December 18, 2015 7:42:48 PM

Rank: Member

Iscritto dal : 2/13/2004
Posts: 16
Fatto tutto come indicato, purtroppo rimane come prima. Posto il log.
Il funzionamento del computer..... i programmi funzionano normalmente, eccetto l'antivirus, internet, l'audio.
Io ho scaricato tutto ciò che mi interessava e sarei disposto di ripristinare con i dischi fatti da computer nuovo oppure con Macrium Reflect, CD Boot e dati su HDD esterno.
Però vorrei essere certo di poterli fare, per come si trova ora il computer (eventuali virus nel sistema) e cambio da Win 8 a 10.
Ma se mi trovate altre possibilità proverei. Ciao.


Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 18:29:04, on 18/12/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16603)

FIREFOX: 42.0 (x86 it)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE
C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.exe
C:\Users\Renato\Desktop\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.it/?gfe_rd=cr&ei=W2JvVZqhMamI8QfIgoDgCg&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Browsing Protection by F-Secure - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files (x86)\MyServices\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll
O2 - BHO: SafeSearchBHO - {690EF1CF-5775-4CB3-A5B8-85A63FD0262B} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O3 - Toolbar: F-Secure Search Toolbar - {B242FC32-2B60-48EA-A8E3-2E280EDBC48F} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure Hoster (45406)] "C:\Program Files (x86)\MyServices\fshoster32.exe" -app -hosterid:1
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [PMSpeed] C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User '?')
O4 - HKUS\.DEFAULT\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIXE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-2510 Series" (User 'Default user')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Visualizza o nasconde HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

--
End of file - 6705 bytes
cbbusto
Inviato: Friday, December 18, 2015 10:15:24 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Le voci che ti ho messo da eliminare ci sono ancora tutte ???
Che antivirus usi, questo a cosa ti serve: C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE
Per le voci che ti ho messo prima, apri ccleaner>Strumenti>Avvio, cerca le voci sopra e fai doppio clic su ognuna e vedrai alla sinistra la voce SI diventare NO, il programma è disattivato, ho dei dubbi ma la voce che si riferisce a MyServices\apps\ComputerSecurity non mi piace e nemmeno il programma sopra, fammi sapere.
domino
Inviato: Saturday, December 19, 2015 1:33:56 AM

Rank: Member

Iscritto dal : 2/13/2004
Posts: 16
Fatto in modalità provvisoria - questo è il log.

Ora come posso far funzionare " l'antivirus - la connessione ad internet - l'audio " che non funzionano ancora.



Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 01:16:23, on 19/12/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16603)

FIREFOX: 42.0 (x86 it)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE
C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.exe
C:\Users\Renato\Desktop\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.it/?gfe_rd=cr&ei=W2JvVZqhMamI8QfIgoDgCg&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Browsing Protection by F-Secure - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files (x86)\MyServices\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll
O2 - BHO: SafeSearchBHO - {690EF1CF-5775-4CB3-A5B8-85A63FD0262B} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O3 - Toolbar: F-Secure Search Toolbar - {B242FC32-2B60-48EA-A8E3-2E280EDBC48F} - C:\Program Files (x86)\MyServices\apps\SafeSearch\IE\FSSafeSearch.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files (x86)\MyServices\apps\ComputerSecurity\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [PMSpeed] C:\Program Files (x86)\NewSoft\Presto! PageManager 9.03\PMSpeed.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Visualizza o nasconde HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

--
End of file - 5567 bytes
cbbusto
Inviato: Saturday, December 19, 2015 12:01:08 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Il log va bene, non mi hai detto che antivirus usi, con win 8 ti consiglio quello integrato nel Sistema, windows defender, lo uso anch'io, va in pannello di controllo- windows defender e lo attivi. Per l'audio dovresti provare ad aggiornare i driver, controlla in sistema le varie parti se vedi un punto interrogativo giallo clicca su aggiorna driver.
Per il collegamento internet non saprei cosa consigliarti, non è il mio settore. Ciao
domino
Inviato: Saturday, December 19, 2015 2:37:45 PM

Rank: Member

Iscritto dal : 2/13/2004
Posts: 16
OK....... l'antivirus è "MyService - Infostrada Security - (lo pago con il contratto telefonico)

Da - Impostazioni > Windows Defender - mi trovo tutto inattivo, senza possibilità di attivare.

Una cosa che penso anomala è: Andando a vedere - Impostazioni > Sistema > Informazioni su....
Sulla voce "Processore (0 processori)" gli altri dati sono OK. E' normale?

Ciao
cbbusto
Inviato: Saturday, December 19, 2015 3:36:13 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
domino ha scritto:
OK....... l'antivirus è "MyService - Infostrada Security - (lo pago con il contratto telefonico)

Questo lo avevo già detto non mi piace, ho dei dubbi.

Da - Impostazioni > Windows Defender - mi trovo tutto inattivo, senza possibilità di attivare.

Questo è normale perchè essendoci un altro antivirus questo disattiva defender, 2 antivirus installati non vanno assolutamente bene, per attivare defender devi disattivare MyService, altrimenti devi rivolgerrti a infostrada.

Una cosa che penso anomala è: Andando a vedere - Impostazioni > Sistema > Informazioni su....
Sulla voce "Processore (0 processori)" gli altri dati sono OK. E' normale?

Questo non è normale, il processore si deve vedere, come la memoria RAM installata e il tipo di sistema se 32 o 64bit, sinceramente non saprei cosa dirti. d'oh! d'oh!
Quando sei in Sistema clicca su Gestione dispositivi alla destra, e ti appaiono tutti, controlla se c'è qualche punto interrogativo giallo e vedi a cosa si riferisce.

Ciao
Speak to the hand
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.