Prima di tutto grazie per esserti interessato,poi, forse non mi sono spiegato bene, dopo la scansione Malwarebytes mi dice di riavviare ma questo riavvio non avviene,non sò perche,ed e per questo che non si riesce ad eliminarlo,questa procedura e stata fatta anche prima in modalità normale ma il risultato è sempre questo,allora ho deciso di andare in modalità provvisoria credendo di fare bene.Nellattesa ho gia scansionato con adwcleaner, Junkware Removal Tool,e anche con otl come la guida di r16 ti posto il tutto,fammi sapere dove ho sbagliato.
# AdwCleaner v3.012 - Report created 17/11/2013 at 14:32:53
# Updated 11/11/2013 by Xplode
# Operating System : Windows 8.1 (32 bits)
# Username : antot_000 - ANTONIO
# Running from : C:\Users\antot_000\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\antot_000\AppData\Roaming\Nosibay
File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\delta-homes.xml
File Deleted : C:\Users\antot_000\AppData\Roaming\Mozilla\Firefox\Profiles\65ajef7i.default\searchplugins\iminent.xml
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dnllcmllkjofnojidnaknldfehfhehoo
Key Deleted : HKLM\SOFTWARE\Classes\jZip.file
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}
Key Deleted : HKLM\Software\hdcode
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E0D3DD9E5E4B74CA43BCE77815E287
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16384
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v25.0.1 (it)
[ File : C:\Users\antot_000\AppData\Roaming\Mozilla\Firefox\Profiles\65ajef7i.default\prefs.js ]
Line Deleted : user_pref("extensions.iminent.admin", false);
Line Deleted : user_pref("extensions.iminent.aflt", "orgnl");
Line Deleted : user_pref("extensions.iminent.appId", "{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}");
Line Deleted : user_pref("extensions.iminent.autoRvrt", "false");
Line Deleted : user_pref("extensions.iminent.dfltLng", "");
Line Deleted : user_pref("extensions.iminent.excTlbr", false);
Line Deleted : user_pref("extensions.iminent.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.iminent.id", "76a523e2000000000000fc1f19fe8d14");
Line Deleted : user_pref("extensions.iminent.instlDay", "16006");
Line Deleted : user_pref("extensions.iminent.instlRef", "");
Line Deleted : user_pref("extensions.iminent.newTab", false);
Line Deleted : user_pref("extensions.iminent.prdct", "iminent");
Line Deleted : user_pref("extensions.iminent.prtnrId", "iminent");
Line Deleted : user_pref("extensions.iminent.rvrt", "false");
Line Deleted : user_pref("extensions.iminent.smplGrp", "none");
Line Deleted : user_pref("extensions.iminent.tlbrId", "base");
Line Deleted : user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q=");
Line Deleted : user_pref("extensions.iminent.vrsn", "1.8.26.8");
Line Deleted : user_pref("extensions.iminent.vrsnTs", "1.8.26.814:44:51");
Line Deleted : user_pref("extensions.iminent.vrsni", "1.8.26.8");
Line Deleted : user_pref("iminent.LayoutId", "1");
Line Deleted : user_pref("iminent.registerToolbarEvent102", "1383753681376");
Line Deleted : user_pref("iminent.version", "7.43.4.1");
Line Deleted : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.43.4.1\",\"InstallEventCTime\":1382967903699,\"InstallEvent\":\"True\"}");
*************************
AdwCleaner[R0].txt - [4439 octets] - [23/08/2013 12:29:49]
AdwCleaner[R1].txt - [2114 octets] - [23/09/2013 18:58:19]
AdwCleaner[R2].txt - [1545 octets] - [07/10/2013 17:55:46]
AdwCleaner[R3].txt - [10649 octets] - [08/11/2013 17:53:55]
AdwCleaner[R4].txt - [4179 octets] - [17/11/2013 14:31:45]
AdwCleaner[S0].txt - [2968 octets] - [23/08/2013 12:30:11]
AdwCleaner[S1].txt - [2150 octets] - [23/09/2013 18:58:34]
AdwCleaner[S2].txt - [1630 octets] - [07/10/2013 17:57:36]
AdwCleaner[S3].txt - [9720 octets] - [08/11/2013 17:54:08]
AdwCleaner[S4].txt - [4072 octets] - [17/11/2013 14:32:53]
########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [4132 octets] ##########
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 8.1 x86
Ran by antot_000 on 17/11/2013 at 14:43:35,66
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [File] C:\Users\antot_000\AppData\Roaming\mozilla\firefox\profiles\65ajef7i.default\extensions\hdvc3@hdvidcodec.com.xpi
Emptied folder: C:\Users\antot_000\AppData\Roaming\mozilla\firefox\profiles\65ajef7i.default\minidumps [12 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17/11/2013 at 14:49:34,33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Extras.TxtOTL.TxtMalwarebytes Anti-Malware (Prova) 1.75.0.1300
www.malwarebytes.orgVersione database: v2013.11.16.05
Windows 8 x86 NTFS
Internet Explorer 11.0.9600.16384
antot_000 :: ANTONIO [amministratore]
Protezione: Disattivata
16/11/2013 19:56:07
MBAM-log-2013-11-16 (21-55-33).txt
Tipo di scansione: Scansione completa (C:\|)
Opzioni di scansione attive: Memoria | Esecuzione automatica | Registro | File di sistema | Euristica/Extra | Euristica/Shuriken | PUP | PUM
Opzioni di scansione disattivate: P2P
Elementi esaminati: 274953
Tempo impiegato: 1 ore, 58 minuti, 40 secondi
Processi rilevati in memoria: 0
(non sono stati rilevati elementi nocivi)
Moduli di memoria rilevati: 0
(non sono stati rilevati elementi nocivi)
Chiavi di registro rilevate: 1
HKLM\SOFTWARE\Google\Chrome\Extensions\dnllcmllkjofnojidnaknldfehfhehoo (PUP.Optional.HDVidCodec.A) -> Nessuna azione intrapresa.
Valori di registro rilevati: 0
(non sono stati rilevati elementi nocivi)
Voci rilevate nei dati di registro: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (Hijack.StartPage) -> Cattivo: (http://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=3219782655_198225_76A523E2&ts=1376146447) Buono: (http://www.google.com) -> Nessuna azione intrapresa.
Cartelle rilevate: 0
(non sono stati rilevati elementi nocivi)
File rilevati: 2
C:\$Recycle.Bin\S-1-5-21-3988939458-3983367898-2963466441-1001\$R68MR9E.exe (PUP.Optional.VIT) -> Nessuna azione intrapresa.
C:\Users\antot_000\Downloads\Random_Password_Generator_downloader.exe (PUP.Optional.FreeNew.A) -> Nessuna azione intrapresa.
(fine)