Adwcleaner lo conoscevo, ma premendo scan non esamina, questa immagine è 1 ora dopo il lancio:
poi ecco il log di Junkware Removal Tool:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by Giancarlo on 22/11/2013 at 12:45:08,44
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?
Value Name Type Value Data
========================================================================================
Pokki REG_EXPAND_SZ C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\driverscanner
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\linkurysmartbar.bandobjectattribute
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetimsetup_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetimsetup_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskPIP_FF__RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskPIP_FF__RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskSLib_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskSLib_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\TaskScheduler_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\TaskScheduler_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_atube-catcher_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_atube-catcher_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_easy-pro-shutdown_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_easy-pro-shutdown_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_utorrent_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_utorrent_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_vlc-media-player_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_vlc-media-player_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskPIP_FF__RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskPIP_FF__RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskSLib_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskSLib_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskScheduler_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskScheduler_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_atube-catcher_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_atube-catcher_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_easy-pro-shutdown_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_easy-pro-shutdown_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_utorrent_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_utorrent_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_vlc-media-player_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_vlc-media-player_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D9C683FC-AF39-42E2-8FC4-46B597A1FB94}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\Giancarlo\AppData\Roaming\nosibay"
Successfully deleted: [Folder] "C:\Users\Giancarlo\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Program Files (x86)\nosibay"
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{03122CD1-0A3E-4BB4-9B04-5133B6BB16DC}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{0D06075D-5925-4C98-8A9F-F229AD338EBF}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{12E34EAB-8595-42CA-9986-9864267A1989}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{18D5C36F-1D38-443F-B658-2ECB78EC7230}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{1D68569E-2A7E-47FC-885C-A168500282A7}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{242BF438-1A3B-4CED-8E09-FA9B3F9692C3}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{2C86109A-FFCF-4A55-B021-DD063CAA0011}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{2E7D4886-B6B1-4D9C-96C0-0167204D5B04}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{2F5BB443-1C7C-487C-BF66-485576F2C990}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{317910FD-9332-4206-AE29-779741D2F46D}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{41B6286C-3673-4E49-8EB2-88FE2554F3B6}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{465286CC-2B73-414E-99F4-1B70B1A6A18C}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{4B50148F-6AA7-454C-9426-5C09B1A6268F}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{516C8B34-F73D-4F0B-9A77-E01C4DB23E46}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{53802A5E-F847-4341-9A26-022F28F73C02}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{58B3EEE1-C79F-4C87-AA90-218196AF4E93}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{5A358CF4-E669-434C-96F4-B6916FC2A7F7}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{5B01CA35-8866-4B80-9FB1-9E44B37BC33F}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{65412FAE-7ACB-4CE0-A00A-D9394C862C58}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{6696FC93-1B41-4753-BA2F-1D8D1C76FF6B}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{6D932284-1A87-46FC-800E-8BDA9C583C6D}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{733AC955-015C-49B1-95C4-43FA43DEF603}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{792BF9F3-F3CE-4F75-A5E6-5F74FAFED634}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{7A437A3E-5ADC-491A-9E32-7CDBFB5D86B7}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{82A5009C-68BC-4055-A192-88E2B18F74E4}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{8676F14A-848C-4F4C-83D6-43185AE2782F}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{87F79DA9-18EB-40A2-8720-98608A77D0BA}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{8CB6EAC5-26CE-426E-9189-0AE2092A3E23}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{9042765B-2DCE-4CB7-AE36-1DFD1E412B74}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{92D997D8-21B3-45EE-96C8-DDA5AA4DBD85}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{93BE025A-3E98-4DCB-8CD5-3CBC306A218C}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{9615258B-463D-4C53-9960-0E02AFD2D530}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{987F1163-25FB-4988-91BE-56A85C47779F}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{99ED467E-8BD5-46AA-A2DA-6659D7EF67C5}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{9CB088D4-DC20-4F7E-A210-96499150587D}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{A559D333-F063-4FDB-B269-C4E35FA19883}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{A8072FB3-B385-4ABE-926F-5DFD4784D0C7}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{AC541E6F-9A1F-4BA0-9D7F-316D32B0E531}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{AF1B8BB6-5247-4723-BAAD-BC7BF1979E16}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{B358E5B1-DEC1-4505-A1F6-E23AB7ECE942}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{B613FB83-2DDA-4662-97F4-7E500D00C393}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{B7181AC1-1447-4F25-A583-627E4ACC0EEB}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{C1501DA3-F02A-4CC8-A3FF-D1DAFEAC20D8}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{C4BB7D99-12A6-4D50-B1D6-262A451A5A86}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{C52BE1BE-4166-4ECD-91F9-47BA01CA2EC0}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{C6846B27-E0C1-4A87-B05C-B8307C7E0CCA}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{D7468051-08ED-4A4F-A1E1-C5FB27F3F4A1}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{E2975235-17C5-4D7A-B35D-90C841E3A424}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{F78A3EDB-9BD6-4FF6-85A6-3D84562BEB7B}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{FA3C1F39-54E5-4C32-BD99-B3E0E417EB8D}
Successfully deleted: [Empty Folder] C:\Users\Giancarlo\appdata\local\{FA6A29B4-040F-49BC-95C4-ED93B36DD363}
~~~ FireFox
Successfully deleted: [File] C:\Users\Giancarlo\AppData\Roaming\mozilla\firefox\profiles\zhgh1qvn.default-1377535971340\user.js
Emptied folder: C:\Users\Giancarlo\AppData\Roaming\mozilla\firefox\profiles\zhgh1qvn.default-1377535971340\minidumps [110 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22/11/2013 at 13:16:28,16
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Spetto istruzioni
Grazie