Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Virus polizia penitenziaria, come toglierlo? Opzioni
clidio
Inviato: Saturday, September 05, 2015 2:35:05 PM
Rank: AiutAmico

Iscritto dal : 4/24/2008
Posts: 123
Ciao a tutti, volevo sapere se posso con il vostro aiuto togliere il virus della polizia penitenziaria, ho provato con il mio antivirus microsoft security essentials, ma non c'è riuscito, possiedo un computer portatile asus con sistema operativo Win 7
Sponsor
Inviato: Saturday, September 05, 2015 2:35:05 PM

 
cbbusto
Inviato: Saturday, September 05, 2015 7:09:45 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Quindi il tuo pc non è bloccato.
Le scansioni con antivirus in questi casi non servono a niente.
Riavvia il PC e premi F8 ripetutamente una volta scomparsa la schermata BIOS.
Usa i tasti con le freccette per navigare e seleziona Modalità Provvisoria con Rete. Premi Invio.
Accedi a questo indirizzo http://www.pcthreat.com/download-sph e scarica SpyHunter.
Installa il programma, seleziona la lingua italiana ed esegui una scansione completa del sistema.
Riavvia il pc in modalità normale e fai queste scansioni, segui attentamente le istruzioni:

Scarica ed installa MalwareBytes: clicca qui per il download: http://it.malwarebytes.org/
Clicca su: scarica la versione Gratuita alla sinistra, nella finestra che appare clic su Salva file,
poi per installarlo clic su: mbam-setup.exe
Alla fine dell'installazione nell’ultima schermata deseleziona la voce Attiva la prova gratuita di Malwarebytes Anti-Malware Pro.
Se il sw è in inglese, vai nella scheda Settings e seleziona la voce Italian dal menu a tendina Language per tradurre il programma in italiano.
Prima di fare la scansione AGGIORNALO. (è molto importante)
Poi clic su SCANSIONE seleziona la voce scansione di minaccia

Elimina gli eventuali file infetti trovati. (li devi selezionare, e poi cliccare su "Rimuovi selezionati")
Posta il log.

Scarica Adwcleaner sul desktop:
http://dw2.it.uptodown.com/dw/1435411607/a94c018f502a4aea50c76175543cf32ee028bd97/adwcleaner-4-207-multi-win.exe
Per il download cliccare su: Download now
Chiudi tutti i browser (è importante IE,Firefox Chrome ecc...)
Clicca sul pulsante "Scan".
Finita la scansione clicca su "Clean"

Conferma con OK le varie finestre che ti compariranno.
Il pc si riavvierà, e uscirà il log con le eliminazioni.
Postalo qui.

Scarica Junkware Removal Tool sul desktop.
http://thisisudax.org/downloads/JRT.exe
Il download dovrebbe partire entro 5 secondi
Disattiva temporaneamente l'antivirus per evitare potenziali conflitti.
Doppio click su JRT
Lo strumento si aprirà e avvierà la scansione del sistema.
Devi avere pazienza in quanto questo tool può richiedere del tempo per completare la scansione .
Al termine, un log (JRT.txt) viene salvato sul desktop e si aprirà automaticamente.
Postalo qui.

Dopo queste operazioni fai una scansione con HijackThis e posta il log, HJT scaricalo da qui:
http://sourceforge.net/projects/hjt/ clic su download.
Fai sapere come va il pc.
Ciao
clidio
Inviato: Saturday, September 05, 2015 11:34:48 PM
Rank: AiutAmico

Iscritto dal : 4/24/2008
Posts: 123
Ciao cbbusto ho fatto come mi hai detto, ho trovato dei problemi dopo la scansione di SpyHunter, infatti per eliminare i files infetti dovevo comprare la versione a pagamento, così sono andato avanti e il problema dopo l'ho trovato quando ho cliccato sul link di Junkware Removal Tool, infatti non trova la pagina del programma, intanto ti posto i log di malwarebytes e di Adwcleaner
<?xml version="1.0" encoding="UTF-8"?>
<logs><record message="Bad md5 or size: akadomains" last_modified_tag="24924f5c-a447-422d-b64b-b38d3b980e5f" code="11" systemname="CLAUDIOPC1" username="SYSTEM" type="Error" source="Update" datetime="2015-09-05T22:08:56.797840+02:00" LoggingEventType="4" severity="debug"/><record message="Bad md5 or size: akaips" last_modified_tag="8da16194-a727-43d7-aa6c-06a03390eb34" code="11" systemname="CLAUDIOPC1" username="SYSTEM" type="Error" source="Update" datetime="2015-09-05T22:08:57.079856+02:00" LoggingEventType="4" severity="debug"/><record last_modified_tag="f772645e-817c-47af-90fb-8af4c7d9146b" systemname="CLAUDIOPC1" username="SYSTEM" type="Update" source="Manual" datetime="2015-09-05T22:08:57.250857+02:00" LoggingEventType="1" severity="debug" toVersion="2015.8.28.2" name="Remediation Database" fromVersion="2015.5.13.1"/><record last_modified_tag="d342d72b-22d2-439a-9b32-66e3739f5b38" systemname="CLAUDIOPC1" username="SYSTEM" type="Update" source="Manual" datetime="2015-09-05T22:08:57.297657+02:00" LoggingEventType="1" severity="debug" toVersion="2015.7.24.3" name="IP Database" fromVersion="0.0.0.0"/><record last_modified_tag="b0e31554-80a2-4f70-9a4e-07b3b74c9868" systemname="CLAUDIOPC1" username="SYSTEM" type="Update" source="Manual" datetime="2015-09-05T22:08:57.375657+02:00" LoggingEventType="1" severity="debug" toVersion="2015.7.24.2" name="Domain Database" fromVersion="0.0.0.0"/><record last_modified_tag="7be4fa80-bd5f-4d31-b6b7-409e6e1663ff" systemname="CLAUDIOPC1" username="SYSTEM" type="Update" source="Manual" datetime="2015-09-05T22:08:57.391257+02:00" LoggingEventType="1" severity="debug" toVersion="2015.8.16.1" name="Rootkit Database" fromVersion="2015.6.2.1"/><record last_modified_tag="d31598a7-3031-4957-93cf-6a44068ccf67" systemname="CLAUDIOPC1" username="SYSTEM" type="Update" source="Manual" datetime="2015-09-05T22:08:58.405259+02:00" LoggingEventType="1" severity="debug" toVersion="2015.9.5.5" name="AKA Domain Database" fromVersion="0.0.0.0"/><record last_modified_tag="cabacc85-eab8-491d-87e6-f0438cf312e2" systemname="CLAUDIOPC1" username="SYSTEM" type="Update" source="Manual" datetime="2015-09-05T22:08:59.481661+02:00" LoggingEventType="1" severity="debug" toVersion="2015.9.4.1" name="AKA IP Database" fromVersion="0.0.0.0"/><record last_modified_tag="296f8c1e-8f49-4c08-a465-71b49806038a" systemname="CLAUDIOPC1" username="SYSTEM" type="Update" source="Manual" datetime="2015-09-05T22:09:06.548473+02:00" LoggingEventType="1" severity="debug" toVersion="2015.9.5.6" name="Malware Database" fromVersion="2015.6.3.3"/><record last_modified_tag="d0b5e66d-fdef-41be-8313-81e69619ec6d" systemname="CLAUDIOPC1" username="SYSTEM" type="Scan" source="Manual" datetime="2015-09-05T22:56:15.141860+02:00" LoggingEventType="6" severity="debug" malwaredetections="0" duration="2662" starttime="2015-09-05T22:10:19+02:00" scantype="threat" scanresult="completed" nonmalwaredetections="153"/><record message="IsLicensed" last_modified_tag="d6e016b4-5a09-4f67-a047-1eb124a7412b" code="13" systemname="CLAUDIOPC1" username="SYSTEM" type="Error" source="Protection" datetime="2015-09-05T22:58:31.526091+02:00" LoggingEventType="4" severity="debug"/><record last_modified_tag="a472a15f-ec81-4da8-9e15-78277004c8a4" systemname="CLAUDIOPC1" username="SYSTEM" type="Protection" source="Protection" datetime="2015-09-05T22:58:31.791291+02:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopping"/><record last_modified_tag="bb13e164-5e5c-4ff8-b849-a3751062ce0d" systemname="CLAUDIOPC1" username="SYSTEM" type="Protection" source="Protection" datetime="2015-09-05T22:58:31.806891+02:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopped"/></logs>


e dopo quello di Adwcleaner


# AdwCleaner v5.001 - Logfile created 05/09/2015 at 23:20:45
# Updated 17/08/2015 by Xplode
# Database : 2015-09-04.4 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Utente Microsoft - CLAUDIOPC1
# Running from : D:\Programmi scaricati\Aiutamici\adwcleaner\adwcleaner-5-001-multi-win.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\Advanced System Protector
[-] Folder Deleted : C:\Program Files (x86)\PC Cleaner
[-] Folder Deleted : C:\Program Files (x86)\Systweak Support Dock
[-] Folder Deleted : C:\Program Files (x86)\Driver Mender
[-] Folder Deleted : C:\Program Files (x86)\DriverWhiz
[-] Folder Deleted : C:\ProgramData\Driver Mender
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Mender
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverWhiz
[-] Folder Deleted : C:\Users\Utente Microsoft\AppData\Roaming\Systweak
[-] Folder Deleted : C:\Users\Utente Microsoft\AppData\Roaming\ProgSense

***** [ Files ] *****

[-] File Deleted : C:\Users\Utente Microsoft\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dnpmlnedpdikbgdghljdepnljfpkhccn_0.localstorage-journal
[-] File Deleted : C:\Users\Utente Microsoft\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_it.ask.com_0.localstorage-journal
[-] File Deleted : C:\Users\Utente Microsoft\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_librecad.softonic.it_0.localstorage-journal
[-] File Deleted : C:\Users\Utente Microsoft\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pdf-xchange-viewer.softonic.it_0.localstorage-journal
[-] File Deleted : C:\Users\Utente Microsoft\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.chatzum.com_0.localstorage-journal
[-] File Deleted : C:\Users\Utente Microsoft\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_tuvaro.com_0.localstorage-journal

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [C:\Program Files (x86)\Plus-HD-9.5\Plus-HD-9.5-nova.exe]
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
[-] Key Deleted : HKCU\Software\APN PIP
[-] Key Deleted : HKCU\Software\distromatic
[-] Key Deleted : HKCU\Software\eSupport.com
[-] Key Deleted : HKCU\Software\Softonic
[-] Key Deleted : HKCU\Software\systweak
[-] Key Deleted : HKCU\Software\ProgSense
[-] Key Deleted : HKCU\Software\DriverWhiz
[-] Key Deleted : HKCU\Software\Context2pro
[-] Key Deleted : HKLM\SOFTWARE\systweak
[-] Key Deleted : HKLM\SOFTWARE\Taronja
[-] Key Deleted : HKLM\SOFTWARE\DriverTuner_Init
[-] Key Deleted : HKLM\SOFTWARE\DriverTuner
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
[!] Key Not Deleted : [x64] HKCU\Software\APN PIP
[!] Key Not Deleted : [x64] HKCU\Software\distromatic
[!] Key Not Deleted : [x64] HKCU\Software\eSupport.com
[!] Key Not Deleted : [x64] HKCU\Software\Softonic
[!] Key Not Deleted : [x64] HKCU\Software\systweak
[!] Key Not Deleted : [x64] HKCU\Software\ProgSense
[!] Key Not Deleted : [x64] HKCU\Software\DriverWhiz
[!] Key Not Deleted : [x64] HKCU\Software\Context2pro
[-] Key Deleted : [x64] HKLM\SOFTWARE\DriverWhiz
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0702826FCAC36EE52AC0441EEEEE2170
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1198E28F40C3E185E9958608554D4253
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\14C66209FCA938858B9729645C666684
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15A073601B9AEC3549BE4A9314794615
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F7C80F9CE5CDF44E9AADDC99402534C
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\206AF45B775E3A445B3B2273827DA85F
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\225C3CBCEB850204D860A6C7CC7724AF
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2310FC151CD4F185798FA0996B3524D7
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\28572D2E2DE533256AC6B560EA573C22
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29C79786B109AC443B0DC7BFD61B1896
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2ABB56EABB920EB59B04BDDD26A62083
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2DABA02DFED47E352A2FA2EBDD6F6187
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311567B4A9A002050BB9423FD73FB880
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\373FCED70D7F84E5FB5F3F7B76BEE024
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3BE992C130B235E53A2937391FDCA35B
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DA5F64B3483DE549947A9164ACBAD21
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3ED93605BB9B6635E9D0D86615AF31F1
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4759B017032BA185F9BA6F7DBC95A2D4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A78ABCBB54E46E5482A3EE0AD66C39E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4F9E947B6B895EB5A86757FC5D3DB862
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4FEEA83BF72B97E43A2DF0EE4BE4F261
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\509EC7EFB89B7D942997574AB14037A4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50A730A9A3A61BF5BA70CA8A3B7C133B
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51A95A1D4CDE4F958A9451FBB39BF54A
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\536133807DE80465BA6CD0A9742B7DE5
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5E25036E68895D45B95E72D1C3C58C74
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\60ECC80C54085B141A40437A96CA2618
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\60FD8CD5BE007315CA3B5C7E41F24017
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\618E7D05458C4F257909ED9C8CDC0D66
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\621C21014D3C152529E2460FA6304EE3
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6241FF6F317CABD4EBBEE0DE9076BD94
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\636B9C23C79154B57AB561F39A139BFD
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\65AAF0F0CB7F0B45F900FDF19CEAAF2B
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6879A5E348601C45986308CA84958E94
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A6F3B7A9805E1F5492A1020EEDF2341
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B1F5D204E4EEB342A5AD1D7E60D61BF
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7005A2A4DCF9DD7548137AB17E3A3AF3
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\712EAF07EE73CC65C822CC3BAE3B2483
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75FF6D97AF9FC004A9521D4B83FA6321
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7947B301B2446E752A3FE06EAD7D26B5
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7987CE52D13E16258B0E1E3DB1BB0974
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7BEED197C514FDA53901AE8DD8EF0891
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DFDCF03D46C34159BDE29FBDBF1ACF5
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8724E58E6C7D00C48A0D4F3345EB2C26
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87EC9ACEAFE8ECD52A529663CD35213F
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\890F436B85B790A55A582B7307DA12CE
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8C13DA6755F685B529615C8E92B3CA39
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8D07CD9CB3E6BE652872BF06A1CCA782
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\90841B1FC98200349925C88999866F17
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94194FDD4DF523E53A888D65722A135D
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\95266D07D008D2E4E9B6F8E0DD15432A
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A4223BBC9438CAD49BBE10B4E344B1DD
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A72F23B1D745C27508518132197BC982
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A89E2B6FB14D8275DA63D075171DA184
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A9C43CD4001E9E4518B274AF9A0EFDA9
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AABA081CF7F19915FBB80B3BAF47CE63
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC2A0FFD0A1686D53A4E24D6E96949E4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE5BDB2750259915D8442D4591A7717B
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B1A79C71D5DC1C150B76B6ED11195DFC
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31BBB0B825EDEF45AB0FE7099C68C81
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B471D8D7319336B4CA89374ED0D7B806
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B6D497DB33974935488761F7C4C3D755
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B752EF3300008394886C402CC27B474F
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B8C8BCC1206978D51A8B9EECBF806C53
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAD3576CEA646895B962F94754612791
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB4091512C8F4295E99CE2D061ED2020
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC30043663AA2CA4DA1DAA9CA5FDCC75
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEE6BBC9A31531F598794A62120B51C7
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C19162788CA4D235E829F88E2F771567
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C71F07DA356B66B5484A8E7F2ADEB7DC
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C96AD15EE8E887B56BAF2136A9088503
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C9E6B66ECC49D155888399C51D05C49E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA360F24F0B214744BE40657FDA0B727
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB13D869D7D092348847B7481BB59E27
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE85F265816AE2D4E9B73C3E207E679C
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5389AEEA4A1E20428D045E86BCF643B
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5B62BB7BC607FB539585E2B7B6AFD16
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB027F01D4D53765C8E4FBE7DB77E07E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DC2EB492393411F5ABE8ED13C59FBF20
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDA2534BD056D1F44B6EC96AAA7F1F6E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDCA763D4C48A105086B4CCCEE78043F
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DEF7558C7CD27EF46AF802AFBE402675
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E05B987540A9E2849AAF9E5B06C27DA8
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E09F4A6B9D2A08B599AE9E38BFC93CD6
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E27B6535D0D94A24E91047C7D86F27BC
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E45D171E075A5425CBACF6631A45FA39
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E513C2076D90AD04F888BD762143F191
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E8F4C985459564F5B8DCFF2B3C7EBD27
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E96E33222BAC06B57A1FA9D72951C945
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EAA46CE9007F70A5CAFA5F26E5DDEBE5
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE43FF091A8714A599F33EF2533FB59A
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE790015CF30DAA569960905FF1651A0
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EEB44C47185BD304D80FDF5A4BBE8F54
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F214EB834D2EC474CA76C1CDE306CF3A
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F25491036D0FA5D5FA6742F5742F151A
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E0D3DD9E5E4B74CA43BCE77815E287
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F4D1BA8B482D9734E943EE260A7ADEF2
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F6704141BAAF6884785EC6843143D6A7
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7507D4D4C310125E9A22BD909A41FB6
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F79C21D785419125595AC59458A6142D
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA15C90F092A60F53A4E0F88CED02968
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA1CF130B3D58B553833ACB6BE8AFAD4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB0F1A18E4F0DBD509A42F4D4C05C02A
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FD17ED194F1C2B457B4F6EF4AE8DEAF3
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDC83385E6C239F4C876A77A37DF581D
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4340C4778499EED41AE496DC3D613EC6
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\547B38670606DF14AA57B0BB83F3AE4D
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F1057DD419AED0B468AD8888429E139A
[-] Data Restored : HKU\S-1-5-21-886697645-454568397-1005252768-1001_Classes\Software\Microsoft\Internet Explorer\Main [Start Page]

***** [ Web browsers ] *****


*************************

:: Proxy settings cleared
:: Winsock settings cleared

*************************

C:\AdwCleaner[C4].txt - [27748 bytes] - [05/09/2015 23:20:45]
C:\AdwCleaner[S5].txt - [27219 bytes] - [05/09/2015 23:18:31]

########## EOF - C:\AdwCleaner[C4].txt - [27874 bytes] ##########

giza
Inviato: Sunday, September 06, 2015 6:13:55 PM

Rank: AiutAmico

Iscritto dal : 10/27/2006
Posts: 9,618
una volta sistemato scarica sandboxie . li puoi "navigare" tranquillo , se ti becchi qualcosa basta chiudere il programma e non ti infetti.
cbbusto
Inviato: Monday, September 07, 2015 10:06:53 AM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Il log di mbam è illeggibile, comunque hai eliminato tutto quello che ha trovato?
Alla fine ti avevo detto di postare il log di HJT e dirmi come va il pc.
Se non si è risolto nulla prova anche questa soluzione, scollegati da internet, non aprire nessun browser, poi fai un ripristino configurazione del sistema ad una data precedente l'infezione, sempre che ci sia.
Ci sono anche altre soluzioni, però attendo che tu mi dica come va il pc e se l'infezione esiste ancora
Aspetto informazioni e log di hjt, se non conosci il programma trovi la scheda istruzioni su aiutamici quì:
http://software.aiutamici.com/software?ID=11175 Speak to the hand
clidio
Inviato: Monday, September 07, 2015 8:58:15 PM
Rank: AiutAmico

Iscritto dal : 4/24/2008
Posts: 123
Ciao cbbusto, ora ti spiego, quando ho fatto la scansione con mbam ha trovato circa 43 file infetti, ho messo in quarantena tutto, ma credo di aver fatto casino con il log, ora sono andato ariprendere il vecchio log fatto il 5 settembre e dopo ho rifatto la scansione oggi 7 settembre, ahh dimenticavo ho eliminato definitivamente tutti i file infetti e dopo ho lanciato HijackThis. ora ti posto tutti e tre i log. Il computer mi sembra che funzioni bene, navigando non mi è apparso più il messaggio della polizia penitenziaria, se ti va mi puoi spiegare come adoperare sandoboxie, come mi ha consigliato giza?
Malwarebytes Anti-Malware
www.malwarebytes.org

Data scansione: 05/09/2015
Ora scansione: 22:10
File di log: Log malwarebytes del 5-9.txt
Amministratore: Sì

Versione: 2.1.8.1057
Database malware: v2015.09.05.06
Database rootkit: v2015.08.16.01
Licenza: Gratuito
Protezione da malware: Disattivata
Protezione da siti web nocivi: Disattivata
Auto-protezione: Disattivata

SO: Windows 7 Service Pack 1
CPU: x64
File system: NTFS
Utente: Utente Microsoft

Tipo di scansione: Ricerca elementi nocivi
Risultati: Completata
Elementi analizzati: 416710
Tempo impiegato: 44 min, 22 sec

Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Disattivata
Euristiche: Attivata
PUP: Avviso
PUM: Attivata

Processi: 0
(Nessun elemento nocivo rilevato)

Moduli: 2
PUP.Optional.Wajam, C:\Program Files\WajInternetEn\dlls\bvqnl.dll, Elimina al riavvio, [f456f23a8a0149ed7498f8c16c9853ad],
PUP.Optional.Wajam, C:\Program Files\WajInternetEn\dlls\bvqnl.dll, Elimina al riavvio, [f456f23a8a0149ed7498f8c16c9853ad],

Chiavi di registro: 0
(Nessun elemento nocivo rilevato)

Valori di registro: 0
(Nessun elemento nocivo rilevato)

Dati di registro: 0
(Nessun elemento nocivo rilevato)

Cartelle: 12
PUP.Optional.Wajam, C:\Program Files\WajInternetEn, Elimina al riavvio, [f456f23a8a0149ed7498f8c16c9853ad],
PUP.Optional.Wajam, C:\Program Files\WajInternetEn\dlls, Elimina al riavvio, [f456f23a8a0149ed7498f8c16c9853ad],
PUP.Optional.Wajam, C:\Program Files\WajInternetEn\logos, In quarantena, [f456f23a8a0149ed7498f8c16c9853ad],
PUP.Optional.Wajam, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajInternetEn, In quarantena, [4dfd7cb05e2dd36326e9efca56aed42c],
PUP.Optional.Wajam, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajInternetEn\Explore Social Search, In quarantena, [4dfd7cb05e2dd36326e9efca56aed42c],
PUP.Optional.Wajam, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajInternetEn\Explore Social Shopping, In quarantena, [4dfd7cb05e2dd36326e9efca56aed42c],
PUP.Optional.Wajam, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajInternetEn\Uninstall Wajam, In quarantena, [4dfd7cb05e2dd36326e9efca56aed42c],
PUP.Optional.OpenCandy, C:\Users\Utente Microsoft\AppData\Roaming\OpenCandy, In quarantena, [61e9b676e6a5f541112f0fe09171b34d],
PUP.Optional.OpenCandy, C:\Users\Utente Microsoft\AppData\Roaming\OpenCandy\BF7E489FE27E479C893EC480D0FF6AD7, In quarantena, [61e9b676e6a5f541112f0fe09171b34d],
PUP.Optional.NewPlayer, C:\Users\Utente Microsoft\AppData\Local\com\NewPlayer.exe_Url_o4dtzvfairwgx2aefcjiiv2m5z1q0lha, In quarantena, [f6547eae2269a591f13859bbff048878],
PUP.Optional.NewPlayer, C:\Users\Utente Microsoft\AppData\Local\com\NewPlayer.exe_Url_o4dtzvfairwgx2aefcjiiv2m5z1q0lha\2.1.1.7, In quarantena, [f6547eae2269a591f13859bbff048878],
PUP.Optional.PicShare, C:\Users\Utente Microsoft\AppData\Local\Google\Chrome\User Data\Default\ext_piccshare, In quarantena, [7ecc89a34d3eb77f9dd1f52054afbd43],

File: 0
(Nessun elemento nocivo rilevato)

Settori fisici: 0
(Nessun elemento nocivo rilevato)


(end)




Ora il log che ho fatto stasera 7 settembre

Malwarebytes Anti-Malware
www.malwarebytes.org

Data scansione: 07/09/2015
Ora scansione: 18:59
File di log: Log malwarebytes.txt
Amministratore: Sì

Versione: 2.1.8.1057
Database malware: v2015.09.07.03
Database rootkit: v2015.08.16.01
Licenza: Gratuito
Protezione da malware: Disattivata
Protezione da siti web nocivi: Disattivata
Auto-protezione: Disattivata

SO: Windows 7 Service Pack 1
CPU: x64
File system: NTFS
Utente: Utente Microsoft

Tipo di scansione: Ricerca elementi nocivi
Risultati: Completata
Elementi analizzati: 416668
Tempo impiegato: 39 min, 2 sec

Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Disattivata
Euristiche: Attivata
PUP: Avviso
PUM: Attivata

Processi: 0
(Nessun elemento nocivo rilevato)

Moduli: 0
(Nessun elemento nocivo rilevato)

Chiavi di registro: 0
(Nessun elemento nocivo rilevato)

Valori di registro: 0
(Nessun elemento nocivo rilevato)

Dati di registro: 1
PUP.Optional.Chatzum, HKU\S-1-5-21-886697645-454568397-1005252768-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://search.chatzum.com/, Buono: (www.google.com), Nocivo (http://search.chatzum.com/),Sostituito,[030cca634a41c76f67cb1b3e65a001ff]

Cartelle: 0
(Nessun elemento nocivo rilevato)

File: 0
(Nessun elemento nocivo rilevato)

Settori fisici: 0
(Nessun elemento nocivo rilevato)


(end)


Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 20:36:39, on 07/09/2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)


Boot mode: Safe mode

Running processes:
D:\Programmi scaricati\Aiutamici\Hijack this_Portable\HijackThis_Portable\HijackThisPortable\HijackThisPortable.exe
D:\Programmi scaricati\Aiutamici\Hijack this_Portable\HijackThis_Portable\HijackThisPortable\App\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Guida per l'accesso a Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe
O4 - HKLM\..\Run: [IDProtect Monitor] "C:\Program Files (x86)\Athena\IDProtect Client\Utils\IDProtect Monitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [RealDownloader] C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R265 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBNE.EXE /FU "C:\Users\UTENTE~1\AppData\Local\Temp\E_SB98.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_D201AD599CEEA55B105D9C25124D4732] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIZIO DI RETE')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe
O4 - Global Startup: RealTimes.lnk = C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpsystray.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Garmin Core Update Service - Garmin Ltd or its subsidiaries - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyEpson Portal Service - SEIKO EPSON CORPORATION - C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RealPlayer Update Service (RealPlayerUpdateSvc) - Unknown owner - C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
O23 - Service: RealTimes Desktop Service - RealNetworks, Inc. - c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Intel(R) Turbo Boost Technology Monitor (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13445 bytes




cbbusto
Inviato: Monday, September 07, 2015 11:08:47 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Mbam ha eliminato alcuni dirottatori, dal log di HJT ci sono delle righe fa fixare ed eliminare.
La scansione con JRT l'hai fatta ?
Non vedo nessun antivirus, magari è stato disattivato ??? cosa usi.

Chiudi tutti i programmi e disconnesso da internet,
Lancia HijackThis e clicca sul secondo pulsante Do a system scan only
inserisci il segno di spunta nel quadratino davanti alle righe sotto elencate, una volta seleziona clicca il tasto
Fix checked per procedere all'eliminazione, comparirà una finestra clicca su SI per accettare e l'operazione è conclusa.

Ti preciso che eliminando le voci 04, i programmi non vengono toccati ma viene solo disattivato l'Avvio automatico, inutile......basterebbe solo l'antivirus.

Ricorda che Hijackthis deve essere avviato da una cartella a lui dedicata meglio sul desktop. Solo così Hijackthis creerà copie di backup di quello che viene eliminato prima di apportare modifiche, così in caso di inconvenienti si possono reinstallare.

O1 - Hosts: 0.0.0.1 mssplus.mcafee.com

O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll

O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll

O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot

O4 - HKLM\..\Run: [RealDownloader] C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe

O4 - HKCU\..\Run: [EPSON Stylus Photo R265 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBNE.EXE /FU "C:\Users\UTENTE~1\AppData\Local\Temp\E_SB98.tmp" /EF "HKCU"

O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_D201AD599CEEA55B105D9C25124D4732] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window

O4 - Global Startup: RealTimes.lnk = C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpsystray.exe
Fai una pulizia con Ccleaner compreso il Registro, per il registro spunta tutte le voci, acconsenti al backup quando richiesto.
Ciao


clidio
Inviato: Tuesday, September 08, 2015 7:42:27 PM
Rank: AiutAmico

Iscritto dal : 4/24/2008
Posts: 123
Carissimo cbbusto ti ringrazio infinitamente di mettere a mia disposizione il tuo sapere, ho fatto come mi hai detto, la scansione con JRT non l'ho fatta, perchè quando clicco sul tuo link mi apre una pagina dove mi da un'errore e quindi non trovo nessun programma, come antivirus uso Microsoft security Essentials, cliccando sulla barra degli strumenti vedo l'icona dell'antivirus verde, quindi do per scontato che stia vigilando sul computer, se c'è un altro modo per controllare se l'antivirus è in funzione ti prego di dirmelo. Ti ringrazio di nuovo per aiutarmi a risolvere il mio problema Applause Applause ciao
cbbusto
Inviato: Tuesday, September 08, 2015 10:30:55 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Per l'antivirus va bene così quando l'icona è verde è attivo, MSE è ottimo, la mia era solo una curiosità non vedendolo nel log.
Per JRT hai ragione si tratta di un link vecchio, chiedo scusa errore mio, scaricalo da qui:
http://download.html.it/page/download/?sw=91342
Se hai risolto sono contento, se c'è qualche altro problema chiedi pure.
Dimmi cosa trova jrt.
Ciao
giza
Inviato: Wednesday, September 09, 2015 9:46:53 AM

Rank: AiutAmico

Iscritto dal : 10/27/2006
Posts: 9,618
per sandboxie qui c'è il programma e le spiegazioni
http://software.aiutamici.com/software?ID=80327

in pratica quando lo apri puoi navigare tranquillo anche se esce l'avviso della polizia o altri virus, perchè quando lo chiudi sul pc non rimane niente.
clidio
Inviato: Wednesday, September 09, 2015 6:31:18 PM
Rank: AiutAmico

Iscritto dal : 4/24/2008
Posts: 123
Ecco cosa ha trovato JRT
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.0 (08.31.2015:1)
OS: Windows 7 Home Premium x64
Ran by Utente Microsoft on 09/09/2015 at 18:27:15,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Successfully deleted: [Service] drvagent64 [Reboot required]



~~~ Tasks



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{71576546-354D-41C9-AAE8-31F2EC22BF0D}
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_D201AD599CEEA55B105D9C25124D4732



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{71576546-354D-41C9-AAE8-31F2EC22BF0D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{C920E44A-7F78-4E64-BDD7-A57026E7FEB7}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C920E44A-7F78-4E64-BDD7-A57026E7FEB7}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{C920E44A-7F78-4E64-BDD7-A57026E7FEB7}



~~~ Files

Successfully deleted: [File] C:\Program Files (x86)\GUT39C7.tmp
Successfully deleted: [File] C:\Users\Utente Microsoft\Appdata\Local\google\chrome\user data\default\local storage\hxxps_www.superfish.com_0.localstorage-journal



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{0A1A84EC-5DF1-420C-9A6E-C595FC788BBE}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{0A8F93D1-DE51-4AB7-84F6-2F48F4B08F4D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{0C126306-F11A-4662-981A-D0CF1B8D6F99}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{11812ABC-AD02-405E-ADDF-84F7BDA11E06}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{11E42B4D-10A4-46DE-BE93-90ACD017A217}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{193F8B99-FAC6-4C5B-AFD9-B527BAD8F33D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{1D176C58-7022-4BCB-8708-453B37F53F03}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{1D6B208F-CA92-406B-A2DE-155E5D34B98F}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{1E4C4C0D-2491-49FA-8477-1B60B22F2475}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{22C2249F-8ED2-4D40-A519-70439F6CE4D9}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{287EED41-B964-4B70-A309-8B6C9108CDA1}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{2A3FAFC4-81A4-4ACA-BAE9-67FD632264BF}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{2D055FCE-59C3-4FC2-8BAD-1A2DCD4BB191}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{2EFB5A48-E01A-4023-AE2C-3C260A2DD22A}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{30292DFA-FC60-45AC-ADFF-F07C3BF99FAB}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{310DAF01-3AB6-420A-B493-5E5B74139C5F}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{319788FB-1DB1-472D-A079-A93257C48F8D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{32CDDBC1-5356-4199-B400-F4B50DD68F93}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{3308B60B-B163-4DCC-877B-1F776DEBA79D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{3548E88A-9FF1-45EE-A42E-D327551B950D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{378C4E29-B170-4957-841D-C312A319B245}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{3BA24D3B-5BB8-4D47-B4C4-DF500CEB9C4B}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{3D0FB498-1FE8-4F9C-A2F3-B630272C7572}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{4165FACD-5E5C-4D43-B6FE-52AF8F31724D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{42C6F77D-7A8A-48CB-99BD-FDD27383B459}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{45E3B7A4-C085-4B91-8ECE-39B2F6439395}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{4B47DCF8-A2B8-4D86-AEC1-B0673E0205EB}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{4BBDAF7A-8A92-4AB6-8D84-E3A70C5CE245}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{4C2AB771-4AA2-4C6B-81AC-37984111DCEF}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{4C5D1397-0739-4159-B9E9-16A953213C97}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{4CA8048F-1F68-4C09-B411-1717D956AF3D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{51D2C4B7-57F5-41F7-A02E-59619EDFAE87}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{528BB46E-DDE9-44A8-9C69-A96BB92CD1FE}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{53626686-9BCE-4446-80CB-80DBC0ED56EA}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{53ACB687-127C-4744-A90D-2C3A886C2B1B}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{5418CD75-D2E2-4AEE-9916-FF3B1647561D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{54265FCE-D3F2-4DC5-A91B-F1633FAF2228}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{556C61A3-4822-4B39-BD02-DA7841AAB088}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{557F2E30-AD60-4A2F-82F0-E6A83D8B6B90}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{57744C95-72BA-4308-B420-BD816F2BCF6B}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{592A01E4-927B-49B9-9380-22B7801746D9}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{5B7753C3-C9A2-4303-9EAC-123D505F4619}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{5CC85CA9-383D-4131-9D30-08251CAB446E}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{5D218BDD-B4D8-400C-B3D8-BB97E290A2E7}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{5F6C989F-1FA0-4E2E-A5D8-E48BE5681F52}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{60F4D6DE-C518-488F-A183-2D8EF33E20A7}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{626756FE-FE1F-4C3B-9F25-AB4681D27DF4}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{62ABFFBD-1AC8-4987-BA6F-E88A555A09F8}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{646518E0-9B48-4E73-90ED-8927C7F700A6}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{6AC062AF-E16F-43C5-B439-1B12F5999A38}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{6C4CA3BA-02CD-4403-BAE2-1E0510268F43}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{7003EB5D-1699-43AD-AC03-4FFF66B545DB}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{717DCE93-D7B9-47FD-90ED-32FDBF9DCCBD}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{77B7AB93-9417-43FC-98DF-15A3099EEDFE}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{77C134BD-1744-49BB-A90C-0FF47C534ACB}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{797FBA78-8657-4BE5-99E7-888CB91393F4}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{7E9A488C-F815-4E5C-89EA-2F289FC32A3B}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{840A171F-CB14-417A-B6D4-DFE51958FFE3}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{862CB165-D7DC-4976-B2CA-D5A039BB84BD}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{8769495B-40CA-4028-9EAD-B3ACE5A7CCD1}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{8801C248-E05F-4CAE-A303-4590AC90DFE0}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{88C85A9B-FD35-4310-971E-32AE16009EF2}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{8A454FD8-A6FC-4105-A7A2-E34419519BD9}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{8B30CE43-27C9-468F-AF23-6110DFC1DD0E}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{8B34013B-864D-46B7-816E-E3541E0F0910}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{8D20A4AC-C262-41FE-B3A6-A5537D399CB7}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{8D703130-9312-4BB8-8568-8B702C24BFD1}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{8F051AEB-FD5A-486F-8404-F94F5B2A04F6}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{95008977-56D8-46BF-8127-4DD6B8CC64C6}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{95C41381-8AD7-45AD-AB58-4F2EDAE3BE4B}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{9C28F65B-802F-493E-B767-E9D2D69EC480}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{9C7B430B-0C68-4837-AEBE-F23D5BDB47D4}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{A307E3EB-33D8-424D-95E8-70A1ED71A1BD}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{A4E581DA-F6BC-4EAB-88DF-F62C7A3ADAD2}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{A7B036D6-690D-47C1-99CD-3ED11A8C6CD3}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{A7C4F889-777A-4EBB-A2CD-AF3257427A51}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{AA486E3C-896D-4CCA-B047-8D068BF8A386}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{AD674290-56F6-4A8D-8E1C-70416114451D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{AEDB53A9-1D2F-4CA2-8570-5D591F2D63AE}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{AF1F6743-8C5C-42C3-9E94-71AE49E20B71}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{AF495E6A-03ED-44BE-BB82-118D39544144}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{AFD1D6C7-9A1A-491A-8619-004382F76B78}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{B0595215-D84D-4400-8429-9BC5BFF3ECD0}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{B3549AA5-D824-4F3D-88EF-3464DE8A48E3}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{B37141AC-A373-4475-B5D5-12487C37A356}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{B8EAD685-5C37-4FB1-891C-C67173A7FBBE}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{B94FFC81-7407-47DB-81AC-C1417E1399C2}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{BB12266F-3074-4F62-A572-C96DAEDE55A5}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{BB785A22-0C43-4CE3-BD7C-21092AFED99F}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{C3F079C1-3307-4917-A841-8F212512A373}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{C58AE221-8A81-4626-8B69-EC8BE7E39B7C}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{C721B7A5-25AD-494B-B2FE-E63F2796EBA9}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{CA52BBD7-2CCA-4CED-8ACF-4F36A9CD903D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{CBF4F6CA-71FF-4DB1-8D4B-C2263031EC67}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{CD4B6393-0648-4886-8F81-19B8D3FB9C36}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{D45B64A5-4187-4D38-9337-F8E7572BA67F}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{DE7912C6-418E-4BC3-8FDD-CDECAB940F7E}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{E2A10B49-DB3E-4CA5-ABC9-98D1E1952356}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{E6995DC1-ABA1-4C3B-B899-8550FAE5B19F}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{E8C9B445-EE43-4B55-8874-C09622A0454E}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{EA4939D3-6241-4FE8-A54F-022C3F2E65D9}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{EAAEC878-1937-42F1-B24D-E9E79192B492}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{EC120483-BAD9-49AB-9B91-0B6B97EC3C66}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{EC3E6817-4072-4076-9AFA-3E4FD28B76C9}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{ED51DC77-5CAF-4E27-9325-9906A7A7A073}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{EF952244-F750-43D7-8763-02DB84CB4C3B}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{F2D84777-B12B-45EA-889E-268A5089DCA0}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{F70E5C5C-FBAE-4E78-98D7-2DA73483023D}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{FC47CA19-0040-444A-8B4D-6E54E76ABA39}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{FEC8C55D-51F4-4680-89BD-D757708CE53C}
Successfully deleted: [Empty Folder] C:\Users\Utente Microsoft\Appdata\Local\{FF52CDD1-F3BF-4CD1-AA12-4BBA3CC8C6E4}
Successfully deleted: [Folder] C:\Program Files (x86)\myfree codec
Successfully deleted: [Folder] C:\Users\Utente Microsoft\Appdata\Local\com
Successfully deleted: [Folder] C:\Users\Utente Microsoft\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\Users\Utente Microsoft\Appdata\Local\pc_drivers_headquarters



~~~ Chrome


[C:\Users\Utente Microsoft\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Utente Microsoft\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Utente Microsoft\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Utente Microsoft\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09/09/2015 at 18:31:47,13
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
clidio
Inviato: Wednesday, September 09, 2015 6:54:22 PM
Rank: AiutAmico

Iscritto dal : 4/24/2008
Posts: 123
Giza ho scaricato sanboxie come mi hai consigliato tu lo sto provando mi sembra che vada più lentamente di google crome, è normale che quando si apre il brouser sia con la stessa grafica di crome?
chiarapini
Inviato: Wednesday, September 09, 2015 7:15:18 PM

Rank: AiutAmico

Iscritto dal : 1/7/2008
Posts: 3,768
Scusate se m'intrometto...tempo fa usavo Sandboxie, quindi ti si dovrebbe aprire il browser che tu usi normalmente , con una cornice gialla intorno che ti avvisa che sei ''protetto''.
giza
Inviato: Wednesday, September 09, 2015 8:31:07 PM

Rank: AiutAmico

Iscritto dal : 10/27/2006
Posts: 9,618
si è normale come dice chiarap. se vai sul bordo compare un contorno giallo.
clidio
Inviato: Thursday, September 10, 2015 9:27:13 PM
Rank: AiutAmico

Iscritto dal : 4/24/2008
Posts: 123
Perfetto allora è tutto ok, infatti ho un bordo giallo sul brouser che di solito adopero, grazie a tutti della dritta
CiaoApplause Applause
giza
Inviato: Thursday, September 10, 2015 9:54:01 PM

Rank: AiutAmico

Iscritto dal : 10/27/2006
Posts: 9,618
se lo ribecchi e se proprio non vuole chiudersi control/alt/canc
clidio
Inviato: Saturday, September 12, 2015 10:00:04 AM
Rank: AiutAmico

Iscritto dal : 4/24/2008
Posts: 123
E' proprio quello che facevo e chiudevo da gestione attività.
giza
Inviato: Saturday, September 12, 2015 3:06:09 PM

Rank: AiutAmico

Iscritto dal : 10/27/2006
Posts: 9,618
fatto con sndboxie non ti becchi niente, se lo facevi col browser normale ormai i virus erano entrati
clidio
Inviato: Sunday, September 20, 2015 8:11:47 PM
Rank: AiutAmico

Iscritto dal : 4/24/2008
Posts: 123
Scusami Giza, sto adoperando sndboxie e nonostante a fine navigazione cancello l'area virtuale, quando lo riapro mi dice che l'area è piena e mi chiede di copiare il contenuto negli appunti, cosa devo fare? se copio negli appunti tanto poi il contenuto viene cancellato ugualmente, ma non capisco perchè mi dica così
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.