ti posto il JRT
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 10 Pro x64
Ran by IO-SUPER (Administrator) on 21/11/2016 at 12:58:28,83
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 5
Successfully deleted: C:\Users\IO-SUPER\AppData\Local\amigo (Folder)
Successfully deleted: C:\Users\IO-SUPER\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\amigo.lnk (Shortcut)
Successfully deleted: C:\Users\IO-SUPER\AppData\Roaming\Mozilla\Firefox\Profiles\xoflq5sh.default\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7} (Folder)
Successfully deleted: C:\Users\IO-SUPER\AppData\Roaming\Mozilla\Firefox\Profiles\xoflq5sh.default\searchplugins\mailru.xml (File)
Successfully deleted: C:\WINDOWS\system32\Tasks\FileSystemDriver (Task)
Deleted the following from C:\Users\IO-SUPER\AppData\Roaming\Mozilla\Firefox\Profiles\xoflq5sh.default\prefs.js
user_pref(browser.search.defaultenginename,
Поиск@Mail.Ru);
user_pref(browser.search.selectedEngine,
Поиск@Mail.Ru);
user_pref(browser.startup.homepage, hxxp://mail.ru/cnt/10445?gp=818407);
user_pref(extensions.homepage@mail.ru.go_metric_url, hxxp://go.mail.ru/distib/mark/?product_id=%7BE2F11CB8-1E09-4FEB-83B2-D0A7DD0CD132%7D&install_id=%7B0F83BE55-42A1-4443-B
user_pref(extensions.homepage@mail.ru.install_id, {0F83BE55-42A1-4443-B9F9-8013047BEF61});
user_pref(extensions.homepage@mail.ru.mrds_metric_url, hxxp://mrds.mail.ru/update/2/version.txt?type=product_online_metric&product_id=%7BE2F11CB8-1E09-4FEB-83B2-D0A7DD0CD13
user_pref(extensions.homepage@mail.ru.partner_product_online_url, hxxp://aztghygvfnzwhp.anglesoftly.ru/affect?hetag=ecf7368fd5753032d3eddc13e0753b77&guid={guid}&did=2599482
user_pref(extensions.homepage@mail.ru.product_id, {E2F11CB8-1E09-4FEB-83B2-D0A7DD0CD132});
user_pref(extensions.homepage@mail.ru.product_type, ff_xtnhp);
user_pref(extensions.homepage@mail.ru.rfr, 818407);
user_pref(extensions.search@mail.ru.go_metric_url, hxxp://go.mail.ru/distib/mark/?product_id=%7B96BD79DC-ACCD-42E3-8B44-F69C118ABCFD%7D&install_id=%7B0F83BE55-42A1-4443-B9F
user_pref(extensions.search@mail.ru.install_id, {0F83BE55-42A1-4443-B9F9-8013047BEF61});
user_pref(extensions.search@mail.ru.mrds_metric_url, hxxp://mrds.mail.ru/update/2/version.txt?type=product_online_metric&product_id=%7B96BD79DC-ACCD-42E3-8B44-F69C118ABCFD%
user_pref(extensions.search@mail.ru.partner_product_online_url, hxxp://aztghygvfnzwhp.anglesoftly.ru/affect?hetag=ecf7368fd5753032d3eddc13e0753b77&guid={guid}&did=259948201
user_pref(extensions.search@mail.ru.product_id, {96BD79DC-ACCD-42E3-8B44-F69C118ABCFD});
user_pref(extensions.search@mail.ru.product_type, ff_xtndse);
user_pref(extensions.search@mail.ru.rfr, 811014);
user_pref(extensions.{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.go_metric_url, hxxp://go.mail.ru/distib/mark/?product_id=%7B74887E0C-4671-41DD-ABFC-865E6FC7872E%7D&install_id=%
user_pref(extensions.{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.mrds_metric_url, hxxp://mrds.mail.ru/update/2/version.txt?type=product_online_metric&product_id=%7B74887E0C-4671
user_pref(keyword.URL, hxxp://go.mail.ru/distib/ep/?product_id=%7BE2BE258D-290C-459B-B110-6A534CDA3272%7D&gp=811014);
Registry: 1
Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\amigo (Registry Value)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21/11/2016 at 13:00:36,51
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~