Ho eseguito le tue istruzioni e spero che ora sia tutto risolto
Per quanto riguarda l'antivirus uso Defender, in passato utilizzavo avira, probabilmente dopo averlo disinstallato è rimasto qualcosa.
Vorrei allegare i log ma non so come fare per cui ti copio i log:
====================================================
Malwarebytes
www.malwarebytes.com-Dettagli log-
Data scansione: 27/01/18
Ora scansione: 16:25
File di log: 55533f6e-0376-11e8-8427-b8aeed7d59fd.json
Amministratore: Sì
-Informazioni software-
Versione: 3.3.1.2183
Versione componenti: 1.0.262
Aggiorna versione pacchetto: 1.0.3797
Licenza: Trial
-Informazioni sistema-
SO: Windows 10 (Build 16299.192)
CPU: x64
File system: NTFS
Utente: DESKTOP-R9H00RN\gipan
-Riepilogo scansione-
Tipo di scansione: Ricerca elementi nocivi
Risultati: Completata
Elementi analizzati: 362416
Minacce rilevate: 73
Minacce messe in quarantena: 0
(Nessun elemento nocivo rilevato)
Tempo impiegato: 1 ore, 42 min, 17 sec
-Opzioni di scansione-
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Attivata
Analisi euristica: Attivata
PUP: Rilevare
PUM: Rilevare
-Dettagli scansione-
Processo: 3
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, Nessuna azione intrapresa, [1138], [398206],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCTRAY.EXE, Nessuna azione intrapresa, [1138], [380353],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, Nessuna azione intrapresa, [1138], [380352],1.0.3797
Modulo: 6
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, Nessuna azione intrapresa, [1138], [398206],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCTRAY.EXE, Nessuna azione intrapresa, [1138], [380353],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, Nessuna azione intrapresa, [1138], [380352],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\OFCOMMON.DLL, Nessuna azione intrapresa, [1138], [396386],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\OFCOMMON.DLL, Nessuna azione intrapresa, [1138], [396386],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\OFCOMMON.DLL, Nessuna azione intrapresa, [1138], [396386],1.0.3797
Chiave di registro: 8
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ASC11_PerformanceMonitor, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{FE7D0FD2-A29D-4064-B3DD-2C4ADD85416B}, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{FE7D0FD2-A29D-4064-B3DD-2C4ADD85416B}, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ASC11_SkipUac_gipan, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{CF2694C2-2310-4787-BD7E-A7F4AAD31805}, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{CF2694C2-2310-4787-BD7E-A7F4AAD31805}, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.InstallCore, HKU\S-1-5-21-874398403-923202251-1869831456-1001\SOFTWARE\csastats, Nessuna azione intrapresa, [2], [260986],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AdvancedSystemCareService11, Nessuna azione intrapresa, [1138], [380352],1.0.3797
Valore di registro: 3
PUP.Optional.AdvancedSystemCare, HKU\S-1-5-21-874398403-923202251-1869831456-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ADVANCED SYSTEMCARE 11, Nessuna azione intrapresa, [1138], [380353],1.0.3797
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Nessuna azione intrapresa, [207], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Nessuna azione intrapresa, [207], [-1],0.0.0
Dati di registro: 0
(Nessun elemento nocivo rilevato)
Flusso di dati: 0
(Nessun elemento nocivo rilevato)
Cartella: 4
PUP.Optional.WinYahoo.Generic, C:\PROGRAMDATA\{3E81FBE2-B4C3-7124-3205-EF66A84764A8}, Nessuna azione intrapresa, [1122], [343986],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\USERS\GIPAN\APPDATA\LOCAL\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\USERS\GIPAN\APPDATA\LOCAL\SPOILAGEPRECOLLEGE, Nessuna azione intrapresa, [8098], [431028],1.0.3797
File: 49
PUP.Optional.WinYahoo.Generic, C:\PROGRAMDATA\{3E81FBE2-B4C3-7124-3205-EF66A84764A8}\dora, Nessuna azione intrapresa, [1122], [343986],1.0.3797
PUP.Optional.WinYahoo.Generic, C:\ProgramData\{3E81FBE2-B4C3-7124-3205-EF66A84764A8}\hdat1, Nessuna azione intrapresa, [1122], [343986],1.0.3797
PUP.Optional.WinYahoo.Generic, C:\ProgramData\{3E81FBE2-B4C3-7124-3205-EF66A84764A8}\hdat2, Nessuna azione intrapresa, [1122], [343986],1.0.3797
PUP.Optional.WinYahoo.Generic, C:\ProgramData\{3E81FBE2-B4C3-7124-3205-EF66A84764A8}\linodo, Nessuna azione intrapresa, [1122], [343986],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\USERS\GIPAN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\USER PINNED\TASKBAR\Advanced SystemCare 11.lnk, Nessuna azione intrapresa, [1138], [380340],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\MD.XML, Nessuna azione intrapresa, [1798], [405192],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\Triszunity.tst, Nessuna azione intrapresa, [1798], [405188],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\NOAH.DAT, Nessuna azione intrapresa, [1798], [405194],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\AGENT.DAT, Nessuna azione intrapresa, [1798], [405184],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\WINDOWS\SYSTEM32\TASKS\ASC11_PerformanceMonitor, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\WINDOWS\SYSTEM32\TASKS\ASC11_SkipUac_gipan, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, Nessuna azione intrapresa, [1138], [398206],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\MAIN.DAT, Nessuna azione intrapresa, [1798], [442901],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCTRAY.EXE, Nessuna azione intrapresa, [1138], [380353],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, Nessuna azione intrapresa, [1138], [380352],1.0.3797
PUP.Optional.WinYahoo, C:\USERS\GIPAN\APPDATA\LOCAL\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HOWTOREMOVE\HOWTOREMOVE.HTML, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\chromium-min.jpg, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\control panel-min-min.JPG, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\down.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\ff menu.JPG, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\ff search engine-min.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\hp-min ff.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\hp-min ie.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\search engine.gif, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\setup pages.gif, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\sp-min.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\start-min.jpg, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\up.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\bapi.dat, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\cori, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\info.dat, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\redo, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\siri, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\uninst.dat, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.MyStartTB.ShrtCln, C:\USERS\GIPAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8RY7GUDR.DEFAULT\PREFS.JS, Nessuna azione intrapresa, [10373], [301376],1.0.3797
PUP.Optional.Linkury.ACMB1, C:\USERS\GIPAN\APPDATA\ROAMING\INSTALLATIONCONFIGURATION.XML, Nessuna azione intrapresa, [207], [302554],1.0.3797
PUP.Optional.WinYahoo, C:\USERS\GIPAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8RY7GUDR.DEFAULT\SEARCHPLUGINS\YAHOO! POWERED.XML, Nessuna azione intrapresa, [56], [302726],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\CONFIG.XML, Nessuna azione intrapresa, [1798], [405168],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\USERS\GIPAN\APPDATA\LOCAL\SPOILAGEPRECOLLEGE\RKEY.DAT, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\Users\gipan\AppData\Local\SpoilagePrecollege\Aliexpress.smenu.URL, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\Users\gipan\AppData\Local\SpoilagePrecollege\Aliexpress.tbar.URL, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\Users\gipan\AppData\Local\SpoilagePrecollege\Booking.smenu.URL, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\Users\gipan\AppData\Local\SpoilagePrecollege\Booking.tbar.URL, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\Users\gipan\AppData\Local\SpoilagePrecollege\SodasAnisic.dat, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\OFCOMMON.DLL, Nessuna azione intrapresa, [1138], [396386],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASC.EXE, Nessuna azione intrapresa, [1138], [396386],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAMDATA\IOBIT\IOBIT UNINSTALLER\DOWNLOADER\UN7\ADVANCED SYSTEMCARE_IU.EXE, Nessuna azione intrapresa, [1138], [396386],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\WINDOWS\SYSTEM32\REGISTRYDEFRAGBOOTTIME.EXE, Nessuna azione intrapresa, [1138], [396386],1.0.3797
Adware.FusionCore, C:\USERS\GIPAN\DESKTOP\PROGRAMMI INSTALLATI\EMULE0.60V2.EXE, Nessuna azione intrapresa, [164], [320181],1.0.3797
Settore fisico: 0
(Nessun elemento nocivo rilevato)
(end)
=========================================================
Malwarebytes
www.malwarebytes.com-Dettagli log-
Data scansione: 27/01/18
Ora scansione: 16:25
File di log: 55533f6e-0376-11e8-8427-b8aeed7d59fd.json
Amministratore: Sì
-Informazioni software-
Versione: 3.3.1.2183
Versione componenti: 1.0.262
Aggiorna versione pacchetto: 1.0.3797
Licenza: Trial
-Informazioni sistema-
SO: Windows 10 (Build 16299.192)
CPU: x64
File system: NTFS
Utente: DESKTOP-R9H00RN\gipan
-Riepilogo scansione-
Tipo di scansione: Ricerca elementi nocivi
Risultati: Completata
Elementi analizzati: 362416
Minacce rilevate: 73
Minacce messe in quarantena: 0
(Nessun elemento nocivo rilevato)
Tempo impiegato: 1 ore, 42 min, 17 sec
-Opzioni di scansione-
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Attivata
Analisi euristica: Attivata
PUP: Rilevare
PUM: Rilevare
-Dettagli scansione-
Processo: 3
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, Nessuna azione intrapresa, [1138], [398206],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCTRAY.EXE, Nessuna azione intrapresa, [1138], [380353],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, Nessuna azione intrapresa, [1138], [380352],1.0.3797
Modulo: 6
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, Nessuna azione intrapresa, [1138], [398206],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCTRAY.EXE, Nessuna azione intrapresa, [1138], [380353],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, Nessuna azione intrapresa, [1138], [380352],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\OFCOMMON.DLL, Nessuna azione intrapresa, [1138], [396386],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\OFCOMMON.DLL, Nessuna azione intrapresa, [1138], [396386],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\OFCOMMON.DLL, Nessuna azione intrapresa, [1138], [396386],1.0.3797
Chiave di registro: 8
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ASC11_PerformanceMonitor, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{FE7D0FD2-A29D-4064-B3DD-2C4ADD85416B}, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{FE7D0FD2-A29D-4064-B3DD-2C4ADD85416B}, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ASC11_SkipUac_gipan, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{CF2694C2-2310-4787-BD7E-A7F4AAD31805}, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{CF2694C2-2310-4787-BD7E-A7F4AAD31805}, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.InstallCore, HKU\S-1-5-21-874398403-923202251-1869831456-1001\SOFTWARE\csastats, Nessuna azione intrapresa, [2], [260986],1.0.3797
PUP.Optional.AdvancedSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AdvancedSystemCareService11, Nessuna azione intrapresa, [1138], [380352],1.0.3797
Valore di registro: 3
PUP.Optional.AdvancedSystemCare, HKU\S-1-5-21-874398403-923202251-1869831456-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ADVANCED SYSTEMCARE 11, Nessuna azione intrapresa, [1138], [380353],1.0.3797
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Nessuna azione intrapresa, [207], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Nessuna azione intrapresa, [207], [-1],0.0.0
Dati di registro: 0
(Nessun elemento nocivo rilevato)
Flusso di dati: 0
(Nessun elemento nocivo rilevato)
Cartella: 4
PUP.Optional.WinYahoo.Generic, C:\PROGRAMDATA\{3E81FBE2-B4C3-7124-3205-EF66A84764A8}, Nessuna azione intrapresa, [1122], [343986],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\USERS\GIPAN\APPDATA\LOCAL\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\USERS\GIPAN\APPDATA\LOCAL\SPOILAGEPRECOLLEGE, Nessuna azione intrapresa, [8098], [431028],1.0.3797
File: 49
PUP.Optional.WinYahoo.Generic, C:\PROGRAMDATA\{3E81FBE2-B4C3-7124-3205-EF66A84764A8}\dora, Nessuna azione intrapresa, [1122], [343986],1.0.3797
PUP.Optional.WinYahoo.Generic, C:\ProgramData\{3E81FBE2-B4C3-7124-3205-EF66A84764A8}\hdat1, Nessuna azione intrapresa, [1122], [343986],1.0.3797
PUP.Optional.WinYahoo.Generic, C:\ProgramData\{3E81FBE2-B4C3-7124-3205-EF66A84764A8}\hdat2, Nessuna azione intrapresa, [1122], [343986],1.0.3797
PUP.Optional.WinYahoo.Generic, C:\ProgramData\{3E81FBE2-B4C3-7124-3205-EF66A84764A8}\linodo, Nessuna azione intrapresa, [1122], [343986],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\USERS\GIPAN\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\USER PINNED\TASKBAR\Advanced SystemCare 11.lnk, Nessuna azione intrapresa, [1138], [380340],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\MD.XML, Nessuna azione intrapresa, [1798], [405192],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\Triszunity.tst, Nessuna azione intrapresa, [1798], [405188],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\NOAH.DAT, Nessuna azione intrapresa, [1798], [405194],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\AGENT.DAT, Nessuna azione intrapresa, [1798], [405184],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\WINDOWS\SYSTEM32\TASKS\ASC11_PerformanceMonitor, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\WINDOWS\SYSTEM32\TASKS\ASC11_SkipUac_gipan, Nessuna azione intrapresa, [1138], [380341],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\MONITOR.EXE, Nessuna azione intrapresa, [1138], [398206],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\MAIN.DAT, Nessuna azione intrapresa, [1798], [442901],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCTRAY.EXE, Nessuna azione intrapresa, [1138], [380353],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASCSERVICE.EXE, Nessuna azione intrapresa, [1138], [380352],1.0.3797
PUP.Optional.WinYahoo, C:\USERS\GIPAN\APPDATA\LOCAL\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HOWTOREMOVE\HOWTOREMOVE.HTML, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\chromium-min.jpg, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\control panel-min-min.JPG, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\down.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\ff menu.JPG, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\ff search engine-min.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\hp-min ff.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\hp-min ie.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\search engine.gif, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\setup pages.gif, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\sp-min.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\start-min.jpg, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\HowToRemove\up.png, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\bapi.dat, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\cori, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\info.dat, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\redo, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\siri, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.WinYahoo, C:\Users\gipan\AppData\Local\{57C3619F-736B-0D27-1EF3-28CF3A9BD457}\uninst.dat, Nessuna azione intrapresa, [56], [302717],1.0.3797
PUP.Optional.MyStartTB.ShrtCln, C:\USERS\GIPAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8RY7GUDR.DEFAULT\PREFS.JS, Nessuna azione intrapresa, [10373], [301376],1.0.3797
PUP.Optional.Linkury.ACMB1, C:\USERS\GIPAN\APPDATA\ROAMING\INSTALLATIONCONFIGURATION.XML, Nessuna azione intrapresa, [207], [302554],1.0.3797
PUP.Optional.WinYahoo, C:\USERS\GIPAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8RY7GUDR.DEFAULT\SEARCHPLUGINS\YAHOO! POWERED.XML, Nessuna azione intrapresa, [56], [302726],1.0.3797
Adware.Linkury.Generic, C:\USERS\GIPAN\APPDATA\ROAMING\CONFIG.XML, Nessuna azione intrapresa, [1798], [405168],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\USERS\GIPAN\APPDATA\LOCAL\SPOILAGEPRECOLLEGE\RKEY.DAT, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\Users\gipan\AppData\Local\SpoilagePrecollege\Aliexpress.smenu.URL, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\Users\gipan\AppData\Local\SpoilagePrecollege\Aliexpress.tbar.URL, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\Users\gipan\AppData\Local\SpoilagePrecollege\Booking.smenu.URL, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\Users\gipan\AppData\Local\SpoilagePrecollege\Booking.tbar.URL, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.PriceFountain.TskLnk, C:\Users\gipan\AppData\Local\SpoilagePrecollege\SodasAnisic.dat, Nessuna azione intrapresa, [8098], [431028],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\OFCOMMON.DLL, Nessuna azione intrapresa, [1138], [396386],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAM FILES (X86)\IOBIT\ADVANCED SYSTEMCARE\ASC.EXE, Nessuna azione intrapresa, [1138], [396386],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\PROGRAMDATA\IOBIT\IOBIT UNINSTALLER\DOWNLOADER\UN7\ADVANCED SYSTEMCARE_IU.EXE, Nessuna azione intrapresa, [1138], [396386],1.0.3797
PUP.Optional.AdvancedSystemCare, C:\WINDOWS\SYSTEM32\REGISTRYDEFRAGBOOTTIME.EXE, Nessuna azione intrapresa, [1138], [396386],1.0.3797
Adware.FusionCore, C:\USERS\GIPAN\DESKTOP\PROGRAMMI INSTALLATI\EMULE0.60V2.EXE, Nessuna azione intrapresa, [164], [320181],1.0.3797
Settore fisico: 0
(Nessun elemento nocivo rilevato)
(end)
==================================================================
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.8 (09.20.2016)
Operating System: Windows 10 Home x64
Ran by gipan (Administrator) on 27/01/2018 sab at 18:58:47.82
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 9
Successfully deleted: C:\ProgramData\iobit\driver booster (Folder)
Successfully deleted: C:\ProgramData\productdata (Folder)
Successfully deleted: C:\Users\gipan\AppData\Roaming\iobit\driver booster (Folder)
Successfully deleted: C:\Users\gipan\AppData\Roaming\Mozilla\Firefox\Profiles\8ry7gudr.default\user.js (File)
Successfully deleted: C:\Users\gipan\AppData\Roaming\productdata (Folder)
Successfully deleted: C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (gipan) (Task)
Successfully deleted: C:\WINDOWS\Tasks\Uninstaller_SkipUac_gipan.job (Task)
Successfully deleted: C:\Program Files (x86)\iobit\driver booster (Folder)
Successfully deleted: C:\WINDOWS\prefetch\FREEMAKEVC.EXE-BF7FE79F.pf (File)
Deleted the following from C:\Users\gipan\AppData\Roaming\Mozilla\Firefox\Profiles\8ry7gudr.default\prefs.js
user_pref(extensions.xpiState, {\app-profile\:{\abs@avira.com\:{\d\:\C:\\\\Users\\\\gipan\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\8ry7gudr.default
Registry: 1
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27/01/2018 sab at 19:06:51.57
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
grazie dei consigli