Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

virus awesomehp Opzioni
andreab
Inviato: Saturday, January 25, 2014 11:02:59 PM
Rank: AiutAmico

Iscritto dal : 2/10/2004
Posts: 95
ciao a tutti
nel portatile del mio amico aprendo internet i browser aprono questa pagina awesomehp.com
e utilizzare internet risulta impossibile per la sua lentezza.
volevo seguire le vostre istruzioni
1) MalwareBytes
2) Adwcleaner
3) Junkware
4) OTL
la scansione di MalwareBytes ha trovato più di 800 "infezioni" che ha rimosso.
ma durante la scansione di Adwcleaner il programma si pianta durante l'analisi dei browser edevo forzare la chiusura.
ho verificato di non avere dei browser aperti, come raccomandato, ma non ne trovo.

come posso fare?
posto la scansione di HijackThis
Grazie in anticipo
Andrea

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:54:12, on 25/01/2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
C:\Users\Luca\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Olympus\ib\olycamdetect.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HomeTab - {19a395c9-823b-4700-b817-396fc84ffb16} - C:\Users\Luca\AppData\Roaming\HomeTab\HomeTab.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: DataMngr - {978C7B0C-1709-4f9e-AE1C-95DC75079894} - C:\PROGRA~2\LPHANT~1\MediaBar\Datamngr\BROWSE~1.DLL
O2 - BHO: Wincore MediaBar - {9a95b751-bf3e-4ea8-a938-2d4d84cd4964} - C:\PROGRA~2\LPHANT~1\MediaBar\Datamngr\ToolBar\lpdtxmltbpi.dll
O2 - BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\coIEPlg.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: DataMngr - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~2\IMESHA~1\Mediabar\Datamngr\BROWSE~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HelloWorldBHO - {E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0} - C:\Program Files (x86)\Flowsurf\FlowSurf.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
O3 - Toolbar: Wincore MediaBar - {9a95b751-bf3e-4ea8-a938-2d4d84cd4964} - C:\PROGRA~2\LPHANT~1\MediaBar\Datamngr\ToolBar\lpdtxmltbpi.dll
O3 - Toolbar: HomeTab - {19a395c9-823b-4700-b817-396fc84ffb16} - C:\Users\Luca\AppData\Roaming\HomeTab\HomeTab.dll (file missing)
O3 - Toolbar: Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\coIEPlg.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe
O4 - HKLM\..\Run: [Olympus ib] "C:\Program Files (x86)\Olympus\ib\olycamdetect.exe" /Startup
O4 - HKLM\..\Run: [MDS_Menu] "C:\Program Files (x86)\Olympus\ib\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Olympus\ib" UpdateWithCreateOnce "Software\OLYMPUS\ib\1.0"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Luca\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIZIO DI RETE')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: I&nvia a OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {3f20b8e1-f256-4db1-a1e4-d0b1dc2ad3bb} - (no file)
O9 - Extra button: FlowSurf - {6CA2A4DE-483E-456B-8634-6445460D7097} - C:\Program Files (x86)\Flowsurf\FlowSurf.dll
O9 - Extra button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Controllo AcPreview) - file:///C:/Program%20Files%20(x86)/AutoCAD%20LT%202002%20Ita/AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC87F561-E529-45EE-A0CB-9000202B28A6}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{E463EBDA-9666-4C15-9C54-4B4F426A56E3}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: TrueSuiteService (FPLService) - HP - C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MgAssist Service (MgAssistService) - Unknown owner - C:\Program Files (x86)\Mobogenie\MgAssist.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: Norton Identity Safe (NCO) - Symantec Corporation - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Pos Service (PowerOffer Service) - PowerOfferService - C:\Users\Luca\AppData\Local\PosService\Pos.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Serv Updater (ServUpdater) - Unknown owner - C:\Users\Luca\AppData\Local\ServUpdater\ServiceUpd.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Software Upd (SoftwareUpd) - SoftwareUpdService - C:\Users\Luca\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16916 bytes
Sponsor
Inviato: Saturday, January 25, 2014 11:02:59 PM

 
cbbusto
Inviato: Sunday, January 26, 2014 12:50:41 AM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Ci sono ancora un po' di porcherie e poi un sacco di programmi inutili, è strano che ADWcleaner non funzioni hai seguito le istruzioni ? dovevi fare una scansione anche con JRT.
Avvia il pc in modalità provvisoria lanci HJT con tutto chiuso anche il browser e clicca sul secondo pulsante: Do a system scan only poi metti la spunta alle voci che ti indico e alla fine clic su Fix checked:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ 5T0_WD-WX31EB1RUS82RUS82

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ 5T0_WD-WX31EB1RUS82RUS82

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1390591622&from=amt&uid=WDCXWD3200BPVT- 60JJ5T0_WD-WX31EB1RUS82RUS82&q={searchTerms}

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1390591622&from=amt&uid=WDCXWD3200BPVT- 60JJ5T0_WD-WX31EB1RUS82RUS82&q={searchTerms}

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ 5T0_WD-WX31EB1RUS82RUS82

O2 - BHO: HomeTab - {19a395c9-823b-4700-b817-396fc84ffb16} - C:\Users\Luca\AppData\Roaming\HomeTab\HomeTab.dll (file missing)

O2 - BHO: Wincore MediaBar - {9a95b751-bf3e-4ea8-a938-2d4d84cd4964} - C:\PROGRA~2\LPHANT~1\MediaBar\Datamngr\ToolBar\lpdtxmltbpi.dll

O2 - BHO: HelloWorldBHO - {E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0} - C:\Program Files (x86)\Flowsurf\FlowSurf.dll

O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll

O3 - Toolbar: Wincore MediaBar - {9a95b751-bf3e-4ea8-a938-2d4d84cd4964} - C:\PROGRA~2\LPHANT~1\MediaBar\Datamngr\ToolBar\lpdtxmltbpi.dll

O3 - Toolbar: HomeTab - {19a395c9-823b-4700-b817-396fc84ffb16} - C:\Users\Luca\AppData\Roaming\HomeTab\HomeTab.dll (file missing)

O3 - Toolbar: Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\coIEPlg.dll

O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O4 - HKLM\..\Run: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"

O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe

O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe

O4 - HKLM\..\Run: [Olympus ib] "C:\Program Files (x86)\Olympus\ib\olycamdetect.exe" /Startup

O4 - HKLM\..\Run: [MDS_Menu] "C:\Program Files (x86)\Olympus\ib\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Olympus\ib" UpdateWithCreateOnce "Software\OLYMPUS\ib\1.0"

O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true

O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin

O4 - HKLM\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe

O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Luca\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver

O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIZIO LOCALE')

O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIZIO DI RETE')

O9 - Extra button: (no name) - {3f20b8e1-f256-4db1-a1e4-d0b1dc2ad3bb} - (no file)
Dopo le eliminazioni riavvia il pc in mod. normale.

Poi devi andare nei Servizi: clicca sul pulsante “Start“, digita “services.msc“, premi il tasto Invio.

Nella pagina dei servizi scorri l'elenco e cerca queste voci:
Pos Service (PowerOffer Service)
Serv Updater (ServUpdater)
Software Upd (SoftwareUpd)

Ad ogni voce fai doppio clic e poi nella finestra seguente in tipo di avvio metti DISABILITATO, OK ESCI.

Poi fai una pulizia con Ccleaner compreso il Registro, per il Registro spunta tutte le voci acconsenti al backup quando richiesto, sempre in Ccleaner vai in Strumenti Ripristino Sistema seleziona tutte le voci tranne l'ultima che non è selezionabile e rimane per sicurezza, poi clic su Rimuovi.

Adesso prova a fare queste scansioni, segui bene le istruzioni:

Scarica Adwcleaner sul desktop:
http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner
Chiudi tutti i browser (è importante IE,Firefox Chrome ecc...)
Clicca sul pulsante "Scan".
Finita la scansione clicca su "Clean"
Conferma con OK le varie finestre che ti compariranno.
Il pc si riavvierà, e uscirà il log con le eliminazioni.
Postalo qui. Vediamo se funziona.

Scarica Junkware Removal Tool sul desktop.
http://www.majorgeeks.com/mg/get/junkware_removal_tool,1.html
Disattiva temporaneamente l'antivirus per evitare potenziali conflitti.
Doppio click su JRT
Lo strumento si aprirà e avvierà la scansione del sistema.
Devi avere pazienza in quanto questo tool può richiedere del tempo per completare la scansione .
Al termine, un log (JRT.txt) viene salvato sul desktop e si aprirà automaticamente.
Postalo qui.
Tutte le scansioni vanno fatte in modalità NORMALE.

Dimmi come va il pc. Ciao







bingoo
Inviato: Sunday, January 26, 2014 1:27:14 AM

Rank: AiutAmico

Iscritto dal : 10/22/2013
Posts: 148
@cbbusto ciao :O) .... scusa se mi intrometto :O) personalmente proporrei .....

start ..... esegui ...... msconfig ....... avvio ...... e togli la spunta a tutti quei programmi che sono elencati da CBBUSTO NELLA POSIZIONE 04

spegni e riaccendi e fai tutto quello descritto da cbbusto IN MODALITà NORMALE quando da lui richiesto


ciao e buon lavoro

ps ..... se vedi che alcuni programmi chiedono di essere autorizzati , .............. NON CONSENTIRE
cbbusto
Inviato: Sunday, January 26, 2014 11:11:57 AM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
bingoo ha scritto:
@cbbusto ciao :O) .... scusa se mi intrometto :O) personalmente proporrei .....

start ..... esegui ...... msconfig ....... avvio ...... e togli la spunta a tutti quei programmi che sono elencati da CBBUSTO NELLA POSIZIONE 04

spegni e riaccendi e fai tutto quello descritto da cbbusto IN MODALITà NORMALE quando da lui richiesto


ciao e buon lavoro

ps ..... se vedi che alcuni programmi chiedono di essere autorizzati , .............. NON CONSENTIRE


Ciao nottambulo, va bene anche la tua soluzione anche se poi il risultato dovrebbe essere uguale, come vedi ascolto tutti e non ho preferenze, per me i consigli, se sono giusti, vanno sempre accettati.
Buona domenica. Speak to the hand
andreab
Inviato: Sunday, January 26, 2014 12:41:07 PM
Rank: AiutAmico

Iscritto dal : 2/10/2004
Posts: 95
ciao ho eseguito i suggerimenti di cbusto (quelli di bingo no perchè mi sono accordo solo alla fine del suo messaggio)
cmq
le operazioni di HJT e di CClenear sono andate a buon fine mentre ADWcleaner si pianta sempre sull'analisi dei browser.
eppure ho verificato e non ci sono browser aperti (IE e crome)
se apro internet ora mi sembra più veloce ma la pagina predefinita è sempre quella di awesomehp
Allego il log di JRT

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows 7 Home Premium x64
Ran by Luca on 26/01/2014 at 12:19:09,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\AboutURLs\\Tabs



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\sim-packages
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\babylonhelper.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\dnsbho.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\yontooieclient.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{28387537-E3F9-4ED7-860C-11E69AF4A8A0}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\apn dtx
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\babsolution
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bi
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\filescout
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\im
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\iminstaller
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\performersoft llc
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\qtrax
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\simplytech
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\torch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\wnlt
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\lyricsfinder
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\plus-hd-2.2
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\pricegong
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\simplytech
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1917911057-4261802172-2969938892-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1917911057-4261802172-2969938892-1001\Software\web assistant
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\omigaplussvc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\caphyon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\desksvc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\esafeseccontrol
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\torch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\web assistant
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\mediaplayer.graphicsutils
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\mediaplayer.graphicsutils.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\speedupmypc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\yontooieclient.api
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\yontooieclient.api.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\yontooieclient.layers
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\yontooieclient.layers.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\babylon_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\babylon_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\bundlesweetimsetup_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\bundlesweetimsetup_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\datamngrui_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\datamngrui_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\hometab_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\hometab_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iminent_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iminent_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\incredibartoolbar_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\incredibartoolbar_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\mybabylontb_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\mybabylontb_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\plus-hd-2_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\plus-hd-2_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetim_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetim_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetpacksupdatemanager_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetpacksupdatemanager_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\torchsetupfull_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\torchsetupfull_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\wajamupdater_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\wajamupdater_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\sweetim.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\torch.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\1clickdownload
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\esafeseccontrol
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\pricegong
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\search results toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchthewebarp
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{953aa732-9afb-49c9-84a4-7f96ca0a08da}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{a0c9df2b-89b5-4483-8983-18a68200f1b4}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{c3e85ee9-5892-4142-b537-bceb3dac4c3d}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ea8fa6be-29be-4af2-9352-841f83215eb0}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322302236}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660366306636}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220322302236}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660366306636}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660366306636}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_audacity_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_audacity_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_call-of-duty-4_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_call-of-duty-4_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_photo-booth-for-windows-7 (1)_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_photo-booth-for-windows-7 (1)_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_photo-booth-for-windows-7_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_photo-booth-for-windows-7_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_songr_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_songr_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_videospin_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_per_videospin_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660366306636}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_audacity_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_audacity_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_call-of-duty-4_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_call-of-duty-4_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_photo-booth-for-windows-7 (1)_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_photo-booth-for-windows-7 (1)_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_photo-booth-for-windows-7_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_photo-booth-for-windows-7_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_songr_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_songr_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_videospin_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_per_videospin_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3D0A4FC8-B8C4-4D97-9182-73FEE0900E0F}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FB1AE33B-8FFF-4975-A90D-CD66E7E0F10F}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{FB1AE33B-8FFF-4975-A90D-CD66E7E0F10F}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{978C7B0C-1709-4f9e-AE1C-95DC75079894}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{978C7B0C-1709-4f9e-AE1C-95DC75079894}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}



~~~ Files

Successfully deleted: [File] "C:\Users\Luca\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"
Successfully deleted: [File] "C:\Users\Luca\AppData\Roaming\microsoft\windows\start menu\programs\qtrax player.lnk"
Successfully deleted: [File] "C:\end"



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\esafe"
Successfully deleted: [Folder] "C:\ProgramData\sweetim"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\Users\Luca\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\Luca\AppData\Roaming\iminent"
Successfully deleted: [Folder] "C:\Users\Luca\AppData\Roaming\nosibay"
Successfully deleted: [Folder] "C:\Users\Luca\AppData\Roaming\performersoft"
Successfully deleted: [Folder] "C:\Users\Luca\AppData\Roaming\specialsavings"
Successfully deleted: [Folder] "C:\Users\Luca\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\local\torch"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\local\wajam"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\locallow\babylontoolbar"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\locallow\claro ltd"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\locallow\delta"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\locallow\minibar"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\locallow\pricegong"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\locallow\searchresultstb"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\locallow\simplytech"
Successfully deleted: [Folder] "C:\Users\Luca\appdata\locallow\sweetim"
Failed to delete: [Folder] "C:\Program Files (x86)\babylon"
Successfully deleted: [Folder] "C:\Program Files (x86)\bearshare applications"
Successfully deleted: [Folder] "C:\Program Files (x86)\chatzum toolbar"
Successfully deleted: [Folder] "C:\Program Files (x86)\file scout"
Successfully deleted: [Folder] "C:\Program Files (x86)\iminent"
Successfully deleted: [Folder] "C:\Program Files (x86)\mypc backup"
Successfully deleted: [Folder] "C:\Program Files (x86)\nosibay"
Successfully deleted: [Folder] "C:\Program Files (x86)\oapps"
Successfully deleted: [Folder] "C:\Program Files (x86)\optimizer pro"
Successfully deleted: [Folder] "C:\Program Files (x86)\pricegong"
Successfully deleted: [Folder] "C:\Program Files (x86)\singalong"
Successfully deleted: [Folder] "C:\Program Files (x86)\sweetim"
Successfully deleted: [Folder] "C:\Program Files (x86)\yontoo"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
Successfully deleted: [Folder] "C:\Windows\syswow64\arfc"
Successfully deleted: [Folder] "C:\Windows\syswow64\jmdp"
Successfully deleted: [Folder] "C:\Windows\syswow64\wnlt"
Successfully deleted: [Folder] "C:\Users\Luca\music\qtrax media library"
Successfully deleted: [Folder] "C:\Users\Luca\qtrax"
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{0DCD90A2-BECD-4D04-9CE5-A2EB308E3C85}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{26E2E039-2C46-4794-9EE9-A0787BCF8121}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{275F15C0-0ABA-41A8-81A0-AFC2604B9FC1}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{320793B5-07CA-4E6B-8331-10E2E5282D21}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{37A3DB8B-48C2-4B57-BA23-C14BEBFEA623}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{393A0A27-7E48-4403-B3EB-A525730AF814}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{3AB59063-7AB5-4CD5-A567-B0D78FE3A911}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{3C7E1963-7B4F-42CB-9462-C3F2D3958EE0}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{422D9EBC-22BF-4153-BE0E-448E0CD001BF}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{4593E60C-FF3D-48DC-B730-F3A5CC507A77}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{45C53A14-0012-4056-818E-8EC25BB905B8}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{4C19ABF3-5225-4686-AEE5-DEE109CFE5D8}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{52C71A24-4735-49D4-B899-DDE33ADF4300}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{5A8780D9-C59E-45A3-A1EC-C1DA4326F256}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{6029BE2E-D644-47F9-8B85-B002DEFFFCBE}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{64C4E521-A5EA-4063-8F99-810563D25C92}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{814EB260-18C9-4A18-AE40-DEC440ACDE58}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{831548EC-FEA2-4030-B1BA-F04C7A941C7A}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{A1A27B31-227A-4F82-AEA3-0B5AAC123FFD}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{ABD8C489-F742-484E-80D1-9FA980FF17D4}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{B16B06A5-A57C-4242-9130-4FAB93B6621A}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{CDD58592-5E20-41C4-992D-DB28836A959F}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{EB9EC1DB-2601-4A3A-BAF1-F76D3883E7F5}
Successfully deleted: [Empty Folder] C:\Users\Luca\appdata\local\{F886160B-5B01-4611-AA1A-FD9581B80784}



~~~ FireFox

Successfully deleted: [File] C:\user.js
Failed to delete: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\web search.xml"
Successfully deleted: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\web search.xml"
Successfully deleted: [File] C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\user.js
Successfully deleted: [File] C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\invalidprefs.js
Successfully deleted: [File] C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\searchplugins\babylon.xml
Successfully deleted: [File] C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\searchplugins\browserprotect.xml
Successfully deleted: [File] C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\searchplugins\delta.xml
Successfully deleted: [File] C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\searchplugins\safesearch.xml
Successfully deleted: [File] C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\searchplugins\web search.xml
Successfully deleted: [Folder] C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\smartbar
Successfully deleted: [Folder] C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\extensions\crossriderapp12765@crossrider.com
Successfully deleted: [Folder] C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\singalong@xenophesoft.com
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\statuswinks@statuswinks
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\statuswinks@statuswinks
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\{8a9386b4-e958-4c4c-adf4-8f26db3e4829}
Successfully deleted the following from C:\Users\Luca\AppData\Roaming\mozilla\firefox\profiles\jmw2er9c.default\prefs.js

user_pref("CT2851640.1000234.TWC_TMP_city", "MILANO");
user_pref("CT2851640.1000234.TWC_TMP_country", "IT");
user_pref("CT2851640.1000234.TWC_country", "ITALY");
user_pref("CT2851640.1000234.TWC_locId", "USNY3957");
user_pref("CT2851640.1000234.TWC_location", "Italy, NY");
user_pref("CT2851640.1000234.TWC_region", "OT");
user_pref("CT2851640.1000234.TWC_temp_dis", "c");
user_pref("CT2851640.1000234.TWC_wind_dis", "kmh");
user_pref("CT2851640.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2851640.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2851640.FirstTime", "true");
user_pref("CT2851640.FirstTimeFF3", "true");
user_pref("CT2851640.PG_ENABLE", "ZmFsc2U=");
user_pref("CT2851640.SF_JUST_INSTALLED", "%CC%C7%D2%D9%CB");
user_pref("CT2851640.SF_JUST_INSTALLED.enc", "RkFMU0U=");
user_pref("CT2851640.SF_STATUS", "%CB%D4%C7%C8%D2%CB%CA");
user_pref("CT2851640.SF_STATUS.enc", "RU5BQkxFRA==");
user_pref("CT2851640.SF_USER_ID", "%E9%EF%EA%E5%B8%B8%B7%B7%B8%B6%B7%B9%BE%B8%B6%BA%B6%BF%BF%B7%BC%BC%BF%B8");
user_pref("CT2851640.SF_USER_ID.enc", "Y2lkXzIyMTEyMDEzODIwNDA5OTE2Njky");
user_pref("CT2851640.SearchAppState.enc", "Mg==");
user_pref("CT2851640.UserID", "UN23387770211646611");
user_pref("CT2851640._key_cl_active", "%B9%EB%EB%BC%EA%BB%BD%BE%B3%E7%E9%BC%E9%B3%BA%B7%B6%BC%B3%BF%E9%B9%EC%B3%BE%BA%BC%BD%B7%B6%B9%B7%BA%BF%BB%E8");
user_pref("CT2851640._key_cl_active.enc", "M2VlNmQ1NzgtYWM2Yy00MTA2LTljM2YtODQ2NzEwMzE0OTVi");
user_pref("CT2851640.addressBarTakeOverEnabledInHidden", "true");
user_pref("CT2851640.cbfirsttime", "%CC%F8%EF%A6%D4%F5%FC%A6%B8%B8%A6%B8%B6%B7%B9%A6%B6%BE%C0%B8%B7%C0%B9%B6%A6%CD%D3%DA%B1%B6%B7%B6%B6%A6%AE%F5%F8%E7%A6%F9%F5%F2%E7%F8%EB%A6%
user_pref("CT2851640.cbfirsttime.enc", "RnJpIE5vdiAyMiAyMDEzIDA4OjIxOjMwIEdNVCswMTAwIChvcmEgc29sYXJlIEV1cm9wYSBvY2NpZGVudGFsZSk=");
user_pref("CT2851640.countryCode", "IT");
user_pref("CT2851640.defaultSearch", "false");
user_pref("CT2851640.embeddedsData", "[{\"appId\":\"129351530187463046\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"get
user_pref("CT2851640.enableSearchFromAddressBar", "false");
user_pref("CT2851640.firstTimeDialogOpened", "true");
user_pref("CT2851640.fixPageNotFoundErrorByUser", "TRUE");
user_pref("CT2851640.fixPageNotFoundErrorInHidden", "true");
user_pref("CT2851640.fullUserID", "UN23387770211646611.IN.20131117154214");
user_pref("CT2851640.installDate", "17/11/2013 15:42:32");
user_pref("CT2851640.installSessionId", "-1");
user_pref("CT2851640.installSp", "FALSE");
user_pref("CT2851640.installType", "xpe");
user_pref("CT2851640.installUsage", "2013-11-22T10:20:30.8466149+03:00");
user_pref("CT2851640.installUsageEarly", "2013-11-22T10:20:26.6657881+03:00");
user_pref("CT2851640.installerVersion", "1.7.0.9");
user_pref("CT2851640.isCheckedStartAsHidden", true);
user_pref("CT2851640.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2851640.isFirstTimeToolbarLoading", "false");
user_pref("CT2851640.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT2851640.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT2851640.keyword", true);
user_pref("CT2851640.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT2851640&octid=CT2851640&SearchSource=15&CUI=UN233877702116466
user_pref("CT2851640.lastVersion", "10.20.0.13");
user_pref("CT2851640.mam_gk_appStateReportTime", "%B7%B9%BF%B6%BA%BE%BA%B9%B9%BB%BD%B9%B8");
user_pref("CT2851640.mam_gk_appStateReportTime.enc", "MTM5MDQ4NDMzNTczMg==");
user_pref("CT2851640.mam_gk_appState_Clarity_Active", "%F5%F4");
user_pref("CT2851640.mam_gk_appState_Clarity_Active.enc", "b24=");
user_pref("CT2851640.mam_gk_appState_CouponBuddy", "%F5%F4");
user_pref("CT2851640.mam_gk_appState_CouponBuddy.enc", "b24=");
user_pref("CT2851640.mam_gk_appState_Easytobook", "%F5%F4");
user_pref("CT2851640.mam_gk_appState_Easytobook.enc", "b24=");
user_pref("CT2851640.mam_gk_appState_Easytobook_targeted", "%F5%F4");
user_pref("CT2851640.mam_gk_appState_Easytobook_targeted.enc", "b24=");
user_pref("CT2851640.mam_gk_appState_PriceGong", "%F5%F4");
user_pref("CT2851640.mam_gk_appState_PriceGong.enc", "b24=");
user_pref("CT2851640.mam_gk_appState_WindowShopper", "%F5%F4");
user_pref("CT2851640.mam_gk_appState_WindowShopper.enc", "b24=");
user_pref("CT2851640.mam_gk_appsConfig.enc", "eyJBcHBzQ29uZmlndXJhdGlvbiI6W3siaWQiOiJDbGFyaXR5X0FjdGl2ZSIsInVybCI6Imh0dHA6Ly9zdG9yYWdlLmNvbmR1aXQuY29tL21hbS8zcmRwYXJ0eWFwcHMvY
user_pref("CT2851640.mam_gk_appsDefaultEnabled", "%F4%FB%F2%F2");
user_pref("CT2851640.mam_gk_appsDefaultEnabled.enc", "bnVsbA==");
user_pref("CT2851640.mam_gk_calledSetupService", "%B7");
user_pref("CT2851640.mam_gk_calledSetupService.enc", "MQ==");
user_pref("CT2851640.mam_gk_currentVersion", "%B7%B4%B7%B8%B4%B6%B4%BB");
user_pref("CT2851640.mam_gk_currentVersion.enc", "MS4xMi4wLjU=");
user_pref("CT2851640.mam_gk_eventsCache", "%u0101%A8%B8%B7%BE%B7%E8%E8%BE%EB%B3%B8%EB%E7%BC%B3%BA%BA%BE%BE%B3%E7%EA%E8%E7%B3%B7%B8%B6%BD%BF%EA%EC%BC%EC%BD%BE%BA%A8%C0%u0101%A8
user_pref("CT2851640.mam_gk_eventsCache.enc", "eyIyMTgxYmI4ZS0yZWE2LTQ0ODgtYWRiYS0xMjA3OWRmNmY3ODQiOnsidG9waWMiOiJzZW5kVXNhZ2UiLCJkYXRhIjp7ImNhdGVnb3J5IjoiV2VsY29tZSIsImFjdGlv
user_pref("CT2851640.mam_gk_existingUsersRecoveryDone", "%B7");
user_pref("CT2851640.mam_gk_existingUsersRecoveryDone.enc", "MQ==");
user_pref("CT2851640.mam_gk_first_time", "%B7");
user_pref("CT2851640.mam_gk_first_time.enc", "MQ==");
user_pref("CT2851640.mam_gk_gadgetOpen", "%FD%EB%F2%E9%F5%F3%EB");
user_pref("CT2851640.mam_gk_gadgetOpen.enc", "d2VsY29tZQ==");
user_pref("CT2851640.mam_gk_globalKeysMigratedToLocalStorage", "%B7");
user_pref("CT2851640.mam_gk_globalKeysMigratedToLocalStorage.enc", "MQ==");
user_pref("CT2851640.mam_gk_installer_preapproved.enc", "ZmFsc2U=");
user_pref("CT2851640.mam_gk_lastLoginTime", "%B7%B9%BF%B6%BA%BE%BA%B9%B9%BC%BA%BC%B6");
user_pref("CT2851640.mam_gk_lastLoginTime.enc", "MTM5MDQ4NDMzNjQ2MA==");
user_pref("CT2851640.mam_gk_localization.enc", "eyJkaWFsb2dPSyI6eyJUZXh0IjoiT0sifSwiZG1ib3gxIjp7IlRleHQiOiJEZWFsXHJcbm9mIHRoZSBkYXkifSwiZG1ib3gyIjp7IlRleHQiOiJGcmVlXHJcblNoaXB
user_pref("CT2851640.mam_gk_mamEnabled", "%EC%E7%F2%F9%EB");
user_pref("CT2851640.mam_gk_mamEnabled.enc", "ZmFsc2U=");
user_pref("CT2851640.mam_gk_new_welcome_experience", "%B7");
user_pref("CT2851640.mam_gk_new_welcome_experience.enc", "MQ==");
user_pref("CT2851640.mam_gk_pgUnloadedOnce", "%FA%F8%FB%EB");
user_pref("CT2851640.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
user_pref("CT2851640.mam_gk_settings1.11.4.2", "%u0101%A8%D9%FA%E7%FA%FB%F9%A8%C0%A8%F9%FB%E9%E9%EB%EB%EA%EB%EA%A8%B2%A8%CA%E7%FA%E7%A8%C0%u0101%A8%E9%FB%F8%F8%EB%F4%FA%CA%E7%
user_pref("CT2851640.mam_gk_settings1.11.4.2.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxMzExMjIiLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6Ijg0XzAiLCJpc1Rlc3Q
user_pref("CT2851640.mam_gk_settings1.11.5.1", "%u0101%A8%D9%FA%E7%FA%FB%F9%A8%C0%A8%F9%FB%E9%E9%EB%EB%EA%EB%EA%A8%B2%A8%CA%E7%FA%E7%A8%C0%u0101%A8%E9%FB%F8%F8%EB%F4%FA%CA%E7%
user_pref("CT2851640.mam_gk_settings1.11.5.1.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxMzEyMDciLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6Ijg0XzAiLCJpc1Rlc3Q
user_pref("CT2851640.mam_gk_settings1.12.0.5", "%u0101%A8%D9%FA%E7%FA%FB%F9%A8%C0%A8%F9%FB%E9%E9%EB%EB%EA%EB%EA%A8%B2%A8%CA%E7%FA%E7%A8%C0%u0101%A8%E9%FB%F8%F8%EB%F4%FA%CA%E7%
user_pref("CT2851640.mam_gk_settings1.12.0.5.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxNDAxMjMiLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6Ijg0XzAiLCJSVEsiOiJ
user_pref("CT2851640.mam_gk_showWelcomeGadget", "%EC%E7%F2%F9%EB");
user_pref("CT2851640.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
user_pref("CT2851640.mam_gk_stamp", "%BE%BA%E5%B6");
user_pref("CT2851640.mam_gk_stamp.enc", "ODRfMA==");
user_pref("CT2851640.mam_gk_userId", "%EB%BD%EB%BC%BC%BF%B8%BB%B3%EB%E8%E8%B7%B3%BA%EC%BE%B9%B3%BF%BF%E8%E8%B3%BD%E9%BF%BD%EB%EC%B8%E9%BE%E9%B8%E9");
user_pref("CT2851640.mam_gk_userId.enc", "ZTdlNjY5MjUtZWJiMS00ZjgzLTk5YmItN2M5N2VmMmM4YzJj");
user_pref("CT2851640.mam_gk_user_approval_interacted", "%B7");
user_pref("CT2851640.mam_gk_user_approval_interacted.enc", "MQ==");
user_pref("CT2851640.mam_gk_welcomeDialogMode", "%B7");
user_pref("CT2851640.mam_gk_welcomeDialogMode.enc", "MQ==");
user_pref("CT2851640.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fhelp.photoscape.org%2Fhelp.php%3Fid%3Dintro\",\"EB_MAIN_FRAME_TITLE\":\"PhotoScape%20Help\"
user_pref("CT2851640.openThankYouPage", "true");
user_pref("CT2851640.openUninstallPage", "false");
user_pref("CT2851640.originalSearchAddressUrl", false);
user_pref("CT2851640.price-gong.isManagedApp", "true");
user_pref("CT2851640.revertSettingsEnabled", "FALSE");
user_pref("CT2851640.search.searchAppId", "129351530187463046");
user_pref("CT2851640.search.searchCount", "0");
user_pref("CT2851640.searchInNewTabEnabledByUser", "false");
user_pref("CT2851640.searchInNewTabEnabledInHidden", "true");
user_pref("CT2851640.searchRevert", "FALSE");
user_pref("CT2851640.searchSuggestEnabledByUser", "false");
user_pref("CT2851640.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2851640.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT2851640.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
user_pref("CT2851640.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2851640\"}");
user_pref("CT2851640.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://uTorrentBarIT.OurToolbar.com//xpi\"}");
user_pref("CT2851640.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentBar_IT \"}");
user_pref("CT2851640.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2851640.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
user_pref("CT2851640.serviceLayer_services_Configuration_lastUpdate", "1389807782422");
user_pref("CT2851640.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1389806057232");
user_pref("CT2851640.serviceLayer_services_appsMetadata_lastUpdate", "1389807782404");
user_pref("CT2851640.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1389806057141");
user_pref("CT2851640.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1385104821189");
user_pref("CT2851640.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1385104825543");
user_pref("CT2851640.serviceLayer_services_login_10.20.0.13_lastUpdate", "1389806060169");
user_pref("CT2851640.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1389806057199");
user_pref("CT2851640.serviceLayer_services_searchAPI_lastUpdate", "1389807782228");
user_pref("CT2851640.serviceLayer_services_serviceMap_lastUpdate", "1389806057191");
user_pref("CT2851640.serviceLayer_services_toolbarContextMenu_lastUpdate", "1389806056820");
user_pref("CT2851640.serviceLayer_services_toolbarSettings_lastUpdate", "1389807782428");
user_pref("CT2851640.serviceLayer_services_translation_lastUpdate", "1389806056751");
user_pref("CT2851640.settingsINI", true);
user_pref("CT2851640.shouldFirstTimeDialog", "false");
user_pref("CT2851640.showToolbarPermission", "false");
user_pref("CT2851640.smartbar.CTID", "CT2851640");
user_pref("CT2851640.smartbar.Uninstall", "0");
user_pref("CT2851640.smartbar.toolbarName", "uTorrentBar_IT ");
user_pref("CT2851640.startPage", "false");
user_pref("CT2851640.toolbarBornServerTime", "22-11-2013");
user_pref("CT2851640.toolbarCurrentServerTime", "15-1-2014");
user_pref("CT2851640.toolbarLoginClientTime", "Fri Nov 22 2013 08:20:35 GMT+0100 (ora solare Europa occidentale)");
user_pref("CT2851640.url_history0001", "%EE%FA%FA%F6%C0%B5%B5%FD%FD%FD%B4%EA%E7%EF%F2%FF%F3%F5%FA%EF%F5%F4%B4%E9%F5%F3%B5%EF%FA%B5%F8%EB%F2%EB%FC%E7%F4%E9%EB%B5%F9%EB%E7%F8%E9
user_pref("CT2851640.url_history0001.enc", "aHR0cDovL3d3dy5kYWlseW1vdGlvbi5jb20vaXQvcmVsZXZhbmNlL3NlYXJjaC96b2V5KzEwMSs0K3N0YWdpb25lLzI6OjpjbGlja2hhbmRsZXI6OjoxMzg5ODA1OTYwMzg
user_pref("CT2851640.versionFromInstaller", "10.20.0.13");
user_pref("CT2851640.xpeMode", "0");
user_pref("CT2851640_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1390484316537,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}
user_pref("CT3287785.1000082.isPlayDisplay", "true");
user_pref("CT3287785.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description\":\"California Rock - Rock\",\"url\":\"hxxp://www.feedlive.net/california.
user_pref("CT3287785.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3287785.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3287785.FF19Solved", "true");
user_pref("CT3287785.FirstTime", "true");
user_pref("CT3287785.FirstTimeFF3", "true");
user_pref("CT3287785.PG_ENABLE", "ZmFsc2U=");
user_pref("CT3287785.PG_ENABLE.enc", "dHJ1ZQ==");
user_pref("CT3287785.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?octid=CT3287785&ctid=CT3287785&SearchSource=2&CUI=UN20979507931997532&UM=1&sspv=TB_TS
user_pref("CT3287785.TopHitsConfig.enc", "ew0KICAgICJzcHJpdGVVcmwiOiAiaHR0cDovL3N0b3JhZ2UuY29uZHVpdC5jb20vcHMvVG9wSGl0c0dlbmVyaWNBcHAvY29uZmlncy9VUy1VSy1EYW5jZS1Sb2NrLVJhcC9zc
user_pref("CT3287785.UserID", "UN20979507931997532");
user_pref("CT3287785.addressBarTakeOverEnabledInHidden", "true");
user_pref("CT3287785.addressUrlXPETakeover", "true");
user_pref("CT3287785.autoDisableScopes", 0);
user_pref("CT3287785.browser.search.defaultthis.engineName", "true");
user_pref("CT3287785.countryCode", "IT");
user_pref("CT3287785.defaultSearch", "true");
user_pref("CT3287785.defaultSearchXPETakeover", "true");
user_pref("CT3287785.embeddedsData", "[{\"appId\":\"130058452159609899\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"get
user_pref("CT3287785.enableAlerts", "true");
user_pref("CT3287785.enableFix404ByUser", "TRUE");
user_pref("CT3287785.enableSearchFromAddressBar", "true");
user_pref("CT3287785.firstTimeDialogOpened", "true");
user_pref("CT3287785.fixPageNotFoundError", "true");
user_pref("CT3287785.fixPageNotFoundErrorByUser", "true");
user_pref("CT3287785.fixPageNotFoundErrorInHidden", "true");
user_pref("CT3287785.fixUrls", true);
user_pref("CT3287785.fullUserID", "UN20979507931997532.IN.20130614174356");
user_pref("CT3287785.installDate", "14/06/2013 17:43:54");
user_pref("CT3287785.installId", "stub.exe");
user_pref("CT3287785.installSessionId", "{EADECCCE-1876-4B69-A6B2-F68EA76D89E8}");
user_pref("CT3287785.installSp", "FALSE");
user_pref("CT3287785.installType", "conduitnsisintegration");
user_pref("CT3287785.installUsage", "2013-06-15T11:39:36.3795092+03:00");
user_pref("CT3287785.installUsageEarly", "2013-06-15T10:07:11.0415631+03:00");
user_pref("CT3287785.installerVersion", "1.5.2.1");
user_pref("CT3287785.isCheckedStartAsHidden", true);
user_pref("CT3287785.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3287785.isFirstTimeToolbarLoading", "false");
user_pref("CT3287785.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT3287785.keyword", "true");
user_pref("CT3287785.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3287785&octid=CT3287785&SearchSource=15&CUI=UN209795079319975
user_pref("CT3287785.lastVersion", "10.16.4.600");
user_pref("CT3287785.mam_gk_appStateReportTime.enc", "MTM3MTgyMzgxMzY3NQ==");
user_pref("CT3287785.mam_gk_appState_CouponBuddy.enc", "b2Zm");
user_pref("CT3287785.mam_gk_appState_Easytobook.enc", "b2Zm");
user_pref("CT3287785.mam_gk_appState_Easytobook_targeted.enc", "b2Zm");
user_pref("CT3287785.mam_gk_appState_PriceGong.enc", "b2Zm");
user_pref("CT3287785.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9wcmljZWdvbmcuY29uZHVpdGFwcHMuY29tL01BTS92MS9odG1sX2NvbXAuaHRtbCIsIm9wdGlvbnN
user_pref("CT3287785.mam_gk_appsDefaultEnabled.enc", "bnVsbA==");
user_pref("CT3287785.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IkVhc3l0b2Jvb2tfdGFyZ2V0ZWQiLCJjcml0ZXJpYXMiOlt7ImNyaXRlcmlhSWQiOiIxYzM1OWNlMy0xZjkwLTRhMjEtOG
user_pref("CT3287785.mam_gk_currentVersion.enc", "MS44LjAuNA==");
user_pref("CT3287785.mam_gk_eventsCache.enc", "eyI5ODhiMDQ2MC0wMWM4LTQwODQtOTUyNi1mY2YyMTY2MWY1MjIiOnsidG9waWMiOiJzZW5kVXNhZ2UiLCJkYXRhIjp7ImNhdGVnb3J5IjoiV2VsY29tZSIsImFjdGlv
user_pref("CT3287785.mam_gk_first_time.enc", "MQ==");
user_pref("CT3287785.mam_gk_gadgetOpen.enc", "MA==");
user_pref("CT3287785.mam_gk_installer_preapproved.enc", "ZmFsc2U=");
user_pref("CT3287785.mam_gk_lastLoginTime.enc", "MTM3MTgyMzgxMDA3Mg==");
user_pref("CT3287785.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50IFBvbGljeSJ9LCJnYWRnZXREZXNjcmlwdGlvblByaW1hcnkiOnsiVGV4dCI6IlZhbHVlIEFwcHM
user_pref("CT3287785.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
user_pref("CT3287785.mam_gk_settings1.8.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNTRfMCIsImlzVGVzdCI6dHJ1ZSwiaXNXZWxjb21lRXhwZXJpZW5j
user_pref("CT3287785.mam_gk_showCloseButton.enc", "dHJ1ZQ==");
user_pref("CT3287785.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
user_pref("CT3287785.mam_gk_userId.enc", "ZGRjYjJkMzAtMzM1MS00ZTY2LWIzODEtN2UyMGIwYTM0MmE5");
user_pref("CT3287785.mam_gk_user_approval_interacted.enc", "MQ==");
user_pref("CT3287785.migrateAppsAndComponents", true);
user_pref("CT3287785.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"\",\"EB_MAIN_FRAME_TITLE\":\"\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://SearchExpress
user_pref("CT3287785.openThankYouPage", "false");
user_pref("CT3287785.openUninstallPage", "true");
user_pref("CT3287785.originalHomepage", "hxxp://search.babylon.com/?affID=121845&babsrc=HP_ss_din2g&mntrId=6A5FC0188519AF7A");
user_pref("CT3287785.originalSearchAddressUrl", "");
user_pref("CT3287785.originalSearchEngine", "Delta Search");
user_pref("CT3287785.price-gong.isManagedApp", "true");
user_pref("CT3287785.revertSettingsEnabled", "true");
user_pref("CT3287785.search.searchAppId", "130058452159609899");
user_pref("CT3287785.search.searchCount", "0");
user_pref("CT3287785.searchFromAddressBarEnabledByUser", "true");
user_pref("CT3287785.searchInNewTabEnabledByUser", "true");
user_pref("CT3287785.searchInNewTabEnabledInHidden", "true");
user_pref("CT3287785.searchRevert", "true");
user_pref("CT3287785.searchSuggestEnabledByUser", "true");
user_pref("CT3287785.searchUserMode", "1");
user_pref("CT3287785.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3287785.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT3287785.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
user_pref("CT3287785.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3287785\"}");
user_pref("CT3287785.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://SearchExpressITB.OurToolbar.com//xpi\"}");
user_pref("CT3287785.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"SearchExpress.IT.B\"}");
user_pref("CT3287785.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3287785.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
user_pref("CT3287785.serviceLayer_services_Configuration_lastUpdate", "1371642261967");
user_pref("CT3287785.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1371285573244");
user_pref("CT3287785.serviceLayer_services_appsMetadata_lastUpdate", "1371727228723");
user_pref("CT3287785.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1371285571259");
user_pref("CT3287785.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1371280026267");
user_pref("CT3287785.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1371285573269");
user_pref("CT3287785.serviceLayer_services_login_10.16.4.600_lastUpdate", "1371724438338");
user_pref("CT3287785.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1371285571458");
user_pref("CT3287785.serviceLayer_services_searchAPI_lastUpdate", "1371642260823");
user_pref("CT3287785.serviceLayer_services_serviceMap_lastUpdate", "1371642259575");
user_pref("CT3287785.serviceLayer_services_toolbarContextMenu_lastUpdate", "1371285571195");
user_pref("CT3287785.serviceLayer_services_toolbarSettings_lastUpdate", "1371727228820");
user_pref("CT3287785.serviceLayer_services_translation_lastUpdate", "1371642259501");
user_pref("CT3287785.settingsINI", true);
user_pref("CT3287785.shouldFirstTimeDialog", "false");
user_pref("CT3287785.showToolbarPermission", "false");
user_pref("CT3287785.smartbar.CTID", "CT3287785");
user_pref("CT3287785.smartbar.Uninstall", "0");
user_pref("CT3287785.smartbar.homepage", "true");
user_pref("CT3287785.smartbar.toolbarName", "SearchExpress.IT.B ");
user_pref("CT3287785.startPage", "true");
user_pref("CT3287785.startPageXPETakeover", "true");
user_pref("CT3287785.toolbarBornServerTime", "15-6-2013");
user_pref("CT3287785.toolbarCurrentServerTime", "20-6-2013");
user_pref("CT3287785.toolbarLoginClientTime", "Sat Jun 15 2013 10:39:35 GMT+0200 (ora solare Europa occidentale)");
user_pref("CT3287785.versionFromInstaller", "10.16.4.600");
user_pref("CT3287785_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1371826164162,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}
user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?octid=CT3287785&ctid=CT3287785&CUI=UN20979507931997532&UM=1&SearchSource=13&sspv=TB_TS3");
user_pref("Smartbar.ConduitSearchEngineList", "SearchExpress.IT.B Customized Web Search");
user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?octid=CT3287785&ctid=CT3287785&SearchSource=2&CUI=UN20979507931997532&UM=1&sspv=TB_TS3&q=
user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
user_pref("Smartbar.keywordURLSelectedCTID", "CT3287785");
user_pref("browser.search.defaultengine", "Web Search");
user_pref("browser.search.defaultthis.engineName", "SearchExpress.IT.B Customized Web Search");
user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3287785&CUI=UN20979507931997532&UM=1&SearchSource=3&q={searchTerms}&sspv=TB_TS3");
user_pref("browser.search.order.1", "Web Search");
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.backgroundjs", "\n\n/****************************************************
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/3518e1eac042730aa1274618984462b3_IT.value", "%22var%20ca
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/530e52021dc20843b1aa62957edeb9f8.value", "%22var%20adsDe
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/5cdf8a7ef2ec84abac286c67587b78d9.value", "%22function%20
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/62cce7d26ab5636bceb113b988d56c59_IT.value", "%22var%20ca
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/658987e48ed8b4a20fa71afdd0c84454_IT.value", "%22var%20ca
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/d965aead622233a60676ef2349956f38_IT.value", "%22var%20ca
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.internaldb.cache/ddedfe6ede02f148caf19a2dec7f877d_IT.value", "%22var%20ca
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.js", "\n\n /************************************************************
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI
user_pref("extensions.a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036.33036.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"
user_pref("extensions.crossrider.bic", "1410dde30bb26b8dd07ba5099a40c71d");
user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?octid=CT3287785&ctid=CT3287785&SearchSource=2&CUI=UN20979507931997532&UM=1&sspv=TB_TS3&q=");
user_pref("smartbar.addressBarOwnerCTID", "CT3287785");
user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?octid=CT3287785&ctid=CT3287785&SearchSource=2&CUI=UN20979507931997532&UM=1&sspv=TB
user_pref("smartbar.machineId", "/5T2XM7AJFQ1S5WAXRTDJ8EAJJPUI0WCJTH+8F7F9+LVR1BJZXREUYCQBWT8P7WR5PDCHNQ5ZVNTIG3Z4GQ0EA");



~~~ Chrome

Successfully deleted: [Folder] C:\Users\Luca\appdata\local\Google\Chrome\User Data\Default\Extensions\dgjkhjdcljddbedokogakmmdjgnbeanf
Successfully deleted: [Folder] C:\Users\Luca\appdata\local\Google\Chrome\User Data\Default\Extensions\hgojaaaiddhmiiakpejiklijbalpckih
Successfully deleted: [Folder] C:\Users\Luca\appdata\local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\hgojaaaiddhmiiakpejiklijbalpckih
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26/01/2014 at 12:28:14,35
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
cbbusto
Inviato: Sunday, January 26, 2014 6:05:01 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Jrt ha rimosso parecchia roba avevi molti adware e dirottatori però non si vede la voce awesomhp.

Tutte le voci che ti ho indicato di fixare e rimuovere da HJT sono state eliminate ?

Prova a cercare la voce nei vari browser.

Internet Explorer

Premere Alt + T e fare clic su Opzioni Internet.
Nella scheda Generale, modificare la home page e fare clic su OK.
Premere Alt + T e fare clic su Gestione componenti aggiuntivi.
Fare clic su Provider di ricerca sul lato sinistro della finestra.
Impostare un nuovo provider di ricerca predefinito e rimuovere Awesomehelp.

Mozilla Firefox

Premere Alt + T e fare clic su opzioni.
Cambiare la pagina iniziale della scheda Generale e scegliere OK.
Clicca l’ icona del motore di ricerca accanto alla casella di ricerca e seleziona un nuovo provider di ricerca.

Google Chrome

Premere Alt + F.
Selezionare Impostazioni.
Sotto all’avvio, fare clic sulla terza opzione e scegliere imposta pagine.
Impostare una nuova pagina di avvio.
Nell’ambito della ricerca, fare clic su Gestisci motori di ricerca e impostare un nuovo provider di ricerca predefinito.

Riproviamo con ADWcleaner in questo modo, il programma dovresti averlo ancora:

Avvia il pc in modalità provvisoria, poi disattiva l'antivirus e ripeti la procedura di ADW come ti ho segnalato.
Se funziona alla fine riavvia il pc in mod. normale e riattiva l'antivirus. Ricordati di postare il log.
Poi rifai la scansione con HJT e posta il log aggiornato vediamo cos'è rimasto.
Fai sapere. Ciao
andreab
Inviato: Sunday, January 26, 2014 7:04:42 PM
Rank: AiutAmico

Iscritto dal : 2/10/2004
Posts: 95
ciao
ho fatto come mi hai detto ma ADW si blocca ancora durante l'analisi dei browsers
sia IE e Crome si aprono sulla pagina awesomehp

ti invio il log di HJT
grazie

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:00:56, on 26/01/2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.altavista.it/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\coIEPlg.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\coIEPlg.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIZIO DI RETE')
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: I&nvia a OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: FlowSurf - {6CA2A4DE-483E-456B-8634-6445460D7097} - C:\Program Files (x86)\Flowsurf\FlowSurf.dll (file missing)
O9 - Extra button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Controllo AcPreview) - file:///C:/Program%20Files%20(x86)/AutoCAD%20LT%202002%20Ita/AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC87F561-E529-45EE-A0CB-9000202B28A6}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{E463EBDA-9666-4C15-9C54-4B4F426A56E3}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: TrueSuiteService (FPLService) - HP - C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MgAssist Service (MgAssistService) - Unknown owner - C:\Program Files (x86)\Mobogenie\MgAssist.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: Norton Identity Safe (NCO) - Symantec Corporation - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12433 bytes
bingoo
Inviato: Sunday, January 26, 2014 7:16:12 PM

Rank: AiutAmico

Iscritto dal : 10/22/2013
Posts: 148
start ..... esegui ...... msconfig ....... avvio ...... e togli la spunta a tutti quei programmi che sono elencati da CBBUSTO NELLA POSIZIONE 04

spegni e riaccendi e RIFAI tutto quello descritto da cbbusto IN MODALITà NORMALE quando da lui richiesto
kyron
Inviato: Sunday, January 26, 2014 7:21:13 PM
Rank: AiutAmico

Iscritto dal : 12/28/2009
Posts: 234
bingoo ha scritto:
start ..... esegui ...... msconfig ....... avvio ...... e togli la spunta a tutti quei programmi che sono elencati da CBBUSTO NELLA POSIZIONE 04

spegni e riaccendi e RIFAI tutto quello descritto da cbbusto IN MODALITà NORMALE quando da lui richiesto

Salve.
Ma non vedi che è stata già fatta quella operazione?
andreab
Inviato: Sunday, January 26, 2014 7:39:56 PM
Rank: AiutAmico

Iscritto dal : 2/10/2004
Posts: 95
c'era solo questo
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe

che ho tolto la spunta, ma il risultato è identico: adw si pianta durante "analyzing browsers"
Andrea

bingoo
Inviato: Sunday, January 26, 2014 8:01:22 PM

Rank: AiutAmico

Iscritto dal : 10/22/2013
Posts: 148
PROVO A RISPNDERTI :o)

quando sei stato infettato questo programma ti ha scaricato altri programmi che si auto installano in apertura ( o perlomeno cercano di farlo )

quindi

se si toglie possibilità di aprirsi il programma in accensione , .... solo allora lo potrai disinstallare senza che lui possa fare nulla

entra in modalità provvisoria f8 .... senza rete

esegui ....... avvio .......e controlla che non vi sia la spunta

pannello di controllo e disinstalla tutti i programmi che non riconosci come installati da parte tua

pulizia

ed avvia adw e cancella tutto quello che c'è da cancellare

alla riaccensione puoi fare una scansione online ....... http://www.microsoft.com/it-it/security/pc-security/malware-removal.aspx


ciao :O)
andreab
Inviato: Sunday, January 26, 2014 8:12:12 PM
Rank: AiutAmico

Iscritto dal : 2/10/2004
Posts: 95
non ho le comperenze per riconoscere quali programmi sono stati installati a mia insaputa e quali invece sono stati installati dall'utente oppure sono di sistema. tra l'altro il PC non è mio.
dubito inoltre che riesca a fare la scansione on line dato che l'apertura delle pagine internet a volte va a buon fine e a volte no.
grazie
r16
Inviato: Sunday, January 26, 2014 8:22:26 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.

clicca con il tasto destro del mouse sull'icona di IE che hai sul desktop, e scegli Proprietà.

In "Destinazione" copia e incolla qui la stringa per intero corrispondente.

Fai la stessa operazione con tutti i browser che usi. (Chrome, Firefofox Safari ecc... )

Poi:
Rifai una scansione con OTL.

Posta il log, come segnalato nella parte finale della guida:

http://forum.aiutamici.com/yaf_postst90814_Guida-per-eliminare-le-pagine-pubblicitarie-SOLO-LETTURA.aspx
andreab
Inviato: Sunday, January 26, 2014 8:50:57 PM
Rank: AiutAmico

Iscritto dal : 2/10/2004
Posts: 95
Ciao
ecco i destinazione
"C:\Program Files\Internet Explorer\iexplore.exe" http://www.awesomehp.com/?type=sc&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" http://www.awesomehp.com/?type=sc&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www.awesomehp.com/?type=sc&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82

solitamente usa IE e Crome
allego i link di OTL e Extras
grazie

OTL.Txt
Extras.Txt

r16
Inviato: Sunday, January 26, 2014 8:56:25 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
andreab ha scritto:
Ciao
ecco i destinazione
"C:\Program Files\Internet Explorer\iexplore.exe" http://www.awesomehp.com/?type=sc&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" http://www.awesomehp.com/?type=sc&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www.awesomehp.com/?type=sc&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82

solitamente usa IE e Crome
allego i link di OTL e Extras
grazie

OTL.Txt
Extras.Txt



Devi eliminare la parte in rosso di ogni browser.

Deve restare così:

Per IE:
"C:\Program Files\Internet Explorer\iexplore.exe" (virgolette comprese)

Per Firefox:
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" (virgolette comprese)

Per Chome:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" (virgolette comprese)

Clicca su "Applica" e poi OK per ogni browser.

Riavvia il pc.

Adesso controllo il log di OTL.
r16
Inviato: Sunday, January 26, 2014 9:17:59 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Quando hai finito:

Avvia OTL.

Sotto "Custom Scans\Fixes" copia-incolla questo codice: (NON copiare la parola Code: )


Code:
:OTL
SRV - (MgAssistService) -- C:\Program Files (x86)\Mobogenie\MgAssist.exe ()
SRV - (SoftwareUpd) -- C:\Users\Luca\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe (SoftwareUpdService)
SRV - (PowerOffer Service) -- C:\Users\Luca\AppData\Local\PosService\Pos.exe (PowerOfferService)
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.awesomehp.com/web/?type=ds&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{FB1AE33B-8FFF-4975-A90D-CD66E7E0F10F}: "URL" = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=46369&st=home&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=46369&st=chrome&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=46369&st=chrome&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=46369&st=home&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=46369&st=home&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://search.chatzum.com/?q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=698&systemid=2&apn_dtid=IME002&apn_ptnrs=AG2&o=APN10641&apn_uid=5901237434504184&q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD24}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=126&systemid=4&sr=0&q={searchTerms}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=46369&st=home&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=46369&st=chrome&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14&q=
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=46369&st=chrome&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14&q=
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=46369&st=home&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=46369&st=home&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=332&systemid=1&apn_dtid=IME001&apn_ptnrs=AGE&o=APN10653&apn_uid=5035024353144548&q={searchTerms}
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=698&systemid=2&apn_dtid=IME002&apn_ptnrs=AG2&o=APN10641&apn_uid=5901237434504184&q={searchTerms}
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD24}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=126&systemid=4&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/724-111084-4166-3/4?mpre=http://www.ebay.it/sch/i.html?_nkw={searchTerms}
IE - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\..\SearchScopes\1321DE08D7E940C9BC9ED714A88288F0: "URL" = http://search.certified-toolbar.com?si=46369&st=bs&tid=3874&ver=4.5&ts=1372543200000.000005&tguid=46369-3874-1371876937997-66DA3406EEF4F6753357CAA207C57F14&q={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "awesomehp"
FF - prefs.js..browser.search.selectedEngine: "awesomehp"
FF - prefs.js..browser.search.useDBForOrder: "false"
FF - prefs.js..browser.startup.homepage: "http://www.awesomehp.com/?type=hp&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82"
FF - prefs.js..extensions.enabledAddons: crossriderapp12765%40crossrider.com:0.91.67
[2013/05/17 13:02:42 | 000,000,000 | ---D | M] (Speed Analysis 2) -- C:\Users\Luca\AppData\Roaming\mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
CHR - homepage: http://www.awesomehp.com/?type=hp&ts=1390591622&from=amt&uid=WDCXWD3200BPVT-60JJ5T0_WD-WX31EB1RUS82RUS82
CHR - plugin: SweetIM GC Helper (Enabled) = C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.0.0.1_0\mgHelperGC.dll
CHR - plugin: Injovo Extension Plugin (Enabled) = C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.478_0\npbrowserext.dll
CHR - plugin: Wajam (Enabled) = C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins/PriamNPAPI.dll
CHR - plugin: Babylon ToolBar (Enabled) = C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.8_0\BabylonChromeToolBar.dll
CHR - plugin: SweetIM GC Helper (Enabled) = C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.1.0.1_0\mgHelperGCFB.dll
O2:[b]64bit:[/b] - BHO: (DataMngr) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\x64\BrowserConnection.dll (iMesh, Inc)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-1917911057-4261802172-2969938892-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe ()

:Files
C:\Users\Luca\AppData\Local\SoftwareUpdater
C:\Users\Luca\AppData\Local\PosService\Pos.exe
C:\Users\Luca\AppData\Local\PosService
C:\Users\Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
ipconfig /flushdns /c

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"

:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot]


Clicca sul pulsante RUN FIX.
Lascia fare la scansione senza interferire.
Posta il log.
andreab
Inviato: Sunday, January 26, 2014 9:32:46 PM
Rank: AiutAmico

Iscritto dal : 2/10/2004
Posts: 95
fatto, ecco il log
01262014_212456.log
grazie
r16
Inviato: Sunday, January 26, 2014 9:39:53 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ti suggerisco di ripristinare Chrome:
https://support.google.com/chrome/answer/3296214?hl=it

Poi dimme se riscontri ancora problemi.
andreab
Inviato: Sunday, January 26, 2014 9:47:58 PM
Rank: AiutAmico

Iscritto dal : 2/10/2004
Posts: 95
fatto. ho reimpostato Chrome ma non vedo grossi cambiamenti.
i broweser non si aprono più sulla pagina incriminata ma se digito qualche pagina questa si apre lentamente o addirittura non si apre proprio!!
grazie
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.