Allora, ho cancellato quello che mi hai detto tranne Nielsen Online perché funziona come i sondaggi: per tenerlo mi pagano.
Adesso copio i log:
# AdwCleaner v5.007 - Creato file registro eventi 12/09/2015 in 20:28:07
# Aggiornato 08/09/2015 da Xplode
# Database : 2015-09-10.1 [Server]
# Sistema operativo : Windows 8.1 Pro (x64)
# Nome utente : Nuccio1 - NUCCIO
# In esecuzione da : C:\Users\Nuccio1\Desktop\AdwCleaner.exe
# Opzione : Pulizia
# Supporto :
http://toolslib.net/forum***** [ Servizi ] *****
***** [ Cartelle ] *****
***** [ File ] *****
***** [ Collegamenti ] *****
***** [ Attività pianificate ] *****
***** [ Registry ] *****
***** [ Browser web ] *****
*************************
:: Impostazioni Winsock azzerate
########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [637 byte] ##########
# AdwCleaner v5.105 - Logfile created 26/03/2016 at 23:26:56
# Updated 21/03/2016 by Xplode
# Database : 2016-03-26.1 [Server]
# Operating system : Windows 8.1 Pro (x64)
# Username : Nuccio1 - NUCCIO
# Running from : C:\Users\Nuccio1\Desktop\AdwCleaner.exe
# Option : Clean
# Support :
http://toolslib.net/forum***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
***** [ Web browsers ] *****
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [3016 bytes] - [05/03/2016 16:00:38]
C:\AdwCleaner\AdwCleaner[C2].txt - [1470 bytes] - [12/09/2015 19:28:07]
C:\AdwCleaner\AdwCleaner[C3].txt - [1253 bytes] - [27/10/2015 23:56:12]
C:\AdwCleaner\AdwCleaner[R0].txt - [814 bytes] - [22/06/2015 09:37:45]
C:\AdwCleaner\AdwCleaner[S0].txt - [872 bytes] - [22/06/2015 09:39:03]
C:\AdwCleaner\AdwCleaner[S1].txt - [2752 bytes] - [05/03/2016 15:43:25]
C:\AdwCleaner\AdwCleaner[S2].txt - [1975 bytes] - [12/09/2015 19:26:49]
C:\AdwCleaner\AdwCleaner[S3].txt - [1160 bytes] - [27/10/2015 23:55:22]
C:\AdwCleaner\AdwCleaner[S4].txt - [777 bytes] - [05/03/2016 15:41:01]
########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [2051 bytes] ##########
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 17:25:30, on 27/03/2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
FIREFOX: 45.0.1 (x86 it)
Boot mode: Normal
Running processes:
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Nuccio1\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.tiscali.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/p/?LinkId=255141R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files (x86)\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync - Chiamata con un clic - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync - Chiamata con un clic - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{107F39D2-40C3-41B3-A53B-9C8BFD9D9369}: NameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{AAEC75FF-5A86-4EA1-AAB0-0CF7B6329B1B}: NameServer = 212.52.97.25 193.70.152.25
O17 - HKLM\System\CS1\Services\Tcpip\..\{107F39D2-40C3-41B3-A53B-9C8BFD9D9369}: NameServer = 192.168.178.1
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMS Server Emulator Service (KMS) - Unknown owner - C:\Windows\KMS\KMS.exe
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nielsen Update (NielsenUpdate) - The Nielsen Company - C:\Program Files (x86)\NetRatingsNetSight\NetSight\NielsenUpdate.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: UltraZip Service (uzsvc) - Unknown owner - C:\Program Files (x86)\UltraZip\uzsvc.exe
O23 - Service: UltraZip Updater (uzupd) - Unknown owner - C:\Program Files (x86)\UltraZip\uzupd.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8574 bytes
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 8.1 Pro x64
Ran by Nuccio1 (Administrator) on 26/03/2016 at 23:34:50,70
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 7
Successfully deleted: C:\Windows\system32\Tasks\Wise Care 365 (Task)
Successfully deleted: C:\Windows\system32\Tasks\Wise Turbo Checker (Task)
Successfully deleted: C:\Windows\Tasks\Wise Care 365.job (Task)
Successfully deleted: C:\Windows\Tasks\Wise Turbo Checker.job (Task)
Successfully deleted: C:\Windows\prefetch\FREE_SPIDER_SOLITAIRE_V40_SET-1C154899.pf (File)
Successfully deleted: C:\Windows\prefetch\FREE_SPIDER_SOLITAIRE_V40_SET-5D0F5513.pf (File)
Successfully deleted: C:\Windows\prefetch\FREESPIDER.EXE-190A4C47.pf (File)
Registry: 1
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26/03/2016 at 23:36:21,84
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Malwarebytes Anti-Malware
www.malwarebytes.orgData scansione: 26/03/2016
Ora scansione: 21:31
File di log: mbam-log-2016-03-26 (21-31-17).txt
Amministratore: Sì
Versione: 2.2.1.1043
Database malware: v2016.03.26.06
Database rootkit: v2016.03.12.01
Licenza: Periodo di prova
Protezione da malware: Attivata
Protezione da siti web nocivi: Attivata
Auto-protezione: Disattivata
SO: Windows 8.1
CPU: x64
File system: NTFS
Utente: Nuccio1
Tipo di scansione: Ricerca elementi nocivi
Risultati: Completata
Elementi analizzati: 343119
Tempo impiegato: 19 min, 19 sec
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Attivata
Euristiche: Attivata
PUP: Attivata
PUM: Attivata
Processi: 0
(Nessun elemento nocivo rilevato)
Moduli: 0
(Nessun elemento nocivo rilevato)
Chiavi di registro: 0
(Nessun elemento nocivo rilevato)
Valori di registro: 0
(Nessun elemento nocivo rilevato)
Dati di registro: 0
(Nessun elemento nocivo rilevato)
Cartelle: 0
(Nessun elemento nocivo rilevato)
File: 0
(Nessun elemento nocivo rilevato)
Settori fisici: 0
(Nessun elemento nocivo rilevato)
(end)
Microsoft Windows Malicious Software Removal Tool v5.33, February 2016 (build 5.33.12300.0)
Started On Wed Mar 09 20:40:47 2016
Engine: 1.1.12400.0
Signatures: 1.213.4702.0
Microsoft Windows Malicious Software Removal Tool Finished On Wed Mar 09 20:44:23 2016
Return code: 0 (0x0)
Microsoft Windows Malicious Software Removal Tool v5.33, February 2016 (build 5.33.12300.0)
Started On Thu Mar 10 09:39:06 2016
Microsoft Windows Malicious Software Removal Tool v5.33, February 2016 (build 5.33.12300.0)
Started On Thu Mar 10 09:59:16 2016
Engine: 1.1.12400.0
Signatures: 1.213.4702.0
Microsoft Windows Malicious Software Removal Tool Finished On Thu Mar 10 10:12:33 2016
Return code: 0 (0x0)
Microsoft Windows Malicious Software Removal Tool v5.34, March 2016 (build 5.34.12400.0)
Started On Mon Mar 14 19:26:37 2016
Engine: 1.1.12400.0
Signatures: 1.213.7173.0
Results Summary:
No infection found.
Microsoft Windows Malicious Software Removal Tool v5.34, March 2016 (build 5.34.12400.0)
Started On Tue Mar 15 22:14:50 2016
Microsoft Windows Malicious Software Removal Tool v5.34, March 2016 (build 5.34.12400.0)
Started On Tue Mar 22 22:44:22 2016
Microsoft Windows Malicious Software Removal Tool v5.34, March 2016 (build 5.34.12400.0)
Started On Fri Mar 25 14:27:52 2016
Engine: 1.1.12400.0
Signatures: 1.213.7173.0
Microsoft Windows Malicious Software Removal Tool Finished On Fri Mar 25 14:30:25 2016
Return code: 0 (0x0)
Microsoft Windows Malicious Software Removal Tool v5.34, March 2016 (build 5.34.12400.0)
Started On Sat Mar 26 21:49:19 2016
Engine: 1.1.12400.0
Signatures: 1.213.7173.0
Microsoft Windows Malicious Software Removal Tool Finished On Sat Mar 26 21:51:51 2016
Return code: 0 (0x0)
Microsoft Windows Malicious Software Removal Tool v5.34, March 2016 (build 5.34.12400.0)
Started On Sat Mar 26 23:40:27 2016
Engine: 1.1.12400.0
Signatures: 1.213.7173.0
Results Summary:
No infection found.
Microsoft Windows Malicious Software Removal Tool Finished On Sun Mar 27 03:35:12 2016
Return code: 0 (0x0)
Ho anche installato la vs di java che mi hai suggerito dopo aver cancellato tutto ciò che riguardava java.
Devo rifare tutte le scansioni o va bene così?