Buonasera a tutti,
ho seguito tutte le istruzioni di shel, partendo dall'utilizzo di AdwCleaner, passando poi perJRT ed infine per OTL.
Come mi ha detto shel posto qua il report in formato txt di AdwCleaner, anche se in realtà nella relativa cartella i report sono quattro, C1, S1, S2 e Quarantine, non so quale sia esattamente il report da postare, ma intanto posto il primo.
# AdwCleaner v5.021 - Creato file registro eventi 22/11/2015 in 16:36:18
# Aggiornato 14/11/2015 da Xplode
# Database : 2015-11-19.4 [Server]
# Sistema operativo : Windows 7 Home Premium Service Pack 1 (x64)
# Nome utente :
# In esecuzione da :
# Opzione : Pulizia
# Supporto :
http://toolslib.net/forum***** [ Servizi ] *****
***** [ Cartelle ] *****
[-] Cartella Eliminato : C:\Program Files (x86)\globalUpdate
[-] Cartella Eliminato : C:\Program Files (x86)\iWebar
[-] Cartella Eliminato : C:\Program Files (x86)\Object Browser
[-] Cartella Eliminato : C:\Program Files (x86)\YTDownloader
[-] Cartella Eliminato : C:\Program Files (x86)\WNetEnhancer
[-] Cartella Eliminato : C:\Program Files (x86)\F1DCD400-1448148238-1060-AD18-D2CBDB657575
[-] Cartella Eliminato : C:\Program Files (x86)\SwiftSearch_1.10.0.25
[!] Cartella Non Eliminato : C:\Program Files (x86)\iWebar
[!] Cartella Non Eliminato : C:\Program Files (x86)\Object Browser
[-] Cartella Eliminato : C:\Program Files (x86)\gmsd_it_005010153
[-] Cartella Eliminato : C:\ProgramData\pWMiniProp
[-] Cartella Eliminato : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WNetEnhancer
[-] Cartella Eliminato : C:\Users\AppData\Local\globalUpdate
[-] Cartella Eliminato : C:\Users\AppData\Local\BrowserHelper
[-] Cartella Eliminato : C:\Users\AppData\Local\gmsd_it_005010153
[-] Cartella Eliminato : C:\Users\AppData\LocalLow\SmartWeb
[-] Cartella Eliminato : C:\Users\AppData\Roaming\oursurfing
[-] Cartella Eliminato : C:\Users\AppData\Roaming\Mozilla\Firefox\Profiles\ml69qkp5.default-1399843554778\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
[-] Cartella Eliminato : C:\Users\AppData\Roaming\Mozilla\Firefox\Profiles\ml69qkp5.default-1399843554778\Extensions\deskCutv2@gmail.com
[-] Cartella Eliminato : C:\Users\AppData\Roaming\Mozilla\Firefox\Profiles\ml69qkp5.default-1399843554778\Extensions\defsearchp@gmail.com
[-] Cartella Eliminato : C:\Users\Public\Documents\ShopperPro
***** [ File ] *****
[-] File Eliminato : C:\END
***** [ DLLs ] *****
***** [ Collegamenti ] *****
***** [ Attività pianificate ] *****
***** [ Registry ] *****
[-] Chiave Eliminata : HKCU\Software\Mozilla\Extends
[-] Chiave Eliminata : HKLM\System\CurrentControlSet\Services\Eventlog\Application\Update Fortunitas
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\Interface\{94F1FD29-FDC2-4BF9-B008-AFB0452634E6}
[-] Chiave Eliminata : HKLM\SOFTWARE\Classes\TypeLib\{EFF4F283-3C8B-4A01-8297-DDC839210B86}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Chiave Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
[-] Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
[-] Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
[-] Valore Eliminata : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Classes\Interface\{94F1FD29-FDC2-4BF9-B008-AFB0452634E6}
[-] Chiave Eliminata : HKLM\SOFTWARE\Taronja
[-] Chiave Eliminata : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
[-] Chiave Eliminata : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D8011310B2622942868A458964FFDC5
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C63F7979DCC2154CB9591969A5CB89D
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DD31E6C1A73B334383DF186676F4D20
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB3204F747B20694B8D49EF92D8DC94B
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C81E33A400B6F814E90C7A3354E2A3A5
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDBF68C5F16790341B7C6FD7C7F8E4FC
[-] Chiave Eliminata : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFA531D0F3A71504DA7AC6A11CE33739
***** [ Browser web ] *****
[-] [C:\Users\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Eliminato : qone8
[-] [C:\Users\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Eliminato :
hxxp://www.oursurfing.com/?type=hp&ts=1 ... 5_F402006C[-] [C:\Users\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Eliminato :
hxxp://www.oursurfing.com/webfavicon.ico[-] [C:\Users\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Eliminato :
hxxp://www.oursurfing.com/web/?type=ds& ... 402006C&q={searchTerms}
[-] [C:\Users\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Eliminato :
hxxp://www.oursurfing.com/?type=hp&ts=1 ... 5_F402006C*************************
:: Chiavi "Tracing" eliminatas
:: Impostazioni Winsock azzerate
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [8398 byte] ##########
Poi ho fatto girare JRT e questo è il suo report:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.0 (11.12.2015)
Operating System: Windows 7 Home Premium x64
Ran by (Administrator) on 24/11/2015 at 14:58:09,30
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 0
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24/11/2015 at 15:00:53,81
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Infine ho utilizzato OTL ed ho ottenuto due report, che shel mi ha consigliato di caricare su un server, ma non sapendo esattamente come fare, intanto posto quelli dei primi due programmi.
Ora come dovrei procedere?
Grazie mille!