di Luke57 » 29/03/13 18:34
Ciao, riavvia in modalità provvisoria, apri otl.exe, sul box bianco copia e incolla il seguente script in nereto:
:OTL
IE - HKU\S-1-5-21-1293937640-2296623661-4142523422-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Programmi\Ask.com\GenericAskToolbar.dll (Ask)
CHR - Extension: YouTube = C:\Users\giuseppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Ricerca Google = C:\Users\giuseppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\giuseppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Users\giuseppe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programmi\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programmi\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKU\S-1-5-21-1293937640-2296623661-4142523422-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programmi\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-1293937640-2296623661-4142523422-1000\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programmi\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKU\S-1-5-21-1293937640-2296623661-4142523422-1000..\RunOnce: [B07F24477F0BE35B0000B07E73D0EB3B] C:\ProgramData\B07F24477F0BE35B0000B07E73D0EB3B\B07F24477F0BE35B0000B07E73D0EB3B.exe ()
[2013/03/28 09:41:08 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{422C5283-2FAA-4481-9EFF-FAC3696ADCCA}
[2013/03/27 18:28:38 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{E23207D2-E83A-4269-8008-6815C70A5C1F}
[2013/03/26 12:38:54 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{28B190EF-FBD8-44D6-AD9B-3FA5875DF361}
[2013/03/25 09:16:02 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{039A19C0-CBBA-4ADA-8F70-E6819160770E}
[2013/03/24 14:38:54 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{50CF7536-7863-42D5-B473-A8994F8C9FE0}
[2013/03/23 09:41:24 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{CFAC982B-26BC-406F-A778-0F00F806AAEE}
[2013/03/22 16:40:22 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{C9407153-C3CC-4B1C-B7FC-A247B32CB1B0}
[2013/03/21 09:10:54 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{74398031-9CD2-4557-A96F-7D16EBF41A4C}
[2013/03/20 16:42:15 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{B0E25EE5-08E9-4DAE-ABB9-900A616C716E}
[2013/03/19 15:17:35 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{26057E35-7F5F-4397-8726-6D461B4F56E4}
[2013/03/18 11:21:43 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{A78C3F1C-A637-4682-961B-6D09050CBBFB}
[2013/03/17 15:13:01 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{C51D2E08-F2CE-441A-9F87-DEDA40DB7921}
[2013/03/16 09:56:28 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{40524295-7856-424F-A63E-EC043B190A88}
[2013/03/15 12:08:43 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{EE1408AA-1006-42B0-B243-95E15A9820F0}
[2013/03/14 13:47:30 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{732DF624-3815-44AA-A117-60ABCAA217A6}
[2013/03/13 10:31:35 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{383C5F54-FBE2-4B99-8663-78C94B8E1772}
[2013/03/12 14:02:46 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{907AD7D0-7FC3-4163-8ECF-9C3E66EC9B0A}
[2013/03/11 10:14:00 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{5A53E120-6D3A-40F0-9054-40C114F6A221}
[2013/03/10 22:13:36 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{17514B0D-A211-4820-A9AC-5FE8EC96043E}
[2013/03/10 10:13:12 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{5544ABC8-D6C3-42DF-A130-4E2BDF2080A3}
[2013/03/09 10:12:24 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{47BADE38-297F-4DE9-B3BC-0EAD8ADC3BC4}
[2013/03/08 15:02:10 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{6EDA7960-9647-4E41-98EB-07C40AB32D50}
[2013/03/07 15:54:54 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{1788E965-2D4D-449E-98C2-2EBEB682A664}
[2013/03/06 12:15:58 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{06DFB13B-3362-4DD0-A3AA-287EF5D3CABF}
[2013/03/05 18:46:34 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{E551F29D-A426-4BE6-947E-A3768F8C9B24}
[2013/03/04 13:45:42 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{79610ED7-5B10-41F0-85CC-9874DFD959AE}
[2013/03/03 14:54:22 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{97699702-3DDD-4ACD-AB15-C314249E5B03}
[2013/03/02 10:59:08 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{A9FF3D56-B968-4DAB-8680-2C49F96E35D3}
[2013/02/28 21:21:57 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{A1F4DBBE-1F29-4504-8A04-F4BB8367F287}
[2013/02/28 09:21:33 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{8E2FC6E8-E6E9-4316-BC88-575DEE28101C}
[2013/02/27 15:19:29 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{0A4249BB-06D7-420F-BD40-E8CB6FCF80F1}
[2013/02/26 13:31:38 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{4773244C-5901-42F8-93A6-853722EA4B1D}
[2013/02/24 16:59:15 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{419581EE-68B5-4D68-819B-84D506623A14}
[2013/02/23 21:05:34 | 000,000,000 | ---D | C] -- C:\Users\giuseppe\AppData\Local\{6E1789C0-8C30-45AE-99B3-819A5362FBDA}
2013/03/28 20:04:41 | 000,002,288 | ---- | M] () -- C:\Users\giuseppe\Desktop\SpyHunter.lnk
[2013/03/28 19:56:31 | 000,014,544 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/28 19:56:31 | 000,014,544 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/25 08:39:44 | 000,000,000 | ---- | C] () -- C:\Users\giuseppe\AppData\Local\{7BE93D75-87CE-487E-83FF-2FAC1F384F9C}
[2013/01/26 16:14:42 | 000,002,048 | -HS- | M] () -- C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\@
[2013/01/26 16:14:42 | 000,048,128 | -HS- | M] () -- C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\n
[2013/01/26 16:14:42 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\L
[2013/01/26 16:14:56 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\U
[2013/01/26 16:14:55 | 000,000,928 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\U\00000001.@
[2013/01/26 16:14:55 | 000,011,776 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\U\80000000.@
[2013/01/26 16:14:56 | 000,021,504 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\U\800000cb.@
[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:D3A96964
:files
C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\@
C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\n
C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\L
C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\U
C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\U\00000001.@
C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\U\80000000.@
C:\$Recycle.Bin\S-1-5-18\$4ece16753df6bfe9b394fd88b1493a2c\U\800000cb.@
:commands
[purity]
premi runfix. Al termine della scnsione riavvia il computer. Posta il report prodotto che trovi sul desktop.