ho anch'io lo stesso problema...appena puoi
:Processes
killallprocesses
:Services
:OTL
PRC - C:\Windows\SysWOW64\NLSSRV32.EXE (Nalpeiron Ltd.)
MOD - c:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
SRV - (nlsX86cc) -- C:\Windows\SysWOW64\NLSSRV32.EXE (Nalpeiron Ltd.)
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851640
IE - HKU\S-1-5-21-1104732500-1895000396-1005763280-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = Claro Search
IE - HKU\S-1-5-21-1104732500-1895000396-1005763280-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
IE - HKU\S-1-5-21-1104732500-1895000396-1005763280-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851640
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar_IT Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2851640&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: fontfinder@bendodson.com:1.0
FF - prefs.js..extensions.enabledAddons: rankchecker@seobook.com:1.8.21
FF - prefs.js..extensions.enabledAddons: seostatus@rubyweb:1.5.9
FF - prefs.js..extensions.enabledAddons: xpirftoolbar@roboform.com:3.1.0
FF - prefs.js..extensions.enabledAddons: {2d4271b9-cc9f-4f37-8b1e-340293eacd5c}:0.9.9.7
FF - prefs.js..extensions.enabledAddons: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.8.6
FF - prefs.js..extensions.enabledAddons: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.12.9.1
FF - prefs.js..extensions.enabledAddons: {b64982b1-d112-42b5-b1e4-d3867c4533f8}:2.3.796.11
FF - prefs.js..extensions.enabledAddons: {0153E448-190B-4987-BDE1-F256CADA672F}:15.0.6
FF - prefs.js..extensions.enabledItems: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.7.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.10.0
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.1.400
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.1.400
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: rankchecker@seobook.com:1.8.5
FF - prefs.js..network.proxy.type: 0
O33 - MountPoints2\{45c189b0-26f5-11e1-9e07-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{45c189b0-26f5-11e1-9e07-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\DiskProtect.exe
O33 - MountPoints2\{71fa6cf7-40de-11e1-8124-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{71fa6cf7-40de-11e1-8124-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{af878ffe-9d91-11e1-9afb-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{af878ffe-9d91-11e1-9afb-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\.\Setup.exe
O33 - MountPoints2\{bb9855f0-4b16-11e1-80f5-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{bb9855f0-4b16-11e1-80f5-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\Windows\Autorun.exe
O33 - MountPoints2\{c719f27a-2bb9-11e1-9d2c-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{c719f27a-2bb9-11e1-9d2c-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\Windows\Autorun.exe
O33 - MountPoints2\{dcccb745-48df-11e1-9fee-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{dcccb745-48df-11e1-9fee-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{dcccb74b-48df-11e1-9fee-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{dcccb74b-48df-11e1-9fee-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Windows\Autorun.exe
[2010/07/08 09:57:27 | 000,000,000 | ---D | M] -- C:\Users\Endoacustica Europe\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/05/10 15:51:26 | 000,000,000 | ---D | M] -- C:\Users\Endoacustica Europe\AppData\Roaming\Datagenn.com
[2010/03/31 10:03:59 | 000,000,000 | ---D | M] -- C:\Users\Endoacustica Europe\AppData\Roaming\Bradsoft.com @alternate Data Stream - 181 bytes -> C:\ProgramData\Temp:0A8E2C33 @alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:63238B95 @alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:FC3571BD
:Files
C:\Users\Endoacustica Europe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager
C:\Users\Endoacustica Europe\AppData\Roaming\Claro
C:\ProgramData\Browser Manager
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[Emptytemp]
[RESETHOSTS]
[Reboot]
:Processes
killallprocesses
:Services
:OTL
PRC - C:\Windows\SysWOW64\NLSSRV32.EXE (Nalpeiron Ltd.)
MOD - c:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
SRV - (nlsX86cc) -- C:\Windows\SysWOW64\NLSSRV32.EXE (Nalpeiron Ltd.)
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851640
IE - HKU\S-1-5-21-1104732500-1895000396-1005763280-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = Claro Search
IE - HKU\S-1-5-21-1104732500-1895000396-1005763280-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
IE - HKU\S-1-5-21-1104732500-1895000396-1005763280-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851640
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar_IT Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2851640&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: fontfinder@bendodson.com:1.0
FF - prefs.js..extensions.enabledAddons: rankchecker@seobook.com:1.8.21
FF - prefs.js..extensions.enabledAddons: seostatus@rubyweb:1.5.9
FF - prefs.js..extensions.enabledAddons: xpirftoolbar@roboform.com:3.1.0
FF - prefs.js..extensions.enabledAddons: {2d4271b9-cc9f-4f37-8b1e-340293eacd5c}:0.9.9.7
FF - prefs.js..extensions.enabledAddons: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.8.6
FF - prefs.js..extensions.enabledAddons: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.12.9.1
FF - prefs.js..extensions.enabledAddons: {b64982b1-d112-42b5-b1e4-d3867c4533f8}:2.3.796.11
FF - prefs.js..extensions.enabledAddons: {0153E448-190B-4987-BDE1-F256CADA672F}:15.0.6
FF - prefs.js..extensions.enabledItems: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.7.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.10.0
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.1.400
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.1.400
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: rankchecker@seobook.com:1.8.5
FF - prefs.js..network.proxy.type: 0
O33 - MountPoints2\{45c189b0-26f5-11e1-9e07-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{45c189b0-26f5-11e1-9e07-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\DiskProtect.exe
O33 - MountPoints2\{71fa6cf7-40de-11e1-8124-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{71fa6cf7-40de-11e1-8124-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{af878ffe-9d91-11e1-9afb-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{af878ffe-9d91-11e1-9afb-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\.\Setup.exe
O33 - MountPoints2\{bb9855f0-4b16-11e1-80f5-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{bb9855f0-4b16-11e1-80f5-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\Windows\Autorun.exe
O33 - MountPoints2\{c719f27a-2bb9-11e1-9d2c-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{c719f27a-2bb9-11e1-9d2c-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\Windows\Autorun.exe
O33 - MountPoints2\{dcccb745-48df-11e1-9fee-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{dcccb745-48df-11e1-9fee-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{dcccb74b-48df-11e1-9fee-e0cb4eb15b2f}\Shell - "" = AutoRun
O33 - MountPoints2\{dcccb74b-48df-11e1-9fee-e0cb4eb15b2f}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Windows\Autorun.exe
[2010/07/08 09:57:27 | 000,000,000 | ---D | M] -- C:\Users\Endoacustica Europe\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/05/10 15:51:26 | 000,000,000 | ---D | M] -- C:\Users\Endoacustica Europe\AppData\Roaming\Datagenn.com
[2010/03/31 10:03:59 | 000,000,000 | ---D | M] -- C:\Users\Endoacustica Europe\AppData\Roaming\Bradsoft.com @alternate Data Stream - 181 bytes -> C:\ProgramData\Temp:0A8E2C33 @alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:63238B95 @alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:FC3571BD
:Files
C:\Users\Endoacustica Europe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager
C:\Users\Endoacustica Europe\AppData\Roaming\Claro
C:\ProgramData\Browser Manager
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[Emptytemp]
[RESETHOSTS]
[Reboot]