Ciao
perfetto....
ora un altra cortesia e pazienza...
riesegui roguekiller e seleziona e cancella cancella queste voci:
¤¤¤ Registro ¤¤¤
[PUP.OnlineIO] (X86) HKEY_LOCAL_MACHINE\Software\Microleaves -> Non selezionato
[PUP.SweetLabs|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005\Software\SweetLabs App Platform -> Non selezionato
[PUP.SweetLabs|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005\Software\SweetLabs App Platform -> Non selezionato
[PUP.SweetLabs|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11292017232723342\Software\SweetLabs App Platform -> Non selezionato
[PUP.Pokki|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki -> Non selezionato
[PUP.Pokki|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki -> Non selezionato
[PUP.Pokki|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11292017232723342\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki -> Non selezionato
[PUP.Pokki|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11292017232723342\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki -> Non selezionato
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://lenovo13.msn.com/?pc=LCJB -> Non selezionato
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://lenovo13.msn.com/?pc=LCJB -> Non selezionato
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11292017232723342\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://lenovo13.msn.com/?pc=LCJB -> Non selezionato
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1467497044-1135459756-2962170632-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11292017232723342\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://lenovo13.msn.com/?pc=LCJB -> Non selezionato
[PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {66345677-25AD-49FD-BAE5-2A3D1DEAF080} : v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe|Name=Popcorn Time| [x] -> Non selezionato
[PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {720F555A-1141-427D-BE89-671BDF68B8E6} : v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe|Name=Popcorn Time| [x] -> Non selezionato
[PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {92C3CA10-78D3-4499-97C3-EAD9F175812C} : v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\Updater.exe|Name=Updater.exe| [x] -> Non selezionato
[PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {B8BF6905-5126-4FA4-A2C9-239F2562377C} : v2.22|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Popcorn Time\Updater.exe|Name=Updater.exe| [x] -> Non selezionato
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Non selezionato
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Non selezionato
¤¤¤ Attività ¤¤¤
[Suspicious.Path] %WINDIR%\Tasks\{1AF468C2-19D6-44EE-88F4-724F8619FFB4}.job -- C:\Users\FRANCE~1\AppData\Local\Temp\is-165ER.tmp\XRD Manager.exe (/exenoupdates /exelang 0 /noprereqs /qr AI_RESUME=1 ADDLOCAL=MainFeature,XRDdrivers64 ACTION="INSTALL" EXECUTEACTION="INSTALL" ROOTDRIVE="C:\" AI_PREREQFILES="C:\Users\FRANCE~1\AppData\Local\Temp\{1AF468C2-19D6-44EE-88F4-724F8619FFB4}\drivers64.msi" AI_PREREQDIRS="C:\Users\FRANCE~1\AppData\Local\Temp" AI_SETUPEXEPATH="C:\Users\FRANCE~1\AppData\Local\Temp\is-165ER.tmp\XRD Manager.exe" SETUPEXEDIR="C:\Users\FRANCE~1\AppData\Local\Temp\is-165ER.tmp\" TARGETDIR="C:\" APPDIR="C:\Program Files (x86)\X-Rite\Devices\") -> Non selezionato
[PUP.OtherSearch] \AQaC20Me1c -- C:\Program Files (x86)\JwYLj8VSzF\updengine.exe -> Non selezionato
[PUP.Pokki|PUP.Gen0|PUP.Gen1] \Pokki -- %LOCALAPPDATA%\Pokki\Engine\ServiceHostAppUpdater.exe (/LOGON) -> Non selezionato
[Suspicious.Path] \{1AF468C2-19D6-44EE-88F4-724F8619FFB4} -- C:\Users\FRANCE~1\AppData\Local\Temp\is-165ER.tmp\XRD Manager.exe (/exenoupdates /exelang 0 /noprereqs /qr AI_RESUME=1 ADDLOCAL=MainFeature,XRDdrivers64 ACTION="INSTALL" EXECUTEACTION="INSTALL" ROOTDRIVE="C:\" AI_PREREQFILES="C:\Users\FRANCE~1\AppData\Local\Temp\{1AF468C2-19D6-44EE-88F4-724F8619FFB4}\drivers64.msi" AI_PREREQDIRS="C:\Users\FRANCE~1\AppData\Local\Temp" AI_SETUPEXEPATH="C:\Users\FRANCE~1\AppData\Local\Temp\is-165ER.tmp\XRD Manager.exe" SETUPEXEDIR="C:\Users\FRANCE~1\AppData\Local\Temp\is-165ER.tmp\" TARGETDIR="C:\" APPDIR="C:\Program Files (x86)\X-Rite\Devices\") -> Non selezionato
¤¤¤ Archivi ¤¤¤
[PUP.Pokki|PUP.Gen0|PUP.Gen1][Archivio] C:\Users\Francesca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Menu Start.lnk [LNK@] C:\Users\FRANCE~1\AppData\Local\Pokki\Engine\SERVIC~1.EXE /OPEN"menu" -> Non selezionato
[PUP.Pokki|PUP.Gen0|PUP.Gen1][Archivio] C:\Users\Francesca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk [LNK@] C:\Users\FRANCE~1\AppData\Local\Pokki\Engine\SERVIC~1.EXE /OPEN"f22abfeae27a67446927d078890381efc546d3e1" -> Non selezionato
[PUP.Pokki|PUP.Gen0|PUP.Gen1][Archivio] C:\Users\Francesca\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Menu Start.lnk [LNK@] C:\Users\FRANCE~1\AppData\Local\Pokki\Engine\SERVIC~1.EXE /OPEN"menu" -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.4.7_42330\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.4.8_42449\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.4.9_42606\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.4.9_43295\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.4.9_43388\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.5.0_43580\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.5.0_43804\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.5.0_43916\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.5.0_44090\utorrentie.exe -> Non selezionato
[PUP.uTorrentAds][Archivio] C:\Users\Francesca\AppData\Roaming\uTorrent\updates\3.5.0_44294\utorrentie.exe -> Non selezionato