Esegui systemscan, clicca sul pulsante "Removal Script" e, nella finestra che si apre, copia/incolla questo script:
Clicca su "Proceed with removal" e il pc si riavviera' per eseguire lo script.files to delete:
C:\DOCUME~1\utente\IMPOST~1\Temp\wJQs.exe
C:\DOCUME~1\utente\IMPOST~1\Temp\8A56EAB7.TMP
C:\WINDOWS\system32\digeste.dll
C:\WINDOWS\system32\__c00818E9.exe
C:\WINDOWS\system32\svcnost.exe
C:\WINDOWS\system32\__c0038EA9.dat
C:\WINDOWS\system32\drivers\amd64si.sys
C:\WINDOWS\system32\drivers\qjiohovc.dat
C:\WINDOWS\system32\wpv461235998315.cpx
C:\WINDOWS\system32\crypts.dll
C:\DOCUME~1\utente\IMPOST~1\Temp\bis5.exe
C:\WINDOWS\system32\drivers\cmpeirfa.sys
C:\DOCUME~1\utente\IMPOST~1\Temp\set49.tmp
C:\DOCUME~1\utente\IMPOST~1\Temp\set4B.tmp
C:\DOCUME~1\utente\IMPOST~1\Temp\set26.tmp
C:\DOCUME~1\utente\IMPOST~1\Temp\Set1D8.tmp
registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | System
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0038EA9
HKLM\system\currentcontrolset\services\amd64si
HKLM\system\controlset001\services\amd64si
HKLM\system\controlset002\services\amd64si
HKLM\system\currentcontrolset\services\vrvlyhju
HKLM\system\controlset001\services\vrvlyhju
HKLM\system\controlset002\services\vrvlyhju
HKLM\system\currentcontrolset\enum\root\legacy_amd 64si
HKLM\system\controlset001\enum\root\legacy_amd64si
HKLM\system\controlset002\enum\root\legacy_amd64si
HKLM\system\currentcontrolset\enum\root\legacy_vrv lyhju
HKLM\system\controlset001\enum\root\legacy_vrvlyhj u
HKLM\system\controlset002\enum\root\legacy_vrvlyhj u
HKLM\system\currentcontrolset\enum\root\legacy_tcv dlhkr
HKLM\system\controlset001\enum\root\legacy_tcvdlhk r
HKLM\system\controlset002\enum\root\legacy_tcvdlhk r
HKLM\system\currentcontrolset\services\tcvdlhkr
HKLM\system\controlset001\services\tcvdlhkr
HKLM\system\controlset002\services\tcvdlhkr
Al riavvio troveri la finestra di SystemScan con un messaggio (blu se lo script e' stato eseguito correttamente - rossa in caso contrario): controlla l'esito e rieseguilo se necessario.

Rispondi quotando
finalmente ci ciamo riusciti...