scarica CCleaner e Avenger

Disattiva il ripristino configurazione di sistema: start -> pannello di controllo -> sistema -> ripristino configurazione di sistema -> spunta "disattiva ripristino configuraz. di sistema"

apri il blocco note e copiaci dentro questo:
Windows Registry Editor Version 5.00

[-HKCR\CLSID\{A6C54318-5AC7-477D-B0A7-49AF5189300C}]

[-HKCR\CLSID\{486414B0-D1F3-4F19-9549-32D6319F5008}]

salvalo così:
nome: fix.reg
tipo di file: tutti i file
salvalo in c:\
e chiudi il file


esegui avenger e nella finestra principale copia/incolla:
files to delete:
C:\WINDOWS\pskt.ini
C:\WINDOWS\BM07600494.xml
C:\WINDOWS\BM07600494.txt
C:\WINDOWS\system32\vtUnnlJa.dll
C:\WINDOWS\system32\iifgFYsr.dll
C:\WINDOWS\system32\byXQGWoo.dll
C:\WINDOWS\system32\hrfadglm.tmp
C:\WINDOWS\system32\hrfadglm.ini
C:\WINDOWS\system32\hrfadglm.ini2
C:\WINDOWS\system32\WabLnnmp.ini2
C:\WINDOWS\system32\WabLnnmp.ini
C:\WINDOWS\system32\tuvWpNhg.dll
C:\WINDOWS\system32\garecakf.dll
C:\WINDOWS\system32\xuklpnmt.dll
C:\WINDOWS\system32\wrypenjy.dll
C:\WINDOWS\system32\yjnepyrw.tmp
C:\WINDOWS\system32\clkcnt.txt
C:\WINDOWS\system32\ivywpqmi.dll
C:\WINDOWS\system32\rkouwmlh.dll
C:\WINDOWS\system32\hlmwuokr.ini
C:\WINDOWS\system32\ltnauuhy.dll
C:\WINDOWS\system32\DVCStateBkp-{00000000-00000000-0000000E-00001102-00000002-80651102}.dat
C:\WINDOWS\system32\DVCState-{00000000-00000000-0000000E-00001102-00000002-80651102}.dat
C:\WINDOWS\system32\BMXStateBkp-{00000000-00000000-0000000E-00001102-00000002-80651102}.rfx
C:\WINDOWS\system32\BMXCtrlState-{00000000-00000000-0000000E-00001102-00000002-80651102}.rfx
C:\WINDOWS\system32\BMXState-{00000000-00000000-0000000E-00001102-00000002-80651102}.rfx
C:\WINDOWS\system32\settingsbkup.sfm
C:\WINDOWS\system32\settings.sfm
C:\WINDOWS\system32\BMXBkpCtrlState-{00000000-00000000-0000000E-00001102-00000002-80651102}.rfx
C:\WINDOWS\system32\ghNpWvut.ini2
C:\WINDOWS\system32\ghNpWvut.ini
C:\DOCUME~1\Admin\IMPOST~1\Temp\ymsgr2
C:\DOCUME~1\Admin\IMPOST~1\Temp\yazzsnet.exe
C:\DOCUME~1\Admin\IMPOST~1\Temp\S6000428(1).JPG
C:\DOCUME~1\Admin\IMPOST~1\Temp\!update.exe
C:\WINDOWS\system32\vtUnnlJa.dll
C:\WINDOWS\system32\tuvWpNhg.dll
C:\DOCUME~1\Admin\IMPOST~1\Temp\winvsnet.exe

folders to delete:
C:\WINDOWS\system32\pnVes01
C:\WINDOWS\system32\p7
C:\WINDOWS\system32\n4

registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {A6C54318-5AC7-477D-B0A7-49AF5189300C}

registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtUnnlJa
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{486414B0-D1F3-4F19-9549-32D6319F5008}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{A6C54318-5AC7-477D-B0A7-49AF5189300C}

programs to launch on reboot:
c:\fix.reg
Spunta "Automatically disable any rootkits found" e clicca su "execute".
Il pc dovrebbe riavviarsi da solo, altrimenti riavvialo tu. Posta il report rilasciato

Esegui CCleaner e ripulisci i file temporanei e i cookie (eseguilo 2 volte).

Riposta un nuovo systemscan