Ciao.
Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su "fix checked":
Fai una pulizia con CCleaner. (registro compreso)codice:R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 R3 - URLSearchHook: (no name) - {1d03a978-ac0c-4004-b9fd-9cf361c7bd3f} - (no file) R3 - URLSearchHook: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file) R3 - URLSearchHook: (no name) - {4ae0c3d6-f713-4eed-bc65-25dc3ffdaac1} - (no file) O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - (no file) O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\Gobbo\AppData\Local\Google\Update\GoogleUpdate.exe" /c O17 - HKLM\System\CCS\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 176.31.229.24,176.31.229.25 O17 - HKLM\System\CCS\Services\Tcpip\..\{FCFC78B3-F880-4061-8060-ED6BC06F19CD}: NameServer = 176.31.229.24,176.31.229.25 O17 - HKLM\System\CS1\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 176.31.229.24,176.31.229.25 O17 - HKLM\System\CS2\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer = 176.31.229.24,176.31.229.25 O23 - Service: Pos Service (PowerOffer Service) - PowerOfferService - C:\Users\Gobbo\AppData\Local\PosService\Pos.exe O23 - Service: Serv Updater (ServUpdater) - ServiceUpd - C:\Users\Gobbo\AppData\Local\ServUpdater\ServiceUpd.exe
N.B :
La voce 023 segnata in rosso, è relativa alla segnalazione di Comodo.
Controlla se hijackthis l'ha eliminata dopo il "fix".
Se non risulta eliminata si dovrà procedere con le "maniere forti".

Rispondi quotando