non c'e' paragone, avira molto meglio del vecchio e pesante norton

quindi ti preparo la procedura per rimuoverlo insieme a tutte le infezioni rimaste

Ora apri una pagina del blocco note e copia incolla quanto segue


file::
c:\documents and settings\user\Dati applicazioni\DownTangoFTToolbar\DownTangoFTToolbar .dll
c:\programmi\Spybot - Search & Destroy\TeaTimer.exe"
c:\windows\system32\drivers\NIS\1402000.013\symds. sys
c:\windows\system32\drivers\NIS\1402000.013\symefa .sys
c:\documents and settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\2 0121005.002\BHDrvx86.sys
c:\windows\system32\drivers\NIS\1402000.013\ccsetx 86.sys
c:\programmi\Norton Internet Security\Engine\20.2.0.19\ccsvchst.exe
c:\programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys

folder::
c:\documents and settings\user\Dati applicazioni\DownTangoFTToolbar
c:\programmi\DownTangoFTToolbar
c:\windows\system32\drivers\NIS\1402000.013
c:\programmi\Norton Internet Security

registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6}]
[-HKEY_CLASSES_ROOT\clsid\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6}]
[-HKEY_CLASSES_ROOT\wtb.Band.1]
[-HKEY_CLASSES_ROOT\TypeLib\{a85e31f1-a6ce-4ace-a560-ec01271b7f55}]
[-HKEY_CLASSES_ROOT\wtb.Band]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e327b07a-0e11-4fd4-bef2-b2c5605b59c6}"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"SpybotSD TeaTimer"=-
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"c:\\Programmi\\Red Sky\\DownTango\\DownTango.exe"=-
"c:\\Programmi\\Red Sky\\DownTango\\pyload-dist\\pyLoadCore.exe"=-


driver::
SymDS
SymEFA
BHDrvx86
ccSet_NIS
NIS
EraserUtilRebootDrv

DDS::
uStart Page = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937
uDefault_Search_URL = hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
mStart Page = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937
mSearch Bar = hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
FF - prefs.js: browser.startup.homepage - hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2937
FF - prefs.js: keyword.URL - hxxp://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
FF - user.js: extensions.BabylonToolbar_i.id - 3c644f5d000000000000001d60913d68
FF - user.js: extensions.BabylonToolbar_i.hardId - 3c644f5d000000000000001d60913d68
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15408
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1720:16
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109981
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.ovrDmn - isearch.babylon.com
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
salva la pagina nominandola obligatoriamente in CFScript.txt
a questo punto trascina e lascia il file CFScript.txt sull'icona di combofix
lascialo lavorare fino alla fine e riposta il suo log ...