Chiudi tutti i programmi ed internet.
Apri HijackThis metti la spunta al fianco delle seguenti voci e clicca su Fix checked
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.suoonerie.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.suoonerie.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.suoonerie.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.suoonerie.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.suoonerie.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.suoonerie.com
O2 - BHO: (no name) - {004A5840-FF59-11d2-B50D-0090271D3FD4} - (no file)
O4 - HKLM\..\Run: [MSAdmin] C:\WINDOWS\SYSTEM\JDBGMRG.EXE
O4 - HKLM\..\Run: [msfindosa.exe] C:\WINDOWS\SYSTEM\msfindosa.exe
O4 - HKLM\..\Run: [atisrc2] C:\WINDOWS\SYSTEM\msfindosa.exe
O4 - HKLM\..\Run: [eros.exe] C:\WINDOWS\SYSTEM\eros.exe -d
O4 - HKLM\..\Run: [girl.exe] C:\WINDOWS\SYSTEM\girl.exe -d
O4 - HKLM\..\Run: [mmxrun] \0000000\msosa.exe
O4 - HKLM\..\Run: [sex_i.exe] C:\WINDOWS\SYSTEM\sex_i.exe -d
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
Riavvia in modalità provvisoria
ed elimina manualmente questi files
C:\WINDOWS\SYSTEM\JDBGMRG.EXE
C:\WINDOWS\SYSTEM\MSFINDOSA.EXE
C:\WINDOWS\SYSTEM\EROS.EXE
C:\WINDOWS\SYSTEM\GIRL.EXE
C:\WINDOWS\SYSTEM\VIETATO.EXE
C:\WINDOWS\SYSTEM\SEX_I.EXE
C:\WINDOWS\SYSTEM\EROS.EXE
C:\0000000\MSOSA.EXE
Riavvia, copia qui nuovamente il nuovo Log di HJT

Rispondi quotando