Ho provato a scansionare con Kaspersky, Malware Bytes e ComboFix ma niente da fare non rilevano niente.
Se volete qui ho i log di ComboFix e HiJackThis... grazie anticipatamente
LOG ComboFix
LOG HiJackThis
Moderatori: m.paolo, kadosh, Luke57

File::
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
c:\users\Andrea\AppData\Local\ServUpdater\ServiceUpd.exe
Driver::
ServUpdater
Firefox::
FF - prefs.js: browser.search.selectedEngine - mail.ru: Пои�к в Интернете
FF - prefs.js: keyword.URL - hxxp://go.mail.ru/search?utf8in=1&fr=fftbUFix&q=
FF - prefs.js: network.proxy.ftp - 173.160.74.252
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - 173.70.96.5
FF - prefs.js: network.proxy.gopher_port - 8839
FF - prefs.js: network.proxy.http - 173.160.74.252
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 173.160.74.252
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - 173.160.74.252
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
Folder::
c:\program files (x86)\SweetIM
c:\programdata\SweetIM
c:\program files (x86)\Ask.com
Registry::
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
"{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[-HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000000
DDS::
uStart Page = hxxp://www.mail.ru/cnt/9514
mStart Page = hxxp://home.sweetim.com/?crg=4.0002002Visitano il forum: Nessuno e 9 ospiti