Salve, mio fratello dice che il suo pc (Asus EEE pc 900 HD) è lento.
Non credo si tratti di malware, ma di incasinamento del pc, e ho fatto una passata con MBAM.
Ho già cancellato quello che MBAM ha trovato, vi passo il log per vedere se c'è altro.
Grazie.
Malwarebytes Anti-Malware
www.malwarebytes.orgScan Date: 08/01/15
Scan Time: 13.36.11
Logfile: Log di MBAM.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.01.08.09
Rootkit Database: v2015.01.07.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows XP Service Pack 3
CPU: x86
File System: NTFS
User: UserXP
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 305282
Time Elapsed: 34 min, 56 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 2
PUP.Optional.WindowsProtectManger.A, C:\Documents and Settings\All Users\Dati applicazioni\WindowsMangerProtect\ProtectWindowsManager.exe, 276, , [15e454a07c0d7abc560916adf40db64a]
PUP.Optional.StormAlert.A, C:\Documents and Settings\All Users\Dati applicazioni\SLfccEEP\QuuPUKhtFfu.exe, 648, , [cd2c6d8798f13303c15e5e96b8494ab6]
Modules: 0
(No malicious items detected)
Registry Keys: 17
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, , [15e454a07c0d7abc560916adf40db64a],
PUP.Optional.StormAlert.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\QuuPUKhtFfu, , [cd2c6d8798f13303c15e5e96b8494ab6],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, , [9366e80c90f9e0569348e0081ae88779],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, , [e41591639dec41f56a40edfbd230738d],
PUP.Optional.SolutionReal.A, HKU\S-1-5-21-606747145-448539723-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{1BB456DA-878F-44A5-B013-4BFE0AE02FCE}, , [9564c23212778bab5705a03fd929c040],
PUP.Optional.SolutionReal.A, HKU\S-1-5-21-606747145-448539723-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{1BB456DA-878F-44A5-B013-4BFE0AE02FCE}, , [9564c23212778bab5705a03fd929c040],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{8d9c9462-4635-4cc0-ab2c-0e46af3a958b}Gt, , [d82144b07f0afd3940835c2628db4bb5],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\IHProtect, , [7188946048411b1b839df57241c2d828],
PUP.Optional.WPM.A, HKLM\SOFTWARE\supWindowsMangerProtect, , [4cad5a9a2267c07646a5845dcd373cc4],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\sweet-pageSoftware, , [fffa31c32d5cb086cda206d005ff8f71],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [6990b53ff6934fe73f574489699b3dc3],
PUP.Optional.SolutionReal.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Solution Real, , [c53447ade4a5f145789f4523f90ae31d],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [04f5c82c573266d0e60af57c5ea542be],
PUP.Optional.DynConIE.A, HKU\S-1-5-21-606747145-448539723-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DynConIE, , [e8111dd74544b1855568fab1976c936d],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-606747145-448539723-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [11e831c39aefb5817181a407db28758b],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-606747145-448539723-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, , [ed0c589cd6b33006c84061616d9726da],
PUP.Optional.Qone8, HKU\S-1-5-21-606747145-448539723-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [f00909ebaedb6acc10855c710ff5af51],
Registry Values: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-606747145-448539723-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, , [ed0c589cd6b33006c84061616d9726da]
Registry Data: 8
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL,
http://www.sweet-page.com/?type=hp&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0, Good: (www.google.com), Bad: (http://www.sweet-page.com/?type=hp&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0),,[fbfe2aca6128c5711778018c2bdab14f]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL,
http://www.sweet-page.com/web/?type=ds&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0&q={searchTerms}, Good: (www.google.com), Bad: (http://www.sweet-page.com/web/?type=ds&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0&q={searchTerms}),,[f405ba3a5b2eb58157395637bc49c838]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page,
http://www.sweet-page.com/web/?type=ds&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0&q={searchTerms}, Good: (www.google.com), Bad: (http://www.sweet-page.com/web/?type=ds&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0&q={searchTerms}),,[798047ada0e903335e2a245ed62f1de3]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page,
http://www.sweet-page.com/?type=hp&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0, Good: (www.google.com), Bad: (http://www.sweet-page.com/?type=hp&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0),,[fefb7381b1d8b185157c74199f66c23e]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant,
http://www.sweet-page.com/web/?type=ds&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0&q={searchTerms}, Good: (www.google.com/), Bad: (http://www.sweet-page.com/web/?type=ds&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0&q={searchTerms}),,[1edbca2a266369cd6e25058827de02fe]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|CustomizeSearch,
http://www.sweet-page.com/web/?type=ds&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0&q={searchTerms}, Good: (www.google.com/), Bad: (http://www.sweet-page.com/web/?type=ds&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0&q={searchTerms}),,[13e6d51fcdbc191d1181b4d92ed7ce32]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[f4051cd83653ea4c16156c21a56042be]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-606747145-448539723-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL,
http://www.sweet-page.com/?type=hp&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0, Good: (www.google.com), Bad: (http://www.sweet-page.com/?type=hp&ts=1420658548&from=cor&uid=ST9160310AS_5SV1TRX0XXXX5SV1TRX0),,[8b6e8e662e5b7abc513a2e5f6d9832ce]
Folders: 7
PUP.Optional.StormAlert.A, C:\Documents and Settings\UserXP\Impostazioni locali\Dati applicazioni\StormAlert, , [12e748ac6128e45220653e3340c3cb35],
Rogue.Multiple, C:\Documents and Settings\All Users\Dati applicazioni\1390424734, , [d722e60eb6d32c0a015862bf8a793dc3],
PUP.Optional.WPM.A, C:\Documents and Settings\All Users\Dati applicazioni\WindowsMangerProtect, , [f108ae46612881b58b29a4a4966d19e7],
PUP.Optional.WPM.A, C:\Documents and Settings\All Users\Dati applicazioni\WindowsMangerProtect\update, , [f108ae46612881b58b29a4a4966d19e7],
PUP.Optional.SolutionReal.A, C:\Programmi\Solution Real, , [e31625cf7811c86e00527beabf44bf41],
PUP.Optional.IHProtectUpDate.A, C:\Documents and Settings\All Users\Dati applicazioni\IHProtectUpDate, , [ea0f5a9a33563501799e3a2cd3302bd5],
PUP.Optional.IHProtectUpDate.A, C:\Documents and Settings\All Users\Dati applicazioni\IHProtectUpDate\update, , [ea0f5a9a33563501799e3a2cd3302bd5],
Files: 8
PUP.Optional.WindowsProtectManger.A, C:\Documents and Settings\All Users\Dati applicazioni\WindowsMangerProtect\ProtectWindowsManager.exe, , [15e454a07c0d7abc560916adf40db64a],
PUP.Optional.StormAlert.A, C:\Documents and Settings\All Users\Dati applicazioni\SLfccEEP\QuuPUKhtFfu.exe, , [cd2c6d8798f13303c15e5e96b8494ab6],
PUP.Optional.HealthAlert.A, C:\Documents and Settings\All Users\Dati applicazioni\SLfccEEP\dat\MVepZQyL.dll, , [a0598c68e2a786b0ff090d6cf5107888],
PUP.Optional.StormAlert.A, C:\Documents and Settings\All Users\Dati applicazioni\SLfccEEP\dat\sklZxuLFRmJ.exe, , [f30622d20e7b0135ba653aba7d84d62a],
PUP.Optional.StormAlert.A, C:\Documents and Settings\UserXP\Impostazioni locali\Dati applicazioni\StormAlert\data2.dat, , [12e748ac6128e45220653e3340c3cb35],
PUP.Optional.Sanbreel.A, C:\WINDOWS\system32\drivers\{8d9c9462-4635-4cc0-ab2c-0e46af3a958b}Gt.sys, , [d82144b07f0afd3940835c2628db4bb5],
Rogue.Multiple, C:\Documents and Settings\All Users\Dati applicazioni\1390424734\BIT36.tmp, , [d722e60eb6d32c0a015862bf8a793dc3],
PUP.Optional.IHProtectUpDate.A, C:\Documents and Settings\All Users\Dati applicazioni\IHProtectUpDate\update\conf, , [ea0f5a9a33563501799e3a2cd3302bd5],
Physical Sectors: 0
(No malicious items detected)
(end)