Ciao ho seguito la guida postata da Giza su come eliminare "pagine pubblicitarie e infezioni varie" vi posto i 3 LOG, e se potete darci una controllata vi sarei devoti!!! :-)
Malwarebytes Anti-Malware
www.malwarebytes.orgData scansione: 14/03/2015
Ora scansione: 09:35:36
File di log: ciao.txt
Amministratore: Si
Versione: 2.00.4.1028
Database malware: v2015.03.14.02
Database rootkit: v2015.02.25.01
Licenza: Free
Protezione da malware: Disattivata
Protezione da siti web nocivi: Disattivata
Autoprotezione: Disattivata
SO: Windows 7 Service Pack 1
CPU: x64
File system: NTFS
Utente: Marco Basilisco
Tipo di scansione: Scansione elementi nocivi
Risultati: Completata
Elementi analizzati: 353704
Tempo impiegato: 24 min, 29 sec
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Attivata
Euristica: Disattivata
PUP: Attivata
PUM: Attivata
Processi: 9
PUP.Optional.FindPositive.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer.exe, 4552, , [3376f72b6a20290d637e30823cc7857b]
PUP.Optional.FindPositive.A, C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\updater.exe, 4512, , [02a7061cf991181e7e63793959aaf50b]
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\3\Plugin.exe, 3340, , [4e5bb66cd2b838fe8d475c48dd26a55b]
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\3\Plugin.exe, 1820, , [4e5bb66cd2b838fe8d475c48dd26a55b]
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\4\Plugin.exe, 4496, , [4e5bb66cd2b838fe8d475c48dd26a55b]
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\4\Plugin.exe, 2180, , [4e5bb66cd2b838fe8d475c48dd26a55b]
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\5\Plugin.exe, 4488, , [4e5bb66cd2b838fe8d475c48dd26a55b]
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\5\Plugin.exe, 728, , [4e5bb66cd2b838fe8d475c48dd26a55b]
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\8\Plugin.exe, 3384, , [4e5bb66cd2b838fe8d475c48dd26a55b]
Moduli: 0
(Nessun elemento malevolo rilevato)
Chiavi di registro: 11
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{30c85a3d-1d96-4589-b63f-91fb7ef45a41}, , [c8e150d2bdcd49ed3f7764b62cd735cb],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{63C63464-1423-4FDB-BA5D-6F75F491C63E}, , [c8e150d2bdcd49ed3f7764b62cd735cb],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{50F60937-910A-4C05-8E36-FE4E299191CF}, , [c8e150d2bdcd49ed3f7764b62cd735cb],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{50F60937-910A-4C05-8E36-FE4E299191CF}, , [c8e150d2bdcd49ed3f7764b62cd735cb],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{63C63464-1423-4FDB-BA5D-6F75F491C63E}, , [c8e150d2bdcd49ed3f7764b62cd735cb],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}, , [c8e150d2bdcd49ed3f7764b62cd735cb],
PUP.Optional.PositiveFinds.A, HKLM\SOFTWARE\WOW6432NODE\PositiveFinds, , [a50454ce3654af87d48e8030fb088e72],
PUP.Optional.FindPositive.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Service Mgr PositiveFinds, , [3376f72b6a20290d637e30823cc7857b],
PUP.Optional.FindPositive.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Mgr PositiveFinds, , [02a7061cf991181e7e63793959aaf50b],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Positive Finds, , [a603f1314347033344a10a99ef14cf31],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{cfd32d46-7d3f-483f-bace-7172aec5592d}, , [a603f1314347033344a10a99ef14cf31],
Valori di registro: 0
(Nessun elemento malevolo rilevato)
Dati di registro: 0
(Nessun elemento malevolo rilevato)
Cartelle: 13
PUP.Optional.FindPositive.A, C:\Program Files (x86)\Positive Finds, , [a603f1314347033344a10a99ef14cf31],
PUP.Optional.FindPositive.A, C:\Program Files (x86)\Positive Finds\Extensions, , [a603f1314347033344a10a99ef14cf31],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\3, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\4, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\4bak, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\5, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\5bak, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\8, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602, , [c5e480a201893afc90286c39897aed13],
PUP.Optional.PositiveFinds.A, C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\updater, , [c5e480a201893afc90286c39897aed13],
File: 20
PUP.Optional.FindPositive.A, C:\Program Files (x86)\Positive Finds\Extensions\30c85a3d-1d96-4589-b63f-91fb7ef45a41.dll, , [c8e150d2bdcd49ed3f7764b62cd735cb],
PUP.Adware.Agent, C:\Users\Marco Basilisco\AppData\Local\Temp\PositiveFinds\Setup.exe, , [981132f0a0ea1620cc0720e660a0619f],
PUP.Optional.BundleInstaller.A, C:\Users\Marco Basilisco\AppData\Local\Temp\Setup.exe\4b337c66319340abb1da7ada36abef5d\parent.txt, , [f7b2e83a701a50e6aeb448e049b79b65],
PUP.Optional.BundleInstaller.A, C:\Users\Marco Basilisco\AppData\Local\Temp\Setup.exe\4b337c66319340abb1da7ada36abef5d\Setup.exe, , [61481d05a3e7a78fb8aad94f6e928977],
PUP.Optional.BundleInstaller.A, C:\Users\Marco Basilisco\Downloads\Setup.exe, , [bcede63cc1c93cfac1a1899f1ae67a86],
PUP.Optional.Softonic.A, C:\Users\Marco Basilisco\Downloads\SoftonicDownloader_per_videospin.exe, , [6c3d76ac226890a6403960eb13eed62a],
PUP.Optional.Softonic.A, C:\Users\Marco Basilisco\Downloads\SoftonicDownloader_per_windows-movie-maker-2012.exe, , [dccd29f9e2a86fc7403976d59f628e72],
PUP.Optional.FindPositive.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer.exe, , [3376f72b6a20290d637e30823cc7857b],
PUP.Optional.FindPositive.A, C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\updater.exe, , [02a7061cf991181e7e63793959aaf50b],
PUP.Optional.FindPositive.A, C:\Program Files (x86)\Positive Finds\7za.exe, , [a603f1314347033344a10a99ef14cf31],
PUP.Optional.FindPositive.A, C:\Program Files (x86)\Positive Finds\Uninstaller.exe, , [a603f1314347033344a10a99ef14cf31],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugincontainer.bak, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\temp, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\3\Plugin.exe, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\4\Plugin.exe, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\4bak\Plugin.exe, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\5\Plugin.exe, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\5bak\Plugin.exe, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\plugins\8\Plugin.exe, , [4e5bb66cd2b838fe8d475c48dd26a55b],
PUP.Optional.PositiveFinds.A, C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602\updater.bak, , [c5e480a201893afc90286c39897aed13],
Settori fisici: 0
(Nessun elemento malevolo rilevato)
(end)
# AdwCleaner v4.112 - Creato file registro eventi 14/03/2015 in 12:02:29
# Aggiornato 09/03/2015 da Xplode
# Database : 2015-03-05.1 [Locale]
# Sistema operativo : Windows 7 Home Premium Service Pack 1 (x64)
# Nome utente : Marco Basilisco - MARCOBASILISCO
# In esecuzione da : C:\Users\Marco Basilisco\Desktop\adwcleaner_4.112.exe
# Opzione : Pulizia
***** [ Servizi ] *****
Servizio Eliminato : Service Mgr PositiveFinds
Servizio Eliminato : Update Mgr PositiveFinds
***** [ File / Cartelle ] *****
Cartella Eliminato : C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602
Cartella Eliminato : C:\Program Files (x86)\Positive Finds
Cartella Eliminato : C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602
Cartella Eliminato : C:\Users\Marco Basilisco\AppData\Roaming\RHEng
Cartella Eliminato : C:\Users\Marco Basilisco\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
File Eliminato : C:\Users\Marco Basilisco\AppData\Roaming\uninstaller.exe
File Eliminato : C:\Users\Marco Basilisco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Eliminato : C:\Users\Marco Basilisco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Eliminato : C:\Users\Marco Basilisco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
File Eliminato : C:\Users\Marco Basilisco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
File Eliminato : C:\Users\Marco Basilisco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal
File Eliminato : C:\Users\Marco Basilisco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage
***** [ Attività pianificate ] *****
***** [ Collegamenti ] *****
***** [ Registry ] *****
Chiave Eliminato : HKLM\SOFTWARE\Google\Chrome\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Chiave Eliminato : HKLM\SOFTWARE\Classes\AppID\{9C81D00A-3DAA-48AB-90C7-8252119ABB93}
Chiave Eliminato : HKLM\SOFTWARE\Classes\AppID\{1DA17428-323D-48FF-857C-98CFEE48BFD5}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}
Chiave Eliminato : HKLM\SOFTWARE\Classes\Interface\{50F60937-910A-4C05-8E36-FE4E299191CF}
Chiave Eliminato : HKLM\SOFTWARE\Classes\TypeLib\{63C63464-1423-4FDB-BA5D-6F75F491C63E}
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}
Chiave Eliminato : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Chiave Eliminato : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Chiave Eliminato : [x64] HKLM\SOFTWARE\Classes\Interface\{50F60937-910A-4C05-8E36-FE4E299191CF}
Chiave Eliminato : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Chiave Eliminato : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Chiave Eliminato : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Chiave Eliminato : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Chiave Eliminato : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Chiave Eliminato : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Chiave Eliminato : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Chiave Eliminato : HKCU\Software\Softonic
Chiave Eliminato : HKLM\SOFTWARE\PositiveFinds
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Positive Finds
***** [ Browser web ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Google Chrome v41.0.2272.89
[C:\Users\Marco Basilisco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://www.softonic.it/s/{searchTerms}
-\\ Chromium v
[C:\Users\Marco Basilisco\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Eliminato [Search Provider] : hxxp://www.softonic.it/s/{searchTerms}
*************************
AdwCleaner[R0].txt - [5362 byte] - [14/03/2015 10:29:59]
AdwCleaner[S0].txt - [5093 byte] - [14/03/2015 12:02:29]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5151 byte] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.3 (03.01.2015:1)
OS: Windows 7 Home Premium x64
Ran by Marco Basilisco on 14/03/2015 at 12:13:57,07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Marco Basilisco\appdata\local\{2292C12C-0BCC-4B27-8855-C34501C216E0}
Successfully deleted: [Empty Folder] C:\Users\Marco Basilisco\appdata\local\{6F618F47-BD4B-4F36-A00C-6E78F73B8B1C}
Successfully deleted: [Empty Folder] C:\Users\Marco Basilisco\appdata\local\{974AF7AB-EEC4-4860-B2F5-FB242FD841EB}
Successfully deleted: [Empty Folder] C:\Users\Marco Basilisco\appdata\local\{A80C895D-30D9-45DD-9F1E-646FD1F8E277}
Successfully deleted: [Empty Folder] C:\Users\Marco Basilisco\appdata\local\{BE02B165-0EB2-4897-AE45-5BF197940144}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14/03/2015 at 12:19:17,20
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~