ciao mi tornano sempre le stesse minacce , anche dopo decine di scansioni con tutti e 5 softwar.
# -------------------------------
# Malwarebytes AdwCleaner 7.2.6.0
# -------------------------------
# Build: 12-18-2018
# Database: 2019-01-25.2 (Cloud)
# Support:
https://www.malwarebytes.com/support#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 01-30-2019
# Duration: 00:00:42
# OS: Windows 7 Professional
# Scanned: 31744
# Detected: 7
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
***** [ Files ] *****
No malicious files found.
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
No malicious registry entries found.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
PUP.Optional.Legacy
http://isearch.avg.com?cid={BE6EAECC-BFE2-4020-9780-47EBD5A4F744}&mid=d8ac0bb5d8d2493c8a955f324b67702e-790ae18025efd56c4d62239176903213a3f45f6a&lang=it&ds=ts024&coid=avgtbdists&pr=sa&d=2013-11-01 16:02:31&v=17.3.0.49&pid=avg&sg=0&sap=hp
PUP.Optional.Legacy
http://isearch.avg.com?cid={BE6EAECC-BFE2-4020-9780-47EBD5A4F744}&mid=d8ac0bb5d8d2493c8a955f324b67702e-790ae18025efd56c4d62239176903213a3f45f6a&lang=it&ds=ts024&coid=avgtbdists&pr=sa&d=2013-11-01 16:02:31&v=17.0.0.12&pid=avg&sg=&sap=hp
PUP.Optional.Legacy
http://www.awesomehp.com/?type=hp&ts=1395046817&from=tt4u&uid=ST3500413AS_Z2A7LKQQXXXXZ2A7LKQQPUP.Optional.SweetPage.ShrtCln
http://www.sweet-page.com/?type=hppp&ts=1401199646&from=cor&uid=ST3500413AS_Z2A7LKQQXXXXZ2A7LKQQPUP.Optional.SweetPage.ShrtCln
http://www.sweet-page.com/?type=hppp&ts=1401137072&from=cor&uid=ST3500413AS_Z2A7LKQQXXXXZ2A7LKQQPUP.Optional.SweetPage.ShrtCln
http://www.sweet-page.com/?type=hppp&ts=1400968750&from=cor&uid=ST3500413AS_Z2A7LKQQXXXXZ2A7LKQQPUP.Optional.SweetPage.ShrtCln
http://www.sweet-page.com/?type=hp&ts=1400968629&from=cor&uid=ST3500413AS_Z2A7LKQQXXXXZ2A7LKQQ***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
AdwCleaner[S00].txt - [2750 octets] - [30/01/2019 01:47:45]
AdwCleaner[C00].txt - [2732 octets] - [30/01/2019 01:49:09]
AdwCleaner[S01].txt - [1379 octets] - [30/01/2019 01:53:08]
AdwCleaner[C01].txt - [1565 octets] - [30/01/2019 01:53:30]
AdwCleaner[S02].txt - [1501 octets] - [30/01/2019 02:01:18]
AdwCleaner_Debug.log - [49741 octets] - [30/01/2019 02:06:42]
AdwCleaner[S03].txt - [2818 octets] - [30/01/2019 02:07:15]
AdwCleaner[S04].txt - [2836 octets] - [30/01/2019 02:24:40]
AdwCleaner[C04].txt - [2894 octets] - [30/01/2019 02:26:20]
AdwCleaner[S05].txt - [2958 octets] - [30/01/2019 02:35:35]
AdwCleaner[C05].txt - [3016 octets] - [30/01/2019 02:36:51]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S06].txt ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Professional x64
Ran by Lucy (Administrator) on 30/01/2019 at 2:59:15,12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 6
Successfully deleted: C:\Users\Lucy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\307I41FI (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Lucy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IWPKL6NB (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Lucy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZEP3HRTW (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\307I41FI (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IWPKL6NB (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZEP3HRTW (Temporary Internet Files Folder)
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30/01/2019 at 3:02:42,80
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Malwarebytes
www.malwarebytes.com-Dettagli log-
Data scansione: 30/01/19
Ora scansione: 02:52
File di log: a71dd1ec-2431-11e9-b524-00ff0cfcb119.json
-Informazioni software-
Versione: 3.6.1.2711
Versione componenti: 1.0.527
Aggiorna versione pacchetto: 1.0.9028
Licenza: Free
-Informazioni sistema-
SO: Windows 7 Service Pack 1
CPU: x64
File system: NTFS
Utente: Lucy-PC\Lucy
-Riepilogo scansione-
Tipo di scansione: Ricerca elementi nocivi
Scansione avviata da: Manuale
Risultati: Completata
Elementi analizzati: 222839
Minacce rilevate: 23
Minacce messe in quarantena: 0
Tempo impiegato: 5 min, 56 sec
-Opzioni di scansione-
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Attivata
Analisi euristica: Attivata
PUP: Rilevare
PUM: Rilevare
-Dettagli scansione-
Processo: 0
(Nessun elemento nocivo rilevato)
Modulo: 0
(Nessun elemento nocivo rilevato)
Chiave di registro: 0
(Nessun elemento nocivo rilevato)
Valore di registro: 1
PUP.Optional.BrowseCoupon, HKU\S-1-5-21-312103867-4227677436-750476336-1000\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|ihjbpjahiibmjdlcgodcnmpelpmilamk, Nessuna azione intrapresa, [2403], [175768],1.0.9028
Dati di registro: 0
(Nessun elemento nocivo rilevato)
Flusso di dati: 0
(Nessun elemento nocivo rilevato)
Cartella: 4
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\_metadata, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\images, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\USERS\LUCY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\IHJBPJAHIIBMJDLCGODCNMPELPMILAMK, Nessuna azione intrapresa, [2403], [175768],1.0.9028
File: 18
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\images\icon128.png, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\images\icon16.png, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\images\icon48.png, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\_metadata\verified_contents.json, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\background.js, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\button.js, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\icon.png, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\manifest.json, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\popup.html, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\popup.js, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\Users\Lucy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjbpjahiibmjdlcgodcnmpelpmilamk\4.75_1\styles.css, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\USERS\LUCY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.BrowseCoupon, C:\USERS\LUCY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Nessuna azione intrapresa, [2403], [175768],1.0.9028
PUP.Optional.SweetPage, C:\USERS\LUCY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Nessuna azione intrapresa, [377], [455284],1.0.9028
PUP.Optional.HTTPBreaker, C:\USERS\LUCY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Nessuna azione intrapresa, [389], [455245],1.0.9028
Adware.Elex.ShrtCln, C:\USERS\LUCY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Nessuna azione intrapresa, [270], [454679],1.0.9028
PUP.Optional.HTTPBreaker, C:\USERS\LUCY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Nessuna azione intrapresa, [389], [455245],1.0.9028
PUP.Optional.HTTPBreaker, C:\USERS\LUCY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Nessuna azione intrapresa, [389], [455245],1.0.9028
Settore fisico: 0
(Nessun elemento nocivo rilevato)
WMI: 0
(Nessun elemento nocivo rilevato)
(end)
Rkill 2.9.1 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/Copyright 2008-2019 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.htmlProgram started at: 01/30/2019 03:03:39 AM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Windows Defender Disabled
[HKLM\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware" = dword:00000001
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* Cannot edit the HOSTS file.
* Permissions could not be fixed. Use Hosts-perm.bat to fix permissions:
http://www.bleepingcomputer.com/download/hosts-permbat/Program finished at: 01/30/2019 03:03:58 AM
Execution time: 0 hours(s), 0 minute(s), and 19 seconds(s)
Logfile of HiJackThis Fork by Alex Dragokas v.2.9.0.18
Platform: x64 Windows 7 (Pro), 6.1.7601.0, Service Pack: 1
Time: 30.01.2019 - 03:05 (UTC+01:00)
Language: OS: Italian (0x410). Display: Italian (0x410). Non-Unicode: Italian (0x410)
Elevated: Yes
Ran by: Lucy (group: Administrator) on LUCY-PC, FirstRun: yes
Chrome: 71.0.3578.98
Internet Explorer: 11.0.9600.19230
Default: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Chrome)
Boot mode: Normal
Running processes:
Number | Path
1 C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
1 C:\Program Files (x86)\Avira\Antivirus\avguard.exe
1 C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
1 C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
1 C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
1 C:\Program Files (x86)\Avira\Antivirus\sched.exe
1 C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
1 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
13 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
1 C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler.exe
1 C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler64.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
1 C:\Program Files\Windows Media Player\wmpnetwk.exe
1 C:\Users\Lucy\Desktop\PULIZIE\HiJackThis.exe
1 C:\Windows\System32\SearchFilterHost.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SearchProtocolHost.exe
1 C:\Windows\System32\WirelessKB850NotificationService.exe
1 C:\Windows\System32\audiodg.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\dllhost.exe
1 C:\Windows\System32\dwm.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\lsm.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
10 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\System32\wuauclt.exe
1 C:\Windows\explorer.exe
O4 - HKCU\..\Run: [GUDelayStartup] = C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun
O4 - HKLM\..\Run: [RTHDVCPL] = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
O4 - HKLM\..\Session Manager: [BootExecute] = C:\Windows\system32\autochk.exe *
O4 - HKU\.DEFAULT\..\RunOnce: [SPReview] = C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
O4-32 - HKLM\..\Run: [Avira SystrayStartTrigger] = C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe
O17 - DHCP DNS 1: 192.168.1.1
O23 - Service R2: Adobe Acrobat Update Service - (AdobeARMservice) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service R2: Avira Pianificatore - (AntiVirSchedulerService) - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service R2: Avira Protezione email - (AntiVirMailService) - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service R2: Avira Protezione in tempo reale - (AntiVirService) - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service R2: Avira Protezione web - (AntiVirWebService) - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service R2: Avira Service Host - (Avira.ServiceHost) - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service R2: Malwarebytes Service - (MBAMService) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service R2: Wireless Keyboard 850 Notification Service - (WirelessKB850NotificationService) - C:\Windows\system32\WirelessKB850NotificationService.exe
O23 - Service S2: NVIDIA Display Driver Service - (nvsvc) - C:\Windows\system32\nvvsvc.exe
O23 - Service S2: Servizio Google Update (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: Google Chrome Elevation Service - (GoogleChromeElevationService) - C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\elevation_service.exe
O23 - Service S3: Servizio Google Update (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
--
End of file - Time spent: 18,3 sec. - 8832 bytes, CRC32: FFFFFFFF. Sign: 冹砇