Malwarebytes Anti-Malware
www.malwarebytes.orgData scansione: 15/07/2015
Ora scansione: 23:35
File di log: log.txt
Amministratore: Sì
Versione: 2.1.8.1057
Database malware: v2015.07.15.06
Database rootkit: v2015.07.15.01
Licenza: Gratuito
Protezione da malware: Disattivata
Protezione da siti web nocivi: Disattivata
Auto-protezione: Disattivata
SO: Windows 7 Service Pack 1
CPU: x64
File system: NTFS
Utente: diego
Tipo di scansione: Ricerca elementi nocivi
Risultati: Completata
Elementi analizzati: 370766
Tempo impiegato: 48 min, 48 sec
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Disattivata
Euristiche: Attivata
PUP: Attivata
PUM: Attivata
Processi: 0
(Nessun elemento nocivo rilevato)
Moduli: 0
(Nessun elemento nocivo rilevato)
Chiavi di registro: 1
PUP.Optional.Spigot.A, HKU\S-1-5-21-3245179290-486166780-4058341772-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0A39F958-B29F-45C7-AB09-E5BB57925832}, In quarantena, [cf43a63c3852af870d9863a4f40fe719],
Valori di registro: 1
PUP.Optional.Spigot.A, HKU\S-1-5-21-3245179290-486166780-4058341772-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0A39F958-B29F-45C7-AB09-E5BB57925832}|URL,
https://it.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=926458&p={searchTerms}, In quarantena, [cf43a63c3852af870d9863a4f40fe719]
Dati di registro: 0
(Nessun elemento nocivo rilevato)
Cartelle: 1
PUP.Optional.PriceMinus.A, C:\Program Files (x86)\PriceMinus, In quarantena, [48cad80a6e1c51e5f712becf0df7e61a],
File: 4
PUP.Optional.Spigot.A, C:\Users\diego\AppData\Roaming\Mozilla\Firefox\Profiles\ifal8ryq.default\searchplugins\yahoo_ff.xml, In quarantena, [ba584a98d6b4e155f55726f0e41f17e9],
PUP.Optional.PriceMinus.A, C:\Program Files (x86)\PriceMinus\5gDc5TgRGgv1cP.tlb, In quarantena, [48cad80a6e1c51e5f712becf0df7e61a],
PUP.Optional.PriceMinus.A, C:\Program Files (x86)\PriceMinus\5gDc5TgRGgv1cP.dat, In quarantena, [48cad80a6e1c51e5f712becf0df7e61a],
PUP.Optional.Spigot.A, C:\Users\diego\AppData\Roaming\Mozilla\Firefox\Profiles\ifal8ryq.default\prefs.js, Buono: (), Nocivo (user_pref("keyword.URL", "https://it.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=926458&p=");), Sostituito,[54bef7eb7e0c6bcb8300f96faf5617e9]
Settori fisici: 0
(Nessun elemento nocivo rilevato)
(end)
# AdwCleaner v4.208 - Creato file registro eventi 16/07/2015 in 01:48:44
# Aggiornato 09/07/2015 da Xplode
# Database : 2015-07-15.1 [Server]
# Sistema operativo : Windows 7 Home Premium Service Pack 1 (x64)
# Nome utente : diego - DIEGO-PC
# In esecuzione da : C:\Users\diego\Desktop\adwcleaner_4.208.exe
# Opzione : Pulizia
***** [ Servizi ] *****
[#] Servizio Eliminato : YahooAUService
[#] Servizio Eliminato : mcaudrv_simple
[#] Servizio Eliminato : ManyCam
***** [ File / Cartelle ] *****
Cartella Eliminato : C:\ProgramData\AVG Security Toolbar
Cartella Eliminato : C:\ProgramData\Yahoo! Companion
Cartella Eliminato : C:\ProgramData\4811658048577681415
Cartella Eliminato : C:\Program Files (x86)\Check Point Software Technologies LTD
Cartella Eliminato : C:\Program Files (x86)\PriiceMinuS
Cartella Eliminato : C:\Users\diego\AppData\LocalLow\ShopperReports3
Cartella Eliminato : C:\Users\diego\AppData\LocalLow\Yahoo! Companion
Cartella Eliminato : C:\Users\diego\AppData\Roaming\Solvusoft
Cartella Eliminato : C:\Users\diego\AppData\Roaming\Check Point Software Technologies LTD
Cartella Eliminato : C:\Users\diego\AppData\Roaming\Mozilla\Firefox\Profiles\ifal8ryq.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Cartella Eliminato : C:\Users\diego\AppData\Roaming\Mozilla\Firefox\Profiles\ifal8ryq.default\Extensions\ffxtlbr@zonealarm.com
Cartella Eliminato : C:\Users\diego\AppData\Roaming\Mozilla\Firefox\Profiles\ifal8ryq.default\Extensions\me4k7Q@2vO.org
Cartella Eliminato : C:\Users\diego\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh
Cartella Eliminato : C:\ProgramData\mobohbhjecahalngepnmlikhcgopdgge
File Eliminato : C:\Users\Public\Desktop\eBay.lnk
File Eliminato : C:\Windows\Reimage.ini
File Eliminato : C:\Windows\System32\roboot64.exe
File Eliminato : C:\Windows\System32\drivers\mcaudrv_x64.sys
File Eliminato : C:\Windows\System32\drivers\mcvidrv.sys
File Eliminato : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
File Eliminato : C:\Users\diego\AppData\Roaming\Mozilla\Firefox\Profiles\ifal8ryq.default\searchplugins\zonealarm.xml
File Eliminato : C:\Users\diego\AppData\Roaming\Mozilla\Firefox\Profiles\ifal8ryq.default\user.js
***** [ Attività pianificate ] *****
***** [ Collegamenti ] *****
***** [ Registry ] *****
Chiave Eliminato : HKCU\Software\Google\Chrome\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh
Chiave Eliminato : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Chiave Eliminato : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Chiave Eliminato : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Chiave Eliminato : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Chiave Eliminato : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
Chiave Eliminato : HKLM\SOFTWARE\Classes\AppID\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Chiave Eliminato : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Chiave Eliminato : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{987D9269-F8A1-408F-BF62-4397D2F5363E}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{E0722BEB-FDA1-4AA1-A2A8-15A74A5B3F70}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Chiave Eliminato : HKLM\SOFTWARE\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Chiave Eliminato : HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Chiave Eliminato : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Chiave Eliminato : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Chiave Eliminato : HKLM\SOFTWARE\Classes\TypeLib\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Chiave Eliminato : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Chiave Eliminato : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Chiave Eliminato : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Chiave Eliminato : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Chiave Eliminato : HKLM\SOFTWARE\Classes\TypeLib\{E00DE9B9-B128-4C39-B732-B5D85013FA48}
Chiave Eliminato : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Chiave Eliminato : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chiave Eliminato : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chiave Eliminato : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Chiave Eliminato : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chiave Eliminato : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chiave Eliminato : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Chiave Eliminato : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Valore Eliminato : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Chiave Eliminato : [x64] HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Chiave Eliminato : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Chiave Eliminato : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Chiave Eliminato : HKCU\Software\AVG Nation toolbar
Chiave Eliminato : HKCU\Software\Reimage
Chiave Eliminato : HKCU\Software\Avg Secure Update
Chiave Eliminato : HKCU\Software\AppDataLow\Software\ShopperReports3
Chiave Eliminato : HKLM\SOFTWARE\AVG Nation toolbar
Chiave Eliminato : HKLM\SOFTWARE\AVG Secure Search
Chiave Eliminato : HKLM\SOFTWARE\AVG Security Toolbar
Chiave Eliminato : HKU\.DEFAULT\Software\Avg Secure Update
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Chiave Eliminato : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Chiave Eliminato : [x64] HKLM\SOFTWARE\Reimage
***** [ Browser web ] *****
-\\ Internet Explorer v11.0.9600.17909
-\\ Mozilla Firefox v38.0.5 (x86 it)
[ifal8ryq.default\prefs.js] - Linea Eliminato : user_pref("browser.search.selectedEngine", "AVG Secure Search");
[ifal8ryq.default\prefs.js] - Linea Eliminato : user_pref("extensions.irc.initialURLs", "irc%3A//irc.icq.com/; irc%3A//irc.icq.com/TriviaHolics");
[ifal8ryq.default\prefs.js] - Linea Eliminato : user_pref("extensions.vg0Y5BKJHzZl3UEa.scode", "(function(){try{if(window.location.href.indexOf(\"rjw4pjY7qHw9rdw7qjCEqHaFqTk\")>-1){return;}}catch(e){}try{var d=[[\"cryptogmail.com\",\"bancdebinary.c[...]
[ifal8ryq.default\prefs.js] - Linea Eliminato : user_pref("extensions.zonealarm.tlbrSrchUrl", "hxxp://search.zonealarm.com/search?src=tb&tbid=HFA5&Lan={dfltLng}&gu=1896995bf7484a5a9341fec16414240a&tu=10G9y00Gy5D33N0&sku=&tstsId=&ver=&&q=");
-\\ Google Chrome v43.0.2357.81
[C:\Users\diego\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Eliminato [Extension] : bopakagnckmlgajfccecajhnimjiiedh
[C:\Users\diego\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Eliminato [Extension] : lmjegmlicamnimmfhcmpkclmigmmcbeh
[C:\Users\diego\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Eliminato [Extension] : mobohbhjecahalngepnmlikhcgopdgge
[C:\Users\diego\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Eliminato [Default_Search_Provider_Data] :
*************************
AdwCleaner[R0].txt - [13838 byte] - [16/07/2015 01:45:27]
AdwCleaner[S0].txt - [9110 byte] - [16/07/2015 01:48:44]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9168 byte] ##########