Ciao,
Ho fatto tutto quello che mi hai detto di fare.
Ho scaricato e passato Malwerebytes, Adwcleaner, JRT, Eusing Free Registry.
La velocità del computer è migliorata molto. Anche se, per il momento,
non sono ancora sicuro che sia tutto a posto. Lo posso verificare lavorandoci su un po’.
Fammi sapere, per favore, se devo anche scaricare e passare HIJAKTHIS.Intanto Posto qui il tutto.
=================Con MalwereBytes, ho fatto 2 scansioni.
La prima con Rootkit: Disattivata.
La seconda con Rootkit: Attivata.
=================================
--PRIMA SCANSIONE--
Log-MalwereBytes-con-Rootkit: Disattivata-28-9-18
=================================
Malwarebytes
www.malwarebytes.com-Dettagli log-
Data scansione: 28/09/18
Ora scansione: 15:42
File di log: 6518e2d2-c324-11e8-87d5-00ff46a9a1f7.json
-Informazioni software-
Versione: 3.6.1.2711
Versione componenti: 1.0.463
Aggiorna versione pacchetto: 1.0.7065
Licenza: Free
-Informazioni sistema-
SO: Windows 7 Service Pack 1
CPU: x86
File system: NTFS
Utente: Moksha-PC\Moksha
-Riepilogo scansione-
Tipo di scansione: Ricerca elementi nocivi
Scansione avviata da: Manuale
Risultati: Completata
Elementi analizzati: 169070
Minacce rilevate: 1
Minacce messe in quarantena: 0
Tempo impiegato: 18 min, 44 sec
-Opzioni di scansione-
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Disattivata
Analisi euristica: Attivata
PUP: Rilevare
PUM: Rilevare
-Dettagli scansione-
Processo: 0
(Nessun elemento nocivo rilevato)
Modulo: 0
(Nessun elemento nocivo rilevato)
Chiave di registro: 0
(Nessun elemento nocivo rilevato)
Valore di registro: 0
(Nessun elemento nocivo rilevato)
Dati di registro: 0
(Nessun elemento nocivo rilevato)
Flusso di dati: 0
(Nessun elemento nocivo rilevato)
Cartella: 0
(Nessun elemento nocivo rilevato)
File: 1
PUP.Optional.Reimage, C:\$RECYCLE.BIN\S-1-5-21-227713952-2352024697-1479288484-1000\$RK2YV8A\REI_UNDOUTILITY.EXE, Nessuna
azione intrapresa, [1385], [327181],1.0.7065
Settore fisico: 0
(Nessun elemento nocivo rilevato)
WMI: 0
(Nessun elemento nocivo rilevato)
(end)
================================
--SECONDA SCANSIONE--
Log-MalwereBytes-con-Rootkit: Attivata-28-9-18
================================
Malwarebytes
www.malwarebytes.com-Dettagli log-
Data scansione: 28/09/18
Ora scansione: 16:38
File di log: 1d306faa-c32c-11e8-a078-00ff46a9a1f7.json
-Informazioni software-
Versione: 3.6.1.2711
Versione componenti: 1.0.463
Aggiorna versione pacchetto: 1.0.7067
Licenza: Free
-Informazioni sistema-
SO: Windows 7 Service Pack 1
CPU: x86
File system: NTFS
Utente: Moksha-PC\Moksha
-Riepilogo scansione-
Tipo di scansione: Ricerca elementi nocivi
Scansione avviata da: Manuale
Risultati: Completata
Elementi analizzati: 169381
Minacce rilevate: 0
Minacce messe in quarantena: 0
Tempo impiegato: 36 min, 5 sec
-Opzioni di scansione-
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Attivata
Analisi euristica: Attivata
PUP: Rilevare
PUM: Rilevare
-Dettagli scansione-
Processo: 0
(Nessun elemento nocivo rilevato)
Modulo: 0
(Nessun elemento nocivo rilevato)
Chiave di registro: 0
(Nessun elemento nocivo rilevato)
Valore di registro: 0
(Nessun elemento nocivo rilevato)
Dati di registro: 0
(Nessun elemento nocivo rilevato)
Flusso di dati: 0
(Nessun elemento nocivo rilevato)
Cartella: 0
(Nessun elemento nocivo rilevato)
File: 0
(Nessun elemento nocivo rilevato)
Settore fisico: 0
(Nessun elemento nocivo rilevato)
WMI: 0
(Nessun elemento nocivo rilevato)
(end)
=========================
--NOTA--
Ho passato Malwarebytes AdwCleaner,
e alla fine si sono prodotti 2 Logs.
Li posto tutti e due.
=========================
--PRIMO LOG--
# -------------------------------
# Malwarebytes AdwCleaner 7.2.4.0
# -------------------------------
# Build: 09-25-2018
# Database: 2018-09-21.1 (Local)
# Support:
https://www.malwarebytes.com/support#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 09-28-2018
# Duration: 00:01:06
# OS: Windows 7 Starter
# Scanned: 42056
# Detected: 5
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
***** [ Files ] *****
PUP.Optional.Reimage C:\Windows\System32\reimage.rep
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
PUP.Optional.ProductSetup.A HKCU\Software\PRODUCTSETUP
PUP.Optional.Reimage HKLM\Software\Reimage
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
PUP.Optional.Legacy Ask
PUP.Optional.Legacy AOL
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
===================================================
--SECONDO LOG--
# -------------------------------
# Malwarebytes AdwCleaner 7.2.4.0
# -------------------------------
# Build: 09-25-2018
# Database: 2018-09-21.1 (Local)
# Support:
https://www.malwarebytes.com/support#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-28-2018
# Duration: 00:00:20
# OS: Windows 7 Starter
# Cleaned: 5
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
No malicious folders cleaned.
***** [ Files ] *****
Deleted C:\Windows\System32\reimage.rep
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\PRODUCTSETUP
Deleted HKLM\Software\Reimage
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
Deleted Ask
Deleted AOL
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [1406 octets] - [28/09/2018 21:22:44]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
===================================
--SEGUE IL RISULTATO DI: Junkware Removal Tool (JRT) .
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Starter x86
Ran by Moksha (Administrator) on Sat 09/29/2018 at 8:10:55.01
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 64
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0XC5BSWP (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2X6I2Y7J (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3GLJQPUU (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3IEDTNNB (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3KVHF2M3 (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3TK5H2W3 (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4P7XAEUE (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JSL8SOO (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5S0JGVT1 (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7IOAQB0P (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9O31QAIC (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A83J97RG (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AC1CO5XG (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EKG6FKJP (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EPT6E13W (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F0YDXLPU (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FRY7R5RU (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GA5Y4D3W (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I98U2CQ2 (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IR9LO6O8 (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N29F4UTB (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NZI2UL0S (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QOND480I (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R8CXFCHB (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RXZF0QS5 (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S77YFQEU (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SM03X5DX (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SMRAUI32 (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TR94FWR1 (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V048AXAS (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y55IKZ5O (Temporary
Internet Files Folder)
Successfully deleted: C:\Users\Moksha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZT1TF8NY (Temporary
Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\0XC5BSWP (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\2X6I2Y7J (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\3GLJQPUU (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\3IEDTNNB (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\3KVHF2M3 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\3TK5H2W3 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\4P7XAEUE (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\5JSL8SOO (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\5S0JGVT1 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\7IOAQB0P (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\9O31QAIC (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\A83J97RG (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\AC1CO5XG (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\EKG6FKJP (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\EPT6E13W (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\F0YDXLPU (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\FRY7R5RU (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\GA5Y4D3W (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\I98U2CQ2 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\IR9LO6O8 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\N29F4UTB (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\NZI2UL0S (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\QOND480I (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\R8CXFCHB (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\RXZF0QS5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\S77YFQEU (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\SM03X5DX (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\SMRAUI32 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\TR94FWR1 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\V048AXAS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\Y55IKZ5O (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files
\Content.IE5\ZT1TF8NY (Temporary Internet Files Folder)
Registry: 4
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C500C267-63BF-451F-8797-4D720C9A2ED9}
(Registry Value)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EC1E29BB-F56A-45D8-B023-
D3EF710FA0E0} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{C500C267-63BF-451F-8797-4D720C9A2ED9} (Registry Value)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 09/29/2018 at 8:18:37.44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--NOTA--
Eusing Free Registry, ha trovato 499 file sospetti.
Ho cliccato su " Ripara registro" e sono stati cancellati tutti.
=====================
Un'ultima cosa. Ho la sensazione che qulche intrusione abbia modificato il Prox di Internet Esplorer.
C'e' un metodo per poterlo verificare?
Grazie di tutto.
Aspetto le tue valutazioni. Ciao.
______
P.S.
Volevo sapere, a parte MalwereBytes, se i programmi che ho scaricato li devo tenere sul computer o li devo disinstallare.