Malwarebytes Anti-Malware
www.malwarebytes.orgData scansione: 11/01/2015
Ora scansione: 20:52:59
File di log: log3.txt
Amministratore: Si
Versione: 2.00.4.1028
Database malware: v2015.01.11.10
Database rootkit: v2015.01.07.01
Licenza: Free
Protezione da malware: Disattivata
Protezione da siti web nocivi: Disattivata
Autoprotezione: Disattivata
SO: Windows 7 Service Pack 1
CPU: x64
File system: NTFS
Utente: 10042014
Tipo di scansione: Scansione elementi nocivi
Risultati: Completata
Elementi analizzati: 316787
Tempo impiegato: 5 min, 13 sec
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Disattivata
Euristica: Attivata
PUP: Attivata
PUM: Attivata
Processi: 0
(Nessun elemento malevolo rilevato)
Moduli: 0
(Nessun elemento malevolo rilevato)
Chiavi di registro: 2
PUP.Optional.Booster.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{423248f1}, Spostato in quarantena, [d452f0062e5be1552d8fc6c4a95a25db],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2158896076-2760410929-1853944569-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, Spostato in quarantena, [e83ed224d5b457df9a6fda94788bfc04],
Valori di registro: 0
(Nessun elemento malevolo rilevato)
Dati di registro: 0
(Nessun elemento malevolo rilevato)
Cartelle: 35
PUP.Optional.StormAlert.A, C:\Users\10042014\AppData\Local\StormAlert, Spostato in quarantena, [7babd81eb9d0df579395571d5ba8e818],
PUP.Optional.StormAlert.A, C:\ProgramData\StormAlert, Spostato in quarantena, [bc6a5f97a0e9191d66c37cf81de67987],
Rogue.Multiple, C:\ProgramData\600440862, Spostato in quarantena, [50d6698d2168a591217256cdbd46817f],
PUP.Optional.OpenCandy, C:\Users\10042014\AppData\Roaming\OpenCandy, Spostato in quarantena, [db4b10e66524b28427fc2f047a8957a9],
PUP.Optional.OpenCandy, C:\Users\10042014\AppData\Roaming\OpenCandy\OpenCandy_17613D7BB99845D4B2EFB901ACEC401C, Spostato in quarantena, [db4b10e66524b28427fc2f047a8957a9],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\code, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Spostato in quarantena, [bd696b8b19702f07de0c2e1c60a36b95],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, Spostato in quarantena, [bd696b8b19702f07de0c2e1c60a36b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.Nosibay.A, C:\Users\10042014\AppData\Roaming\Nosibay, Spostato in quarantena, [34f2678fb5d4d363bfeffb6743c0cf31],
File: 72
PUP.Optional.OpenCandy, C:\$Recycle.Bin\S-1-5-21-2158896076-2760410929-1853944569-1000\$R4XUM4X.exe, Spostato in quarantena, [180e43b35a2f6dc994da55611aeb08f8],
PUP.Optional.Somoto, C:\Users\10042014\AppData\Local\Temp\bitool.dll, Spostato in quarantena, [0c1a94625f2afb3beb92d8d209f916ea],
PUP.Optional.Clara.A, C:\Users\10042014\AppData\Local\Temp\setup.exe, Spostato in quarantena, [2ef8d0265a2f171f65255b789a67867a],
PUP.Optional.Somoto, C:\Users\10042014\AppData\Local\Temp\nscE7A4.tmp, Spostato in quarantena, [71b5d026f2973006df188f6ce61ed52b],
PUP.Optional.Wajam.A, C:\Users\10042014\AppData\Local\Temp\4591.tmp, Spostato in quarantena, [d0565b9bdaafc373bc5ee08599678f71],
PUP.Optional.Softonic, C:\Users\10042014\Downloads\SoftonicDownloader_per_daemon-tools-lite.exe, Spostato in quarantena, [9096975f6128a78f842ef9616799de22],
PUP.Optional.Softonic, C:\Users\10042014\Downloads\SoftonicDownloader_per_farming-simulator-2013-update.exe, Spostato in quarantena, [1214ce28bdcce94d0fa38ad0916f7b85],
PUP.Optional.BoBrowser.A, C:\Windows\System32\Tasks\Run_Bobby_Browser, Spostato in quarantena, [5fc720d62762b680de021158e41f25db],
PUP.Optional.Bubbledock.A, C:\Users\10042014\AppData\Roaming\Bubble Dock.boostrap.log, Spostato in quarantena, [a28410e6d5b40e282ff4e687bc478a76],
PUP.Optional.Bubbledock.A, C:\Users\10042014\AppData\Roaming\Bubble Dock.installation.log, Spostato in quarantena, [cc5a11e51079b97d1c072d40748f2bd5],
PUP.Optional.WindApp.A, C:\Users\10042014\AppData\Roaming\WindApp.boostrap.log, Spostato in quarantena, [4fd73abc127779bd45dfc6a77a895ca4],
PUP.Optional.StormAlert.A, C:\Users\10042014\AppData\Local\StormAlert\data2.dat, Spostato in quarantena, [7babd81eb9d0df579395571d5ba8e818],
PUP.Optional.StormAlert.A, C:\ProgramData\StormAlert\app.dat, Spostato in quarantena, [bc6a5f97a0e9191d66c37cf81de67987],
PUP.Optional.StormAlert.A, C:\ProgramData\StormAlert\data.dat, Spostato in quarantena, [bc6a5f97a0e9191d66c37cf81de67987],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\239.json, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\MessageBox.xml, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\uninstallDlg2.xml, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\bg.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\bg1.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\bk_shadow.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\button.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\button1.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\checkbox.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\checkbox_select.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\checked.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\close.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\loading_bg.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\loading_light.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\min.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\scrollbar.bmp, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\Thumbs.db, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\unchecked.png, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\code\code1.jpg, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\code\code2.jpg, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\code\code3.jpg, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\code\code4.jpg, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\code\code5.jpg, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\code\code6.jpg, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WebsSearches.A, C:\Users\10042014\AppData\Roaming\webssearches\images\code\Thumbs.db, Spostato in quarantena, [f72ff204f99072c4475a1d1ce81b8779],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, Spostato in quarantena, [bd696b8b19702f07de0c2e1c60a36b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, Spostato in quarantena, [9195c531632669cd5d994d03f013669a],
Settori fisici: 0
(Nessun elemento malevolo rilevato)
(end)