|
|||||||
|
|
|
![]() |
|
|
Strumenti |
|
|
#1 |
|
Junior Member
Iscritto dal: Jul 2018
Messaggi: 11
|
Spam aggressivo
Salve da un paio di settimane mi si aprono pagine di spam su chrome (e su qualsiasi browser impostato come predefinito), l'utilizzo di antimalware e antispam che di solito mi hanno risolto il problema stavolta non hanno funzionato e il problema continua a persistere.
Tra l'altro mi è difficilissimo provare programmi di pulizia diversi perché ogni volta che cerco su un motore di ricerca frasi che contengono le parole malware o spam chrome si chiude istantaneamente così come quando riesco a scaricare fortunosamente i file di installazione l'exe crasha e l'installazione non parte mai. A volte trovo anche il firewall disattivato e l'antivirus disattivato senza che io li tocchi, e le prestazioni del computer sono ai minimi storici. Questo è il log di Hijackthis, ma per me è arabo e non ci ho capito nulla Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 14:52:59, on 30/07/2018 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.19081) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Windows\PLFSetI.exe C:\Program Files\Panda Security\Panda Security Protection\PSUAMain.exe C:\Program Files\Steam\Steam.exe C:\Users\Pietro\AppData\Local\FluxSoftware\Flux\flux.exe C:\Users\Pietro\AppData\Roaming\uTorrent Web\utweb.exe C:\Program Files\DAEMON Tools Lite\DTAgent.exe C:\Users\Pietro\AppData\Roaming\Spotify\SpotifyWebHelper.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\conhost.exe C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Pietro\Desktop\HijackThis.exe C:\Windows\system32\taskeng.exe C:\Program Files\Google\Chrome\Application\chrome.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Panda Safe Web - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\pandasecuritytb\pandasecurityDx.dll O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office15\URLREDIR.DLL O2 - BHO: Panda Safe Web - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\pandasecuritytb\pandasecurityDx.dll O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL O3 - Toolbar: Panda Safe Web - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\pandasecuritytb\pandasecurityDx.dll O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [PSUAMain] "C:\Program Files\Panda Security\Panda Security Protection\PSUAMain.exe" /LaunchSysTray O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent O4 - HKCU\..\Run: [f.lux] "C:\Users\Pietro\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow O4 - HKCU\..\Run: [Skype for Desktop] C:\Program Files\Microsoft\Skype for Desktop\Skype.exe O4 - HKCU\..\Run: [utweb] "C:\Users\Pietro\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun O4 - HKCU\..\Run: [Spotify Web Helper] C:\Users\Pietro\AppData\Roaming\Spotify\SpotifyWebHelper.exe --autostart O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIZIO LOCALE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIZIO LOCALE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIZIO DI RETE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIZIO DI RETE') O4 - HKUS\S-1-5-18\..\RunOnce: [panda] reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [panda] reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f (User 'Default user') O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000 O8 - Extra context menu item: I&nvia a OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105 O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra button: Lync - Chiamata con un clic - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll O9 - Extra 'Tools' menuitem: Lync - Chiamata con un clic - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll O9 - Extra button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe O23 - Service: Servizio Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Servizio Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Panda Protection Service (NanoServiceMain) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Security Protection\PSANHost.exe O23 - Service: Panda Devices Agent (PandaAgent) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Devices Agent\AgentSvc.exe O23 - Service: panda_url_filtering Service (panda_url_filtering) - Visicom Media Inc. - C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe O23 - Service: Panda Product Service (PSUAService) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Security Protection\PSUAService.exe O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe -- End of file - 8701 bytes Come posso fare prima di lanciare il computer dalla finestra? |
|
|
|
|
|
#2 |
|
Senior Member
Iscritto dal: Oct 2016
Città: Tamriel
Messaggi: 1149
|
No.. io ripristinerei di brutto con un ripristino alle impostazioni di fabbrica (o distruttivo)
__________________
Hp Pavilion A1640.it Intel Core 2 quad q6600 - 6 gb DDR2 - Asus GTX 750 TI - Corsair CX850M - Windows 7 Home Premium x64 / Windows XP Media Center Edition ----------------------------------------------- |
|
|
|
|
|
#3 |
|
Junior Member
Iscritto dal: Jul 2018
Messaggi: 11
|
Dici che potrebbe funzionare? Prima del ripristino non c'è nient'altro che posso provare a fare? Come si fa il ripristino? E, soprattutto, i miei file in memoria vengono toccati nella procedura? Devo fare un backup?
|
|
|
|
|
|
#4 |
|
Member
Iscritto dal: Jun 2017
Messaggi: 175
|
Ciao
proviamo a vedere se cè qualche cosa che non va.... teniamo il ripristino o il format come ultima spiaggia... Esegui le scansioni in ordine come scritte: scansione con mbar scaricalo da qui: https://it.malwarebytes.com/antirootkit/ elimina quello che trova e posta il log Malwarebyte antimalware scaricalo da qui https://it.malwarebytes.com/ fai la scansione ed elimina cio che trova e posta il log generato Scarica adwcleaner da qui https://www.bleepingcomputer.com/download/adwcleaner/ tasto dx sopra eseguibile avvia come amministratore e fai la scansione elimina quello che trova e posta il log Poi scarica frst da qui https://www.bleepingcomputer.com/dow...ery-scan-tool/ scarica la versione adatta al tuo sistemaoperativo 32 o 64 bit posiziona l eseguibile sul desktop tasto dx sopra eseguibile--apri come amministratore una volta aperto clicca su scan postare log frst.txt e addition.txt |
|
|
|
|
|
#5 | |
|
Junior Member
Iscritto dal: Jul 2018
Messaggi: 11
|
Quote:
|
|
|
|
|
|
|
#6 |
|
Senior Member
Iscritto dal: Mar 2008
Messaggi: 20985
|
Cosa stai aspettando a formattare e reinstallare da zero o ripristinare una immagine di backup delle partizioni di sistema fatta quando tutto era a posto?
Che parti qualche processo che si metta a criptare i tuoi file chiedendoti il riscatto in moneta per la chiave di decodifica? Lasciate stare le scansioni e le disinfezioni, perdete più tempo che rifare tutto d'accapo, senza alcuna sicurezza di riuscire veramente a ripristinare e nel frattempo potete avere ancora più danni. Mia opinione. sia chiaro. Tu fai pure come pensi sia giusto |
|
|
|
|
|
#7 |
|
Junior Member
Iscritto dal: Jul 2018
Messaggi: 11
|
è possibile ripristinare un'immagine di backup precedente anche se negli ultimi mesi non ho fatto un backup su disco esterno?
|
|
|
|
|
|
#8 |
|
Member
Iscritto dal: Jun 2017
Messaggi: 175
|
Prova a scaricare mbar e rinominalo in mbar.com....vedi se funge...
In alternativa fa cosi: 1. Scarica la versione 1.10.3.1001 di Malwarebytes Anti Rootkit (MBAR) https://malwarebytes.app.box.com/s/f...lkentlvycq0f3z 2. Eseguire il programma come amministratore. Click ok per estrarre.. Se Mbar non funziona, scaricare la copia zip dell articolo ALL INIZIO e seguire le istruzioni. Quindi continua al passaggio 3. https://support.malwarebytes.com/docs/DOC-1267 3. Dopo l'estrazione, dovrebbe iniziare MBAR. Cliccare su next 4. Aggiorna lo strumento premendo il pulsante di aggiornamento UPDATE. Dopo l'aggiornamento, cliccare su next. 5. Premi il pulsante di scansione. Per favore lascia che finisca la scansione. Questo rootkit potrebbe rallentare il tuo computer e MBAR potrebbe sembrare che si bloccherà ma continuerà a scansionare. Si prega di lascirlo lavorare. Se la scansione fallisce provare a lasciare selezionato solo DRIVER e deselezionare SECTOR e SYSTEM….Poi riprovare la scansione…. Se si ottiene l errore dda driver was not installed.... Fare clic su Sì e il computer verrà riavviato. Dopo il riavvio, la finestra di MBAR dovrebbe aprirsi automaticamente. Nota: se il desktop è mancante / nero, non preoccuparti. Questo è normale e si prega di procedere con il seguito. Fare clic su Avanti seguito da Avanti. Fare click su scan elimina cio che trova... Ciao fa sapere... NB: fa come vuoi, secondo me ripristinare da punti di ripristino interni al pc è un rischio con la probabilita che il malware li abbia infettati.... Altro discorso da un beckup esterno...pero se è stato effettuato quando il pc era gia infetto ti trascinerai dietro pure l infezione.. Se sei sicuro della bonta del beckup è un conto se no...vedi te Ci mancherebbe altro sono mie opinioni personali... Ultima modifica di Dan1979 : 31-07-2018 alle 14:32. |
|
|
|
|
|
#9 | |
|
Member
Iscritto dal: Jun 2017
Messaggi: 175
|
Quote:
In piu i file erano gia criptati.... Perche lasciare stare le scansioni quando ci sono programmi appositamente creati per effettuare pulizie varie...??? Non capisco!!! Mia opinione....ci mancherebbe Forse concordo per il fatto dei tempi... Con la formattazione o beckup (con i relativi rischi) è vero che che si fa prima, ma non è sempre vero...dipende da infezione a infezione e da quanto si è radicata in profondita al S.O (se è a livello kernel è complicato ma non impossibile sbarazzarsene,vedi rootkit livello kernel simil driver....) Io tento quasi sempre, poi se vedo che non cavo un ragno dal buco dopo un po si che formatto tutto.... Ciao |
|
|
|
|
|
|
#10 |
|
Junior Member
Iscritto dal: Jul 2018
Messaggi: 11
|
Sono riuscito ad eseguire la scansione e a cleanare i due file sospetti trovati col file zip di mbar, ma non è cambiato nulla, continuo a non poter installare mbar o altri antimalware e se cerco la parola malware sugoogle o clicco su uno dei tuoi link mi si chiude chrome.
|
|
|
|
|
|
#11 |
|
Senior Member
Iscritto dal: Mar 2008
Messaggi: 20985
|
|
|
|
|
|
|
#12 | |||
|
Senior Member
Iscritto dal: Mar 2008
Messaggi: 20985
|
Quote:
Quote:
Quote:
Sempre mie opinioni ed esperienze sia chiaro, ognuno faccia come gli pare. ps. ha postato ieri sera alle 19, son passate quasi 24 ore ed è ancora punto e accapo, non so se mi spiego... Ultima modifica di Nicodemo Timoteo Taddeo : 31-07-2018 alle 16:00. |
|||
|
|
|
|
|
#13 |
|
Member
Iscritto dal: Jun 2017
Messaggi: 175
|
Ciao Nicodemo
I ransomware generalmente si prendono tramite allegati di posta ,tranne wannacry che sfruttato un exploit per intrufolarsi ....questo solo chi ha vista.... Questo per quanto ne so io.... Quel genere di sintomi sono dovuti in teoria da rootkit o trojan...è per quello che gli faccio eseguire un antirootkit... Be ieri sera ha postato il problema.... Siccome penso che scriviamo qui per hobby e quando ceneè il tempo diciamo che siamo ancora nei tempi giusti .... Correggimi se sbaglio... Ripeto, se hai un beckup infetto tantovale non usarlo... Allora meglio formattare.... Io proverei prima a bonificare.... Decisione che spetta l utente.... |
|
|
|
|
|
#14 |
|
Junior Member
Iscritto dal: Jul 2018
Messaggi: 11
|
Ora ho provato a scansionare di nuovo e non ha trovato niente, ho anche riavviato il computer e niente sembra esser cambiato.
|
|
|
|
|
|
#15 | ||
|
Senior Member
Iscritto dal: Mar 2008
Messaggi: 20985
|
Quote:
Quote:
La cosa principale ripeto è che se hai un sistema infetto non puoi mettere la mano sul fuoco su nulla. Non sei più tu il "padrone" del computer, ma chi ha programmato quel malware. Quindi ci si può aspettare di tutto, e secondo me, tranne che non si tratti qualche fesseria facilmente eliminabile tipo quelli che agiscono solo sul browser, meglio rifare tutto d'accapo o richiamare un backup. Meno sbattimento e più sicurezza e tranquillità. Poi se uno vuole divertirsi a fare scansioni, controscansioni, verifiche, contro verifiche, proviamo questo e poi proviamo quello, vediamo che succede così ecc. ecc. ecc. faccia pure. Ci siam passati tutti, e ci siamo quelli che abbiamo capito che è innanzitutto una gran perdita di tempo. |
||
|
|
|
|
|
#16 |
|
Junior Member
Iscritto dal: Jul 2018
Messaggi: 11
|
Io vorrei provare a bonificare prima e in extremis formattare, se non funziona niente sarò costretto a farlo evidentemente ed ero già pronto all'evenienza ancor prima di scrivere il post nel forum. Cosa posso fare adesso visto che mbar sembra non aver risolto nulla?
|
|
|
|
|
|
#17 |
|
Member
Iscritto dal: Jun 2017
Messaggi: 175
|
Provalo in modalita provvisoria...poi vai avanti con il resto delle scansioni....
|
|
|
|
|
|
#18 | |
|
Senior Member
Iscritto dal: Oct 2016
Città: Tamriel
Messaggi: 1149
|
Quote:
2)Il ripristino lo si può fare in tre modi: -Se hai i dischi di ripristino li inserisci,spegni il computer e una volta acceso dovrebbe partirti l'utility per ripristinarlo. Qui stai attento a seguire la procedura per il ripristino alle impostazioni di fabbrica e non solo ripristino standard... -Se hai la partizione di ripristino,appena acceso il computer devi schiacciare ripetutamente il tasto che serve ad accedere alla partizione e quindi all'utility per il ripristino. Per il resto la procedura è come quella con i dischi. -Se non hai ne dischi di ripristino ne partizione devi installare il sistema operativo tramite installazione pulita. Quindi devi reperire l'immagine del sistema operativo (o il CD) e fare una installazione pulita con formattazione dell'unità. Nel caso tu abbia Windows 10 la Microsoft mette a disposizione un tool sul sito in cui puoi scaricarti l'immagine di Windows 10 o su CD o su Pen Drive. Queste,per lo meno,sono le procedure più diffuse o che io conosco meglio. Per tutte queste modalità di ripristino descritte devi salvarti su un supporto tutto ciò che vuoi salvare e non vuoi perdere. IMPORTANTE che tu sappia il codice product key prima di proseguire con una installazione pulita,altrimenti rischi di perderlo a vita se non ce l'hai da qualche parte e di dover comprare un nuovo sistema operativo.
__________________
Hp Pavilion A1640.it Intel Core 2 quad q6600 - 6 gb DDR2 - Asus GTX 750 TI - Corsair CX850M - Windows 7 Home Premium x64 / Windows XP Media Center Edition ----------------------------------------------- |
|
|
|
|
|
|
#19 | |
|
Junior Member
Iscritto dal: Jul 2018
Messaggi: 11
|
Quote:
Questo è il log di Malwarebytes: Malwarebytes www.malwarebytes.com -Dettagli log- Data scansione: 01/08/18 Ora scansione: 10:28 File di log: e3d149ff-9564-11e8-9283-1c7508451efc.json Amministratore: Sì -Informazioni software- Versione: 3.5.1.2522 Versione componenti: 1.0.391 Aggiorna versione pacchetto: 1.0.6151 Licenza: Free -Informazioni sistema- SO: Windows 7 Service Pack 1 CPU: x86 File system: NTFS Utente: pc\Pietro -Riepilogo scansione- Tipo di scansione: Ricerca elementi nocivi Scansione avviata da: Manuale Risultati: Completata Elementi analizzati: 181592 Minacce rilevate: 10 Minacce messe in quarantena: 10 Tempo impiegato: 7 min, 2 sec -Opzioni di scansione- Memoria: Attivata Esecuzioni automatiche: Attivata File system: Attivata Archivi compressi: Attivata Rootkit: Disattivata Analisi euristica: Attivata PUP: Rilevare PUM: Rilevare -Dettagli scansione- Processo: 0 (Nessun elemento nocivo rilevato) Modulo: 0 (Nessun elemento nocivo rilevato) Chiave di registro: 0 (Nessun elemento nocivo rilevato) Valore di registro: 0 (Nessun elemento nocivo rilevato) Dati di registro: 0 (Nessun elemento nocivo rilevato) Flusso di dati: 0 (Nessun elemento nocivo rilevato) Cartella: 0 (Nessun elemento nocivo rilevato) File: 10 PUP.Optional.Reimage, C:\USERS\PIETRO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\PREFERENCES, Sostituito, [1367], [541062],1.0.6151 PUP.Optional.MyStart, C:\PROGRAM FILES\PANDASECURITYTB\TOOLBARCLEANER.EXE, In quarantena, [227], [455885],1.0.6151 PUP.Optional.Iminent, C:\USERS\PIETRO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\SyncData.sqlite3, Sostituito, [101], [455248],1.0.6151 PUP.Optional.Iminent, C:\USERS\PIETRO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sostituito, [101], [455248],1.0.6151 PUP.Optional.Iminent, C:\USERS\PIETRO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sostituito, [101], [455248],1.0.6151 PUP.Optional.Iminent, C:\USERS\PIETRO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\SyncData.sqlite3, Sostituito, [101], [455248],1.0.6151 PUP.Optional.Iminent, C:\USERS\PIETRO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sostituito, [101], [455248],1.0.6151 PUP.Optional.Iminent, C:\USERS\PIETRO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\SyncData.sqlite3, Sostituito, [101], [455248],1.0.6151 PUP.Optional.Iminent, C:\USERS\PIETRO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Sostituito, [101], [455248],1.0.6151 PUP.Optional.Iminent, C:\USERS\PIETRO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sostituito, [101], [455248],1.0.6151 Settore fisico: 0 (Nessun elemento nocivo rilevato) WMI: 0 (Nessun elemento nocivo rilevato) (end) Questo è il log di Adwcleaner: # AdwCleaner 7.0.7.0 - Logfile created on Wed Aug 01 08:53:32 2018 # Updated on 2018/18/01 by Malwarebytes # Database: 2018-07-25.1 # Running on Windows 7 Ultimate (X86) # Mode: scan # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** PUP.Optional.Panda, panda_url_filtering ***** [ Folders ] ***** PUP.Optional.Legacy, C:\Program Files\pandasecuritytb PUP.Optional.Legacy, C:\Windows\System32\config\systemprofile\AppData\LocalLow\pandasecuritytb PUP.Optional.Legacy, C:\Users\Pietro\AppData\LocalLow\pandasecuritytb PUP.Optional.Solvusoft, C:\Users\Pietro\AppData\Roaming\WinThruster PUP.Optional.Panda, C:\Program Files\Panda Security URL Filtering ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {72E0B1DE-7B7C-489A-AAEA-69AA892A96EE} PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {72E0B1DE-7B7C-489A-AAEA-69AA892A96EE} PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {8B308A8C-B706-45F4-AF10-5C30818A67F0} PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {8B308A8C-B706-45F4-AF10-5C30818A67F0} PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {96178B12-D8F2-4ADD-8F6D-723F74F76C14} PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {DC484EAF-7CC8-4570-BD55-E8DABDD73331} PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {5D1F038C-E479-4A4B-85E3-29385B899DF9} PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {5D1F038C-E479-4A4B-85E3-29385B899DF9} PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {83F79830-6962-4EC7-96F0-5B454CCB9A10} PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {83F79830-6962-4EC7-96F0-5B454CCB9A10} PUP.Optional.SofTonicAssistant, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries. ************************* ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ########## Questo il log di frst: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21.07.2018 Ran by Pietro (administrator) on PC (01-08-2018 11:45:07) Running from C:\Users\Pietro\Desktop Loaded Profiles: Pietro (Available Profiles: Pietro) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: Italiano (Italia) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Safe Mode (with Networking) Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSUAService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PSANHost.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Security Protection\PAV3WSC.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [206208 2010-06-09] () HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-10-28] (Advanced Micro Devices, Inc.) HKLM\...\Run: [PSUAMain] => C:\Program Files\Panda Security\Panda Security Protection\PSUAMain.exe [141760 2017-02-22] (Panda Security, S.L.) HKU\S-1-5-21-3475549784-737223174-1249760543-1000\...\Run: [f.lux] => C:\Users\Pietro\AppData\Local\FluxSoftware\Flux\flux.exe [1806344 2018-07-03] (f.lux Software LLC) HKU\S-1-5-21-3475549784-737223174-1249760543-1000\...\Run: [utweb] => C:\Users\Pietro\AppData\Roaming\uTorrent Web\utweb.exe [5179064 2018-03-29] (BitTorrent Inc.) HKU\S-1-5-21-3475549784-737223174-1249760543-1000\...\Run: [Spotify Web Helper] => C:\Users\Pietro\AppData\Roaming\Spotify\SpotifyWebHelper.exe [774544 2018-07-22] (Spotify Ltd) HKU\S-1-5-18\...\RunOnce: [panda] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f HKU\S-1-5-18\...\RunOnce: [panda_XP] => reg.exe delete "HKCU\Software\panda" /f GroupPolicyScripts: Restriction <==== ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{C11EF9E9-8CE1-4917-AA25-844B5D1D3F5F}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{ECC88173-E57E-4622-A400-1B9EE911E625}: [DhcpNameServer] 192.168.0.254 Internet Explorer: ================== HKU\S-1-5-21-3475549784-737223174-1249760543-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.it/ URLSearchHook: HKU\S-1-5-21-3475549784-737223174-1249760543-1000 - Panda Safe Web - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\pandasecuritytb\pandasecurityDx.dll No File BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2017-08-24] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation) BHO: Panda Safe Web -> {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} -> C:\Program Files\pandasecuritytb\pandasecurityDx.dll => No File BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation) Toolbar: HKLM - Panda Safe Web - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\pandasecuritytb\pandasecurityDx.dll No File Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2017-08-15] (Microsoft Corporation) FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_30_0_0_134.dll [2018-07-11] () FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-06-12] (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-20] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-07-20] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com CHR StartupUrls: Default -> "hxxps://www.google.com/" CHR Session Restore: Default -> is enabled. CHR Profile: C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default [2018-08-01] CHR Extension: (Presentazioni) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13] CHR Extension: (Documenti) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13] CHR Extension: (Google Drive) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-03] CHR Extension: (Giovanni Ficarra) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\bicbnmkiaocihaoagfeccdlbhjegpbpp [2017-08-03] CHR Extension: (YouTube) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-03] CHR Extension: (Adblock Plus) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-07-18] CHR Extension: (Adobe Acrobat) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-10-19] CHR Extension: (Fogli) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13] CHR Extension: (Ripples) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfnjgbmalioedafbpahlobnkgbjkllod [2017-08-03] CHR Extension: (Google Documenti offline) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-08-04] CHR Extension: (AdBlock) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-07-27] CHR Extension: (Google Maps) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2017-08-03] CHR Extension: (StudentiAristofane) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnljalkpjbjhgagkobdehjlmpbnbgdbm [2017-08-03] CHR Extension: (Pagamenti Chrome Web Store) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04] CHR Extension: (Dusky Waves) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pckedjlckloojeaklbodeeoblnkmhkhn [2017-08-03] CHR Extension: (Gmail) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-03] CHR Extension: (Chrome Media Router) - C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-07] CHR Profile: C:\Users\Pietro\AppData\Local\Google\Chrome\User Data\System Profile [2017-08-03] CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4753104 2018-05-09] (Malwarebytes) R2 NanoServiceMain; C:\Program Files\Panda Security\Panda Security Protection\PSANHost.exe [110384 2017-02-14] (Panda Security, S.L.) S2 PandaAgent; C:\Program Files\Panda Security\Panda Devices Agent\AgentSvc.exe [86104 2016-07-19] (Panda Security, S.L.) R2 PSUAService; C:\Program Files\Panda Security\Panda Security Protection\PSUAService.exe [47096 2017-04-26] (Panda Security, S.L.) S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [98304 2013-04-12] () [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW73.sys [102416 2017-08-03] (ATI Technologies, Inc.) S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [278728 2017-08-15] () S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [26168 2018-07-07] (Disc Soft Ltd) S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [40504 2018-07-07] (Disc Soft Ltd) S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25416 2017-08-15] () R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [220896 2018-08-01] (Malwarebytes) S1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [98624 2017-02-08] (Panda Security, S.L.) S1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [210984 2016-06-29] (Panda Security, S.L.) S1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [119760 2017-02-08] (Panda Security, S.L.) S1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [134368 2016-06-29] (Panda Security, S.L.) R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [67352 2016-06-30] (Panda Security, S.L.) S1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [114536 2016-06-29] (Panda Security, S.L.) S1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [75048 2017-02-08] (Panda Security, S.L.) S1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [129224 2016-06-29] (Panda Security, S.L.) S1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [315904 2016-06-29] (Panda Security, S.L.) S1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [232536 2017-02-08] (Panda Security, S.L.) S1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [116224 2016-06-29] (Panda Security, S.L.) S1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [261064 2016-07-01] (Panda Security, S.L.) S1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [109904 2016-06-29] (Panda Security, S.L.) S2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [152336 2017-02-12] (Panda Security, S.L.) S2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [112400 2017-02-12] (Panda Security, S.L.) S1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [175888 2017-02-20] (Panda Security, S.L.) S2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [121616 2017-02-12] (Panda Security, S.L.) S2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [132880 2017-02-12] (Panda Security, S.L.) S2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [107792 2017-02-12] (Panda Security, S.L.) U3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [58288 2016-08-08] (Panda Security, S.L.) S3 panda_url_filteringd; \??\C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-08-01 11:45 - 2018-08-01 11:46 - 000012360 _____ C:\Users\Pietro\Desktop\FRST.txt 2018-08-01 11:44 - 2016-08-08 11:00 - 000058288 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\PSKMAD.sys 2018-08-01 10:53 - 2018-08-01 10:53 - 000003025 _____ C:\Users\Pietro\Desktop\AdwCleaner[S0].txt 2018-08-01 10:25 - 2018-08-01 11:44 - 000220896 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2018-07-31 21:06 - 2018-08-01 11:45 - 000000000 ____D C:\FRST 2018-07-31 21:05 - 2018-07-31 21:05 - 000002020 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2018-07-31 21:05 - 2018-07-31 21:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2018-07-31 21:04 - 2018-07-31 22:14 - 000129248 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae.sys 2018-07-31 21:04 - 2018-07-31 21:04 - 000000000 ____D C:\Program Files\Malwarebytes 2018-07-31 20:46 - 2018-07-31 20:46 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\1655554A.sys 2018-07-31 20:43 - 2018-07-31 20:43 - 001773056 ____N (Farbar) C:\Users\Pietro\Desktop\FRST.exe 2018-07-31 20:34 - 2018-08-01 11:44 - 000445258 _____ C:\Windows\ntbtlog.txt 2018-07-31 18:29 - 2018-07-31 18:29 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\5272E707.sys 2018-07-31 16:17 - 2018-07-31 16:17 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\4C6306E4.sys 2018-07-31 15:41 - 2018-07-31 21:04 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2018-07-31 15:41 - 2018-07-31 21:04 - 000000000 ____D C:\ProgramData\Malwarebytes 2018-07-31 15:41 - 2018-07-31 20:46 - 000166848 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2018-07-31 15:41 - 2018-07-31 15:41 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\6751C2EE.sys 2018-07-30 14:50 - 2018-07-30 14:50 - 000388608 _____ (Trend Micro Inc.) C:\Users\Pietro\Desktop\HijackThis.exe 2018-07-30 12:29 - 2018-08-01 10:59 - 000000000 ____D C:\AdwCleaner 2018-07-30 12:29 - 2018-07-27 11:21 - 008206624 ____N (Malwarebytes) C:\Users\Pietro\Desktop\adwcleaner-7-0-7-0.exe 2018-07-23 11:12 - 2018-07-23 11:13 - 000028657 _____ C:\Users\Pietro\Desktop\modulo_disdetta_contratto_affitto.pdf 2018-07-20 15:57 - 2018-07-20 15:57 - 000002240 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-07-20 15:57 - 2018-07-20 15:57 - 000002199 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2018-07-17 19:24 - 2018-07-17 19:24 - 000000000 ____D C:\Users\Pietro\Documents\telecamera 2018-07-14 00:37 - 2018-07-14 00:37 - 000000000 ____D C:\Program Files\Mozilla Firefox 2018-07-11 23:54 - 2018-06-21 02:00 - 000348824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2018-07-11 23:54 - 2018-06-16 18:36 - 020286464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2018-07-11 23:54 - 2018-06-16 18:06 - 000498176 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2018-07-11 23:54 - 2018-06-16 18:02 - 002295296 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2018-07-11 23:54 - 2018-06-16 17:49 - 000668160 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2018-07-11 23:54 - 2018-06-16 17:47 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2018-07-11 23:54 - 2018-06-16 17:39 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2018-07-11 23:54 - 2018-06-16 17:34 - 004496384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2018-07-11 23:54 - 2018-06-16 17:32 - 013680128 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2018-07-11 23:54 - 2018-06-16 17:28 - 002060288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2018-07-11 23:54 - 2018-06-16 17:27 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2018-07-11 23:54 - 2018-06-16 17:08 - 002767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2018-07-11 23:54 - 2018-06-16 17:05 - 001313792 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2018-07-11 23:54 - 2018-06-13 17:55 - 012880384 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2018-07-11 23:54 - 2018-06-13 17:54 - 001499648 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2018-07-11 23:54 - 2018-06-13 17:25 - 002404352 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2018-07-11 23:54 - 2018-06-08 18:02 - 004050624 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2018-07-11 23:54 - 2018-06-08 18:02 - 003962048 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2018-07-11 23:54 - 2018-06-08 18:02 - 000189632 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll 2018-07-11 23:54 - 2018-06-08 18:02 - 000189632 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll 2018-07-11 23:54 - 2018-06-08 18:02 - 000137920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2018-07-11 23:54 - 2018-06-08 18:02 - 000136384 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll 2018-07-11 23:54 - 2018-06-08 18:02 - 000067264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2018-07-11 23:54 - 2018-06-08 17:57 - 001310488 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2018-07-11 23:54 - 2018-06-08 17:55 - 000330240 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll 2018-07-11 23:54 - 2018-06-08 17:54 - 000269824 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2018-07-11 23:54 - 2018-06-08 17:54 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2018-07-11 23:54 - 2018-06-08 17:28 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2018-07-11 23:54 - 2018-06-07 17:34 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys 2018-07-11 23:54 - 2018-05-31 17:56 - 001310912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2018-07-11 23:54 - 2018-05-31 17:56 - 000240832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2018-07-11 23:54 - 2018-05-31 17:56 - 000187584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2018-07-11 23:54 - 2018-05-02 17:30 - 000285184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2018-07-11 23:54 - 2018-05-02 17:30 - 000259584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2018-07-11 23:54 - 2018-05-02 17:30 - 000046592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2018-07-11 23:54 - 2018-05-02 17:30 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2018-07-11 23:54 - 2018-04-26 15:05 - 000918296 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000065880 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000021848 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000018776 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000017240 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000017240 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000015192 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000013152 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000011096 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000011096 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000011096 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2018-07-11 23:54 - 2018-04-26 15:05 - 000011096 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2018-07-11 23:54 - 2018-04-25 17:54 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll 2018-07-11 23:54 - 2018-04-25 17:17 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys 2018-07-11 23:53 - 2018-06-16 18:19 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2018-07-11 23:53 - 2018-06-16 18:19 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2018-07-11 23:53 - 2018-06-16 18:06 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2018-07-11 23:53 - 2018-06-16 18:05 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2018-07-11 23:53 - 2018-06-16 18:05 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2018-07-11 23:53 - 2018-06-16 18:04 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2018-07-11 23:53 - 2018-06-16 17:59 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2018-07-11 23:53 - 2018-06-16 17:59 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2018-07-11 23:53 - 2018-06-16 17:57 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2018-07-11 23:53 - 2018-06-16 17:56 - 000662016 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2018-07-11 23:53 - 2018-06-16 17:56 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2018-07-11 23:53 - 2018-06-16 17:56 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2018-07-11 23:53 - 2018-06-16 17:55 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2018-07-11 23:53 - 2018-06-16 17:42 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2018-07-11 23:53 - 2018-06-16 17:42 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2018-07-11 23:53 - 2018-06-16 17:41 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2018-07-11 23:53 - 2018-06-16 17:38 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2018-07-11 23:53 - 2018-06-16 17:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2018-07-11 23:53 - 2018-06-16 17:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2018-07-11 23:53 - 2018-06-16 17:30 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2018-07-11 23:53 - 2018-06-16 17:29 - 000696320 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2018-07-11 23:53 - 2018-06-16 17:28 - 000692224 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2018-07-11 23:53 - 2018-06-16 17:04 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 001417728 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 001063424 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000377344 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll 2018-07-11 23:53 - 2018-06-08 17:55 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:29 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll 2018-07-11 23:53 - 2018-06-08 17:27 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2018-07-11 23:53 - 2018-06-08 17:27 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2018-07-11 23:53 - 2018-06-08 17:27 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2018-07-11 23:53 - 2018-06-08 17:27 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2018-07-11 23:53 - 2018-06-08 17:27 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2018-07-11 23:53 - 2018-06-08 17:25 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2018-07-11 23:53 - 2018-06-08 17:24 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2018-07-11 23:53 - 2018-06-08 17:24 - 000107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys 2018-07-11 23:53 - 2018-06-08 17:21 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2018-07-11 23:53 - 2018-06-08 17:21 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2018-07-11 23:53 - 2018-06-08 17:21 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2018-07-11 23:53 - 2018-06-08 17:19 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2018-07-11 23:53 - 2018-06-08 17:19 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2018-07-11 23:53 - 2018-06-08 17:19 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2018-07-11 23:53 - 2018-06-08 17:19 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2018-07-11 23:53 - 2018-06-08 17:19 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:19 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2018-07-11 23:53 - 2018-06-08 17:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2018-07-11 23:53 - 2018-06-07 17:57 - 000564736 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2018-07-11 23:53 - 2018-06-07 17:57 - 000463360 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll 2018-07-11 23:53 - 2018-06-07 17:57 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll 2018-07-11 23:53 - 2018-06-07 17:34 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll 2018-07-11 23:53 - 2018-05-02 17:30 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2018-07-11 23:53 - 2018-05-02 17:30 - 000020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2018-07-11 23:53 - 2018-05-02 17:29 - 000006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2018-07-11 23:52 - 2018-06-13 19:59 - 000122560 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2018-07-11 23:52 - 2018-06-13 17:53 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2018-07-11 23:52 - 2018-06-08 15:05 - 002703872 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2018-07-11 23:52 - 2018-06-08 15:05 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2018-07-11 23:52 - 2018-06-08 15:05 - 000619520 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2018-07-11 23:52 - 2018-06-08 15:05 - 000517120 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2018-07-11 23:52 - 2018-06-08 15:05 - 000358912 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2018-07-11 23:52 - 2018-06-08 15:05 - 000353792 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2018-07-11 23:52 - 2018-06-08 15:05 - 000246272 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2018-07-11 23:52 - 2018-06-08 15:05 - 000202752 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2018-07-08 12:25 - 2018-07-08 12:25 - 000000000 ____D C:\Users\Pietro\AppData\Roaming\SUPERAntiSpyware.com 2018-07-08 12:24 - 2018-07-08 12:24 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2018-07-07 19:18 - 2018-07-07 19:18 - 000000000 ____D C:\Users\Pietro\AppData\Roaming\Steam 2018-07-07 19:10 - 2018-07-07 19:10 - 000001893 _____ C:\Users\Public\Desktop\Total War Attila.lnk 2018-07-07 18:39 - 2018-07-07 20:25 - 000000000 ____D C:\Program Files\Total War Attila 2018-07-07 18:35 - 2018-07-07 18:35 - 000000000 ____D C:\Users\Public\Documents\Catch! 2018-07-07 18:34 - 2018-07-07 18:35 - 000040504 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtliteusbbus.sys 2018-07-07 18:33 - 2018-07-07 18:36 - 000000000 ____D C:\Users\Pietro\AppData\Local\Disc_Soft_Ltd 2018-07-07 18:33 - 2018-07-07 18:33 - 000000000 ____D C:\Users\Public\Documents\Daemon Tools Images 2018-07-07 18:31 - 2018-07-07 18:35 - 000000000 ____D C:\Users\Pietro\AppData\Roaming\DAEMON Tools Lite 2018-07-07 18:31 - 2018-07-07 18:33 - 000026168 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys 2018-07-07 18:30 - 2018-07-07 18:30 - 000000000 ____D C:\ProgramData\DAEMON Tools Lite 2018-07-07 17:24 - 2018-07-07 18:02 - 000000000 ____D C:\Users\Pietro\Downloads\Total.War.Attila.RePack.by.Valdeni 2018-07-06 13:32 - 2018-07-06 13:32 - 000000002 _____ C:\Users\Pietro\AppData\Local\WMI.ini ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-08-01 11:41 - 2018-04-22 17:43 - 000000000 ____D C:\Users\Pietro\AppData\Roaming\uTorrent Web 2018-08-01 11:06 - 2018-02-21 18:39 - 000009984 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2018-08-01 11:06 - 2018-02-21 18:39 - 000009984 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2018-08-01 10:57 - 2017-08-03 00:11 - 000000000 ____D C:\Program Files\KMSpico 2018-08-01 10:56 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2018-07-31 21:04 - 2015-01-28 01:02 - 000000000 ____D C:\Users\Pietro\Desktop\mbar 2018-07-31 20:39 - 2017-11-12 01:31 - 000000000 ____D C:\Users\Pietro\AppData\Local\ElevatedDiagnostics 2018-07-31 16:06 - 2017-08-15 16:54 - 000000000 ____D C:\Program Files\Steam 2018-07-30 20:46 - 2018-03-12 21:15 - 000000000 ____D C:\Users\Pietro\Desktop\ricordati che ogni tanto sei anche un cazzo di scrittore 2018-07-30 14:51 - 2017-08-03 18:21 - 000000000 ____D C:\Users\Pietro\AppData\Local\Spotify 2018-07-30 14:39 - 2017-08-03 18:20 - 000000000 ____D C:\Users\Pietro\AppData\Roaming\Spotify 2018-07-29 02:26 - 2017-08-16 09:19 - 000000000 ____D C:\Windows\system32\Macromed 2018-07-24 12:09 - 2011-01-15 13:50 - 001644010 _____ C:\Windows\system32\PerfStringBackup.INI 2018-07-24 12:09 - 2009-07-14 10:21 - 000744404 _____ C:\Windows\system32\perfh010.dat 2018-07-24 12:09 - 2009-07-14 10:21 - 000148734 _____ C:\Windows\system32\perfc010.dat 2018-07-24 12:08 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf 2018-07-20 15:56 - 2017-08-03 16:44 - 000000000 ____D C:\Program Files\Google 2018-07-20 15:54 - 2017-08-03 16:43 - 000000000 ____D C:\Users\Pietro\AppData\Local\Deployment 2018-07-17 00:02 - 2011-01-15 14:00 - 000480888 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2018-07-16 01:57 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\rescache 2018-07-14 19:38 - 2017-10-19 19:28 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2018-07-14 19:21 - 2009-07-14 06:33 - 000464392 _____ C:\Windows\system32\FNTCACHE.DAT 2018-07-14 19:17 - 2017-08-16 04:52 - 000000000 ____D C:\Windows\system32\appraiser 2018-07-14 00:53 - 2017-08-02 23:59 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2018-07-14 00:34 - 2009-07-14 04:37 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2018-07-11 19:02 - 2017-09-13 20:58 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2018-07-11 19:02 - 2017-08-16 09:19 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2018-07-10 18:10 - 2017-09-19 17:46 - 000002078 _____ C:\Users\Pietro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk 2018-07-07 19:18 - 2017-08-16 09:19 - 000000000 ____D C:\Users\Pietro\AppData\Roaming\The Creative Assembly 2018-07-07 14:33 - 2017-11-12 21:49 - 000000000 ____D C:\Users\Pietro\AppData\Local\Ubisoft Game Launcher 2018-07-07 14:31 - 2017-08-03 08:28 - 000000000 ___HD C:\Program Files\InstallShield Installation Information 2018-07-07 13:52 - 2017-08-15 16:50 - 000000000 ____D C:\Windows\system32\appmgmt 2018-07-06 13:32 - 2017-08-02 23:44 - 000000000 ____D C:\Users\Pietro 2018-07-06 13:12 - 2018-05-07 14:41 - 000000000 ____D C:\Users\Pietro\Documents\il gioco 2018-07-06 13:12 - 2017-12-05 15:20 - 000000000 ____D C:\Users\Pietro\Desktop\Cenerentola 2018-07-05 13:23 - 2009-07-14 04:04 - 000000478 _____ C:\Windows\win.ini ==================== Files in the root of some directories ======= 2009-07-14 03:14 - 2009-07-14 03:14 - 000186368 ____N (Microsoft Corporation) C:\Users\Pietro\AKKZk.exe 2018-05-17 23:03 - 2018-05-17 23:03 - 007649280 _____ () C:\Program Files\GUT7D73.tmp 2017-11-15 22:45 - 2017-11-15 22:45 - 007649280 _____ () C:\Program Files\GUTFA49.tmp 2009-07-14 03:14 - 2009-07-14 03:14 - 000073216 ____N (Microsoft Corporation) C:\Users\Pietro\AppData\Local\TxiCYYmoEGki.exe 2018-07-06 13:32 - 2018-07-06 13:32 - 000000002 _____ () C:\Users\Pietro\AppData\Local\WMI.ini Some files in TEMP: ==================== 2012-10-01 12:22 - 2012-10-01 12:22 - 000150648 ____R (Microsoft Corporation) C:\Users\Pietro\AppData\Local\Temp\ose00000.exe 2017-08-03 08:48 - 2017-08-03 08:50 - 062220008 _____ () C:\Users\Pietro\AppData\Local\Temp\{5D7B7A09-D066-467F-8179-FD7ECE607679}.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2018-07-27 12:30 ==================== End of FRST.txt ============================ Nonostante abbia cleanato i risultati di malwarebytes ed adwcleaner la situazione non è cambiata rispetto a prima, tr l'altro stranamente molti di questi file infetti sembrano provenire da PANDA che sarebbe il mio antivirus (????). Ci si cava un ragno dal buco? |
|
|
|
|
|
|
#20 |
|
Member
Iscritto dal: Jun 2017
Messaggi: 175
|
Allora disinstalla panda antivirus, lo reinstalleremo alla fine....
Pulisci con ccleaner sia sistema che registro.. Poi ,esegui una scansione con roguekiller... Scaricalo da qui... http://www.adlice.com/download/roguekiller/ Segui questa guida per usare il programma http://it.ccm.net/faq/3204-come-usare Cancella solo le voci di colore rosso... Posta il.report Ripeti una scansione con frst facendo attenzione a spuntare addition....posta i nuovi log frst.txt e addition.txt Fai attenzione a non sbagliarti con i vecchi log.. Mi raccomando pista anche addition.txt l altra volta non lo hai postato.... |
|
|
|
|
| Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 01:58.




















