Malwarebytes Anti-Malware
www.malwarebytes.org
Data scansione: 07/08/2016
Ora scansione: 20:17
File di log:
Amministratore: Sì
Versione: 2.2.1.1043
Database malware: v2016.08.07.03
Database rootkit: v2016.05.27.01
Licenza: Periodo di prova
Protezione da malware: Attivata
Protezione da siti web nocivi: Attivata
Auto-protezione: Disattivata
SO: Windows 8.1
CPU: x64
File system: NTFS
Utente: Francesco
Tipo di scansione: Ricerca elementi nocivi
Risultati: Completata
Elementi analizzati: 311353
Tempo impiegato: 24 min, 39 sec
Memoria: Attivata
Esecuzioni automatiche: Attivata
File system: Attivata
Archivi compressi: Attivata
Rootkit: Disattivata
Euristiche: Attivata
PUP: Attivata
PUM: Attivata
Processi: 0
(Nessun elemento nocivo rilevato)
Moduli: 0
(Nessun elemento nocivo rilevato)
Chiavi di registro: 12
Trojan.ProxyHijacker, HKLM\SOFTWARE\CLASSES\Office 365 Crack.DynamicNS, In quarantena, [6ad5e4645248a195c8c8138328da758b],
Trojan.ProxyHijacker, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Office 365 Crack.DynamicNS, In quarantena, [7cc390b8227860d6365a3c5ad42ebc44],
Trojan.ProxyHijacker, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Office 365 Crack.DynamicNS, In quarantena, [7cc390b8227860d6365a3c5ad42ebc44],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5058DF79-EC0D-4F18-B38A-80EF6CE9323F}, Elimina al riavvio, [ca7564e48f0b89ad589b30c3877c817f],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5963CF18-EAD1-40F1-A56B-8673FD9C9205}, Elimina al riavvio, [9ba41b2d881258deb83b5c97bf4434cc],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{60D184A4-AFC2-4626-8984-2CF141C01CD4}, Elimina al riavvio, [b48bb5935842cf67ed0637bc58ab6b95],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{628FD23D-0351-4D33-9494-4613516AA2EC}, Elimina al riavvio, [241b99af8713fb3b995a2bc8e81b53ad],
PUP.Optional.Bench, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{79234E69-54BE-4633-A333-930549ADF8C7}, Elimina al riavvio, [e9560444ecae0c2ac374896e649fa060],
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{7F961BA4-B8C3-4EBB-98E5-065A20AC9FA6}, Elimina al riavvio, [39067bcd0892b482f2019a5900035ba5],
PUP.Optional.Bench, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B179BB40-56E2-4167-8F07-E89937E667F3}, Elimina al riavvio, [37082028b1e97abc14e07754a95943bd],
PUP.Optional.BoBrowser, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{D01C8E1B-0B4E-4254-84B5-160FDD560923}, Elimina al riavvio, [0e31fb4d495187af1adc2da00ff3768a],
PUP.Optional.SoftwareUpdater, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\SrvUpd4terExe, In quarantena, [67d8ba8e35651d19e6248f3516ed9b65],
Valori di registro: 9
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5058DF79-EC0D-4F18-B38A-80EF6CE9323F}|Path, \700c531e-65be-4dc3-89de-8862cd85b51d-5, Elimina al riavvio, [ca7564e48f0b89ad589b30c3877c817f]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5963CF18-EAD1-40F1-A56B-8673FD9C9205}|Path, \700c531e-65be-4dc3-89de-8862cd85b51d-6, Elimina al riavvio, [9ba41b2d881258deb83b5c97bf4434cc]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{60D184A4-AFC2-4626-8984-2CF141C01CD4}|Path, \700c531e-65be-4dc3-89de-8862cd85b51d-7, Elimina al riavvio, [b48bb5935842cf67ed0637bc58ab6b95]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{628FD23D-0351-4D33-9494-4613516AA2EC}|Path, \700c531e-65be-4dc3-89de-8862cd85b51d-3, Elimina al riavvio, [241b99af8713fb3b995a2bc8e81b53ad]
PUP.Optional.Bench, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{79234E69-54BE-4633-A333-930549ADF8C7}|Path, \bench-S-1-5-21-2961635379-1552717557-3161034885-1001, Elimina al riavvio, [e9560444ecae0c2ac374896e649fa060]
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{7F961BA4-B8C3-4EBB-98E5-065A20AC9FA6}|Path, \700c531e-65be-4dc3-89de-8862cd85b51d-5_user, Elimina al riavvio, [39067bcd0892b482f2019a5900035ba5]
PUP.Optional.Bench, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B179BB40-56E2-4167-8F07-E89937E667F3}|Path, \bench-sys, Elimina al riavvio, [37082028b1e97abc14e07754a95943bd]
PUP.Optional.BoBrowser, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{D01C8E1B-0B4E-4254-84B5-160FDD560923}|Path, \Run_Bobby_Browser, Elimina al riavvio, [0e31fb4d495187af1adc2da00ff3768a]
PUP.Optional.MBot, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mbot_it_435, In quarantena, [76c92f19bcde76c060224762956e6e92],
Dati di registro: 0
(Nessun elemento nocivo rilevato)
Cartelle: 0
(Nessun elemento nocivo rilevato)
File: 12
PUP.Optional.Nosibay, C:\Users\Francesco\AppData\Roaming\ZHP\Quarantine\64999.Selection_Tools.ALT001[1].exe, In quarantena, [e15ec682bae0c0761474781933d143bd],
PUP.Optional.ConvertAd, C:\Users\Francesco\AppData\Roaming\ZHP\Quarantine\ConvertAdSetup[1].exe, In quarantena, [f34c92b68c0eb18526a206a98b7645bb],
PUP.Optional.Nosibay, C:\Users\Francesco\AppData\Roaming\ZHP\Quarantine\downloader.63088[1].exe, In quarantena, [89b6e2667b1f6fc7ef994f4247bda957],
PUP.Optional.Nosibay, C:\Users\Francesco\AppData\Roaming\ZHP\Quarantine\downloader.64470[2].exe, In quarantena, [9ca350f81c7e84b291f7e2af5da7817f],
FraudTool.YAC, C:\Users\Francesco\AppData\Roaming\ZHP\Quarantine\yet_another_cleaner_ava.exe, In quarantena, [1827ee5a84161422e07e74afec1538c8],
FraudTool.YAC, C:\Users\Francesco\AppData\Roaming\ZHP\Quarantine\yet_another_cleaner_cnt[1].exe, In quarantena, [58e71c2cc1d9033393cb8d9643bec040],
PUP.Optional.CrossRider, C:\Users\Francesco\AppData\Roaming\ZHP\Quarantine\d668c6e4-c695-496b-a69b-5f9cdb00d3e5\56c1bd2c-11a6-4254-9e94-79357885f251.dll, In quarantena, [d06fc7818e0c55e176d01a0e768b32ce],
CrackTool.Agent, C:\Program Files (x86)\AVS4YOU\avs4you.all.products.activator.2011.(v1.1a)-FIXED-mpt.exe, In quarantena, [b58a70d845552b0b2abdfdac00003dc3],
CrackTool.Agent, C:\Users\Francesco\Downloads\AVS all products ACTIVATOR.rar, In quarantena, [d76884c41486989ed80fddcc40c009f7],
PUP.Optional.BrowserWarden, C:\Users\Francesco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hjjjegfhiceggepdokloeepnhlfnedkk_0.localstorage, In quarantena, [e758e1677a20b482f7798911ec1747b9],
PUP.Optional.Linkury.Gen, C:\Users\Francesco\AppData\Roaming\Stringdex.tst, In quarantena, [f847f652e3b786b0343037c6cc378878],
PUP.Optional.Linkury.Gen, C:\Users\Francesco\AppData\Roaming\ZenStrong.tst, In quarantena, [231c2b1d36641e18164e2dd050b37a86],
Settori fisici: 0
(Nessun elemento nocivo rilevato)
(end)