ho provato a fare delle scansioni con vari programmi, questi sono i risultati:
HijackThis:
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 15:12:30, on 16/04/2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
FIREFOX: 34.0.5 (x86 it)
Boot mode: Normal
Running processes:
C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\GWX\GWX.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Accedi a Hotmail, Messenger, Outlook e Skype: MSN Italia!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone:
http://*.webcompanion.com
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: Bitdefender Antivirus Free Edition (gzserv) - Bitdefender - C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
O23 - Service: HWDeviceService.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mobile Partner. OUC (Mobile Partner. RunOuc) - Unknown owner - C:\Program Files\Mobile Partner\UpdateDog\ouc.exe
O23 - Service: UltraZip Service (uzsvc) - Unknown owner - C:\Program Files\UltraZip\uzsvc.exe
O23 - Service: UltraZip Updater (uzupd) - Unknown owner - C:\Program Files\UltraZip\uzupd.exe
O23 - Service: WPS2.0 HW PBC Service (WPSService20) - Unknown owner - C:\Program Files\Edimax\Edimax AC600 Wireless LAN Driver\WPSService20.exe
--
End of file - 3115 bytes
AdwCleaner:
# AdwCleaner v5.111 - File di log creato 16/04/2016 a 15:18:34
# Aggiornato 14/04/2016 da Xplode
# Database : 2016-04-15.1 [Server]
# Sistema operativo : Windows 7 Professional Service Pack 1 (X86)
# Nome utente : marco - MARCO-P
# Eseguendo da : C:\Users\marco\Downloads\adwcleaner_5.111 (1).exe
# Opzione : Analizza
# Supporto :
ToolsLib - Forum: Ask for help or share your experience.
***** [ Servizi ] *****
***** [ Cartelle ] *****
***** [ File ] *****
***** [ DLL ] *****
***** [ Collegamenti ] *****
***** [ Attività pianificate ] *****
***** [ Registro ] *****
***** [ Browser web ] *****
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [5164 byte] - [22/03/2016 05:01:06]
C:\AdwCleaner\AdwCleaner[C2].txt - [2324 byte] - [16/04/2016 03:59:13]
C:\AdwCleaner\AdwCleaner[R0].txt - [7580 byte] - [24/01/2015 05:42:50]
C:\AdwCleaner\AdwCleaner[S0].txt - [7197 byte] - [24/01/2015 05:43:58]
C:\AdwCleaner\AdwCleaner[S1].txt - [5269 byte] - [22/03/2016 04:59:59]
C:\AdwCleaner\AdwCleaner[S2].txt - [1072 byte] - [28/03/2016 18:13:20]
C:\AdwCleaner\AdwCleaner[S3].txt - [1701 byte] - [07/04/2016 03:50:50]
C:\AdwCleaner\AdwCleaner[S4].txt - [2716 byte] - [16/04/2016 03:57:53]
C:\AdwCleaner\AdwCleaner[S5].txt - [1222 byte] - [16/04/2016 15:18:34]
########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [1294 byte] ##########
ComboFix:
ComboFix 16-04-01.01 - marco 16/04/2016 15:26:06.6.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.39.1040.18.3267.2147 [GMT 2:00]
Eseguito da: c:\users\marco\Desktop\ComboFix_16-03-19.1.exe
AV: Bitdefender Antivirus Free Edition *Disabled/Updated* {3FB17364-4FCC-0FA7-6BBF-973897395371}
SP: Bitdefender Antivirus Free Edition *Disabled/Updated* {84D09280-69F6-0029-510F-AC4AECBE19CC}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Creati Da 2016-03-16 al 2016-04-16 )))))))))))))))))))))))))))))))))))
.
.
2016-04-16 13:29 . 2016-04-16 13:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-04-16 13:29 . 2016-04-16 13:29 -------- d-----w- c:\users\Administrator.marco-p\AppData\Local\temp
2016-04-16 00:35 . 2016-03-17 01:50 9302992 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{68D18151-83C8-42DC-9091-D200577DAF7B}\mpengine.dll
2016-04-09 16:49 . 2016-04-09 16:49 -------- d-----w- c:\users\marco\AppData\Roaming\ProductData
2016-04-09 13:00 . 2000-10-12 19:55 299520 ----a-w- c:\windows\uninst.exe
2016-04-07 00:49 . 2016-04-07 00:54 -------- d-----w- C:\ComboFix_16-03-19.1
2016-04-05 17:56 . 2016-04-05 17:56 -------- d-----w- c:\users\marco\AppData\Local\Diagnostics
2016-04-02 02:53 . 2016-04-02 02:53 -------- d-----w- c:\users\marco\AppData\Roaming\KoshyJohn.com
2016-04-02 02:53 . 2016-04-02 02:53 -------- d-----w- c:\program files\KoshyJohn.com
2016-04-02 02:38 . 2016-04-02 02:39 -------- d-----w- c:\users\Administrator.marco-p\AppData\Roaming\GlarySoft
2016-04-01 21:51 . 2016-04-01 21:51 -------- d-----r- c:\users\Administrator.marco-p\OneDrive
2016-04-01 21:42 . 2016-04-01 21:42 -------- d-----w- c:\users\Administrator.marco-p\AppData\Local\Apps
2016-03-31 20:19 . 2013-07-04 07:18 2443480 ----a-w- c:\windows\system32\drivers\RTWlanU.sys
2016-03-31 20:19 . 2016-03-31 20:19 -------- d-----w- c:\program files\Edimax
2016-03-31 20:19 . 2013-05-15 13:27 451072 ----a-w- c:\windows\system32\ISSRemoveSP.exe
2016-03-31 19:21 . 2013-05-15 13:27 451072 ----a-w- c:\windows\system32\ISSR225e.rra
2016-03-28 21:47 . 2016-03-30 02:00 -------- d-----w- c:\programdata\Lenovo
2016-03-28 21:47 . 2016-03-30 02:00 -------- d-----w- c:\users\marco\AppData\Local\Lenovo
2016-03-28 21:32 . 2016-03-28 21:32 -------- d-----w- c:\program files\Xirrus
2016-03-28 21:32 . 2016-03-28 21:32 -------- d-----w- c:\users\marco\AppData\Local\Downloaded Installations
2016-03-28 16:15 . 2016-03-28 16:15 1610352 ----a-w- C:\JRT.exe
2016-03-28 12:50 . 2016-04-16 13:12 -------- d-----w- C:\HijackThis
2016-03-27 13:06 . 2016-03-28 21:59 -------- d-----w- c:\program files\CCleaner
2016-03-25 01:49 . 2016-03-25 01:49 -------- d-----w- c:\users\marco\AppData\Local\Windows Live Writer
2016-03-25 01:49 . 2016-03-25 01:49 -------- d-----w- c:\users\marco\AppData\Roaming\Windows Live Writer
2016-03-20 19:58 . 2016-03-20 19:58 -------- d-----w- c:\program files\D-Link
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-04-10 13:26 . 2014-12-26 21:14 797376 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2016-04-10 13:26 . 2014-12-26 21:14 142528 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2016-04-06 08:18 . 2014-12-26 21:25 374944 ------w- c:\windows\system32\MpSigStub.exe
2016-03-12 17:58 . 2016-03-12 17:58 1791800 ----a-w- c:\windows\system32\WavesLib.dll
2016-03-12 17:58 . 2016-03-12 17:58 1832072 ----a-w- c:\windows\system32\WavesGUILib.dll
2016-03-12 17:58 . 2016-03-12 17:58 936624 ----a-w- c:\windows\system32\SFSS_APO.dll
2016-03-12 17:58 . 2016-03-12 17:58 927800 ----a-w- c:\windows\system32\sl3apo32.dll
2016-03-12 17:58 . 2016-03-12 17:58 863616 ----a-w- c:\windows\system32\tossaeapo32.dll
2016-03-12 17:58 . 2016-03-12 17:58 860528 ----a-w- c:\windows\system32\tadefxapo2.dll
2016-03-12 17:58 . 2016-03-12 17:58 83648 ----a-w- c:\windows\system32\SFCOM.dll
2016-03-12 17:58 . 2016-03-12 17:58 786352 ----a-w- c:\windows\system32\SEHDRA32.dll
2016-03-12 17:58 . 2016-03-12 17:58 78488 ----a-w- c:\windows\system32\SFAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 67760 ----a-w- c:\windows\system32\TepeqAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 589080 ----a-w- c:\windows\system32\SECOMN32.dll
2016-03-12 17:58 . 2016-03-12 17:58 575936 ----a-w- c:\windows\system32\tosasfapo32.dll
2016-03-12 17:58 . 2016-03-12 17:58 401056 ----a-w- c:\windows\system32\SRAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 384528 ----a-w- c:\windows\system32\SEAPO32.dll
2016-03-12 17:58 . 2016-03-12 17:58 3681024 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys
2016-03-12 17:58 . 2016-03-12 17:58 357160 ----a-w- c:\windows\system32\SRSTSXT.dll
2016-03-12 17:58 . 2016-03-12 17:58 341160 ----a-w- c:\windows\system32\SRCOM.dll
2016-03-12 17:58 . 2016-03-12 17:58 2897152 ----a-w- c:\windows\system32\RtkPgExt.dll
2016-03-12 17:58 . 2016-03-12 17:58 2826496 ----a-w- c:\windows\system32\RTSndMgr.cpl
2016-03-12 17:58 . 2016-03-12 17:58 2424272 ----a-w- c:\windows\system32\RtkApoApi.dll
2016-03-12 17:58 . 2016-03-12 17:58 231880 ----a-w- c:\windows\system32\slprp32.dll
2016-03-12 17:58 . 2016-03-12 17:58 230920 ----a-w- c:\windows\system32\tossaemaxapo32.dll
2016-03-12 17:58 . 2016-03-12 17:58 225048 ----a-w- c:\windows\system32\SFNHK.dll
2016-03-12 17:58 . 2016-03-12 17:58 22160 ----a-w- c:\windows\system32\RtkCoLDR.dll
2016-03-12 17:58 . 2016-03-12 17:58 1984120 ----a-w- c:\windows\system32\RtkCoInstII.dll
2016-03-12 17:58 . 2016-03-12 17:58 196008 ----a-w- c:\windows\system32\SRSTSHD.dll
2016-03-12 17:58 . 2016-03-12 17:58 183616 ----a-w- c:\windows\system32\SRSHP360.dll
2016-03-12 17:58 . 2016-03-12 17:58 1604792 ----a-w- c:\windows\system32\sltech32.dll
2016-03-12 17:58 . 2016-03-12 17:58 151920 ----a-w- c:\windows\system32\toseaeapo32.dll
2016-03-12 17:58 . 2016-03-12 17:58 150560 ----a-w- c:\windows\system32\SRSWOW.dll
2016-03-12 17:58 . 2016-03-12 17:58 144688 ----a-w- c:\windows\system32\tadefxapo.dll
2016-03-12 17:58 . 2016-03-12 17:58 1400808 ----a-w- c:\windows\system32\tosade.dll
2016-03-12 17:58 . 2016-03-12 17:58 1180224 ----a-w- c:\windows\system32\slcnt32.dll
2016-03-12 17:58 . 2016-03-12 17:58 1074056 ----a-w- c:\windows\system32\SRRPTR.dll
2016-03-12 17:58 . 2016-03-12 17:58 965688 ----a-w- c:\windows\system32\MaxxSpeechAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 954200 ----a-w- c:\windows\system32\NahimicAPONSControl.dll
2016-03-12 17:58 . 2016-03-12 17:58 88280 ----a-w- c:\windows\system32\RTEEL32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 868456 ----a-w- c:\windows\system32\MISS_APO.dll
2016-03-12 17:58 . 2016-03-12 17:58 834328 ----a-w- c:\windows\system32\MaxxVoiceAPO20.dll
2016-03-12 17:58 . 2016-03-12 17:58 74384 ----a-w- c:\windows\system32\RTEEG32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 72203792 ----a-w- c:\windows\system32\RCoRes.dat
2016-03-12 17:58 . 2016-03-12 17:58 71712 ----a-w- c:\windows\system32\R4EEG32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 7170872 ----a-w- c:\windows\system32\R4EEP32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 522712 ----a-w- c:\windows\system32\MaxxVolumeSDAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 5134064 ----a-w- c:\windows\system32\NAHIMICV2apo.dll
2016-03-12 17:58 . 2016-03-12 17:58 4763576 ----a-w- c:\windows\system32\NAHIMICAPOlfx.dll
2016-03-12 17:58 . 2016-03-12 17:58 371816 ----a-w- c:\windows\system32\RTEEP32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 364024 ----a-w- c:\windows\system32\R4EED32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 307240 ----a-w- c:\windows\system32\RP3DHT32.dll
2016-03-12 17:58 . 2016-03-12 17:58 307240 ----a-w- c:\windows\system32\RP3DAA32.dll
2016-03-12 17:58 . 2016-03-12 17:58 2692848 ----a-w- c:\windows\system32\RltkAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 181232 ----a-w- c:\windows\system32\RTEED32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 13798184 ----a-w- c:\windows\system32\MaxxAudioRealtek.dll
2016-03-12 17:58 . 2016-03-12 17:58 12014440 ----a-w- c:\windows\system32\MaxxVoiceAPO30.dll
2016-03-12 17:58 . 2016-03-12 17:58 11922520 ----a-w- c:\windows\system32\MaxxVoiceAPO40.dll
2016-03-12 17:58 . 2016-03-12 17:58 116656 ----a-w- c:\windows\system32\R4EEL32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 101624 ----a-w- c:\windows\system32\R4EEA32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 990792 ----a-w- c:\windows\system32\MaxxAudioAPO40.dll
2016-03-12 17:58 . 2016-03-12 17:58 858264 ----a-w- c:\windows\system32\DolbyDAX2APOProp.dll
2016-03-12 17:58 . 2016-03-12 17:58 799016 ----a-w- c:\windows\system32\MaxxAudioAPOShell.dll
2016-03-12 17:58 . 2016-03-12 17:58 7053696 ----a-w- c:\windows\system32\DDPP32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 669592 ----a-w- c:\windows\system32\DTSBassEnhancementDLL.dll
2016-03-12 17:58 . 2016-03-12 17:58 645824 ----a-w- c:\windows\system32\DTSSymmetryDLL.dll
2016-03-12 17:58 . 2016-03-12 17:58 615880 ----a-w- c:\windows\system32\DTSVoiceClarityDLL.dll
2016-03-12 17:58 . 2016-03-12 17:58 522704 ----a-w- c:\windows\system32\MaxxAudioAPO30.dll
2016-03-12 17:58 . 2016-03-12 17:58 471288 ----a-w- c:\windows\system32\DTSNeoPCDLL.dll
2016-03-12 17:58 . 2016-03-12 17:58 439608 ----a-w- c:\windows\system32\DTSU2PLFX32.dll
2016-03-12 17:58 . 2016-03-12 17:58 4235656 ----a-w- c:\windows\system32\DolbyDAX2APOv211.dll
2016-03-12 17:58 . 2016-03-12 17:58 415872 ----a-w- c:\windows\system32\DTSU2PGFX32.dll
2016-03-12 17:58 . 2016-03-12 17:58 402072 ----a-w- c:\windows\system32\DTSGainCompensatorDLL.dll
2016-03-12 17:58 . 2016-03-12 17:58 387632 ----a-w- c:\windows\system32\DTSLimiterDLL.dll
2016-03-12 17:58 . 2016-03-12 17:58 369792 ----a-w- c:\windows\system32\KAAPORT.dll
2016-03-12 17:58 . 2016-03-12 17:58 357992 ----a-w- c:\windows\system32\DTSU2PREC32.dll
2016-03-12 17:58 . 2016-03-12 17:58 312984 ----a-w- c:\windows\system32\HiFiDAX2API.dll
2016-03-12 17:58 . 2016-03-12 17:58 308064 ----a-w- c:\windows\system32\ICEsoundAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 2899224 ----a-w- c:\windows\system32\FMAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 285624 ----a-w- c:\windows\system32\DDPO32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 243864 ----a-w- c:\windows\system32\MaxxAudioAPO20.dll
2016-03-12 17:58 . 2016-03-12 17:58 2400320 ----a-w- c:\windows\system32\MaxxAudioAPO70.dll
2016-03-12 17:58 . 2016-03-12 17:58 232424 ----a-w- c:\windows\system32\DDPA32.dll
2016-03-12 17:58 . 2016-03-12 17:58 229592 ----a-w- c:\windows\system32\DTSGFXAPONS.dll
2016-03-12 17:58 . 2016-03-12 17:58 229584 ----a-w- c:\windows\system32\DTSGFXAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 229040 ----a-w- c:\windows\system32\DTSLFXAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 1948808 ----a-w- c:\windows\system32\MaxxAudioEQ.dll
2016-03-12 17:58 . 2016-03-12 17:58 1816352 ----a-w- c:\windows\system32\DolbyDAX2APOv201.dll
2016-03-12 17:58 . 2016-03-12 17:58 1531680 ----a-w- c:\windows\system32\DTSS2SpeakerDLL.dll
2016-03-12 17:58 . 2016-03-12 17:58 1512320 ----a-w- c:\windows\system32\DDPD32A.dll
2016-03-12 17:58 . 2016-03-12 17:58 142328 ----a-w- c:\windows\system32\MaxxAudioAPO.dll
2016-03-12 17:58 . 2016-03-12 17:58 1313120 ----a-w- c:\windows\system32\DTSS2HeadphoneDLL.dll
2016-03-12 17:58 . 2016-03-12 17:58 1239808 ----a-w- c:\windows\system32\DTSBoostDLL.dll
2016-03-12 17:58 . 2016-03-12 17:58 1199992 ----a-w- c:\windows\system32\MaxxAudioAPO60.dll
2016-03-12 17:58 . 2016-03-12 17:58 1028016 ----a-w- c:\windows\system32\MaxxAudioAPO50.dll
2016-03-12 17:58 . 2016-03-12 17:58 96608 ----a-w- c:\windows\system32\audioLibVc.dll
2016-03-12 17:58 . 2016-03-12 17:58 532896 ----a-w- c:\windows\system32\AERTACap.dll
2016-03-12 17:58 . 2016-03-12 17:58 197448 ----a-w- c:\windows\system32\AcpiServiceVnA.dll
2016-03-12 17:58 . 2016-03-12 17:58 1515176 ----a-w- c:\windows\system32\CX32APO.dll
2016-03-12 17:58 . 2016-03-12 17:58 105656 ----a-w- c:\windows\system32\AERTARen.dll
.
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2016-03-10 00:28 1587912 ----a-w- c:\users\marco\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2016-03-10 00:28 1587912 ----a-w- c:\users\marco\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2016-03-10 00:28 1587912 ----a-w- c:\users\marco\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotPostWindows10UpgradeReInstall"="c:\program files\Common Files\AV\Spybot - Search and Destroy\Test.exe" [2015-07-28 1011200]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner.exe" [2016-03-11 6667992]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FAH.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk
backup=c:\windows\pss\FAH.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=c:\windows\pss\Ralink Wireless Utility.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Preloader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk
backup=c:\windows\pss\WinZip Preloader.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 01:38 34672 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
2015-02-19 12:53 855768 ----a-w- c:\program files\BlueStacks\HD-Agent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4400 Series]
2007-03-01 06:01 180736 ----a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATICAE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAStorIcon]
2013-04-30 11:27 36352 ----a-w- c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
2016-03-12 17:58 14688512 ----a-w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2013-12-19 13:42 5580752 ----a-w- c:\program files\Spybot - Search & Destroy 2\SDTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB3MON]
2013-04-11 03:11 292848 ----a-r- c:\program files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe]
2014-06-04 08:22 2024800 ----a-w- c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFast LAN]
2013-05-31 15:23 1546080 ----a-r- c:\program files\ASRock\XFast LAN\cfosspeed.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XFastUSB]
2014-12-28 10:48 6311104 ----a-w- c:\program files\XFastUSB\XFastUsb.exe
.
R2 HWDeviceService.exe;HWDeviceService.exe;c:\programdata\DatacardService\HWDeviceService.exe [2014-01-15 276048]
R2 LiveUpdateSvc;LiveUpdate;c:\program files\IObit\LiveUpdate\LiveUpdate.exe [2016-01-14 2945312]
R2 Mobile Partner. RunOuc;Mobile Partner. OUC;c:\program files\Mobile Partner\UpdateDog\ouc.exe [2013-10-26 651856]
R2 uzsvc;UltraZip Service;c:\program files\UltraZip\uzsvc.exe [2016-03-30 45248]
R2 uzupd;UltraZip Updater;c:\program files\UltraZip\uzupd.exe [2016-03-30 85696]
R3 AsrDrv101;AsrDrv101;c:\windows\system32\Drivers\AsrDrv101.sys [2014-12-28 19720]
R3 AsrSetupDrv;AsrSetupDrv;c:\windows\system32\Drivers\AsrSetupDrv.sys [x]
R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [2013-04-17 486536]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2013-01-25 95232]
R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys [2012-12-22 11904]
R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS [2015-07-26 29760]
R3 HWHandSet;HUAWEIFWTMODEM0;c:\windows\system32\DRIVERS\hw_quusbmdm.sys [2011-10-24 195200]
R3 hwusb_cdcacm;hwusb_cdcacm;c:\windows\system32\DRIVERS\ew_cdcacm.sys [2014-07-25 111872]
R3 hwusb_wwanecm;hwusb_wwanecm;c:\windows\system32\DRIVERS\ew_wwanecm.sys [2014-09-30 319872]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-12-27 108032]
R3 IntcDAud;Audio Intel(R) per schermi;c:\windows\system32\DRIVERS\IntcDAud.sys [2016-03-12 393480]
R3 massfilter_hs;HS HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [2012-06-20 17672]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2015-12-08 14848]
R3 RtlWlanu;Realtek Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtwlanu.sys [2013-07-04 2443480]
R3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys [2015-12-08 25768]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2015-12-08 27136]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys [2014-11-24 95608]
R4 ASRockIOMon;ASRock IO Monitor Service;c:\program files\ASRock Utility\A-Tuning\Bin\IOMonitorSrv.exe [2013-07-25 454656]
R4 BstHdAndroidSvc;BlueStacks Android Service;c:\program files\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R4 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files\BlueStacks\HD-LogRotatorService.exe [2015-02-19 388824]
R4 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files\BlueStacks\HD-UpdaterService.exe [2015-02-19 794328]
R4 Freemake Improver;Freemake Improver;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2014-12-03 108032]
R4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-04-30 15344]
R4 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-09-18 171072]
R4 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service;c:\windows\system32\igfxCUIService.exe [2016-03-12 274024]
R4 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2013-02-13 583680]
R4 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [2013-02-13 637912]
R4 Intel(R) ME Service;Intel(R) ME Service;c:\program files\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-03-12 131544]
R4 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-03-12 169432]
R4 RaMediaServer;RaMediaServer;c:\program files\Ralink\Common\RaMediaServer.exe [x]
R4 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-12-19 3666392]
R4 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-12-19 2729432]
R4 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-12-19 171928]
S0 AsrRamDisk;AsrRamDisk;c:\windows\system32\DRIVERS\AsrRamDisk.sys [2013-05-13 38152]
S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [2016-03-10 633344]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys [2016-01-25 1987008]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys [2016-01-25 27560]
S0 iusb3hcs;Driver dello switch Controller Host Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys [2013-04-11 16880]
S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys [2011-11-07 15656]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2014-12-27 42784]
S1 bdfwfpf;bdfwfpf;c:\program files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys [2013-07-02 108008]
S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [2014-12-28 16136]
S1 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys [2013-04-22 164952]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2015-12-08 23840]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2015-10-15 784696]
S1 VBoxNetAdp;VirtualBox NDIS 6.0 Miniport Service;c:\windows\system32\DRIVERS\VBoxNetAdp6.sys [2015-10-15 98704]
S1 VBoxNetLwf;VirtualBox NDIS6 Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetLwf.sys [2015-10-15 119304]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2015-10-15 112112]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files\BlueStacks\HD-Hypervisor-x86.sys [2015-02-19 112856]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 gzserv;Bitdefender Antivirus Free Edition;c:\program files\Bitdefender\Antivirus Free Edition\gzserv.exe [2016-03-10 67592]
S2 WPSService20;WPS2.0 HW PBC Service;c:\program files\Edimax\Edimax AC600 Wireless LAN Driver\WPSService20.exe [2013-05-15 96768]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2015-12-08 78336]
S3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD.sys [2015-12-08 37576]
S3 iusb3hub;Driver hub Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys [2013-04-11 359408]
S3 iusb3xhc;Driver Controller Host estendibile Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys [2013-04-11 792560]
S3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\TeeDriver.sys [2016-03-12 156416]
S3 netr28u;Driver scheda LAN wireless USB RT2870 per Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2016-01-25 769280]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
utcsvc REG_MULTI_SZ DiagTrack
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-04-12 00:02 1106072 ----a-w- c:\program files\Google\Chrome\Application\49.0.2623.112\Installer\chrmstp.exe
.
Contenuto della cartella 'Scheduled Tasks'
.
2016-04-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-26 13:26]
.
2016-04-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-12-26 12:25]
.
2016-04-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-12-26 12:25]
.
2014-12-27 c:\windows\Tasks\Open Chrome.job
- c:\program files\Google\Chrome\Application\chrome.exe [2014-12-26 10:05]
.
.
------- Scansione supplementare -------
.
uStart Page = about:blank
mStart Page = about:blank
Trusted Zone: localhost
Trusted Zone: webcompanion.com
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\marco\AppData\Roaming\Mozilla\Firefox\Profiles\lwthgfdh.default\
FF - prefs.js: browser.startup.homepage -
www.tiscali.it
.
.
------- Associazioni dei file -------
.
inifile="%SystemRoot%\system32\NOTEPAD.EXE" %1
txtfile="%SystemRoot%\system32\NOTEPAD.EXE" %1
.
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @DenieD: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @DenieD: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @DenieD: (A) (Users) @DenieD: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @DenieD: (A) (Users) @DenieD: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @DenieD: (Full) (Everyone)
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
.
- - - - - - - > 'Explorer.exe'(5080)
c:\windows\system32\DeviceCenter.dll
.
Ora fine scansione: 2016-04-16 15:30:05
ComboFix-quarantined-files.txt 2016-04-16 13:30
ComboFix2.txt 2016-04-07 00:54
ComboFix3.txt 2016-04-02 00:48
ComboFix4.txt 2016-04-02 00:12
ComboFix5.txt 2016-04-16 13:25
.
Pre-Run: 48.312.623.104 byte disponibili
Post-Run: 48.273.330.176 byte disponibili
.
- - End Of File - - 0A915E2755D5764E83E75C86B22F466E
A36C5E4F47E84449FF07ED3517B43A31