Dylan666 ha scritto:Scarica questo:
https://dragokas.com/tools/HiJackThis.zipNella prima finestra premi "Accept"
In quella successiva premi "Do a System Scan and Save a text file"
Alla fine dell'analisi si crea un grosso file di testo.
Copiane il contenuto e incollalo qui.
Logfile of HiJackThis Fork by Alex Dragokas v.2.10.0.16
Platform: x64 Windows 10 (Home), 10.0.19042.1466 (ReleaseId: 2009, 20H2), Service Pack: 0
Time: 31.01.2022 - 14:40 (UTC+01:00)
Language: OS: Italian (0x410). Display: Italian (0x410). Non-Unicode: Italian (0x410)
Elevated: Yes
Ran by: Cartella Dati (group: Administrators) on DESKTOP-6EO4N1T, FirstRun: yes
Chrome: 97.0.4692.99
Internet Explorer: 11.0.19041.1202
Default: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument %1 (Microsoft Edge)
Boot mode: Normal
Running processes:
Number | Path
1 C:\Program Files (x86)\Acer Bio Protection\BASVC.exe
1 C:\Program Files (x86)\Acer Bio Protection\CompPtcVUI.exe
1 C:\Program Files (x86)\Athena\IDProtect Client\Utils\IDProtect Monitor.exe
1 C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
1 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
8 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
1 C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler.exe
1 C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler64.exe
1 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
1 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
1 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
1 C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
7 C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
1 C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
1 C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
1 C:\Program Files (x86)\Wondershare\WAF\2.4.3.242\WsAppService.exe
1 C:\Program Files\Bonjour\mDNSResponder.exe
1 C:\Program Files\CardOS API\bin\cardoscp.exe
1 C:\Program Files\Common Files\SPBA\upeksvr.exe
1 C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
1 C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
1 C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
1 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
1 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2111.12605.0_x64__8wekyb3d8bbwe\Cortana.exe
1 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2111.12605.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe
1 C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
1 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21121.250.0_x64__8wekyb3d8bbwe\YourPhone.exe
1 C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.21102.11411.0_x64__8wekyb3d8bbwe\Music.UI.exe
1 C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.21111.10511.0_x64__8wekyb3d8bbwe\Video.UI.exe
1 C:\Program Files\WinRAR\WinRAR.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.6-0\MsMpEng.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.6-0\NisSrv.exe
1 C:\Users\Cartella Dati\AppData\Local\Temp\RtkBtMnt.exe
1 C:\Users\Cartella Dati\Documents\Desktop\HiJackThis\HiJackThis.exe
1 C:\Windows\explorer.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
1 C:\Windows\System32\audiodg.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
2 C:\Windows\System32\dllhost.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\lsass.exe
2 C:\Windows\System32\nvvsvc.exe
1 C:\Windows\System32\oobe\UserOOBEBroker.exe
7 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchFilterHost.exe
1 C:\Windows\System32\SearchIndexer.exe
2 C:\Windows\System32\SearchProtocolHost.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\SecurityHealthSystray.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\SettingSyncHost.exe
1 C:\Windows\System32\SgrmBroker.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
79 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\System32\WUDFHost.exe
1 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe
2 C:\Windows\SysWOW64\svchost.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxyOverride] = *.local
O2 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_261\bin\jp2ssv.dll
O2 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_261\bin\ssv.dll
O4 - HKCU\..\Run: [MicrosoftEdgeAutoLaunch_FE4C3C5D60AAB192E108FAB2866E220A] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --no-startup-window --win-session-start /prefetch:5
O4 - HKCU\..\StartupApproved\Run: [CCleaner Smart Cleaning] = C:\Program Files\CCleaner\CCleaner64.exe /MONITOR (2021/02/08)
O4 - HKCU\..\StartupApproved\Run: [Dropbox Update] = C:\Users\Cartella Dati\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c (2021/05/15)
O4 - HKCU\..\StartupApproved\Run: [OneDrive] = C:\Users\Cartella Dati\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background (2018/01/18)
O4 - HKCU\..\StartupApproved\Run: [Spotify] = C:\Users\Cartella Dati\AppData\Roaming\Spotify\Spotify.exe --autostart (2017/06/17)
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Cartella Dati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk -> C:\Users\Cartella Dati\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup (2022/01/28)
O4 - HKLM\..\Run: [CardOS API] = C:\Program Files\CardOS API\bin\cardoscp.exe
O4 - HKLM\..\Run: [NvBackend] = C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
O4 - HKLM\..\Run: [RtHDVCpl] = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
O4 - HKLM\..\StartupApproved\Run32: [VitaKeyPdtWzd] = C:\Program Files (x86)\Acer Bio Protection\PdtWzd.exe (2017/04/24)
O4 - HKLM\..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\$McRebootA5E6DEAA56$.lnk -> (lnk is corrupted) (2021/05/15)
O4 - Startup Global: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O4-32 - HKLM\..\Run: [HP Software Update] = C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4-32 - HKLM\..\Run: [IDProtect Monitor] = C:\Program Files (x86)\Athena\IDProtect Client\Utils\IDProtect Monitor.exe
O4-32 - HKLM\..\Run: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
O5 - Applet: C:\WINDOWS\System32\RTSnMg64.cpl (Sign: 'Realtek Semiconductor Corp')
O7 - KnownFolder: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, Desktop = C:\Users\Cartella Dati\Documents\Desktop
O7 - KnownFolder: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, Desktop = C:\Users\Cartella Dati\Documents\Desktop
O9 - Button: HKLM\..\{10954C80-4F0F-11d3-B17C-00C0DFE39736}: Quick-Launch Area - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe
O9 - Tools menu item: HKLM\..\{10954C80-4F0F-11d3-B17C-00C0DFE39736}: Quick-Launch Area - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe
O9-32 - Button: HKLM\..\{10954C80-4F0F-11d3-B17C-00C0DFE39736}: Quick-Launch Area - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe
O9-32 - Tools menu item: HKLM\..\{10954C80-4F0F-11d3-B17C-00C0DFE39736}: Quick-Launch Area - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe
O17 - DHCP DNS 1: 192.168.1.1
O20 - HKLM\..\Winlogon\Notify\spba: [DllName] = C:\Program Files\Common Files\SPBA\homefus2.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Users\Cartella Dati\AppData\Roaming\Dropbox\bin\DropboxExt64.52.0.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\00asw: (no name) - {472083B0-C522-11CF-8763-00608CC02F24} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\00avg: (no name) - {472083B0-C522-11CF-8763-00608CC02F24} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Users\Cartella Dati\AppData\Roaming\Dropbox\bin\DropboxExt.52.0.dll
O22 - Task (.job): (disabled) (Not scheduled) DropboxUpdateTaskUserS-1-5-21-3755254378-1422919837-4236689458-1001Core.job - C:\Users\Cartella Dati\AppData\Local\Dropbox\Update\DropboxUpdate.exe
O22 - Task (.job): (disabled) (Not scheduled) DropboxUpdateTaskUserS-1-5-21-3755254378-1422919837-4236689458-1001UA.job - C:\Users\Cartella Dati\AppData\Local\Dropbox\Update\DropboxUpdate.exe
O22 - Task: (disabled) \Agent Activation Runtime\S-1-5-21-3755254378-1422919837-4236689458-1001 - C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Shell\FamilySafetyMonitorToastTask - {D2CBF5F7-5702-440B-8D8F-8203034A6B82},$(Arg0) - (no file)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\WINDOWS\system32\usoclient.exe StartWork (Microsoft)
O22 - Task: (disabled) \S-1-5-21-3755254378-1422919837-4236689458-1001\DataSenseLiveTileTask - C:\WINDOWS\System32\DataUsageLiveTileTask.exe
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Task: \Apple\AppleSoftwareUpdate - C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe -task
O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ClientTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client"
O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ServerTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server"
O22 - Task: CCleaner Update - C:\Program Files\CCleaner\CCUpdate.exe
O22 - Task: CCleanerSkipUAC - Cartella Dati - C:\Program Files\CCleaner\CCleaner.exe $(Arg0)
O22 - Task: DropboxUpdateTaskUserS-1-5-21-3755254378-1422919837-4236689458-1001Core - C:\Users\Cartella Dati\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
O22 - Task: DropboxUpdateTaskUserS-1-5-21-3755254378-1422919837-4236689458-1001UA - C:\Users\Cartella Dati\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
O22 - Task: GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task: GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Task: OneDrive Reporting Task-S-1-5-21-3755254378-1422919837-4236689458-1001 - C:\Users\Cartella Dati\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting
O23 - Service R2: Servizio Bonjour - (Bonjour Service) - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service R2: EgisTec Service - (IGBASVC) - C:\Program Files (x86)\Acer Bio Protection\BASVC.exe
O23 - Service R2: HP Network Devices Support - (HPSLPSVC) - C:\WINDOWS\system32\svchost.exe -k HPService; "ServiceDll" = C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
O23 - Service R2: HP Print Scan Doctor Service - (HPPrintScanDoctorService) - C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
O23 - Service R2: HsfXAudioService - C:\WINDOWS\system32\svchost.exe -k HsfXAudioService; "ServiceDll" = C:\WINDOWS\SysWOW64\XAudio64.dll
O23 - Service R2: Net Driver HPZ12 - C:\Windows\System32\svchost.exe -k HPZ12; "ServiceDll" = C:\Windows\System32\HPZinw12.dll
O23 - Service R2: NVIDIA Display Driver Service - (nvsvc) - C:\WINDOWS\system32\nvvsvc.exe
O23 - Service R2: Pml Driver HPZ12 - C:\Windows\System32\svchost.exe -k HPZ12; "ServiceDll" = C:\Windows\System32\HPZipm12.dll
O23 - Service R2: Servizio di rilevamento dispositivi HP CUE - (hpqddsvc) - C:\WINDOWS\system32\svchost.exe -k hpdevmgmt; "ServiceDll" = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
O23 - Service R2: TeamViewer 12 - (TeamViewer) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service R2: Wondershare Application Framework Service - (WsAppService) - C:\Program Files (x86)\Wondershare\WAF\2.4.3.242\WsAppService.exe
O23 - Service R3: hpqcxs08 - C:\WINDOWS\system32\svchost.exe -k hpdevmgmt; "ServiceDll" = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
O23 - Service S2: Servizio Google Update (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files (x86)\Google\Chrome\Application\97.0.4692.99\elevation_service.exe
O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service S3: Servizio Google Update (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
O23 - Service S3: Servizio iPod - (iPod Service) - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - Time spent: 20,9 sec. - 28460 bytes, CRC32: FFFFFFFF. Sign: ┶㲋