Allego qui per una svista.
Logfile of HiJackThis Fork by Alex Dragokas v.2.9.0.18
Platform: x32 Windows XP (Professional), 5.1.2600.0, Service Pack: 3
Time: 30.09.2019 - 10:31 (UTC+02:00)
Language: OS: Italian (0x410). Display: Italian (0x410). Non-Unicode: Italian (0x410)
Ran by: Administrator (group: Administrator) on GIUSEPPE, FirstRun: yes
Chrome: 49.0.2623.112
Firefox: 52.9.0.6746
Internet Explorer: 6.0.2900.5512 SP3
Default: "C:\Programmi\Mozilla Firefox\firefox.exe" -osint -url "%1" (Firefox)
Boot mode: Normal
Processus en cours:
Nombre | Chemin
1 C:\Documents and Settings\Administrator.GIUSEPPE\Desktop\HiJackThis\HiJackThis.exe
1 C:\Programmi\Google\Update\1.3.35.111\GoogleCrashHandler.exe
1 C:\Programmi\Mozilla Firefox\firefox.exe
1 C:\Programmi\Panda Security\Panda Security Protection\PSANHost.exe
1 C:\Programmi\Panda Security\Panda Security Protection\PSUAMain.exe
1 C:\Programmi\Panda Security\Panda Security Protection\PSUAService.exe
1 C:\Programmi\PrivaZer\privazer.exe
1 C:\WINDOWS\Explorer.EXE
1 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
1 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
1 C:\WINDOWS\System32\alg.exe
1 C:\WINDOWS\System32\smss.exe
1 C:\WINDOWS\system32\csrss.exe
1 C:\WINDOWS\system32\ctfmon.exe
1 C:\WINDOWS\system32\lsass.exe
1 C:\WINDOWS\system32\services.exe
1 C:\WINDOWS\system32\spoolsv.exe
8 C:\WINDOWS\system32\svchost.exe
1 C:\WINDOWS\system32\winlogon.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar: [LinksFolderName] = Collegamenti
R3 - HKCU\..\URLSearchHooks: (no name) - {b60873b9-51aa-4566-b2fc-c16de2ec8bff} - (no file)
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: [URL] =
http://www.google.com/search?q={searc - Goo
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AEF4CA18-24F3-4AD1-B9B1-05942524DC9E}: [SuggestionsURLFallback] =
http://clients5.google.com/complete/search?hl={language}&q={searchTerms}&client=ie8&inputencoding={inputEncoding}&outputencoding={outputEncoding} - Google
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AEF4CA18-24F3-4AD1-B9B1-05942524DC9E}: [URL] =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 - Google
O1 - Hosts: Reset contents to default
O1 - Hosts: 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
O1 - Hosts: 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
O1 - Hosts: 0.0.0.0 media.opencandy.com
O1 - Hosts: 0.0.0.0 cdn.opencandy.com
O1 - Hosts: 0.0.0.0 tracking.opencandy.com
O1 - Hosts: 0.0.0.0 api.opencandy.com
O1 - Hosts: 0.0.0.0 api.recommendedsw.com
O1 - Hosts: 0.0.0.0 rp.yefeneri2.com
O1 - Hosts: 0.0.0.0 os.yefeneri2.com
O1 - Hosts: 0.0.0.0 os2.yefeneri2.com
O1 - Hosts: 0.0.0.0 installer.betterinstaller.com
O1 - Hosts: 0.0.0.0 installer.filebulldog.com
O1 - Hosts: 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
O1 - Hosts: 0.0.0.0 inno.bisrv.com
O1 - Hosts: 0.0.0.0 nsis.bisrv.com
O1 - Hosts: 0.0.0.0 cdn.file2desktop.com
O1 - Hosts: 0.0.0.0 cdn.goateastcach.us
O1 - Hosts: 0.0.0.0 cdn.guttastatdk.us
O1 - Hosts: 0.0.0.0 cdn.inskinmedia.com
O1 - Hosts: 0.0.0.0 cdn.insta.oibundles2.com
O1 - Hosts: 0.0.0.0 cdn.insta.playbryte.com
O1 - Hosts: 0.0.0.0 cdn.llogetfastcach.us
O1 - Hosts: 0.0.0.0 cdn.montiera.com
O1 - Hosts: 0.0.0.0 cdn.msdwnld.com
O1 - Hosts: 0.0.0.0 cdn.mypcbackup.com
O1 - Hosts: 0.0.0.0 cdn.ppdownload.com
O1 - Hosts: 0.0.0.0 cdn.riceateastcach.us
O1 - Hosts: 0.0.0.0 cdn.shyapotato.us
O1 - Hosts: 0.0.0.0 cdn.solimba.com
O1 - Hosts: 0.0.0.0 cdn.tuto4pc.com
O1 - Hosts: 0.0.0.0 cdn.appround.biz
O1 - Hosts: 0.0.0.0 cdn.bigspeedpro.com
O1 - Hosts: 0.0.0.0 cdn.bispd.com
O1 - Hosts: 0.0.0.0 cdn.bisrv.com
O1 - Hosts: 0.0.0.0 cdn.cdndp.com
O1 - Hosts: 0.0.0.0 cdn.download.sweetpacks.com
O1 - Hosts: 0.0.0.0 cdn.dpdownload.com
O1 - Hosts: 0.0.0.0 cdn.visualbee.net
O3 - HKCU\..\Toolbar: (no name) - {710EB7A1-45ED-11D0-924A-0020AFC7AC4D} - (no file)
O3 - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] = C:\CCleaner.exe /MONITOR
O4 - HKLM\..\Run: [PSUAMain] = C:\Programmi\Panda Security\Panda Security Protection\PSUAMain.exe /LaunchSysTray
O4 - HKLM\..\Session Manager: [BootExecute] = avgBoot.exe /M:a13981b05 /dir:"C:\Programmi\AVG\Antivirus" (file missing)
O4 - Startup other users: C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\McAfee Security Scan Plus.lnk -> C:\Programmi\McAfee Security Scan\3.11.1114\SSScheduler.exe
O8 - Context menu item: HKU\S-1-5-19\..\Internet Explorer\MenuExt\Add to Google Photos Screensa&ver: (default) = C:\WINDOWS\system32\GPhotos.scr
O8 - Context menu item: HKU\S-1-5-20\..\Internet Explorer\MenuExt\Add to Google Photos Screensa&ver: (default) = C:\WINDOWS\system32\GPhotos.scr
O9 - Button: HKLM\..\{FB5F1910-F110-11d2-BB9E-00C04F795683}: Messenger - C:\Programmi\Messenger\msmsgs.exe (file missing)
O9 - Tools menu item: HKLM\..\{FB5F1910-F110-11d2-BB9E-00C04F795683}: Windows Messenger - C:\Programmi\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: C:\WINDOWS\System32\nwprovau.dll
O17 - DHCP DNS 1: 192.168.1.254
O22 - ScheduledTask: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - ScheduledTask: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - Task (.job): (Ready) CCleaner Update.job - C:\CCUpdate.exe
O22 - Task (.job): (disabled) (Ready) Adobe Flash Player NPAPI Notifier.job - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_32_0_0_255_Plugin.exe -check plugin
O22 - Task (.job): (disabled) (Ready) GoogleUpdateTaskMachineCore.job - C:\Programmi\Google\Update\GoogleUpdate.exe /c
O22 - Task (.job): (disabled) (Ready) GoogleUpdateTaskMachineUA.job - C:\Programmi\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O23 - Service R2: Net.Tcp Port Sharing Service - (NetTcpPortSharing) - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
O23 - Service R2: Panda Product Service - (PSUAService) - C:\Programmi\Panda Security\Panda Security Protection\PSUAService.exe
O23 - Service R2: Panda Protection Service - (NanoServiceMain) - C:\Programmi\Panda Security\Panda Security Protection\PSANHost.exe
O23 - Service S2: Servizio di Google Update (gupdate) - (gupdate) - C:\Programmi\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: Agere Modem Call Progress Audio - (AgereModemAudio) - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service S3: Google Software Updater - (gusvc) - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service S3: ServiceLayer - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service S3: Servizio Google Update (gupdatem) - (gupdatem) - C:\Programmi\Google\Update\GoogleUpdate.exe /medsvc
O24 - Desktop Component 0: (no name) - [Source] =
https://mail1.virgilio.it/appsuite/#app=io.ox/mail&folder=default0//sazm4Zqdm
--
End of file - Time spent: 19,2 sec. - 14790 bytes, CRC32: FFFFFFFF. Sign: ࣇЦ