Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

risultato hiack Opzioni
libero1962
Inviato: Monday, February 10, 2020 3:47:06 PM

Rank: AiutAmico

Iscritto dal : 1/26/2009
Posts: 570
Mi sembra che il pc sia un po lento

Logfile of HiJackThis Fork by Alex Dragokas v.2.9.0.18

Platform: x32 Windows 7 (Ultimate), 6.1.7601.24544, Service Pack: 1
Time: 10.02.2020 - 15:44 (UTC+01:00)
Language: OS: Italian (0x410). Display: Italian (0x410). Non-Unicode: Italian (0x410)
Elevated: Yes
Ran by: Sergio (group: Administrator) on SERGIO-PC, FirstRun: yes

Chrome: 80.0.3987.87
Internet Explorer: 11.0.9600.19597
Default: "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Chrome)

Boot mode: Normal

Running processes:
Number | Path
1 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
2 C:\Program Files\AVAST Software\Avast\AvastUI.exe
1 C:\Program Files\AVAST Software\Avast\aswidsagent.exe
1 C:\Program Files\AVAST Software\Browser\Update\1.5.245.0\AvastBrowserCrashHandler.exe
2 C:\Program Files\AnyDesk\AnyDesk.exe
1 C:\Program Files\Glary Utilities 5\Integrator.exe
1 C:\Program Files\Google\Update\1.3.35.442\GoogleCrashHandler.exe
1 C:\Program Files\Java\jre6\bin\jusched.exe
1 C:\Program Files\SAntivirus\SegurazoClient.exe
1 C:\Program Files\SAntivirus\SegurazoIC.exe
1 C:\Program Files\SAntivirus\SegurazoService.exe
1 C:\Program Files\Windows Media Player\wmpnetwk.exe
1 C:\Users\Sergio\Desktop\HiJackThis.exe
1 C:\Windows\System32\SearchFilterHost.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SearchProtocolHost.exe
1 C:\Windows\System32\audiodg.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\dwm.exe
1 C:\Windows\System32\hkcmd.exe
1 C:\Windows\System32\igfxpers.exe
1 C:\Windows\System32\igfxsrvc.exe
1 C:\Windows\System32\igfxtray.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\lsm.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
11 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\taskeng.exe
1 C:\Windows\System32\taskhost.exe
1 C:\Windows\System32\wbem\WmiApSrv.exe
2 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wbem\unsecapp.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\explorer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main: [Start Page] = https://it.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=88dpyqptgki1320egikmoq9ay000220&param1=y6bdVFVIsvuYsgEClQfz8Hp%2FDKLQJBXkKHVBcimHc9cJeCL%2BU0bwl9EH6nNFJ21fUDxAA2lZ90%2FohjndVTreSG%2Fr74o4FBXqu2qocP5XBgWVGHm%2B7Hz14sparLVSw2b6clJ%2BPnr6hRs3boyRiU6CF%2Bxre1ns157RBYEDb4iutu6KTTxDSet0IX1EAATiBgn%2BNkPl98zgGb7weldurlrJ0dHH02zZ9e6bftXXFAyyAXBEdC0AAOCvGN%2F5VGjR0sfT3g%2BNQfgdiWRC2X%2B4sXPMii6vMxWL1ckpwmil4%2FypPt%2FUa9LFBGQuTNhYYFtfDKaCC9x17DfmjfGeEziLlubpjD6R5NVM7qXWvg8jDbfXpjvTQzWQjufx4RSpPsGaDBPc4dHMuhwHi34GkcWfdUOyUA%3D%3D
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: [SuggestionsURL_JSON] = https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms} - Yahoo powered search
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: [TopResultURLFallback] = https://it.search.yahoo.com/yhs/search?hspart=omr&hsimp=yhs-001&type=88dpyqptgki1320egikmoq9ay000220&param1=y6bdVFVIsvuYsgEClQfz8Hp%2FDKLQJBXkKHVBcimHc9cJeCL%2BU0bwl9EH6nNFJ21fUDxAA2lZ90%2FohjndVTreSBj5XuZXikPSKn5IWLGfo5l01Ko4PY88sRXBp90GP2fnFOKuX%2B81Z9WFIfBh8r%2FZVypakftvKaUyJ3bbRzmEAXcY%2BnFw%2Bjqggml1q63K2ljI4pSti8nSq%2FL8nZEvORe0Vjcq4Mmnpw5IfLxIrHFZeZV6WrXdSVrSOr5Px08lN4SAskFP%2BDC19FTBiV4wkkt%2BKE%2BO%2BftZBgrXQ6wY5vskah3TOvlYTaXmnDzKO04KdePCvTWUAxv21QTEm5cemsczl9r2mFghFS%2BDq5D3tsESM6qkH96rSt%2FjBG13rrXUDce7zKj4Tihu0nFSoAi%2Brqk65w%3D%3D&p={searchTerms} - Yahoo powered search
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: [URL] = https://it.search.yahoo.com/yhs/search?hspart=omr&hsimp=yhs-001&type=88dpyqptgki1320egikmoq9ay000220&param1=y6bdVFVIsvuYsgEClQfz8Hp%2FDKLQJBXkKHVBcimHc9cJeCL%2BU0bwl9EH6nNFJ21fUDxAA2lZ90%2FohjndVTreSBj5XuZXikPSKn5IWLGfo5l01Ko4PY88sRXBp90GP2fnFOKuX%2B81Z9WFIfBh8r%2FZVypakftvKaUyJ3bbRzmEAXcY%2BnFw%2Bjqggml1q63K2ljI4pSti8nSq%2FL8nZEvORe0Vjcq4Mmnpw5IfLxIrHFZeZV6WrXdSVrSOr5Px08lN4SAskFP%2BDC19FTBiV4wkkt%2BKE%2BO%2BftZBgrXQ6wY5vskah3TOvlYTaXmnDzKO04KdePCvTWUAxv21QTEm5cemsczl9r2mFghFS%2BDq5D3tsESM6qkH96rSt%2FjBG13rrXUDce7zKj4Tihu0nFSoAi%2Brqk65w%3D%3D&p={searchTerms} - Yahoo powered search
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0AA24E16-07B3-4694-8357-3C21ACC5F516}: [SuggestionsURL] = http://ie.search.yahoo.com/os?appid=chrie&command= - Yahoo! Search
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0AA24E16-07B3-4694-8357-3C21ACC5F516}: [URL] = http://it.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo&type=33010001005_10.0.1.6258_u_ds - Yahoo! Search
O2 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O4 - Global User Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk -> C:\Program Files\AnyDesk\AnyDesk.exe --control
O4 - HKCU\..\Run: [AvastBrowserAutoLaunch_0EE3CF92E3C27CAC7674238441872C1C] = C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe --auto-launch-at-startup --check-run=src=logon --profile-directory=Default
O4 - HKCU\..\Run: [GUDelayStartup] = C:\Program Files\Glary Utilities 5\StartupManager.exe -delayrun
O4 - HKLM\..\Run: [AvastUI.exe] = C:\Program Files\AVAST Software\Avast\AvLaunch.exe /gui
O4 - HKLM\..\Run: [HotKeysCmds] = C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] = C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] = C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] = C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKLM\..\Session Manager: [BootExecute] = C:\Windows\system32\autochk.exe *
O4 - HKU\.DEFAULT\..\RunOnce: [SPReview] = C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
O16 - DPF: HKLM\..\{8AD9C840-044E-11D1-B3E9-00805F499D93}\DownloadInformation: Java Plug-in 1.6.0_11 [CODEBASE] = http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
O16 - DPF: HKLM\..\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\DownloadInformation: Java Plug-in 1.6.0_11 [CODEBASE] = http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
O16 - DPF: HKLM\..\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\DownloadInformation: Java Plug-in 1.6.0_11 [CODEBASE] = http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
O17 - DHCP DNS 1: 192.168.1.1
O21 - HKLM\..\ShellIconOverlayIdentifiers\00asw: avast - {472083B0-C522-11CF-8763-00608CC02F24} - C:\Program Files\AVAST Software\Avast\ashShell.dll
O22 - Task (.job): (Not scheduled) GlaryInitialize.job - C:\Program Files\Glary Utilities\initialize.exe
O23 - Service R2: AnyDesk Service - (AnyDesk) - C:\Program Files\AnyDesk\AnyDesk.exe --service
O23 - Service R2: Avast Antivirus - (avast! Antivirus) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service R2: Diagnostics Tracking Service - (DiagTrack) - C:\Windows\System32\svchost.exe -k utcsvc; "ServiceDll" = C:\Windows\system32\diagtrack.dll
O23 - Service R2: SegurazoSvc - C:\Program Files\SAntivirus\SegurazoService.exe
O23 - Service R3: aswbIDSAgent - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service S2: Servizio Avast Browser Update (avast) - (avast) - C:\Program Files\AVAST Software\Browser\Update\AvastBrowserUpdate.exe /svc
O23 - Service S2: Servizio Google Update (gupdate) - (gupdate) - C:\Program Files\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: Adobe Flash Player Update Service - (AdobeFlashPlayerUpdateSvc) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service S3: Avast Secure Browser Elevation Service - (AvastSecureBrowserElevationService) - C:\Program Files\AVAST Software\Browser\Application\77.2.2152.121\elevation_service.exe
O23 - Service S3: Google Chrome Elevation Service - (GoogleChromeElevationService) - C:\Program Files\Google\Chrome\Application\80.0.3987.87\elevation_service.exe
O23 - Service S3: Servizio Avast Browser Update (avastm) - (avastm) - C:\Program Files\AVAST Software\Browser\Update\AvastBrowserUpdate.exe /medsvc
O23 - Service S3: Servizio Google Update (gupdatem) - (gupdatem) - C:\Program Files\Google\Update\GoogleUpdate.exe /medsvc


--
End of file - Time spent: 26,2 sec. - 17728 bytes, CRC32: FFFFFFFF. Sign: 읣
Sponsor
Inviato: Monday, February 10, 2020 3:47:06 PM

 
fax71ita
Inviato: Monday, February 10, 2020 8:02:50 PM

Rank: AiutAmico

Iscritto dal : 4/23/2010
Posts: 3,837
Ciao hai installato segurazo antivirus, che antivirus non è.....
Fai attenzione quando installi programmi altrimenti ogni 15 gg hai il pc impestato.
Lascio agli amici più esperti di aiutarti in questa impresa .

cbbusto
Inviato: Tuesday, February 11, 2020 2:11:10 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Tieni presente che win 7 non è più supportato da microsoft.
Come già suggerito dall'amico fax, elimina segurazo.
Fixa ed elimina le seguenti voci:

1 C:\Program Files\SAntivirus\SegurazoClient.exe
1 C:\Program Files\SAntivirus\SegurazoIC.exe
1 C:\Program Files\SAntivirus\SegurazoService.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main: [Start Page] = https://it.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=88dpyqptgki1320egikmoq9ay000220&param1=y6bdVFVIsvuYsgEClQfz8Hp%2FDKLQJBXkKHVBcimHc9cJeCL%2BU0bwl9EH6nNFJ21fUDxAA2lZ90%2FohjndVTreSG%2Fr74o4FBXqu2qocP5XBgWVGHm%2B7Hz14sparLVSw2b6clJ%2BPnr6hRs3boyRiU6CF%2Bxre1ns157RBYEDb4iutu6KTTxDSet0IX1EAATiBgn%2BNkPl98zgGb7weldurlrJ0dHH02zZ9e6bftXXFAyyAXBEdC0AAOCvGN%2F5VGjR0sfT3g%2BNQfgdiWRC2X%2B4sXPMii6vMxWL1ckpwmil4%2FypPt%2FUa9LFBGQuTNhYYFtfDKaCC9x17DfmjfGeEziLlubpjD6R5NVM7qXWvg8jDbfXpjvTQzWQjufx4RSpPsGaDBPc4dHMuhwHi34GkcWfdUOyUA%3D%3D

R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: [SuggestionsURL_JSON] = https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms} - Yahoo powered search

R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: [TopResultURLFallback] = https://it.search.yahoo.com/yhs/search?hspart=omr&hsimp=yhs-001&type=88dpyqptgki1320egikmoq9ay000220&param1=y6bdVFVIsvuYsgEClQfz8Hp%2FDKLQJBXkKHVBcimHc9cJeCL%2BU0bwl9EH6nNFJ21fUDxAA2lZ90%2FohjndVTreSBj5XuZXikPSKn5IWLGfo5l01Ko4PY88sRXBp90GP2fnFOKuX%2B81Z9WFIfBh8r%2FZVypakftvKaUyJ3bbRzmEAXcY%2BnFw%2Bjqggml1q63K2ljI4pSti8nSq%2FL8nZEvORe0Vjcq4Mmnpw5IfLxIrHFZeZV6WrXdSVrSOr5Px08lN4SAskFP%2BDC19FTBiV4wkkt%2BKE%2BO%2BftZBgrXQ6wY5vskah3TOvlYTaXmnDzKO04KdePCvTWUAxv21QTEm5cemsczl9r2mFghFS%2BDq5D3tsESM6qkH96rSt%2FjBG13rrXUDce7zKj4Tihu0nFSoAi%2Brqk65w%3D%3D&p={searchTerms} - Yahoo powered search

R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: [URL] = https://it.search.yahoo.com/yhs/search?hspart=omr&hsimp=yhs-001&type=88dpyqptgki1320egikmoq9ay000220&param1=y6bdVFVIsvuYsgEClQfz8Hp%2FDKLQJBXkKHVBcimHc9cJeCL%2BU0bwl9EH6nNFJ21fUDxAA2lZ90%2FohjndVTreSBj5XuZXikPSKn5IWLGfo5l01Ko4PY88sRXBp90GP2fnFOKuX%2B81Z9WFIfBh8r%2FZVypakftvKaUyJ3bbRzmEAXcY%2BnFw%2Bjqggml1q63K2ljI4pSti8nSq%2FL8nZEvORe0Vjcq4Mmnpw5IfLxIrHFZeZV6WrXdSVrSOr5Px08lN4SAskFP%2BDC19FTBiV4wkkt%2BKE%2BO%2BftZBgrXQ6wY5vskah3TOvlYTaXmnDzKO04KdePCvTWUAxv21QTEm5cemsczl9r2mFghFS%2BDq5D3tsESM6qkH96rSt%2FjBG13rrXUDce7zKj4Tihu0nFSoAi%2Brqk65w%3D%3D&p={searchTerms} - Yahoo powered search

R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0AA24E16-07B3-4694-8357-3C21ACC5F516}: [SuggestionsURL] = http://ie.search.yahoo.com/os?appid=chrie&command= - Yahoo! Search

R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0AA24E16-07B3-4694-8357-3C21ACC5F516}: [URL] = http://it.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo&type=33010001005_10.0.1.6258_u_ds - Yahoo! Search
O4 - HKCU\..\Run: [GUDelayStartup] = C:\Program Files\Glary Utilities 5\StartupManager.exe -delayrun (inutile averlo in Avvio automatico)
O4 - HKLM\..\Run: [HotKeysCmds] = C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] = C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] = C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] = C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKLM\..\Session Manager: [BootExecute] = C:\Windows\system32\autochk.exe *
O4 - HKU\.DEFAULT\..\RunOnce: [SPReview] = C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601

Scarica Adwcleaner sul desktop: http://www.bleepingcomputer.com/download/adwcleaner/
Per il download cliccare su: Download now
Chiudi tutti i browser (è importante IE,Firefox Chrome ecc...)
Clicca sul pulsante "Analisi".
Finita la scansione clicca su "Pulizia"

Conferma con OK le varie finestre che ti compariranno.
Riavvia il pc e uscirà il log con le eliminazioni.
Postalo qui.
ADW crea un backup dei files e delle impostazioni eliminati, si trova in "C:\AdwCleaner\Quarantine" in modo da consentire l'eventuale ripristino di dati erroneamente cancellati.
Per il ripristino, aprire il programma>Strumenti>Gestione quarantena>Ripristino.

Scarica Junkware Removal Tool sul desktop.
http://junkware-removal-tool.it.uptodown.com/download
Il download dovrebbe partire entro 5 secondi
Disattiva temporaneamente l'antivirus per evitare potenziali conflitti.
Doppio click su JRT
Lo strumento si aprirà e avvierà la scansione del sistema.
Devi avere pazienza in quanto questo tool può richiedere del tempo per completare la scansione .
Al termine, un log (JRT.txt) viene salvato sul desktop e si aprirà automaticamente.
Postalo qui.
Fai una pulizia del Registro.

Per una pulizia profonda del registro, usa Eusing Free Registry Cleaner sw da usare saltuariamente, lo scarichi da qui: http://www.eusing.com/free_registry_cleaner/registry_cleaner.htm
clic su Download Site1, una volta lanciato appare una finestra che chiede il codice, clic su ignora e procedi, poi in alto a sinistra clic su Analizza Registro, lascia fare fino alla fine non ti preoccupare se trova molte voci, poi clicca su Ripara Registro, il sw è sicuro comunque crea un punto di ripristino e fa anche il backup dei file eliminati infatti in alto sotto ripara registro si trova la voce Ripristina Registro.
Per fare questa pulizia meglio chiudere tutti i programmi e disconnesso.
Il programma è compatibile con tutti i S.O. windows compreso win 10.

Fai sapere se il pc è migliorato. Ciao




libero1962
Inviato: Tuesday, February 11, 2020 7:00:26 PM

Rank: AiutAmico

Iscritto dal : 1/26/2009
Posts: 570
Da dove le elimino segurazo termina processo o altro canale
libero1962
Inviato: Tuesday, February 11, 2020 7:49:34 PM

Rank: AiutAmico

Iscritto dal : 1/26/2009
Posts: 570
Nei programmi istallati non risulta è nascosto
cbbusto
Inviato: Wednesday, February 12, 2020 1:01:56 AM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
il programma lo trovi quì: C:\Program Files\SAntivirus\SegurazoClient.exe e lo cancelli
libero1962
Inviato: Wednesday, February 12, 2020 7:45:59 PM

Rank: AiutAmico

Iscritto dal : 1/26/2009
Posts: 570
mi è entrato da solo non lo istallato io
wolfestein
Inviato: Wednesday, February 12, 2020 11:52:11 PM

Rank: AiutAmico

Iscritto dal : 2/15/2009
Posts: 15,954
Occhio quando scarichi o installi qualcosa.
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.