buon giorno al forum, ho necessità che un volenteroso mi analizzi l'estratto di hijackthis in quanto il pc
è diventato lentissimo all'avvio e allo spegnimento(ho già eseguito scansioni con adwcleaner e malwareby
senza rilievo di anomalie). Grazie anticipatamente per eventuali suggerimenti
break
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 11:28:40, on 04/06/2022
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
C:\Program Files (x86)\Thunderbird-Tray\TBTray.exe
C:\Users\Michele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KeyboardLeds.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files (x86)\Softland\FBackup 9\bTray.exe
C:\Users\Michele\Documents\SICUREZZA\HIJACKTHIS\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\102.0.1245.30\BHO\ie_to_edge_bho.dll
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Volume2] "C:\Program Files (x86)\Volume2\Volume2.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [EPSDNMON] "C:\Program Files (x86)\Epson Software\Download Navigator\EPSDNMON.EXE"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000001] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIRFE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-243 245 247 Series" /EF "HKCU"
O4 - HKCU\..\Run: [KeyboardLeds.exe] "C:\Users\Michele\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KeyboardLeds.exe"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIRFE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-243 245 247 Series"
O4 - HKCU\..\Run: [MicrosoftEdgeAutoLaunch_EAC917FD4AC17650BD07D7FB19558C87] "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
O4 - HKCU\..\Run: [FBackup 9 Tray Agent] "C:\Program Files (x86)\Softland\FBackup 9\bTray.exe"
O4 - HKCU\..\RunOnce: [Delete Cached Update Binary] C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
O4 - HKCU\..\RunOnce: [Delete Cached Standalone Update Binary] C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
O4 - HKCU\..\RunOnce: [Uninstall 21.205.1003.0003] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\21.205.1003.0003"
O4 - HKCU\..\RunOnce: [Uninstall 21.205.1003.0005] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\21.205.1003.0005"
O4 - HKCU\..\RunOnce: [Uninstall 21.220.1024.0005] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\21.220.1024.0005"
O4 - HKCU\..\RunOnce: [Uninstall 21.230.1107.0004] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\21.230.1107.0004"
O4 - HKCU\..\RunOnce: [Uninstall 21.245.1128.0002] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\21.245.1128.0002"
O4 - HKCU\..\RunOnce: [Uninstall 22.002.0103.0004] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\22.002.0103.0004"
O4 - HKCU\..\RunOnce: [Uninstall 22.012.0117.0003] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\22.012.0117.0003"
O4 - HKCU\..\RunOnce: [Uninstall 22.022.0130.0001] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\22.022.0130.0001"
O4 - HKCU\..\RunOnce: [Uninstall 22.033.0213.0002] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\22.033.0213.0002"
O4 - HKCU\..\RunOnce: [Uninstall 22.045.0227.0004] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\22.045.0227.0004"
O4 - HKCU\..\RunOnce: [Uninstall 22.055.0313.0001] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\22.055.0313.0001"
O4 - HKCU\..\RunOnce: [Uninstall 22.077.0410.0007] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\22.077.0410.0007"
O4 - HKCU\..\RunOnce: [Uninstall 22.089.0426.0003] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michele\AppData\Local\Microsoft\OneDrive\22.089.0426.0003"
O4 - Startup: KeyboardLeds.exe
O4 - Startup: TB-Tray.lnk = C:\Program Files (x86)\Thunderbird-Tray\TBTray.exe
O4 - Startup: thunderbird.exe.lnk = C:\ProgramData\Chameleon Manager\Roaming\Michele\thunderbird.exe
O4 - Startup: YoWindow.lnk = C:\Program Files (x86)\YoWindow\yowindow.exe
O4 - Global Startup: TB-Tray.lnk = C:\Program Files (x86)\Thunderbird-Tray\TBTray.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Advanced SystemCare Service 15 (AdvancedSystemCareService15) - Unknown owner - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AOMEI Backupper Scheduler Service (Backupper Service) - AOMEI International Network Limited - C:\Program Files (x86)\AOMEI\AOMEI Backupper 6.4.0\ABService.exe
O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CCleaner Performance Optimizer Service (CCleanerPerformanceOptimizerService) - Unknown owner - C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_61218 - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Digital Wave Update Service (DigitalWave.Update.Service) - Digital Wave Ltd - C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\WINDOWS\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FBackup 9 Service (FBackup9Srv) - Softland - C:\Program Files (x86)\Softland\FBackup 9\bService.exe
O23 - Service: Foxit PDF Reader Update Service (FoxitReaderUpdateService) - Foxit Software Inc. - C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: IObit Uninstaller Service (IObitUnSvr) - IObit - C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MyEpson Portal Service - Seiko Epson Corporation - C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: Unchecky (unchecky) - Reason Software Company Inc. - C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: VirtualBox system service (VBoxSDS) - Oracle Corporation - C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12457 bytes