Il fatto è che mi ha lasciato abbastanza dubbioso sui risultati.
Qui c'è il mio log e in rosso ho segnato le voci che quel sito mi consiglia di togliere (voci che oltretutto ritornano al successivo scan)
Logfile of HijackThis v1.98.2
Scan saved at 1.00.12, on 29/09/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Programmi\Sygate\SPF\smc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Programmi\AVPersonal\AVWUPSRV.EXE
C:\WINNT\system32\crypserv.exe
C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
C:\Programmi\File comuni\Logitech\QCDriver\LVCOMS.EXE
C:\Programmi\AVPersonal\AVGNT.EXE
C:\Programmi\MemTurbo\MemTurbo.exe
C:\WINNT\webshots.scr
C:\WINNT\explorer.exe
C:\Programmi\Mozilla\Firefox\firefox.exe
C:\Programmi\Gaim\gaim.exe
C:\Programmi\AVPersonal\AVGUARD.EXE
C:\Programmi\Serv-U\ServUDaemon.exe
D:\Utility - live!\Pulizia\HijackThis\HijackThis.exe
C:\Programmi\Ahead\ImgTool Burn\ImgTool.exe
C:\PROGRA~1\Ahead\Nero\SELFDEL.EXE
C:\PROGRA~1\Ahead\Nero\SELFDEL.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wintricks.it/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wintricks.it
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Programmi\Clone\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Programmi\Clone\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LMPDPSRV] C:\WINNT\system32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
O4 - HKLM\..\Run: [LVCOMS] C:\Programmi\File comuni\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [STARTRIGHT] "C:\Programmi\StartRight\StartRight.exe" -go
O4 - HKLM\..\RunOnce: [STARTRIGHT] "C:\Programmi\StartRight\StartRight.exe" -pre
O4 - HKLM\..\RunOnce: [defrag] "VoptXP.exe"
O4 - Startup: MemTurbo.lnk = C:\Programmi\MemTurbo\MemTurbo.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix:
O13 - Mosaic Prefix:
O13 - FTP Prefix:
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{2BDDE9B3-6708-4ED2-B78E-C6D4EABF7814}: NameServer = 195.31.96.214 151.99.125.1
Il punto è che:
- sono voci VUOTE
- se le cancello ritornano
Grazie mille!!!
![Smile [std]](http://www.megalab.it/forum/images/smilies/happy.gif)