Salve , qualche giorno fa, non riuscendo più ad installare alcun antivirusne a riavviare in modalità provissoria il pc, dopo varii "smanettamenti" ho scoperto di avere un Beagle...Ho eseguito il fix di symantec ed il beagle è stato rimosso(il computer adesso si riavvia in provissoria)
però non riesco, comunque, ad installare alcun antivurus... Panda trova traccia di AVG, che non c'è nel mio pc, Kasperspy on line idem...
Ho eseguito GMER
ecco i risultati
gmerfile..Del log(lunghissimo) riporto solo i file che mi sembrano strani
File C:\Programmi\Yahoo!\Shared\YbSkinSelectRes.dll
File C:\WINDOWS\ime\shared
File C:\WINDOWS\ime\shared\res
File C:\WINDOWS\system32\drivers\srosa.sys
Da quel che ho compreso smanettando anche tra i vostri post il file
C:\WINDOWS\system32\drivers\srosa.sys
non è sicuro o sbaglio?
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-09-13 07:19:32
Windows 5.1.2600 Service Pack 2
---- Devices - GMER 1.0.13 ----
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_CREATE [F95D24B0] HSFBS2S2.sys
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_CLOSE [F95D24B0] HSFBS2S2.sys
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_READ [F95D24B0] HSFBS2S2.sys
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_POWER [F95D24B0] HSFBS2S2.sys
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_SYSTEM_CONTROL [F95D24B0] HSFBS2S2.sys
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_PNP [F95D24B0] HSFBS2S2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_CREATE [F94B0430] HSFDPSP2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_CLOSE [F94B0430] HSFDPSP2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_READ [F94B0430] HSFDPSP2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_POWER [F94B0430] HSFDPSP2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_SYSTEM_CONTROL [F94B0430] HSFDPSP2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_PNP [F94B0430] HSFDPSP2.sys
Device \Driver\srosa \Device\srosa IRP_MJ_CREATE 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_CREATE_NAMED_PIPE 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_CLOSE 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_READ 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_WRITE 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_QUERY_INFORMATION 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SET_INFORMATION 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_QUERY_EA 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SET_EA 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_FLUSH_BUFFERS 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_QUERY_VOLUME_INFORMATION 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SET_VOLUME_INFORMATION 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_DIRECTORY_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_FILE_SYSTEM_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_DEVICE_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_INTERNAL_DEVICE_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SHUTDOWN 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_LOCK_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_CLEANUP 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_CREATE_MAILSLOT 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_QUERY_SECURITY 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SET_SECURITY 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_POWER 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SYSTEM_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_DEVICE_CHANGE 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_QUERY_QUOTA 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SET_QUOTA 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_PNP 819B4F1E
Device \Driver\Gpc \Device\Gpc IRP_MJ_CREATE [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_CREATE_NAMED_PIPE [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_CLOSE [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_READ [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_WRITE [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_QUERY_INFORMATION [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SET_INFORMATION [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_QUERY_EA [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SET_EA [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_FLUSH_BUFFERS [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_QUERY_VOLUME_INFORMATION [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SET_VOLUME_INFORMATION [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_DIRECTORY_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_FILE_SYSTEM_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_DEVICE_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_INTERNAL_DEVICE_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SHUTDOWN [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_LOCK_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_CLEANUP [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_CREATE_MAILSLOT [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_QUERY_SECURITY [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SET_SECURITY [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_POWER [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SYSTEM_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_DEVICE_CHANGE [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_QUERY_QUOTA [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SET_QUOTA [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_PNP [F9B58886] msgpc.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_CREATE [F949DBE6] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_CLOSE [F949DDE0] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_READ [F949DE8C] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_WRITE [F949DF1C] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_QUERY_INFORMATION [F949DB14] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_SET_INFORMATION [F949DB7C] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_FLUSH_BUFFERS [F949DF76] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_DEVICE_CONTROL [F949DFA4] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_INTERNAL_DEVICE_CONTROL [F94A162C] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_CLEANUP [F949DA52] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_POWER [F94A1F96] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_SYSTEM_CONTROL [F94A2C72] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_PNP [F94A0E56] HSFCXTS2.sys
---- EOF - GMER 1.0.13 ----
gmer section
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-09-13 07:20:02
Windows 5.1.2600 Service Pack 2
---- Kernel code sections - GMER 1.0.13 ----
? C:\WINDOWS\system32\ntoskrnl.exe Impossibile trovare il file specificato.
---- User code sections - GMER 1.0.13 ----
.text C:\WINDOWS\Explorer.EXE[1740] SHELL32.dll!SHFileOperationW 7CA7D1B9 5 Bytes JMP 00FB1102 C:\Programmi\Unlocker\UnlockerHook.dll
---- EOF - GMER 1.0.13 ----
Arttendo aiuto



![Uhm... [uhm]](http://www.megalab.it/forum/images/smilies/Dubbio.gif)