![Smile [:)]](http://www.megalab.it/forum/images/smilies/smile.gif)
![Mi metto a piangere... [cry]](http://www.megalab.it/forum/images/smilies/crying.gif)
Ho eseguito GMER
ecco i risultati
![Non sono d'accordo! [nonono]](http://www.megalab.it/forum/images/smilies/Nonsonodaccordo.gif)
gmerfile..Del log(lunghissimo) riporto solo i file che mi sembrano strani
File C:\Programmi\Yahoo!\Shared\YbSkinSelectRes.dll
File C:\WINDOWS\ime\shared
File C:\WINDOWS\ime\shared\res
File C:\WINDOWS\system32\drivers\srosa.sys
![Indeciso [8)]](http://www.megalab.it/forum/images/smilies/unsure.gif)
C:\WINDOWS\system32\drivers\srosa.sys
non è sicuro o sbaglio?
![Oh cacchio! [acc2]](http://www.megalab.it/forum/images/smilies/Acc.gif)
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-09-13 07:19:32
Windows 5.1.2600 Service Pack 2
---- Devices - GMER 1.0.13 ----
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_CREATE [F95D24B0] HSFBS2S2.sys
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_CLOSE [F95D24B0] HSFBS2S2.sys
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_READ [F95D24B0] HSFBS2S2.sys
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_POWER [F95D24B0] HSFBS2S2.sys
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_SYSTEM_CONTROL [F95D24B0] HSFBS2S2.sys
Device \Driver\HSFHWBS2 \Device\RKSAMPLE0 IRP_MJ_PNP [F95D24B0] HSFBS2S2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_CREATE [F94B0430] HSFDPSP2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_CLOSE [F94B0430] HSFDPSP2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_READ [F94B0430] HSFDPSP2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_POWER [F94B0430] HSFDPSP2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_SYSTEM_CONTROL [F94B0430] HSFDPSP2.sys
Device \Driver\HSF_DP \Device\HSF_MDMDevice0 IRP_MJ_PNP [F94B0430] HSFDPSP2.sys
Device \Driver\srosa \Device\srosa IRP_MJ_CREATE 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_CREATE_NAMED_PIPE 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_CLOSE 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_READ 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_WRITE 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_QUERY_INFORMATION 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SET_INFORMATION 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_QUERY_EA 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SET_EA 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_FLUSH_BUFFERS 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_QUERY_VOLUME_INFORMATION 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SET_VOLUME_INFORMATION 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_DIRECTORY_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_FILE_SYSTEM_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_DEVICE_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_INTERNAL_DEVICE_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SHUTDOWN 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_LOCK_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_CLEANUP 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_CREATE_MAILSLOT 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_QUERY_SECURITY 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SET_SECURITY 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_POWER 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SYSTEM_CONTROL 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_DEVICE_CHANGE 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_QUERY_QUOTA 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_SET_QUOTA 819B4F1E
Device \Driver\srosa \Device\srosa IRP_MJ_PNP 819B4F1E
Device \Driver\Gpc \Device\Gpc IRP_MJ_CREATE [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_CREATE_NAMED_PIPE [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_CLOSE [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_READ [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_WRITE [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_QUERY_INFORMATION [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SET_INFORMATION [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_QUERY_EA [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SET_EA [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_FLUSH_BUFFERS [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_QUERY_VOLUME_INFORMATION [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SET_VOLUME_INFORMATION [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_DIRECTORY_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_FILE_SYSTEM_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_DEVICE_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_INTERNAL_DEVICE_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SHUTDOWN [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_LOCK_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_CLEANUP [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_CREATE_MAILSLOT [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_QUERY_SECURITY [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SET_SECURITY [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_POWER [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SYSTEM_CONTROL [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_DEVICE_CHANGE [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_QUERY_QUOTA [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_SET_QUOTA [F9B58886] msgpc.sys
Device \Driver\Gpc \Device\Gpc IRP_MJ_PNP [F9B58886] msgpc.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_CREATE [F949DBE6] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_CLOSE [F949DDE0] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_READ [F949DE8C] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_WRITE [F949DF1C] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_QUERY_INFORMATION [F949DB14] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_SET_INFORMATION [F949DB7C] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_FLUSH_BUFFERS [F949DF76] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_DEVICE_CONTROL [F949DFA4] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_INTERNAL_DEVICE_CONTROL [F94A162C] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_CLEANUP [F949DA52] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_POWER [F94A1F96] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_SYSTEM_CONTROL [F94A2C72] HSFCXTS2.sys
Device \Driver\winachsf \Device\Winachsf0 IRP_MJ_PNP [F94A0E56] HSFCXTS2.sys
---- EOF - GMER 1.0.13 ----
gmer section
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-09-13 07:20:02
Windows 5.1.2600 Service Pack 2
---- Kernel code sections - GMER 1.0.13 ----
? C:\WINDOWS\system32\ntoskrnl.exe Impossibile trovare il file specificato.
---- User code sections - GMER 1.0.13 ----
.text C:\WINDOWS\Explorer.EXE[1740] SHELL32.dll!SHFileOperationW 7CA7D1B9 5 Bytes JMP 00FB1102 C:\Programmi\Unlocker\UnlockerHook.dll
---- EOF - GMER 1.0.13 ----
Arttendo aiuto
![Fischiettando [fischio]](http://www.megalab.it/forum/images/smilies/whistling.gif)