Grazie mille per l'aiuto!!!
![Smile [:)]](http://www.megalab.it/forum/images/smilies/smile.gif)
-----------------------------------------
Rootkit
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2008-01-02 12:43:10
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.13 ----
SSDT \??\C:\WINDOWS\system32\drivers\srosa.sys ZwCreateFile
SSDT \??\C:\WINDOWS\system32\drivers\srosa.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\system32\drivers\srosa.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\system32\drivers\srosa.sys ZwQueryDirectoryFile
SSDT \??\C:\WINDOWS\system32\drivers\srosa.sys ZwQueryKey
SSDT \??\C:\WINDOWS\system32\drivers\srosa.sys ZwQuerySystemInformation
---- Kernel code sections - GMER 1.0.13 ----
? dkxwbyhn.sys Impossibile trovare il file specificato.
---- User code sections - GMER 1.0.13 ----
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] kernel32.dll!LoadResource 7C809FB5 7 Bytes JMP 28001CC0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] kernel32.dll!FindResourceExW 7C80AC88 7 Bytes JMP 28001B00 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] kernel32.dll!FindResourceW 7C80BBCE 7 Bytes JMP 28001A80 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] kernel32.dll!SizeofResource 7C80BC69 7 Bytes JMP 28001D80 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] kernel32.dll!FindResourceA 7C80BE89 7 Bytes JMP 28001B90 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] kernel32.dll!LockResource 7C80CC97 5 Bytes JMP 28001DF0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] kernel32.dll!CreateEventA 7C8308AD 5 Bytes JMP 28001840 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] kernel32.dll!FindResourceExA 7C835F78 7 Bytes JMP 28001C20 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 004DE392 C:\Programmi\MSN Messenger\MsnMsgr.Exe
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] kernel32.dll!OutputDebugStringW 7C85A42D 5 Bytes JMP 28001E50 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] ADVAPI32.dll!CryptDeriveKey 77F5A685 7 Bytes JMP 28001000 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] ADVAPI32.dll!CryptDecrypt 77F5A7B1 2 Bytes JMP 28001060 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] ADVAPI32.dll!CryptDecrypt + 3 77F5A7B4 4 Bytes [ 0A, B0, CC, CC ]
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] USER32.dll!PeekMessageW 7E39929B 5 Bytes JMP 28003F90 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] USER32.dll!CreateWindowExW 7E39FC25 5 Bytes JMP 280037C0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] USER32.dll!SetWindowRgn 7E39FFB2 7 Bytes JMP 28005880 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] USER32.dll!LoadIconW 7E3A0894 5 Bytes JMP 28006240 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] USER32.dll!LoadImageW 7E3A2CFE 5 Bytes JMP 28006050 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] USER32.dll!CreateDialogParamW 7E3A7D4F 5 Bytes JMP 28005A50 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] USER32.dll!SetWindowPlacement 7E3AD84C 5 Bytes JMP 28005740 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] USER32.dll!MessageBoxIndirectW 7E3E62AB 5 Bytes JMP 28005C40 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] USER32.dll!TrackPopupMenuEx 7E3ECD28 5 Bytes JMP 28004870 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] WS2_32.dll!send 71A3428A 5 Bytes JMP 2800A360 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] WS2_32.dll!WSARecv 71A34318 5 Bytes JMP 2800A140 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] WS2_32.dll!recv 71A3615A 5 Bytes JMP 28009FA0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] WS2_32.dll!WSASend 71A36233 5 Bytes JMP 2800A540 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] WS2_32.dll!closesocket 71A39639 5 Bytes JMP 2800A780 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] SHELL32.dll!Shell_NotifyIconW 7CA31B6A 5 Bytes JMP 28002FE0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] ole32.dll!CoInitializeEx 774CEF6B 5 Bytes JMP 28002100 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] ole32.dll!CoRegisterClassObject 774E8720 5 Bytes JMP 28002200 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] WININET.dll!HttpOpenRequestA 771936CD 5 Bytes JMP 28008E60 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] WININET.dll!InternetCloseHandle 77194D8C 5 Bytes JMP 280091A0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] WININET.dll!HttpSendRequestA 77196269 5 Bytes JMP 280090D0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Programmi\MSN Messenger\MsnMsgr.Exe[324] WININET.dll!InternetReadFile 77198114 5 Bytes JMP 28008FF0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll
---- Processes - GMER 1.0.13 ----
Process C:\WINDOWS\system32\drivers\hldrrr.exe (*** hidden *** ) 448