ti ringrazio per la risposta, ti incollo i log
rootkit
GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-07 16:14:53
Windows 5.1.2600
---- System - GMER 1.0.12 ----
SSDT \??\D:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\D:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
---- Kernel code sections - GMER 1.0.12 ----
.text ntoskrnl.exe!FsRtlLegalAnsiCharacterArray + 274 804F21DC 4 Bytes [ AC, 98, E8, F7 ]
.text ntoskrnl.exe!FsRtlLegalAnsiCharacterArray + 490 804F23F8 4 Bytes [ 12, 98, E8, F7 ]
---- Devices - GMER 1.0.12 ----
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F7DBD85A] avgtdi.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F7DBD85A] avgtdi.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F7DBD85A] avgtdi.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F7DBD85A] avgtdi.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F7DBD85A] avgtdi.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN A8100866
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP A80F739A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP A80F739A
Device \FileSystem\Cdfs \Cdfs FastIoCheckIfPossible A81007FC
---- Files - GMER 1.0.12 ----
ADS C:\Documents and Settings\ALESSIO\Documenti\My Music\Anime\Last Exile Ep 21 Rook Dio - By Blackman.ogm:SummaryInformation
ADS C:\Documents and Settings\ALESSIO\Documenti\My Music\Anime\Last Exile Ep 21 Rook Dio - By Blackman.ogm:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS C:\Documents and Settings\ALESSIO\Documenti\roba\fumetti\Jude_degli_Angeli.zip:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS C:\Documents and Settings\ALESSIO\Impostazioni locali\Temporary Internet Files\Content.IE5\CSTI8XRA\images[1].:
ADS C:\Documents and Settings\ALESSIO\Impostazioni locali\Temporary Internet Files\Content.IE5\WHG3WP0F\en[1].:
ADS C:\Documents and Settings\ALESSIO\Impostazioni locali\Temporary Internet Files\Content.IE5\WRNJE09L\search[1].:
ADS C:\Documents and Settings\ALESSIO\Impostazioni locali\Temporary Internet Files\Content.IE5\ZIABUVEX\search[1].:
ADS D:\Documents and Settings\Ale\Desktop\[Zeonic-Corps]_Gundam_Seed_Destiny_Special_Edition_I_[DVD]_[41FD53A4].mkv:SummaryInformation
ADS D:\Documents and Settings\Ale\Desktop\[Zeonic-Corps]_Gundam_Seed_Destiny_Special_Edition_I_[DVD]_[41FD53A4].mkv:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
---- EOF - GMER 1.0.12 ----
Autostart
GMER 1.0.12.12011 - http://www.gmer.net
Autostart scan 2007-01-07 16:11:40
Windows 5.1.2600
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = D:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@DLLName = Ati2evxx.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Ati HotKey Poller@ = %SystemRoot%\System32\Ati2evxx.exe
ATI Smart /*ATI Smart*/@ = D:\WINDOWS\system32\ati2sgag.exe
AVG Anti-Spyware Guard /*AVG Anti-Spyware Guard*/@ = D:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Avg7Alrt /*AVG7 Alert Manager Server*/@ = D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
Avg7UpdSvc /*AVG7 Update Service*/@ = D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
AVGEMS /*AVG E-mail Scanner*/@ = D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
RichVideo /*Cyberlink RichVideo Service(CRVS)*/@ = "D:\Programmi\CyberLink\Shared Files\RichVideo.exe" ??????????????????????????????????????????????????
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@AtiPTAatiptaxx.exe = atiptaxx.exe
@C-Media MixerMixer.exe /startup = Mixer.exe /startup
@AVG7_CCD:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP = D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
@!AVG Anti-Spyware"D:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized = "D:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
HKCU\Software\Microsoft\Windows\CurrentVersion\
[email protected] = D:\WINDOWS\System32\ctfmon.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{57B86673-276A-48B2-BAE7-C6DBB3020EB8} = D:\Programmi\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{5F327514-6C5E-4d60-8F16-D07FA08A78ED} /*Estensione finestra proprietà di aggiornamento automatico*/D:\WINDOWS\System32\wuaueng.dll = D:\WINDOWS\System32\wuaueng.dll
@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} /*AVG7 Shell Extension*/D:\Programmi\Grisoft\AVG Free\avgse.dll = D:\Programmi\Grisoft\AVG Free\avgse.dll
@{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} /*AVG7 Find Extension*/D:\Programmi\Grisoft\AVG Free\avgse.dll = D:\Programmi\Grisoft\AVG Free\avgse.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/D:\Programmi\WinRAR\rarext.dll = D:\Programmi\WinRAR\rarext.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/D:\Programmi\MSN Messenger\fsshext.8.0.0812.00.dll = D:\Programmi\MSN Messenger\fsshext.8.0.0812.00.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = D:\Programmi\Grisoft\AVG Anti-Spyware 7.5\context.dll
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = D:\Programmi\Grisoft\AVG Free\avgse.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = D:\Programmi\WinRAR\rarext.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = D:\Programmi\Grisoft\AVG Anti-Spyware 7.5\context.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = D:\Programmi\WinRAR\rarext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = D:\Programmi\Grisoft\AVG Free\avgse.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = D:\Programmi\WinRAR\rarext.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
@Local PageD:\WINDOWS\System32\blank.htm = D:\WINDOWS\System32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = D:\WINDOWS\System32\msvidctl.dll
its@CLSID = D:\WINDOWS\System32\itss.dll
lid@CLSID = D:\WINDOWS\System32\msvidctl.dll
livecall@CLSID = D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-its@CLSID = D:\WINDOWS\System32\itss.dll
msnim@CLSID = D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
tv@CLSID = D:\WINDOWS\System32\msvidctl.dll
vnd.ms.radio@CLSID = D:\WINDOWS\System32\msdxm.ocx
HKLM\Software\Classes\PROTOCOLS\Handler\wia@CLSID = D:\WINDOWS\System32\wiascr.dll
D:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica = WarpSpeeder Tray Icon.lnk
---- EOF - GMER 1.0.12 ----