disabilità il system restore (http://www.google.it/url?sa=t&ct=res&cd=1&url=http%3A%2F%2Fwww.sicurezzainrete.com%2Fdisabilitare_system_restore.htm&ei=QWNERvWVB4G-0wTTwOgU&usg=AFrqEzc5_nmKaM82rO8fOqtT4PiZ1h7KkQ&sig2=nize6bT48Y2J4qa6gFE-qQ);
e rifai la scan con bitdef; credo tu abbia gromozon, ma di fonte alla non concordansa dei due scanner antirootkit; ne proviamo un terzo
http://download.sysinternals.com/Files/RootkitRevealer.zip
scansiona e vedi che ti dice
ecco RootkitRevealer:
HKU\S-1-5-21-2052111302-1604221776-725345543-1003\Software\Adobe\MediaBrowser\MRU\Photoshop\ApplicationPath 20/01/2007 16.24 53 bytes Data mismatch between Windows API and raw hive data.
HKU\S-1-5-21-2052111302-1604221776-725345543-1003\Software\Microsoft\RAS Autodial\Control\LoginSessionDisable 31/05/2007 18.30 4 bytes Data mismatch between Windows API and raw hive data.
HKU\S-1-5-21-2052111302-1604221776-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Qbphzragf naq Frggvatf\Znepb\Qrfxgbc\Ahbin pnegryyn\Qocbjrenzc Zhfvp Pbairegre I 1 31/05/2007 18.29 16 bytes Hidden from Windows API.
HKU\S-1-5-21-2052111302-1604221776-725345543-1003\Software\Zepter Software\RegLib*4c656ba6 11/05/2006 7.12 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAC* 08/09/2005 10.50 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 08/09/2005 10.50 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\ 29/03/2007 12.15 19 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-408-1D6E 29/05/2007 20.48 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-77C4-5CF5 29/05/2007 20.48 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-77C4-5CF5\0000\Service 31/05/2007 18.27 34 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-77C4-5CF5\0000\DeviceDesc 31/05/2007 18.27 34 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 03/10/2006 9.17 0 bytes Access is denied.
HKLM\SYSTEM\ControlSet001\Services\windev-77c4-5cf5 31/05/2007 18.27 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\windev-77c4-5cf5\ImagePath 31/05/2007 18.27 90 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\windev-77c4-5cf5\DisplayName 31/05/2007 18.27 34 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINDEV-408-1D6E 29/05/2007 20.48 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINDEV-77C4-5CF5 29/05/2007 20.48 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINDEV-77C4-5CF5\0000\Service 31/05/2007 18.27 34 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINDEV-77C4-5CF5\0000\DeviceDesc 31/05/2007 18.27 34 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Services\windev-77c4-5cf5 31/05/2007 18.27 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Services\windev-77c4-5cf5\ImagePath 31/05/2007 18.27 90 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Services\windev-77c4-5cf5\DisplayName 31/05/2007 18.27 34 bytes Hidden from Windows API.
C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{996AB4EA-19F3-575A-7FEB-9EE2E33EBB13}\01\10-{996AB4EA-19F3-575A-7FEB-9EE2E33EBB13}-v1-{A62002D 24/09/2006 21.42 8 bytes Hidden from Windows API.
C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{996AB4EA-19F3-575A-7FEB-9EE2E33EBB13}\11\11-{8178A223-976C-41A4-AC87-6563EDF693B6}-v11-{8178A2 24/09/2006 21.42 3.22 KB Hidden from Windows API.
C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{996AB4EA-19F3-575A-7FEB-9EE2E33EBB13}\14\14-{8178A223-976C-41A4-AC87-6563EDF693B6}-v14-{8178A2 24/09/2006 21.42 3.43 KB Hidden from Windows API.
C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\
[email protected]\SharingMetadata\
[email protected]\DFSR\Staging\CS{996AB4EA-19F3-575A-7FEB-9EE2E33EBB13}\16\16-{8178A223-976C-41A4-AC87-6563EDF693B6}-v16-{8178A2 24/09/2006 21.42 80 bytes Hidden from Windows API.
C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG:KAVICHS 31/05/2007 18.29 36 bytes Hidden from Windows API.
C:\Documents and Settings\Marco\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat:KAVICHS 29/05/2007 14.06 36 bytes Hidden from Windows API.
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb 31/05/2007 18.29 64.00 KB Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\system32\windev-77c4-5cf5.sys 29/05/2007 20.48 150.13 KB Hidden from Windows API.
C:\WINDOWS\system32\windev-peers.ini 31/05/2007 18.25 42.81 KB Hidden from Windows API.