ok fatta con rootkitrevealer..all'inizio non mi salvava lo scan e il pc si piantava poi ci sono riuscito
HKLM\SECURITY\Policy\Secrets\SAC* 03/09/2004 12.16 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 03/09/2004 12.16 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{3E42295C-1558-42d3-85D7-3F0C8695F26D}\Control 04/06/2007 17.54 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\CLSID\{3E42295C-1558-42d3-85D7-3F0C8695F26D}\InprocServer32 04/06/2007 17.54 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\CLSID\{3E42295C-1558-42d3-85D7-3F0C8695F26D}\Insertable 04/06/2007 17.54 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\CLSID\{3E42295C-1558-42d3-85D7-3F0C8695F26D}\MiscStatus 04/06/2007 17.54 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\CLSID\{3E42295C-1558-42d3-85D7-3F0C8695F26D}\ProgID 04/06/2007 17.54 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\CLSID\{3E42295C-1558-42d3-85D7-3F0C8695F26D}\Programmable 04/06/2007 17.54 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\CLSID\{3E42295C-1558-42d3-85D7-3F0C8695F26D}\ToolboxBitmap32 04/06/2007 17.54 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\CLSID\{3E42295C-1558-42d3-85D7-3F0C8695F26D}\TypeLib 04/06/2007 17.54 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\CLSID\{3E42295C-1558-42d3-85D7-3F0C8695F26D}\Version 04/06/2007 17.54 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\CLSID\{3E42295C-1558-42d3-85D7-3F0C8695F26D}\VersionIndependentProgID 04/06/2007 17.54 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32* 28/08/2005 11.34 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed 04/06/2007 18.32 80 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 20/05/2007 12.28 0 bytes Access is denied.
C:\Documents and Settings\All Users\Dati applicazioni\AOL\AVP6\Report\03ad_File_Monitoring_eventcritlog.rpt 04/06/2007 18.53 4.28 KB Hidden from Windows API.
C:\Documents and Settings\Roberto\Cookies\roberto@cgi-bin[1].txt 04/06/2007 18.44 111 bytes Hidden from Windows API.
C:\Documents and Settings\Roberto\Cookies\roberto@google[1].txt 04/06/2007 18.38 130 bytes Hidden from Windows API.
C:\Documents and Settings\Roberto\Cookies\
[email protected][2].txt 04/06/2007 18.45 108 bytes Hidden from Windows API.
C:\Documents and Settings\Roberto\Cookies\roberto@oxado[1].txt 04/06/2007 18.38 89 bytes Hidden from Windows API.
C:\Documents and Settings\Robert
ho rifatto lo scan con gmer e mi è uscito questo
http://img526.imageshack.us/img526/4510/gmerimagelf7.jpg (http://imageshack.us)
mentre questa me la dà sophos
http://img515.imageshack.us/img515/6519/sophosimagebp3.jpg (http://imageshack.us)