Ho appena fatto le scansioni suggerite e ne e' venuto fuori questo:
- per gmer
Codice:
GMER 1.0.14.14116 - http://www.gmer.net
Rootkit scan 2008-02-19 16:59:38
Windows 5.1.2600 Service Pack 2
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\IPMULTICAST avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)
---- EOF - GMER 1.0.14 ----
- per asquared
Codice:
a-squared Free - Version 3.1
Last update: 19/02/2008 17.17.41
Impostazioni scansione:
Oggetti: Memoria, Tracce, Cookies, C:\WINDOWS\, C:\Programmi
Archivio scansioni: On
Scientifico: On
ADS Scan: On
Scansione avviata: 19/02/2008 17.35.51
c:\programmi\helper rilevati: Trace.Directory.I-Spy
Key: HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy__11f*00df*00e4*0006#*00b7*00ba*00c4*00d6`i rilevati: Trace.Registry.CWS.HomeSearch
Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\d:\installshield\kazaa rilevati: Trace.Registry.KaZaA
Value: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\control panel\extended properties\{305ca226-d286-468e-b848-2b2e8e697b74} 2 --> %systemroot%\system32\p2p networking v126.cpl rilevati: Trace.Registry.PeerEnabler
Scansionati
Files: 20414
Tracce: 374149
Cookies: 23
Processi: 43
Rilevato
Files: 0
Tracce: 4
Cookies: 0
Processi: 0
Chiavi registro: 0
Fine scansione: 19/02/2008 17.54.42
Tempo scansione: 0:18:51
Mi sembra che qualcosa sia venuto fuori, cosa dovrei fare? Per quanto riguarda le voci rilevate con asquared metto in quarantena o elimino?