hahah lol ecco la scansione autostart (a dire il vero sembra che io ti stia perseguitando hihi) grazie della disponibilità
GMER 1.0.10.10122 -
http://www.gmer.net
Autostart 2006-08-11 13:08:33
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@DLLName = Ati2evxx.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Ati HotKey Poller@ = %SystemRoot%\system32\Ati2evxx.exe
ATI Smart /*ATI Smart*/@ = C:\WINDOWS\system32\ati2sgag.exe
MDM /*Machine Debug Manager*/@ = "C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE"
NOD32krn /*NOD32 Kernel Service*/@ = "C:\Programmi\Eset\nod32krn.exe"
SecMzm /*SecMzm*/@ = "C:\Programmi\File comuni\System\TGf.exe" /*file not found*/
SLService /*SmartLinkService*/@ = slserv.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\system32\wdfmgr.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@nod32kui"C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE = "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
@NWEReboot /*file not found*/ = /*file not found*/
@NeroFilterCheckC:\WINDOWS\system32\NeroCheck.exe = C:\WINDOWS\system32\NeroCheck.exe
@RaidToolC:\Programmi\VIA\RAID\raid_tool.exe pd = C:\Programmi\VIA\RAID\raid_tool.exe pd
@RemoteControl"C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" = "C:\Programmi\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
@ATICCC"C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay = "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
@ViewMgrC:\Programmi\Viewpoint\Viewpoint Manager\ViewMgr.exe = C:\Programmi\Viewpoint\Viewpoint Manager\ViewMgr.exe
@SunJavaUpdateSchedE:\Programmi\Java\jre1.5.0_06\bin\jusched.exe = E:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
@UnlockerAssistant"C:\Programmi\Unlocker\UnlockerAssistant.exe" /*file not found*/ = "C:\Programmi\Unlocker\UnlockerAssistant.exe" /*file not found*/
@pvcsgswuC:\cldocatf.bat = C:\cldocatf.bat
@ljomqyksC:\dmdihdkk.bat = C:\dmdihdkk.bat
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe" = "C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe"
@MSMSGS"C:\Programmi\Messenger\msmsgs.exe" /background = "C:\Programmi\Messenger\msmsgs.exe" /background
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Pagina proprietà versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL = C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\OFFICE11\msohev.dll = C:\Programmi\Microsoft Office\OFFICE11\msohev.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRAR\rarext.dll = C:\Programmi\WinRAR\rarext.dll
@{B089FE88-FB52-11d3-BDF1-0050DA34150D} /*NOD32 Context Menu Shell Extension*/C:\Programmi\Eset\nodshex.dll = C:\Programmi\Eset\nodshex.dll
@{B327765E-D724-4347-8B16-78AE18552FC3} /*NeroDigitalIconHandler*/C:\Programmi\File comuni\Ahead\Lib\NeroDigitalExt.dll = C:\Programmi\File comuni\Ahead\Lib\NeroDigitalExt.dll
@{7F1CF152-04F8-453A-B34C-E609530A9DC8} /*NeroDigitalPropSheetHandler*/C:\Programmi\File comuni\Ahead\Lib\NeroDigitalExt.dll = C:\Programmi\File comuni\Ahead\Lib\NeroDigitalExt.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Programmi\MSN Messenger\fsshext.8.0.0792.00.dll = C:\Programmi\MSN Messenger\fsshext.8.0.0792.00.dll
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/E:\Programmi\iTunesMiniPlayer.dll = E:\Programmi\iTunesMiniPlayer.dll
@{5E2121EE-0300-11D4-8D3B-444553540000} /*Catalyst Context Menu extension*/C:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll = C:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/E:\PROGRA~1\ALCOHO~1\ALCOHO~1\axshlex.dll = E:\PROGRA~1\ALCOHO~1\ALCOHO~1\axshlex.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
NOD32 Context Menu Shell Extension@{B089FE88-FB52-11d3-BDF1-0050DA34150D} = C:\Programmi\Eset\nodshex.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = C:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
NOD32 Context Menu Shell Extension@{B089FE88-FB52-11d3-BDF1-0050DA34150D} = C:\Programmi\Eset\nodshex.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = C:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} = E:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
@Start
Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pageabout:blank = about:blank
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
livecall@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
ms-itss@CLSID = C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL
msnim@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mso-offdap@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\system32\wiascr.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = imon.dll
000000000002@PackedCatalogItem = imon.dll
000000000003@PackedCatalogItem = imon.dll
000000000004@PackedCatalogItem = imon.dll
000000000005@PackedCatalogItem = imon.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011@PackedCatalogItem = imon.dll
C:\Documents and Settings\Giacomo\Menu Avvio\Programmi\Esecuzione automatica = Adobe Gamma.lnk
---- EOF - GMER 1.0.10 ----
ed ecco la scansione dei fastidiosissimi rootkit sui 3 HDs (anche se quello infetto è:C)
GMER 1.0.10.10122 -
http://www.gmer.net
Rootkit 2006-08-11 13:16:51
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.10 ----
SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
---- Devices - GMER 1.0.10 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 823999C0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 8207B860
Device \Driver\NetBT \Device\NetBT_Tcpip_{B7A34EBB-6AD9-411B-8D08-5B483183FAA9} IRP_MJ_CREATE 82061B60
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 8239A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 8239A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 8239A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 8239A510
Device \Driver\prodrv06 \Device\ProDrv06 IRP_MJ_CREATE E1A2D008
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 8239A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 8239A7C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 8208A858
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSEIRP_MJ_READ 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 81E99B28
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_PNP 81E99B28
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 8239A7C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN [F8A406C1] prosync1.sys
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN [F8A406C1] prosync1.sys
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SHUTDOWN [F8A406C1] prosync1.sys
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SHUTDOWN [F8A406C1] prosync1.sys
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SHUTDOWN [F8A406C1] prosync1.sys
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SHUTDOWN [F8A406C1] prosync1.sys
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 8208A858
Device \Driver\NetBT \Device\NetBT_Tcpip_{36D0DD1C-2914-4919-9B40-DD32ABC8680E} IRP_MJ_CREATE 82061B60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 8208A858
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE 8208A858
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_CREATE 8208A858
Device \Driver\prohlp02 \Device\ProHlp02 IRP_MJ_CREATE E1018978
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 82061B60
Device \Driver\00000073 \Device\0000004b IRP_MJ_SYSTEM_CONTROL [F8450F68] sptd.sys
Device \Driver\00000073 \Device\0000004b IRP_MJ_DEVICE_CHANGE [F8465A70] sptd.sys
Device \Driver\00000073 \Device\0000004b IRP_MJ_PNP_POWER [F845E728] sptd.sys
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 82061B60
Device \Driver\00000073 \Device\0000004c IRP_MJ_SYSTEM_CONTROL [F8450F68] sptd.sys
Device \Driver\00000073 \Device\0000004c IRP_MJ_DEVICE_CHANGE [F8465A70] sptd.sys
Device \Driver\00000073 \Device\0000004c IRP_MJ_PNP_POWER [F845E728] sptd.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{4BC9D832-13E3-4BF1-BCB6-C99CD792C0E4} IRP_MJ_CREATE 82061B60
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 82399C78
Device \Driver\Disk \Device\Harddisk1\DR1 IRP_MJ_CREATE 82399C78
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSEIRP_MJ_READ 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP_POWER 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSEIRP_MJ_READ 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 81ECD8F0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP_POWER 81ECD8F0
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 81F38A80
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 81F38A80
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSEIRP_MJ_READ 81F38A80
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 81F38A80
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 81F38A80
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION 81F38A80
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_EA 81F38A80
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 8239A7C8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE 81EA8EB0
Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CREATE 81E00788
Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_CREATE 82399EB0
Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_SHUTDOWN [F8A406C1] prosync1.sys
Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CREATE 81E00788
Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_CREATE 82399EB0
Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_SHUTDOWN [F8A406C1] prosync1.sys
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE 81FADE08
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port3Path0Target0Lun0 IRP_MJ_CREATE 81FADE08
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 8207B860
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 81E4E260
---- Files - GMER 1.0.10 ----
File C:\System Volume Information\MountPointManagerRemoteDatabase
File C:\System Volume Information\tracking.log
File C:\System Volume Information\_restore{5999C35E-1E39-4596-9E8D-D173C0BC1CC6}
File D:\System Volume Information\MountPointManagerRemoteDatabase
File D:\System Volume Information\tracking.log
File D:\System Volume Information\_restore{5999C35E-1E39-4596-9E8D-D173C0BC1CC6}
File E:\System Volume Information\MountPointManagerRemoteDatabase
File E:\System Volume Information\tracking.log
File E:\System Volume Information\_restore{5999C35E-1E39-4596-9E8D-D173C0BC1CC6}
File E:\System Volume Information\_restore{86A49D97-8230-471F-8767-68A971C9318B}
---- EOF - GMER 1.0.10 ----
comunque prima ho eliminato uno strano .exe di nome ZZ dal task manager di hijackthis, situato nella cartella temporanea di documents and settings
ciao