Ho appena terminato quello che mi hai consigliato di fare Luke57... hai perfettamente ragione e' tutto come hai pronosticato... nel pannello utente c'e solo il mio profilo ma LinkOptimizer e' installato nel sistema...cosi' con MyUnistaller lo ho eliminato e ho fatto le 2 scansioni con Gmer che ho notato mi segnalava qualcosa di anomalo... ecco i rispettivi log Rootkit e Autostart.
GMER 1.0.10.10122 -
http://www.gmer.net
Rootkit 2006-08-16 22:18:24
Windows 5.1.2600 Service Pack 1
---- System - GMER 1.0.10 ----
SSDT a347bus.sys ZwClose
SSDT 85A302D8 ZwConnectPort
SSDT a347bus.sys ZwCreateKey
SSDT a347bus.sys ZwCreatePagingFile
SSDT a347bus.sys ZwEnumerateKey
SSDT a347bus.sys ZwEnumerateValueKey
SSDT a347bus.sys ZwOpenKey
SSDT 863D1AA0 ZwOpenProcess
SSDT 869F1318 ZwOpenThread
SSDT a347bus.sys ZwQueryKey
SSDT a347bus.sys ZwQueryValueKey
SSDT a347bus.sys ZwSetSystemPowerState
SSDT sptd.sys ZwSetValueKey
---- Devices - GMER 1.0.10 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 86FA5708
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 86D537C0
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CREATE 86E03458
Device \FileSystem\vobiw \vobIW IRP_MJ_CREATE 864A2DD8
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CREATE 86E03458
Device \Driver\NetBT \Device\NetBT_Tcpip_{DDE601B4-EC36-4C1D-A8D2-2449F049D625} IRP_MJ_CREATE 85EAE0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 86FA6390
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 86FA6390
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 86FA6390
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 86FA6390
Device \Driver\NetBT \Device\NetBT_Tcpip_{8859C497-CCAF-439C-B7CA-4D99B309F939} IRP_MJ_CREATE 85EAE0E8
Device \Driver\prodrv06 \Device\ProDrv06 IRP_MJ_CREATE E1739450
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 86FA6648
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 86FA6648
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSEIRP_MJ_READ 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 86E10008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP_POWER 86E10008
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSEIRP_MJ_READ 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 85A294B8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 863CD330
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_PNP 863CD330
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 86FA6648
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSEIRP_MJ_READ 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 86E10008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP_POWER 86E10008
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSEIRP_MJ_READ 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 86D84E60
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_NAMED_PIPE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLOSEIRP_MJ_READ 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_WRITE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_FLUSH_BUFFERS 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DIRECTORY_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_FILE_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SHUTDOWN 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_LOCK_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLEANUP 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_MAILSLOT 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CHANGE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_PNP 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_PNP_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSEIRP_MJ_READ 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 86D84E60
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE_NAMED_PIPE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLOSEIRP_MJ_READ 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_WRITE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_FLUSH_BUFFERS 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DIRECTORY_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_FILE_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_INTERNAL_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SHUTDOWN 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_LOCK_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLEANUP 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE_MAILSLOT 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DEVICE_CHANGE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_PNP 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_PNP_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_CREATE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_CREATE_NAMED_PIPE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_CLOSEIRP_MJ_READ 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_WRITE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_QUERY_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SET_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_QUERY_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SET_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_FLUSH_BUFFERS 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_QUERY_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SET_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_DIRECTORY_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_FILE_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_INTERNAL_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SHUTDOWN 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_LOCK_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_CLEANUP 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_CREATE_MAILSLOT 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_QUERY_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SET_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_DEVICE_CHANGE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_QUERY_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SET_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_PNP 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_PNP_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_CREATE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_CREATE_NAMED_PIPE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_CLOSEIRP_MJ_READ 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_WRITE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_QUERY_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SET_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_QUERY_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SET_EA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_FLUSH_BUFFERS 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_QUERY_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SET_VOLUME_INFORMATION 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_DIRECTORY_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_FILE_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_INTERNAL_DEVICE_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SHUTDOWN 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_LOCK_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_CLEANUP 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_CREATE_MAILSLOT 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_QUERY_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SET_SECURITY 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_POWER 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SYSTEM_CONTROL 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_DEVICE_CHANGE 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_QUERY_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SET_QUOTA 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_PNP 86D84E60
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_PNP_POWER 86D84E60
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE 86FA6648
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSEIRP_MJ_READ 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 86E10008
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP_POWER 86E10008
Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_CREATE 86FA6648
Device \Driver\Ftdisk \Device\HarddiskVolume6 IRP_MJ_CREATE 86FA6648
Device \Driver\prohlp02 \Device\ProHlp02 IRP_MJ_CREATE E161B5B0
Device \Driver\00000066 \Device\00000077 IRP_MJ_SYSTEM_CONTROL [F7586A26] sptd.sys
Device \Driver\00000066 \Device\00000077 IRP_MJ_DEVICE_CHANGE [F759ABD8] sptd.sys
Device \Driver\00000066 \Device\00000077 IRP_MJ_PNP_POWER [F759354E] sptd.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 85EAE0E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 85EAE0E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{F9482DB6-B478-4EBC-935C-4785097EBB7C} IRP_MJ_CREATE 85EAE0E8
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 86FA5940
Device \Driver\Disk \Device\Harddisk1\DR1 IRP_MJ_CREATE 86FA5940
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSEIRP_MJ_READ 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 85A3C3C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP_POWER 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSEIRP_MJ_READ 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 85A3C3C0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 85A37CF0
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP_POWER 85A37CF0
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 863CAEB0
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 863CAEB0
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSEIRP_MJ_READ 863CAEB0
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 86496D98
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 863CAEB0
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION 863CAEB0
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_EA 863CAEB0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 86FA6648
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE 8648B450
Device \Driver\NetBT \Device\NetBT_Tcpip_{0BDE4542-85C0-4724-B8A5-F77B03832662} IRP_MJ_CREATE 85EAE0E8
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CREATE 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CLOSEIRP_MJ_READ 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_WRITE 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SET_INFORMATION 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_QUERY_EA 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SET_EA 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SHUTDOWN 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CLEANUP 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SET_SECURITY 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_POWER 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SET_QUOTA 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_PNP 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_PNP_POWER 86C47950
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CREATE 86FA5BF8
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE_NAMED_PIPE 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CLOSEIRP_MJ_READ 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_WRITE 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_QUERY_INFORMATION 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SET_INFORMATION 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_QUERY_EA 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SET_EA 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_FLUSH_BUFFERS 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_QUERY_VOLUME_INFORMATION 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SET_VOLUME_INFORMATION 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_DIRECTORY_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_FILE_SYSTEM_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_DEVICE_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SHUTDOWN 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_LOCK_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CLEANUP 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE_MAILSLOT 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_QUERY_SECURITY 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SET_SECURITY 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_POWER 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SYSTEM_CONTROL 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_DEVICE_CHANGE 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_QUERY_QUOTA 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SET_QUOTA 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_PNP 86C47950
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_PNP_POWER 86C47950
Device \FileSystem\vobiw \UDFFileSys IRP_MJ_CREATE 864A2DD8
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 86D537C0
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 86E03D48
---- Processes - GMER 1.0.10 ----
Library C:\WINDOWS\ylwvx1.dll (*** hidden *** ) @ C:\Programmi\Internet Explorer\iexplore.exe [536] 0x014B0000 <-- ROOTKIT !!!
Library C:\WINDOWS\ylwvx1.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [1364] 0x10000000 <-- ROOTKIT !!!
---- Modules - GMER 1.0.10 ----
Module _________ F74B7000
---- Files - GMER 1.0.10 ----
File C:\WINDOWS\ylwvx1.dll
---- EOF - GMER 1.0.10 ----
Log autostart
GMER 1.0.10.10122 -
http://www.gmer.net
Autostart 2006-08-16 22:20:06
Windows 5.1.2600 Service Pack 1
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\ >>>
Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
Windows@AppInit_DLLs = C:\:c_87u.nls
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Automatic LiveUpdate Scheduler /*Automatic LiveUpdate Scheduler*/@ = "C:\Programmi\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
btwdins /*Bluetooth Service*/@ = C:\Programmi\Software Bluetooth\bin\btwdins.exe
ccEvtMgr /*Symantec Event Manager*/@ = "C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe"
ccSetMgr /*Symantec Settings Manager*/@ = "C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe"
Creative Service for CDROM Access /*Creative Service for CDROM Access*/@ = C:\WINDOWS\System32\CTsvcCDA.exe
ILM /*Infobel License Manager*/@ = C:\Programmi\Finson\ILM\Ilm.exe
navapsvc /*Norton AntiVirus Auto-Protect Service*/@ = "C:\Programmi\Norton AntiVirus\navapsvc.exe"
NetRqh /*NetRqh*/@ = "C:\Programmi\File comuni\Microsoft Shared\lmkXMo.exe"
NPFMntor /*Norton AntiVirus Firewall Monitor Service*/@ = C:\Programmi\Norton AntiVirus\IWP\NPFMntor.exe
NVSvc /*NVIDIA Display Driver Service*/@ = %SystemRoot%\System32\nvsvc32.exe
SBService /*ScriptBlocking Service*/@ = C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
SNDSrvc /*Symantec Network Drivers Service*/@ = C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
SPBBCSvc /*Symantec SPBBCSvc*/@ = C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
Symantec Core LC /*Symantec Core LC*/@ = C:\Programmi\File comuni\Symantec Shared\CCPD-LC\symlcsvc.exe
SymWSC /*SymWMI Service*/@ = C:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\System32\wdfmgr.exe
WMDM PMSP Service /*WMDM PMSP Service*/@ = C:\WINDOWS\System32\MsPMSPSv.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@SSC_UserPromptC:\Programmi\File comuni\Symantec Shared\Security Center\UsrPrmpt.exe = C:\Programmi\File comuni\Symantec Shared\Security Center\UsrPrmpt.exe
@SoundManSOUNDMAN.EXE = SOUNDMAN.EXE
@PE2CKFNT SEC:\Programmi\Ulead Photo Express 2 SE\ChkFont.exe = C:\Programmi\Ulead Photo Express 2 SE\ChkFont.exe
@NeroFilterCheckC:\WINDOWS\system32\NeroCheck.exe = C:\WINDOWS\system32\NeroCheck.exe
@IW ControlcenterC:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE = C:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE
@CTSysVolC:\Programmi\Creative\Surround Mixer\CTSysVol.exe /r /*file not found*/ = C:\Programmi\Creative\Surround Mixer\CTSysVol.exe /r /*file not found*/
@CTHelperCTHELPER.EXE = CTHELPER.EXE
@CTDVDDETC:\Programmi\Creative\DVDAudio\CTDVDDET.EXE = C:\Programmi\Creative\DVDAudio\CTDVDDET.EXE
@RivaTunerStartupDaemon"C:\Programmi\rivatuner\RivaTuner.exe" /S = "C:\Programmi\rivatuner\RivaTuner.exe" /S
@ccApp"C:\Programmi\File comuni\Symantec Shared\ccApp.exe" = "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
@GAINWARDC:\WINDOWS\TBPanel.exe /A = C:\WINDOWS\TBPanel.exe /A
@Symantec NetDriver MonitorC:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer = C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
@RemoteControlC:\Programmi\CyberLink\PowerDVD\PDVDServ.exe = C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
@nwiznwiz.exe /install = nwiz.exe /install
@NvMediaCenterRUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit = RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
@QuickTime Task"C:\Programmi\QuickTime\qttask.exe" -atboottime = "C:\Programmi\QuickTime\qttask.exe" -atboottime
@DAEMON Tools"C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033 = "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
@KernelFaultCheck%systemroot%\system32\dumprep 0 -k = %systemroot%\system32\dumprep 0 -k
@EPSON Stylus DX4800 SeriesC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /O6 "USB002" /M "Stylus DX4800" = C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /O6 "USB002" /M "Stylus DX4800"
@yylb1.exeC:\WINDOWS\Temp\yylb1.exe = C:\WINDOWS\Temp\yylb1.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@RemoteCenterC:\Programmi\Creative\MediaSource\RemoteControl\RCMan.EXE = C:\Programmi\Creative\MediaSource\RemoteControl\RCMan.EXE
@MsnMsgr"C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background /*file not found*/ = "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background /*file not found*/
@Spyware Doctor"C:\Programmi\Spyware Doctor\swdoctor.exe" /Q = "C:\Programmi\Spyware Doctor\swdoctor.exe" /Q
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRAR\rarext.dll = C:\Programmi\WinRAR\rarext.dll
@{E0D79304-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79305-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79306-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{8FF88D21-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.11 Context Menu Shell Extension*/C:\Programmi\WinAce\arcext.dll = C:\Programmi\WinAce\arcext.dll
@{8FF88D25-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.11 DragDrop Shell Extension*/C:\Programmi\WinAce\arcext.dll = C:\Programmi\WinAce\arcext.dll
@{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.11 Context Menu Shell Extension*/C:\Programmi\WinAce\arcext.dll = C:\Programmi\WinAce\arcext.dll
@{8FF88D23-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.11 Property Sheet Shell Extension*/C:\Programmi\WinAce\arcext.dll = C:\Programmi\WinAce\arcext.dll
@{E0D79307-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{F5D92341-0A64-11D0-9956-0000E8096023} /*CD Copy Shell Extension*/C:\WINDOWS\System32\Shellext\CDWSHEXT.DLL = C:\WINDOWS\System32\Shellext\CDWSHEXT.DLL
@{F5D92342-0A64-11D0-9956-0000E8096023} /*CD Wizard Shell Extension*/C:\WINDOWS\System32\Shellext\CDWSHEXT.DLL = C:\WINDOWS\System32\Shellext\CDWSHEXT.DLL
@{F5D92344-0A64-11D0-9956-0000E8096023} /*InstantWrite Shellextension*/C:\WINDOWS\System32\Shellext\iwshex.dll = C:\WINDOWS\System32\Shellext\iwshex.dll
@{B8323370-FF27-11D2-97B6-204C4F4F5020} /*SmartFTP Shell Extension DLL*/E:\win88\SmartFTP\smarthook.dll /*file not found*/ = E:\win88\SmartFTP\smarthook.dll /*file not found*/
@{63AFBDFB-5EF8-4791-AF79-9A3C0DE48974} /*EditPlus Context Menu Handler*/C:\Programmi\EditPlus 2\eppshell.dll = C:\Programmi\EditPlus 2\eppshell.dll
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\System32\nvcpl.dll = C:\WINDOWS\System32\nvcpl.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Programmi\RealPlayer\rpshell.dll = C:\Programmi\RealPlayer\rpshell.dll
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll = C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll
@{6EE51AA0-77A0-11D7-B4E1-000347126E46} /*Window Washer Shell Shredding Utility*/C:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL = C:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL
@(null) =
@{6af09ec9-b429-11d4-a1fb-0090960218cb} /*My Bluetooth Places*/C:\WINDOWS\System32\btneighborhood.dll = C:\WINDOWS\System32\btneighborhood.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\OFFICE11\msohev.dll = C:\Programmi\OFFICE11\msohev.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\System32\nvcpl.dll = C:\WINDOWS\System32\nvcpl.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\System32\nvshell.dll = C:\WINDOWS\System32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\System32\nvshell.dll = C:\WINDOWS\System32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\System32\nvshell.dll = C:\WINDOWS\System32\nvshell.dll
@{00020000-0000-1011-8004-0000C06B5161} /*WIBU-SYSTEMS Shell Extension*/(null) =
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
7-Zip@{23170F69-40C1-278A-1000-000100020000} = C:\Programmi\7-Zip\7-zipn.dll
EditPlus@{63AFBDFB-5EF8-4791-AF79-9A3C0DE48974} = C:\Programmi\EditPlus 2\eppshell.dll
Symantec.Norton.Antivirus.IEContextMenu@{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2} = C:\Programmi\Norton AntiVirus\NavShExt.dll
Washer@{6EE51AA0-77A0-11D7-B4E1-000347126E46} = C:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
ZFAdd@{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} = C:\Programmi\WinAce\arcext.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
7-Zip@{23170F69-40C1-278A-1000-000100020000} = C:\Programmi\7-Zip\7-zipn.dll
Washer@{6EE51AA0-77A0-11D7-B4E1-000347126E46} = C:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
ZFAdd@{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} = C:\Programmi\WinAce\arcext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
7-Zip@{23170F69-40C1-278A-1000-000100020000} = C:\Programmi\7-Zip\7-zipn.dll
Symantec.Norton.Antivirus.IEContextMenu@{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2} = C:\Programmi\Norton AntiVirus\NavShExt.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@(null) =
@{92D8B666-1C89-5191-5D7B-C4B9B6F3B9BF}C:\WINDOWS\ylwvx1.dll = C:\WINDOWS\ylwvx1.dll
@{AA58ED58-01DD-4d91-8333-CF10577473F7}c:\programmi\google\googletoolbar2.dll = c:\programmi\google\googletoolbar2.dll
@(null) =
@{BDF3E430-B101-42AD-A544-FADC6B084872}C:\Programmi\Norton AntiVirus\NavShExt.dll = C:\Programmi\Norton AntiVirus\NavShExt.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
@Start
Pagehttp://www.google.it =
http://www.google.it
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start
Pagehttp://www.google.it/ =
http://www.google.it/
@Local Pagec:\windows\system32\blank.htm = c:\windows\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\System32\msvidctl.dll
its@CLSID = C:\WINDOWS\System32\itss.dll
lid@CLSID = C:\WINDOWS\System32\msvidctl.dll
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\System32\itss.dll
mso-offdap11@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\System32\msvidctl.dll
vnd.ms.radio@CLSID = C:\WINDOWS\System32\msdxm.ocx
HKLM\Software\Classes\PROTOCOLS\Handler\wia@CLSID = C:\WINDOWS\System32\wiascr.dll
C:\Documents and Settings\SER DAN\Menu Avvio\Programmi\Esecuzione automatica >>>
Collegamento a emule.lnk = Collegamento a emule.lnk
Copia di Avvia il browser Internet Explorer.lnk = Copia di Avvia il browser Internet Explorer.lnk
TurboLaunch.lnk = TurboLaunch.lnk
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica >>>
BTTray.lnk = BTTray.lnk
DSLMON.lnk = DSLMON.lnk
EPSON Status Monitor 3 Environment Check 2.lnk = EPSON Status Monitor 3 Environment Check 2.lnk
---- EOF - GMER 1.0.10 ----
Cosa debbo fare ora?
Grazie