ecco i due LOG
adesso faggio rigirare anche il prg di cui cestinato il log
GMER 1.0.11.11390 -
http://www.gmer.net
Rootkit 2006-10-22 19:25:53
Windows 5.1.2600
---- System - GMER 1.0.11 ----
SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwCreateKey
SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwDeleteKey
SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwDeleteValueKey
SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwEnumerateKey
SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwEnumerateValueKey
SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwOpenKey
SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwQueryKey
SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwQueryValueKey
SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwSetValueKey
SSDT \??\C:\WINDOWS\System32\DRIVERS\PavProc.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\System32\DRIVERS\PavProc.sys ZwTerminateThread
SSDT \??\C:\WINDOWS\System32\PavSRK.sys ZwWriteVirtualMemory
---- Devices - GMER 1.0.11 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F8886810] ShldDrv.SYS
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F8886BD8] ShldDrv.SYS
---- Files - GMER 1.0.11 ----
File C:\Documents and Settings\cri-jeky\Documenti\P-ZIP\NOKIA\Programmi Nokia(37 Programmi per nokia 6600,6630,n70,n90)antivirus,ultra mp3,converter dvix to 3gp,vboy e altri\Camcoder\Nokia_6600_camcoder_pro_v3.75_for_s60(1)\Nokia_6600_camcoder_pro_v3.75_for_s60(1)\blzpda.nfo
File C:\Documents and Settings\cri-jeky\Documenti\P-ZIP\NOKIA\Programmi Nokia(37 Programmi per nokia 6600,6630,n70,n90)antivirus,ultra mp3,converter dvix to 3gp,vboy e altri\Camcoder\Nokia_6600_camcoder_pro_v3.75_for_s60(1)\Nokia_6600_camcoder_pro_v3.75_for_s60(1)\file_id.diz
File C:\Documents and Settings\cri-jeky\Documenti\P-ZIP\NOKIA\Programmi Nokia(37 Programmi per nokia 6600,6630,n70,n90)antivirus,ultra mp3,converter dvix to 3gp,vboy e altri\Camcoder\Nokia_6600_camcoder_pro_v3.75_for_s60(1)\Nokia_6600_camcoder_pro_v3.75_for_s60(1)\keygen.exe
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\01\10-{2C1C0D15-58F8-CF11-8456-804EC66CB836}-v1-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\11\12-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v11-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\11\12-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v11-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\13\14-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v13-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\13\14-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v13-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\15\16-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v15-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\15\16-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v15-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\17\18-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v17-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\17\18-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v17-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\19\20-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v19-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\19\20-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v19-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\21\22-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v21-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\21\22-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v21-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\23\24-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v23-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\23\24-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v23-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\25\26-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v25-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\25\26-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v25-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\27\29-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v27-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\27\29-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v27-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\30\32-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v30-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\30\32-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v30-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\33\35-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v33-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\33\35-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v33-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\34\37-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v34-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\34\37-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v34-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\38\38-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v38-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\38\38-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v38-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\39\40-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v39-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v40-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\39\40-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v39-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v40-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\42\42-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v42-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\42\42-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v42-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\43\43-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v43-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v43-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\43\43-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v43-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v43-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\44\44-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v44-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\44\44-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v44-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\45\45-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v45-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v45-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\45\45-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v45-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v45-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\46\46-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v46-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v46-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
ADS C:\Documents and Settings\cri-jeky\Impostazioni locali\Dati applicazioni\Microsoft\Messenger\aliki79@hotmail.com\SharingMetadata\morrafabrizio@hotmail.it\DFSR\Staging\CS{2C1C0D15-58F8-CF11-8456-804EC66CB836}\46\46-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v46-{02ED2354-A3F6-4F88-9872-4532135C6BCB}-v46-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
---- EOF - GMER 1.0.11 ----
GMER 1.0.11.11390 -
http://www.gmer.net
Autostart 2006-10-22 19:28:49
Windows 5.1.2600
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
AtiExtEvent@DLLName = Ati2evxx.dll
avldr@DLLName = avldr.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Ati HotKey Poller@ = %SystemRoot%\System32\Ati2evxx.exe
ATI Smart /*ATI Smart*/@ = C:\WINDOWS\system32\ati2sgag.exe
EPSONStatusAgent2 /*EPSON Printer Status Agent2*/@ = C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
PAVFNSVR /*Panda Function Service*/@ = "C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\PavFnSvr.exe"
PavPrSrv /*Panda Process Protection Service*/@ = "C:\Programmi\File comuni\Panda Software\PavShld\pavprsrv.exe"
PAVSRV /*Panda anti-virus service*/@ = "C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavsrv51.exe"
PNMSRV /*Panda Network Manager*/@ = "C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\FIREWALL\PNMSRV.EXE"
PSIMSVC /*Panda IManager Service*/@ = "C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\PsImSvc.exe"
SoundMAX Agent Service (default) /*SoundMAX Agent Service*/@ = C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
TPSrv /*Panda TPSrv*/@ = "C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\TPSrv.exe"
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\System32\wdfmgr.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@Logitech UtilityLogi_MwX.Exe = Logi_MwX.Exe
@SmappC:\Programmi\Analog Devices\SoundMAX\SMTray.exe = C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
@ATIPTAC:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe = C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
@APVXDWIN"C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\APVXDWIN.EXE" /s = "C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\APVXDWIN.EXE" /s
@WinampAgentC:\Programmi\Winamp\winampa.exe = C:\Programmi\Winamp\winampa.exe
@LVCOMSXC:\WINDOWS\System32\LVCOMSX.EXE = C:\WINDOWS\System32\LVCOMSX.EXE
@LogitechVideoRepairC:\Programmi\Logitech\Video\ISStart.exe = C:\Programmi\Logitech\Video\ISStart.exe
@LogitechVideoTrayC:\Programmi\Logitech\Video\LogiTray.exe = C:\Programmi\Logitech\Video\LogiTray.exe
@NeroCheckC:\WINDOWS\system32\NeroCheck.exe = C:\WINDOWS\system32\NeroCheck.exe
@CnxTrApprundll32.exe "C:\Programmi\Aethra\ADSL EB1070 USB\CnxTrApp.dll",AppEntry -REG "Aethra\ADSL EB1070 USB" = rundll32.exe "C:\Programmi\Aethra\ADSL EB1070 USB\CnxTrApp.dll",AppEntry -REG "Aethra\ADSL EB1070 USB"
@DataLayerC:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe = C:\Programmi\File comuni\PCSuite\DataLayer\DataLayer.exe
@PCSuiteTrayApplicationC:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray /*file not found*/ = C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray /*file not found*/
@H2OC:\Programmi\SyncroSoft\Pos\H2O\cledx.exe = C:\Programmi\SyncroSoft\Pos\H2O\cledx.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@MSMSGS"C:\Programmi\Messenger\msmsgs.exe" /background = "C:\Programmi\Messenger\msmsgs.exe" /background
@LogitechSoftwareUpdateC:\Programmi\Logitech\Video\ManifestEngine.exe boot = C:\Programmi\Logitech\Video\ManifestEngine.exe boot
@PcSyncC:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog /*file not found*/ = C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog /*file not found*/
@FAST DefragC:\DOCUME~1\cri-jeky\DOCUME~1\P-ZIP\FASTDE~1\FAST2.EXE -tray = C:\DOCUME~1\cri-jeky\DOCUME~1\P-ZIP\FASTDE~1\FAST2.EXE -tray
@WinMediaC:\361101032253584.exe 2 5 3 5 8 4 . e x e /*file not found*/ = C:\361101032253584.exe 2 5 3 5 8 4 . e x e /*file not found*/
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{65756541-C65C-11CD-0000-4B656E696100} /*Panda Antivirus*/C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\ShellTit.DLL = C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\ShellTit.DLL
@{E0D79304-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79305-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79306-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79307-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3} /*Immagini Logitech*/C:\Programmi\Logitech\Video\Namespc2.dll = C:\Programmi\Logitech\Video\Namespc2.dll
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL
@{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} /*PhoneBrowser*/C:\Programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll = C:\Programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
@{FBFE7864-D495-41f0-B7DC-4BB601CC295E} /*Contact View*/C:\Programmi\Nokia\Nokia PC Suite 6\ContactView.dll = C:\Programmi\Nokia\Nokia PC Suite 6\ContactView.dll
@{C0C4375A-5B72-4efe-929D-3B848C3A1E91} /*Message View*/C:\Programmi\Nokia\Nokia PC Suite 6\MessageView.dll = C:\Programmi\Nokia\Nokia PC Suite 6\MessageView.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRAR\rarext.dll = C:\Programmi\WinRAR\rarext.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Programmi\MSN Messenger\fsshext.8.0.0812.00.dll = C:\Programmi\MSN Messenger\fsshext.8.0.0812.00.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{BDEADF00-C265-11d0-BCED-00A0C90AB50F} /*Web Folders*/ = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Panda Antivirus@{65756541-C65C-11CD-0000-4B656E696100} = C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\ShellTit.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
Panda Antivirus@{65756541-C65C-11CD-0000-4B656E696100} = C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\ShellTit.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\System32\logon.scr
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
@Start
Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start
Pagehttp://www.google.it/ =
http://www.google.it/
@Local PageC:\WINDOWS\System32\blank.htm = C:\WINDOWS\System32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\System32\msvidctl.dll
its@CLSID = C:\WINDOWS\System32\itss.dll
lid@CLSID = C:\WINDOWS\System32\msvidctl.dll
livecall@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\System32\itss.dll
msnim@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
tv@CLSID = C:\WINDOWS\System32\msvidctl.dll
vnd.ms.radio@CLSID = C:\WINDOWS\System32\msdxm.ocx
wia@CLSID = C:\WINDOWS\System32\wiascr.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavlsp.dll
000000000002@PackedCatalogItem = C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavlsp.dll
000000000003@PackedCatalogItem = C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavlsp.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000024@PackedCatalogItem = C:\Programmi\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavlsp.dll
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica >>>
Logitech Desktop Messenger.lnk = Logitech Desktop Messenger.lnk
Microsoft Office.lnk = Microsoft Office.lnk
WinZip Quick Pick.lnk = WinZip Quick Pick.lnk
---- EOF - GMER 1.0.11 ----