Ciao,
purtroppo ci sono le voci che mi hai detto di controllare e sono molte. Tutte in carattere verde.
Eccole:
PXR1A.tmp
PXR1B.tmp
PXR1C.tmp
PXR6.tmp
PXR7.tmp
PXR8.tmp
PXR9.tmp
PXR10.tmp
PXR11.tmp
PXR12.tmp
PXR13.tmp
PXR14.tmp
PXR15.tmp
PXR16.tmp
PXR17.tmp
PXR18.tmp
PXR19.tmp
PXRA.tmp
PXRB.tmp
PXRC.tmp
PXRD.tmp
PXRE.tmp
PXRF.tmp
Il percorso è questo:
C:\Documents and Settings\Sarak\Impostazioni locali\Temp
Questi sono i report di GMER, uno di seguito all'altro.
Grazie ancora.
GMER 1.0.12.12011 -
http://www.gmer.net
Rootkit scan 2007-01-16 17:13:25
Windows 5.1.2600 Service Pack 2
.text ...
---- Files - GMER 1.0.12 ----
ADS C:\Documents and Settings\All Users\Dati applicazioni\TEMP:2A81F9CE
ADS C:\Documents and Settings\All Users\Dati applicazioni\TEMP:8FB6501C
ADS C:\Programmi\Internet Explorer\iexplore.exe:SummaryInformation
ADS C:\Programmi\Internet Explorer\iexplore.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
---- Kernel code sections - GMER 1.0.12 ----
.text ntoskrnl.exe!_abnormal_termination + 1D5 804E2831 3 Bytes [ 14, B7, F6 ]
.text ntoskrnl.exe!_abnormal_termination + 1D5 804E2831 3 Bytes [ 14, B7, F6 ]
.text ntoskrnl.exe!_abnormal_termination + 310 804E296C 1 Byte [ 76 ]
.text ntoskrnl.exe!_abnormal_termination + 310 804E296C 1 Byte [ 76 ]
.text ntoskrnl.exe!_abnormal_termination + 312 804E296E 2 Bytes [ 67, F8 ]
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_READ 82799E10
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 82799E10
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_READ 82799E10
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 82799E10
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_READ 82799E10
Device \Driver\nvatabus \Device\0000007b IRP_MJ_CLEANUP 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_CLOSE 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_CREATE 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_CREATE_MAILSLOT 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_CREATE_NAMED_PIPE 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_DEVICE_CHANGE 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_DEVICE_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_DIRECTORY_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_FILE_SYSTEM_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_FLUSH_BUFFERS 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_INTERNAL_DEVICE_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_LOCK_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_PNP 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_POWER 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_QUERY_EA 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_QUERY_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_QUERY_QUOTA 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_QUERY_SECURITY 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_QUERY_VOLUME_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_READ 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_SET_EA 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_SET_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_SET_QUOTA 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_SET_SECURITY 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_SET_VOLUME_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_SHUTDOWN 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_SYSTEM_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007b IRP_MJ_WRITE 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_CLEANUP 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_CLOSE 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_CREATE 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_CREATE_MAILSLOT 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_CREATE_NAMED_PIPE 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_DEVICE_CHANGE 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_DEVICE_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_DIRECTORY_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_FILE_SYSTEM_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_FLUSH_BUFFERS 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_INTERNAL_DEVICE_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_LOCK_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_PNP 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_POWER 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_QUERY_EA 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_QUERY_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_QUERY_QUOTA 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_QUERY_SECURITY 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_QUERY_VOLUME_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_READ 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_SET_EA 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_SET_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_SET_QUOTA 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_SET_SECURITY 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_SET_VOLUME_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_SHUTDOWN 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_SYSTEM_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007c IRP_MJ_WRITE 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_CLEANUP 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_CLOSE 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_CREATE 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_CREATE_MAILSLOT 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_CREATE_NAMED_PIPE 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_DEVICE_CHANGE 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_DEVICE_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_DIRECTORY_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_FILE_SYSTEM_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_FLUSH_BUFFERS 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_INTERNAL_DEVICE_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_LOCK_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_PNP 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_POWER 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_QUERY_EA 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_QUERY_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_QUERY_QUOTA 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_QUERY_SECURITY 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_QUERY_VOLUME_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_READ 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_SET_EA 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_SET_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_SET_QUOTA 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_SET_SECURITY 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_SET_VOLUME_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_SHUTDOWN 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_SYSTEM_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007d IRP_MJ_WRITE 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_CLEANUP 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_CLOSE 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_CREATE 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_CREATE_MAILSLOT 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_CREATE_NAMED_PIPE 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_DEVICE_CHANGE 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_DEVICE_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_DIRECTORY_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_FILE_SYSTEM_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_FLUSH_BUFFERS 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_INTERNAL_DEVICE_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_LOCK_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_PNP 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_POWER 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_QUERY_EA 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_QUERY_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_QUERY_QUOTA 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_QUERY_SECURITY 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_QUERY_VOLUME_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_READ 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_SET_EA 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_SET_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_SET_QUOTA 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_SET_SECURITY 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_SET_VOLUME_INFORMATION 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_SHUTDOWN 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_SYSTEM_CONTROL 82D63218
Device \Driver\nvatabus \Device\0000007e IRP_MJ_WRITE 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_CLEANUP 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_CLOSE 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_CREATE 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_CREATE_MAILSLOT 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_CREATE_NAMED_PIPE 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_DEVICE_CHANGE 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_DEVICE_CONTROL 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_DIRECTORY_CONTROL 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_FILE_SYSTEM_CONTROL 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_FLUSH_BUFFERS 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_LOCK_CONTROL 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_PNP 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_POWER 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_QUERY_EA 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_QUERY_INFORMATION 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_QUERY_QUOTA 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_QUERY_SECURITY 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_QUERY_VOLUME_INFORMATION 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_READ 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_SET_EA 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_SET_INFORMATION 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_SET_QUOTA 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_SET_SECURITY 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_SET_VOLUME_INFORMATION 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_SHUTDOWN 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_SYSTEM_CONTROL 82D63218
Device \Driver\nvatabus \Device\NvAta0 IRP_MJ_WRITE 82D63218
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 82D67258
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 82D67258
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82EF12F8
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CLEANUP 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CLOSE 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CREATE 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CREATE_MAILSLOT 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CREATE_NAMED_PIPE 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_DEVICE_CHANGE 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_DEVICE_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_DIRECTORY_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_FILE_SYSTEM_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_FLUSH_BUFFERS 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_LOCK_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_PNP 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_POWER 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_EA 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_INFORMATION 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_QUOTA 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_SECURITY 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_VOLUME_INFORMATION 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_READ 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_EA 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_INFORMATION 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_QUOTA 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_SECURITY 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_VOLUME_INFORMATION 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SHUTDOWN 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SYSTEM_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_WRITE 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_CLEANUP 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_CLOSE 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_CREATE 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_PNP 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_POWER 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_QUERY_EA 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_READ 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_SET_EA 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_SET_INFORMATION 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_SET_QUOTA 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_SET_SECURITY 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_SHUTDOWN 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 82FAE008
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port0Path0Target0Lun0 IRP_MJ_WRITE 82FAE008
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F6B7D230] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F6B7D230] vsdatant.sys
Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ FF2F1298
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ FF9175F0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ FF996528
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ FF996528
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ FF99E698
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ FFA31708
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ FFA55698
---- System - GMER 1.0.12 ----
SSDT a347bus.sys ZwClose
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateKey
SSDT a347bus.sys ZwCreatePagingFile
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey
SSDT a347bus.sys ZwEnumerateKey
SSDT a347bus.sys ZwEnumerateValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile
SSDT a347bus.sys ZwOpenKey
SSDT \??\C:\Programmi\ewido anti-spyware 4.0\guard.sys ZwOpenProcess
SSDT a347bus.sys ZwQueryKey
SSDT a347bus.sys ZwQueryValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSetInformationFile
SSDT a347bus.sys ZwSetSystemPowerState
SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey
SSDT \??\C:\Programmi\ewido anti-spyware 4.0\guard.sys ZwTerminateProcess
---- EOF - GMER 1.0.12 ----
GMER 1.0.12.12011 -
http://www.gmer.net
Autostart scan 2007-01-16 17:14:28
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = c:\windows\system32\userinit.exe,"c:\windows\ibmnet.exe",
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@DLLName = WgaLogon.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
aswUpdSv /*avast! iAVS4 Control Service*/@ = "C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe"
avast! Antivirus /*avast! Antivirus*/@ = "C:\Programmi\Alwil Software\Avast4\ashServ.exe"
Creative Service for CDROM Access /*Creative Service for CDROM Access*/@ = C:\WINDOWS\System32\CTsvcCDA.exe
ewido anti-spyware 4.0 guard /*ewido anti-spyware 4.0 guard*/@ = C:\Programmi\ewido anti-spyware 4.0\guard.exe
ewido security suite control /*ewido security suite control*/@ = C:\Programmi\ewido anti-malware\ewidoctrl.exe
MDM /*Machine Debug Manager*/@ = "C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe"
Pml Driver HPZ12 /*Pml Driver HPZ12*/@ = C:\WINDOWS\system32\HPZipm12.exe
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\system32\wdfmgr.exe
vsmon /*TrueVector Internet Monitor*/@ = C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service
WMDM PMSP Service /*WMDM PMSP Service*/@ = C:\WINDOWS\System32\MsPMSPSv.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@NeroFilterCheckC:\WINDOWS\system32\NeroCheck.exe = C:\WINDOWS\system32\NeroCheck.exe
@avast!C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
@TkBellExe"C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot = "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
@SunJavaUpdateSched"C:\Programmi\Java\jre1.5.0_08\bin\jusched.exe" = "C:\Programmi\Java\jre1.5.0_08\bin\jusched.exe"
@Zone Labs ClientC:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe = C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
@QuickTime Task"C:\Programmi\QuickTime\qttask.exe" -atboottime = "C:\Programmi\QuickTime\qttask.exe" -atboottime
@DownloadAccelerator"C:\Programmi\DAP\DAP.EXE" /STARTUP = "C:\Programmi\DAP\DAP.EXE" /STARTUP
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run >>>
@ibmnet"c:\windows\ibmnet.exe" = "c:\windows\ibmnet.exe"
@wifipack"c:\windows\wifipack.exe" /*file not found*/ = "c:\windows\wifipack.exe" /*file not found*/
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@CTFMON.EXEC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@TaskTrayC:\Programmi\Creative\SBAudigy\TaskBar\CTLTray.exe = C:\Programmi\Creative\SBAudigy\TaskBar\CTLTray.exe
@TaskBarC:\Programmi\Creative\SBAudigy\TaskBar\CTLTask.exe = C:\Programmi\Creative\SBAudigy\TaskBar\CTLTask.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks >>>
@{54D9498B-CF93-414F-8984-8CE7FDE0D391}C:\Programmi\ewido anti-malware\shellhook.dll = C:\Programmi\ewido anti-malware\shellhook.dll
@{57B86673-276A-48B2-BAE7-C6DBB3020EB8}C:\Programmi\ewido anti-spyware 4.0\shellexecutehook.dll = C:\Programmi\ewido anti-spyware 4.0\shellexecutehook.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\System32\nvshell.dll = C:\WINDOWS\System32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\System32\nvshell.dll = C:\WINDOWS\System32\nvshell.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Outlook Custom Icon Handler*/C:\Programmi\Microsoft Office\Office10\OLKFSTUB.DLL = C:\Programmi\Microsoft Office\Office10\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\Office10\msohev.dll = C:\Programmi\Microsoft Office\Office10\msohev.dll
@{E0D79304-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79305-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79306-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79307-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRAR\rarext.dll = C:\Programmi\WinRAR\rarext.dll
@{4CCEFB41-18FA-11D3-9EF3-00A0C9E897FD} /*CorelDRAW Shell Extension Component*/C:\Programmi\Corel\Corel Graphics 11\DRAW\CDRVIEWER\CrlShell110.dll = C:\Programmi\Corel\Corel Graphics 11\DRAW\CDRVIEWER\CrlShell110.dll
@CorelDRAW Shell Extension Component /*CorelDRAW Shell Extension Component*/(null) =
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll = C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\System32\extmgr.dll = C:\WINDOWS\System32\extmgr.dll
@{B327765E-D724-4347-8B16-78AE18552FC3} /*NeroDigitalIconHandler*/C:\Programmi\File comuni\Ahead\Lib\NeroDigitalExt.dll = C:\Programmi\File comuni\Ahead\Lib\NeroDigitalExt.dll
@{7F1CF152-04F8-453A-B34C-E609530A9DC8} /*NeroDigitalPropSheetHandler*/C:\Programmi\File comuni\Ahead\Lib\NeroDigitalExt.dll = C:\Programmi\File comuni\Ahead\Lib\NeroDigitalExt.dll
@{472083B0-C522-11CF-8763-00608CC02F24} /*avast*/C:\Programmi\Alwil Software\Avast4\ashShell.dll = C:\Programmi\Alwil Software\Avast4\ashShell.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Programmi\Real\RealPlayer\rpshell.dll = C:\Programmi\Real\RealPlayer\rpshell.dll
@{D3796116-94D3-4009-96D7-51578411CC7D} /*Outpost Shell Extension*/C:\PROGRA~1\Agnitum\OUTPOS~1.0\oshdlr.dll /*file not found*/ = C:\PROGRA~1\Agnitum\OUTPOS~1.0\oshdlr.dll /*file not found*/
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
avast@{472083B0-C522-11CF-8763-00608CC02F24} = C:\Programmi\Alwil Software\Avast4\ashShell.dll
DAP_ShredMenu@{BED4C38B-F765-45AC-8C56-613F76BBF43E} = C:\PROGRA~1\DAP\PRIVAC~1\DAPCTX~1.DLL
ewido anti-spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmi\ewido anti-spyware 4.0\context.dll
Resurrector@{3B177BCE-B599-4ABD-BECE-B57EE18187FA} = C:\WINDOWS\system32\iddqd.dll /*file not found*/
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = C:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
DAP_ShredMenu@{BED4C38B-F765-45AC-8C56-613F76BBF43E} = C:\PROGRA~1\DAP\PRIVAC~1\DAPCTX~1.DLL
ewido anti-spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmi\ewido anti-spyware 4.0\context.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
avast@{472083B0-C522-11CF-8763-00608CC02F24} = C:\Programmi\Alwil Software\Avast4\ashShell.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = C:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\System32\ssmypics.scr
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.libero.it =
http://www.libero.it
@Start
Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start
Pagehttp://www.rocorosso.splinder.com/ =
http://www.rocorosso.splinder.com/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
cdo@CLSID = C:\Programmi\File comuni\Microsoft Shared\Web Folders\PKMCDO.DLL
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\System32\itss.dll
lid@CLSID = C:\WINDOWS\System32\msvidctl.dll
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\System32\itss.dll
ms-itss@CLSID = C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\MSITSS.DLL
msnim@CLSID = "C:\PROGRA~1\MSNMES~1\msgrapp.dll"
mso-offdap@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
skype4com@CLSID = C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\System32\wiascr.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = C:\PROGRA~1\LIBERO~1\sliplsp.dll
000000000002@PackedCatalogItem = C:\PROGRA~1\LIBERO~1\sliplsp.dll
000000000003@PackedCatalogItem = C:\PROGRA~1\LIBERO~1\sliplsp.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009@PackedCatalogItem = C:\PROGRA~1\LIBERO~1\sliplsp.dll
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica >>>
Adobe Gamma Loader.lnk = Adobe Gamma Loader.lnk
Adobe Reader Speed Launch.lnk = Adobe Reader Speed Launch.lnk
Avvio rapido di HP Image Zone.lnk = Avvio rapido di HP Image Zone.lnk
HP Digital Imaging Monitor.lnk = HP Digital Imaging Monitor.lnk
Microsoft Office.lnk = Microsoft Office.lnk
---- EOF - GMER 1.0.12 ----