lupos3 ha scritto:Luke57 ha scritto:@ lupos2
Ciao, sospetto un'infezione da linkoptimizer; allora scarica Gmer :
http://www.gmer.net/gmer110.zip Dopo averlo scompattato, lo avvii, selezioni "Rootkit"
Clicca su "Scan"
Attendi la fine della scansione e clicca su "Copy"
Apri il block notes di windows, clicca su modifica e seleziona incolla
Poi fai una scansione con GMer dalla posizione
Autostart, con le stesse procedure del precedente. Incolli il log generato nel suddetto block notes e poi incolli i due log in un post nel forum.
seconbda parte del log
---- Registry - GMER 1.0.10 ----
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{107E6D21-54ED-32EA-89EBEFDD29F12B2C}\{B975045C-7EA8-ADE1-408732B9E3F99960}\{A296A331-83C2-2419-70104A7C6B45B24D}@SE4K5INHHR1EDZYY15BVZC6TKG1 0x01 0x00 0x01 0x00 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{18E09523-0BB1-0E75-6B141AE958ABE9E7}\{8E8BA3D9-389B-9F43-3B5B6490B54F898E}\{0E0922CC-9ECE-C3AB-5B05A5FA1997F2CA}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{60778762-8BE2-5BE8-74B1F534DECE7DD7}\{033814D8-F5F0-69C3-B63A6822FA3F97AC}\{BB1878CD-9C66-F7AC-793F8981AF2E0354}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{6283EF60-5306-646F-3E2A60A6F3147012}\{EC258BE5-E5B0-C834-EB7A48F96467BF3F}\{829C9D27-3E4A-4D61-8C18630CF0B6A85C}@SE4K5INHHR1EDZYY15BVZC6TKG1 0x01 0x00 0x01 0x00 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x25 0xDA 0xEC 0x7E ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xE9 0x02 0x6C 0xFA ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
---- Files - GMER 1.0.10 ----
File C:\System Volume Information\MountPointManagerRemoteDatabase
File C:\System Volume Information\tracking.log
File C:\System Volume Information\_restore{089CB069-B16F-490A-A43E-018DC2F6F949}
File C:\WINDOWS\cfjdh1.dll
---- EOF - GMER 1.0.10 ----
GMER 1.0.10.10122 -
http://www.gmer.net
Autostart 2006-08-20 18:16:16
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier@DLLName = WRLogonNTF.dll
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs = C:\:zapotmc.bmp
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Creative Service for CDROM Access /*Creative Service for CDROM Access*/@ = C:\WINDOWS\System32\CTSvcCDA.exe
kavsvc /*kavsvc*/@ = "C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"
MDM /*Machine Debug Manager*/@ = "C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE"
NVSvc /*NVIDIA Display Driver Service*/@ = %SystemRoot%\System32\nvsvc32.exe
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
SecCrm /*SecCrm*/@ = "C:\Programmi\File comuni\Microsoft Shared\gRa.exe"
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\system32\wdfmgr.exe
viritsvclite /*Virit eXplorer Lite*/@ = C:\VEXPLITE\viritsvc.exe
WebrootSpySweeperService /*Sistema Webroot Spy Sweeper*/@ = "C:\Programmi\Webroot\Spy Sweeper\SpySweeper.exe"
WMDM PMSP Service /*WMDM PMSP Service*/@ = C:\WINDOWS\System32\MsPMSPSv.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@NvCplDaemon"RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup = "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
@nwiz"nwiz.exe" /install = "nwiz.exe" /install
@NvMediaCenter"RUNDLL32.EXE" C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit = "RUNDLL32.EXE" C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
@FamilyKeyLoggerC:\Programmi\FamilyKeyLogger\cisvc.exe = C:\Programmi\FamilyKeyLogger\cisvc.exe
@SunJavaUpdateSchedC:\Programmi\Java\jre1.5.0_06\bin\jusched.exe = C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
@DAEMON Tools-1033"C:\Programmi\D-Tools\daemon.exe" -lang 1033 = "C:\Programmi\D-Tools\daemon.exe" -lang 1033
@Disc DetectorC:\Programmi\Creative\ShareDLL\CtNotify.exe p ? X ? ? ? ? ? C ??? Disc Detector B ??A ? ??A ` ? ??B ??@ $?@ ? C ??? U?@ ? ??? @?B ??A ? ??A ? ? ??B ??@ P $?@ p ? ? k??w @ ? " ? ? ? ?? ??B ? ? ?????? ??B = C:\Programmi\Creative\ShareDLL\CtNotify.exe p ? X ? ? ? ? ? C ??? Disc Detector B ??A ? ??A ` ? ??B ??@ $?@ ? C ??? U?@ ? ??? @?B ??A ? ??A ? ? ??B ??@ P $?@ p ? ? k??w @ ? " ? ? ? ?? ??B ? ? ?????? ??B
@PhilipsDM"C:\Programmi\Philips\Philips Device Manager\Bin\DeviceManager.exe" = "C:\Programmi\Philips\Philips Device Manager\Bin\DeviceManager.exe"
@PinnacleDriverCheck"C:\WINDOWS\system32\PSDrvCheck.exe" -CheckReg = "C:\WINDOWS\system32\PSDrvCheck.exe" -CheckReg
@EPSON Stylus C64 Series"C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" /P23 "EPSON Stylus C64 Series" /O6 "USB001" /M "Stylus C64" = "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" /P23 "EPSON Stylus C64 Series" /O6 "USB001" /M "Stylus C64"
@KAVPersonal50"C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize = "C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
@VIRIT LITE MONITORC:\VEXPLITE\MONLITE.EXE = C:\VEXPLITE\MONLITE.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run@1 = C:\WINDOWS\svchost.exe /*file not found*/
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@IncrediMail"C:\PROGRA~1\INCRED~1\bin\IncMail.exe" /c = "C:\PROGRA~1\INCRED~1\bin\IncMail.exe" /c
@H/PC Connection Agent"C:\Programmi\Microsoft ActiveSync\WCESCOMM.EXE" = "C:\Programmi\Microsoft ActiveSync\WCESCOMM.EXE"
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\System32\nvcpl.dll = C:\WINDOWS\System32\nvcpl.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\System32\nvcpl.dll = C:\WINDOWS\System32\nvcpl.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\System32\nvshell.dll = C:\WINDOWS\System32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\System32\nvshell.dll = C:\WINDOWS\System32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\System32\nvshell.dll = C:\WINDOWS\System32\nvshell.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRAR\rarext.dll = C:\Programmi\WinRAR\rarext.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\OFFICE11\msohev.dll = C:\Programmi\Microsoft Office\OFFICE11\msohev.dll
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll = C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll
@{E0D79304-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79305-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79306-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79307-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{FED7043D-346A-414D-ACD7-550D052499A7} /*dBpowerAMP Music Converter 1*/C:\Programmi\Illustrate\dBpowerAMP\dBShell.dll = C:\Programmi\Illustrate\dBpowerAMP\dBShell.dll
@{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5} /*dBpowerAMP Music Converter*/C:\Programmi\Illustrate\dBpowerAMP\dMCShell.dll = C:\Programmi\Illustrate\dBpowerAMP\dMCShell.dll
@{73B24247-042E-4EF5-ADC2-42F62E6FD654} /*ICQ Lite Shell Extension*/C:\Programmi\ICQLite\ICQLiteShell.dll = C:\Programmi\ICQLite\ICQLiteShell.dll
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/C:\Programmi\iTunes\iTunesMiniPlayer.dll = C:\Programmi\iTunes\iTunesMiniPlayer.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\System32\extmgr.dll = C:\WINDOWS\System32\extmgr.dll
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL = C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Programmi\MSN Messenger\fsshext.8.0.0792.00.dll = C:\Programmi\MSN Messenger\fsshext.8.0.0792.00.dll
@{7C9D5882-CB4A-4090-96C8-430BFE8B795B} /*Webroot Spy Sweeper Context Menu Integration*/C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll = C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
ICQLiteMenu@{73B24247-042E-4EF5-ADC2-42F62E6FD654} = C:\Programmi\ICQLite\ICQLiteShell.dll
IMMenuShellExt@{F8984111-38B6-11D5-8725-0050DA2761C4} = C:\Programmi\IncrediMail\bin\IMShExt.dll
Kaspersky Anti-Virus@{dd230880-495a-11d1-b064-008048ec2fc5} = C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
WS_FTP@{797F3885-5429-11D4-8823-0050DA59922B} = C:\Programmi\Ipswitch\WS_FTP Professional\wsftpsi.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = C:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
ICQLiteMenu@{73B24247-042E-4EF5-ADC2-42F62E6FD654} = C:\Programmi\ICQLite\ICQLiteShell.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
Kaspersky Anti-Virus@{dd230880-495a-11d1-b064-008048ec2fc5} = C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll
SpySweeper@{7C9D5882-CB4A-4090-96C8-430BFE8B795B} = C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
WS_FTP@{797F3885-5429-11D4-8823-0050DA59922B} = C:\Programmi\Ipswitch\WS_FTP Professional\wsftpsi.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = C:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll = C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
@{6F27B670-F0CE-A282-B9B2-B653694F900D}C:\WINDOWS\cfjdh1.dll = C:\WINDOWS\cfjdh1.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
@Start
Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local PageC:\windows\system32\blank.htm = C:\windows\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start
Pagehttp://www.google.it/ =
http://www.google.it/
@Local PageC:\windows\system32\blank.htm = C:\windows\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\System32\itss.dll
livecall@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mctp@CLSID = C:\Programmi\Microsoft ActiveSync\aatp.dll
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\System32\itss.dll
ms-itss@CLSID = C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\msitss.dll
msnim@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mso-offdap@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\System32\wiascr.dll
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9DB0EE55-91E5-4E3F-823B-10E951FA5701} /*Connessione alla rete locale (LAN)*/ >>>
@IPAddress192.168.2.141 = 192.168.2.141
@NameServer193.70.192.25,193.70.152.25 = 193.70.192.25,193.70.152.25
@DefaultGateway192.168.2.1 = 192.168.2.1
@Domain =
---- EOF - GMER 1.0.10 ----
GMER 1.0.10.10122 -
http://www.gmer.net
Rootkit 2006-08-20 18:15:35
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.10 ----
SSDT 82F7F570 ZwAllocateVirtualMemory
SSDT \SystemRoot\System32\drivers\klif.sys ZwClose
SSDT 82FE43D8 ZwCreateKey
SSDT d347bus.sys ZwCreatePagingFile
SSDT \SystemRoot\System32\drivers\klif.sys ZwCreateProcess
SSDT \SystemRoot\System32\drivers\klif.sys ZwCreateProcessEx
SSDT \SystemRoot\System32\drivers\klif.sys ZwCreateSection
SSDT \SystemRoot\System32\drivers\klif.sys ZwCreateThread
SSDT 82FE4890 ZwDeleteKey
SSDT 82F9A1E8 ZwDeleteValueKey
SSDT d347bus.sys ZwEnumerateKey
SSDT d347bus.sys ZwEnumerateValueKey
SSDT kl1.sys ZwOpenFile
SSDT d347bus.sys ZwOpenKey
SSDT \SystemRoot\System32\drivers\klif.sys ZwOpenProcess
SSDT \SystemRoot\System32\drivers\klif.sys ZwQueryInformationFile
SSDT d347bus.sys ZwQueryKey
SSDT \SystemRoot\System32\drivers\klif.sys ZwQuerySystemInformation
SSDT d347bus.sys ZwQueryValueKey
SSDT 82F7F5E8 ZwQueueApcThread
SSDT 82F58990 ZwReadVirtualMemory
SSDT 82F99C50 ZwRenameKey
SSDT \SystemRoot\System32\drivers\klif.sys ZwResumeThread
SSDT 82F7FC50 ZwSetContextThread
SSDT 82F58180 ZwSetInformationKey
SSDT \SystemRoot\System32\drivers\klif.sys ZwSetInformationProcess
SSDT 82FEB8E0 ZwSetInformationThread
SSDT d347bus.sys ZwSetSystemPowerState
SSDT 82F88228 ZwSetValueKey
SSDT 82FAD100 ZwSuspendProcess
SSDT \SystemRoot\System32\drivers\klif.sys ZwSuspendThread
SSDT \SystemRoot\System32\drivers\klif.sys ZwTerminateProcess
SSDT 82FEB958 ZwTerminateThread
SSDT 82F58A08 ZwWriteVirtualMemory
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[284]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[285]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[286]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[287]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[288]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[289]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[290]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[291]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[292]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[293]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[294]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[295]
SSDT \SystemRoot\System32\drivers\klif.sys SSDT[296]
---- Devices - GMER 1.0.10 ----
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE 82C0E5C8
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE 82C0CC38
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSEIRP_MJ_READ 82D93198
Device \Driver\Tcpip \Device\Ip IRP_MJ_WRITE 82C67020
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION 82C0BF68
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION 82C17020
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA 82C0C568
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA 82C0DD30
Device \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS 82C0D538
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION 82C0CF40
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION 82C0E150
Device \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL 82C0F1F0
Device \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL 82C0EA20
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL 82C0FAB0
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL 82C0F678
Device \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN [F727DBF6] klmc.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL 829C40C8
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP 82A400C8
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT 82DF5810
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY 82918220
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY 82A460C8
Device \Driver\Tcpip \Device\Ip IRP_MJ_POWER 82A8A0C8
Device \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL 82A8D0C8
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE 82AB40C8
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA 82AA50C8
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA 82A9B0C8
Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP 82AC00C8
Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP_POWER 82AC0210
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE 82C0E5C8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE 82C0CC38
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSEIRP_MJ_READ 82D93198
Device \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE 82C67020
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION 82C0BF68
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION 82C17020
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA 82C0C568
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA 82C0DD30
Device \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS 82C0D538
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION 82C0CF40
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION 82C0E150
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL 82C0F1F0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL 82C0EA20
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL 82C0FAB0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL 82C0F678
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN [F727DBF6] klmc.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL 829C40C8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP 82A400C8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT 82DF5810
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY 82918220
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY 82A460C8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_POWER 82A8A0C8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL 82A8D0C8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE 82AB40C8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA 82AA50C8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA 82A9B0C8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP 82AC00C8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP_POWER 82AC0210
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSEIRP_MJ_READ 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 82A32008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP_POWER 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSEIRP_MJ_READ 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 82A32008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP_POWER 82A32008
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSEIRP_MJ_READ 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 82B1C0B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP_POWER 82B1C0B8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE 82B1C0B8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_NAMED_PIPE 82B1C0B8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLOSEIRP_MJ_READ 82B1C0B8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_WRITE 82B1C0B8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_INFORMATION 82B1C0B8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_INFORMATION 82B1C0B8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_EA 82B1C0B8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_EA