Incollo i due log come mi ha detto Luke57.
Il primo,con rootkit:
GMER 1.0.10.10122 -
http://www.gmer.net
Rootkit 2006-09-10 20:13:18
Windows 5.1.2600 Service Pack 2
---- Devices - GMER 1.0.10 ----
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSEIRP_MJ_READ 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 86B2C4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP_POWER 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSEIRP_MJ_READ 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 86B2C4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP_POWER 86B2C4F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSEIRP_MJ_READ 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 86B71F00
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP_POWER 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_NAMED_PIPE 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLOSEIRP_MJ_READ 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_WRITE 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_EA 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_EA 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_FLUSH_BUFFERS 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_VOLUME_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_VOLUME_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DIRECTORY_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_FILE_SYSTEM_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SHUTDOWN 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_LOCK_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLEANUP 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_MAILSLOT 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_SECURITY 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_SECURITY 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_POWER 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SYSTEM_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CHANGE 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_QUOTA 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_QUOTA 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_PNP 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_PNP_POWER 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE_NAMED_PIPE 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLOSEIRP_MJ_READ 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_WRITE 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_EA 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_EA 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_FLUSH_BUFFERS 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_VOLUME_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_VOLUME_INFORMATION 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DIRECTORY_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_FILE_SYSTEM_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DEVICE_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_INTERNAL_DEVICE_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SHUTDOWN 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_LOCK_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLEANUP 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE_MAILSLOT 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_SECURITY 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_SECURITY 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_POWER 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SYSTEM_CONTROL 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DEVICE_CHANGE 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_QUOTA 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_QUOTA 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_PNP 86B71F00
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_PNP_POWER 86B71F00
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_CREATE 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_CLOSEIRP_MJ_READ 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_WRITE 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_SET_INFORMATION 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_QUERY_EA 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_SET_EA 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_SHUTDOWN 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_CLEANUP 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_SET_SECURITY 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_POWER 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_SET_QUOTA 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_PNP 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port1Path0Target0Lun0 IRP_MJ_PNP_POWER 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_CREATE 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_CREATE_NAMED_PIPE 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_CLOSEIRP_MJ_READ 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_WRITE 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_QUERY_INFORMATION 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_SET_INFORMATION 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_QUERY_EA 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_SET_EA 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_FLUSH_BUFFERS 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_QUERY_VOLUME_INFORMATION 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_SET_VOLUME_INFORMATION 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_DIRECTORY_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_FILE_SYSTEM_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_DEVICE_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_SHUTDOWN 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_LOCK_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_CLEANUP 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_CREATE_MAILSLOT 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_QUERY_SECURITY 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_SET_SECURITY 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_POWER 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_SYSTEM_CONTROL 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_DEVICE_CHANGE 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_QUERY_QUOTA 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_SET_QUOTA 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_PNP 86BF13C8
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 IRP_MJ_PNP_POWER 86BF13C8
---- Modules - GMER 1.0.10 ----
Module _________ F7384000
---- Files - GMER 1.0.10 ----
File C:\System Volume Information\MountPointManagerRemoteDatabase
File C:\System Volume Information\tracking.log
File C:\System Volume Information\_restore{D5A749AC-A504-4219-AC34-9F71BF750816}
---- EOF - GMER 1.0.10 ----
il secondo, con autostart:
GMER 1.0.10.10122 -
http://www.gmer.net
Autostart 2006-09-10 20:15:05
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui@DLLName = igfxdev.dll
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs = ,
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
AdobeActiveFileMonitor4.0 /*Adobe Active File Monitor V4*/@ = C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
EvtEng /*EvtEng*/@ = C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
MDM /*Machine Debug Manager*/@ = "C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE"
NOD32krn /*NOD32 Kernel Service*/@ = C:\Programmi\Eset\nod32krn.exe
NVSvc /*NVIDIA Display Driver Service*/@ = %SystemRoot%\system32\nvsvc32.exe
RegSrvc /*RegSrvc*/@ = C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
S24EventMonitor /*Spectrum24 Event Monitor*/@ = C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINDOWS\system32\wdfmgr.exe
VCI /*VAIO Cooporated Initialisation*/@ = C:\Programmi\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
WSCM /*Windows Service Manager*/@ = %SystemRoot%\System32\service.exe /*file not found*/
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ApointC:\Programmi\Apoint\Apoint.exe = C:\Programmi\Apoint\Apoint.exe
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
@RTHDCPLRTHDCPL.EXE = RTHDCPL.EXE
@AlcmtrALCMTR.EXE = ALCMTR.EXE
@AzMixerSelC:\Programmi\Realtek\InstallShield\AzMixerSel.exe = C:\Programmi\Realtek\InstallShield\AzMixerSel.exe
@Mouse Suite 98 DaemonICO.EXE = ICO.EXE
@IgfxTrayC:\WINDOWS\system32\igfxtray.exe = C:\WINDOWS\system32\igfxtray.exe
@HotKeysCmdsC:\WINDOWS\system32\hkcmd.exe = C:\WINDOWS\system32\hkcmd.exe
@PersistenceC:\WINDOWS\system32\igfxpers.exe = C:\WINDOWS\system32\igfxpers.exe
@ISBMgr.exeC:\Programmi\Sony\ISB Utility\ISBMgr.exe = C:\Programmi\Sony\ISB Utility\ISBMgr.exe
@PDService.exeC:\Programmi\Utimaco\SafeGuard PrivateDisk\pdservice.exe = C:\Programmi\Utimaco\SafeGuard PrivateDisk\pdservice.exe
@Acrobat Assistant 7.0"C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" = "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
@ /*file not found*/ = /*file not found*/
@SsAAD.exeC:\PROGRA~1\Sony\SONICS~1\SsAAD.exe = C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
@NeroFilterCheckC:\WINDOWS\system32\NeroCheck.exe = C:\WINDOWS\system32\NeroCheck.exe
@SunJavaUpdateSched"C:\Programmi\Java\jre1.5.0_08\bin\jusched.exe" = "C:\Programmi\Java\jre1.5.0_08\bin\jusched.exe"
@WinPatrolC:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe = C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
@nod32kuiC:\Programmi\Eset\nod32kui.exe /WAITSERVICE = C:\Programmi\Eset\nod32kui.exe /WAITSERVICE
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@CTFMON.EXEC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@MSMSGS"C:\Programmi\Messenger\msmsgs.exe" /background = "C:\Programmi\Messenger\msmsgs.exe" /background
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Pagina proprietà versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{ED58A35B-B554-42AF-A26C-6F3D424200D3} /*Sony Power Management Extensiond*/C:\Programmi\Sony\VAIO Power Management\SPMPanel.dll /*file not found*/ = C:\Programmi\Sony\VAIO Power Management\SPMPanel.dll /*file not found*/
@{F6A51CCC-6AA6-46ad-B726-97466F0A38BF} /*SafeGuard® PrivateDisk extension*/C:\Programmi\Utimaco\SafeGuard PrivateDisk\pdshell.dll = C:\Programmi\Utimaco\SafeGuard PrivateDisk\pdshell.dll
@{C6643EC0-49AC-4c15-A455-04104DB900A9} /*Image Converter context menu extension*/C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll = C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll
@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} /*Adobe.Acrobat.ContextMenu*/C:\Programmi\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll = C:\Programmi\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll = C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\OFFICE11\msohev.dll = C:\Programmi\Microsoft Office\OFFICE11\msohev.dll
@{4EB37360-49E8-11D3-95B5-004033382980} /*ALZip 4.0 Context Menu Shell Extension*/C:\Programmi\ESTsoft\ALZip\AZCTM.dll = C:\Programmi\ESTsoft\ALZip\AZCTM.dll
@{B089FE88-FB52-11d3-BDF1-0050DA34150D} /*NOD32 Context Menu Shell Extension*/C:\Programmi\Eset\nodshex.dll = C:\Programmi\Eset\nodshex.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Adobe.Acrobat.ContextMenu@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Programmi\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll
ALZip@{4EB37360-49E8-11D3-95B5-004033382980} = C:\Programmi\ESTsoft\ALZip\AZCTM.dll
ImageConverter2@{C6643EC0-49AC-4c15-A455-04104DB900A9} = C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll
NOD32 Context Menu Shell Extension@{B089FE88-FB52-11d3-BDF1-0050DA34150D} = C:\Programmi\Eset\nodshex.dll
SGPDMenu@{F6A51CCC-6AA6-46ad-B726-97466F0A38BF} = C:\Programmi\Utimaco\SafeGuard PrivateDisk\pdshell.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
ALZip@{4EB37360-49E8-11D3-95B5-004033382980} = C:\Programmi\ESTsoft\ALZip\AZCTM.dll
ImageConverter2@{C6643EC0-49AC-4c15-A455-04104DB900A9} = C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
ALZip@{4EB37360-49E8-11D3-95B5-004033382980} = C:\Programmi\ESTsoft\ALZip\AZCTM.dll
NOD32 Context Menu Shell Extension@{B089FE88-FB52-11d3-BDF1-0050DA34150D} = C:\Programmi\Eset\nodshex.dll
SGPDMenu@{F6A51CCC-6AA6-46ad-B726-97466F0A38BF} = C:\Programmi\Utimaco\SafeGuard PrivateDisk\pdshell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll = C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
@{53707962-6F74-2D53-2644-206D7942484F}C:\PROGRA~1\SPYBOT~1\SDHelper.dll = C:\PROGRA~1\SPYBOT~1\SDHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Programmi\Java\jre1.5.0_08\bin\ssv.dll = C:\Programmi\Java\jre1.5.0_08\bin\ssv.dll
@{AA58ED58-01DD-4d91-8333-CF10577473F7}c:\programmi\google\googletoolbar2.dll = c:\programmi\google\googletoolbar2.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.club-vaio.com/en/ =
http://www.club-vaio.com/en/
@Start
Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start
Pagehttp://www.google.it/ =
http://www.google.it/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
ms-itss@CLSID = C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\msitss.dll
mso-offdap@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\system32\wiascr.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = imon.dll
000000000002@PackedCatalogItem = imon.dll
000000000003@PackedCatalogItem = imon.dll
000000000004@PackedCatalogItem = imon.dll
000000000005@PackedCatalogItem = imon.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021@PackedCatalogItem = imon.dll
C:\Documents and Settings\Marialucia\Menu Avvio\Programmi\Esecuzione automatica = Stardock ObjectDock.lnk
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica >>>
Adobe Gamma Loader.lnk = Adobe Gamma Loader.lnk
Avvio veloce di Adobe Reader.lnk = Avvio veloce di Adobe Reader.lnk
---- EOF - GMER 1.0.10 ----
grazie + di mille!
aprile