qualcuno mi aiuta?
GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-21 21:58:56
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT Vax347b.sys ZwClose
SSDT Vax347b.sys ZwCreateKey
SSDT Vax347b.sys ZwCreatePagingFile
SSDT Vax347b.sys ZwEnumerateKey
SSDT Vax347b.sys ZwEnumerateValueKey
SSDT Vax347b.sys ZwOpenKey
SSDT Vax347b.sys ZwQueryKey
SSDT Vax347b.sys ZwQueryValueKey
SSDT Vax347b.sys ZwSetSystemPowerState
---- User code sections - GMER 1.0.12 ----
.text C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE[152] WS2_32.dll!connect 71A3406A 5 Bytes JMP 00E73E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Programmi\iTunes\iTunesHelper.exe[192] WS2_32.dll!connect 71A3406A 5 Bytes JMP 00FC3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Programmi\McAfee.com\VSO\oasclnt.exe[204] WS2_32.dll!connect 71A3406A 5 Bytes JMP 00C53E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSOEMON.EXE[224] WS2_32.dll!connect 71A3406A 5 Bytes JMP 008F3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\WINDOWS\SYSTEM32\CTFMON.EXE[244] WS2_32.dll!connect 71A3406A 5 Bytes JMP 10003E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text ...
.text H:\gmer.exe[3880] WS2_32.dll!connect 71A3406A 5 Bytes JMP 010A3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 86783378
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 86106860
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 862024B8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 862024B8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 86736298
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 862024B8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 862024B8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 86202BD0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_NAMED_PIPE 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLOSE 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_READ 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_WRITE 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_EA 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_EA 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_FLUSH_BUFFERS 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_VOLUME_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_VOLUME_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DIRECTORY_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_FILE_SYSTEM_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SHUTDOWN 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_LOCK_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLEANUP 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_MAILSLOT 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_SECURITY 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_SECURITY 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_POWER 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SYSTEM_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CHANGE 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_QUOTA 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_QUOTA 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_PNP 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 86202BD0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE_NAMED_PIPE 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLOSE 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_READ 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_WRITE 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_EA 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_EA 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_FLUSH_BUFFERS 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_VOLUME_INFORMATION 86202BD0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_VOLUME_INFORMATION