Pagina 1 di 2 1 2 ultimoultimo
Visualizzazione dei risultati da 1 a 10 su 20
  1. #1

    Ma porc... CHE LENTEZZA!

    Ciao ragazzi, ho da poco sostituito la scheda madre del pc, formattato e reinstallato il sistema operativo (XP PRO SP2)

    Negli ultimi giorni ho notato però dei continui rallentamenti del sistema, che è velocissimo in avvio, ma poi, dopo qualche minuto di funzionamento si perde in infiniti tempi di caricamento per programmi o anche per aprire un semplice "risorse del computer".. tempi accompagnati da un infinito lavoro del disco rigido... come se ci fossero programmi in background che mi occupano le risorse (RAM E PROCIO) del pc...

    Ho già provveduto a deframmentazioni, check del disco, scan con anti-spyware (adaware e spybot), antivirus (norton e kaperky)... non so cos'altro fare, anche la memoria virtuale è correttamente configurata (nonostante per un paio di volte mi sia apparso un messaggio del tipo:"memoria virtuale insufficiente per le applicazioni...."

    Vi posto la mia configurazione: AMD Athlon64 3000+, sk madre gigabyte nforce4 sli, 1gb RAM kingston, ATI radeon x850XT, HD IBM 60Gb+ HD IBM 80 GB, il tutto a configurazione di default senza nessun overclock.

    E un log di Hijackthis:

    Logfile of HijackThis v1.99.1
    Scan saved at 16.40.15, on 10/09/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Programmi\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\NORTON~1\navapw32.exe
    C:\Programmi\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Programmi\FuzLez\WheelsOfVolume\WheelsOfVolume. exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA EE.EXE
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
    C:\Programmi\3Com\3Com Wireless USB Utility\Wlan.exe
    C:\Programmi\Ray Adams\ATI Tray Tools\atitray.exe
    C:\Programmi\Nokia\Nokia PC Suite 6\PCSync2.exe
    C:\Programmi\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\PROGRA~1\FILECO~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Programmi\ATI Technologies\ATI.ACE\cli.exe
    C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe
    C:\WINDOWS\system32\svchost.exe
    C:\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmi\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Class - {FEF4EC70-0F07-1241-66C9-804C00DDA3CD} - C:\WINDOWS\pkdwp1.dll (file missing)
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmi\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [ATICCC] "C:\Programmi\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [stos1.exe] C:\WINDOWS\TEMP\stos1.exe
    O4 - HKLM\..\Run: [FuzLez WheelsOfVolume] "C:\Programmi\FuzLez\WheelsOfVolume\WheelsOfVolume .exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [EPSON Stylus DX4200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA EE.EXE /P26 "EPSON Stylus DX4200 Series" /O6 "USB001" /M "Stylus DX4200"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKCU\..\Run: [3COM] "C:\Programmi\3Com\3Com Wireless USB Utility\Wlan.exe"
    O4 - HKCU\..\Run: [AtiTrayTools] "C:\Programmi\Ray Adams\ATI Tray Tools\atitray.exe"
    O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PCSync2.exe /NoDialog
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmi\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: LG SyncManager.lnk = ?
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1157201743406
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Servizio Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Programmi\Norton AntiVirus\navapsvc.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Programmi\File comuni\PCSuite\Services\ServiceLayer.exe


    Qualche suggerimento? Grazie........

  2. #2
    Utente di HTML.it L'avatar di LUCASS
    Registrato dal
    May 2005
    Messaggi
    1,354
    Ciao,apri C:\ clicca con il destro Nuova>cartella
    Inserisci nella nuova cartella l'eseguibile Hijackthis.exe

    Avvia Hijackthis,clicca su "Do a system scan only"
    Metti i flags nelle caselle che corrispondono alle stringhe che ti metto sotto

    R3 - Default URLSearchHook is missing

    O2 - BHO: Class - {FEF4EC70-0F07-1241-66C9-804C00DDA3CD} - C:\WINDOWS\pkdwp1.dll (file missing)

    O4 - HKLM\..\Run: [stos1.exe] C:\WINDOWS\TEMP\stos1.exe


    Clicca sul pulsante "Fix checked" per eliminarle

    scarica questo removal tool sul desktop
    http://info.prevx.com/download.asp?grab=GROMOZONREMTOOL
    Disattiva eventuali programmi antivirus/antispyware in real time
    Avvia il tool,nota che il tool per funzionare ha bisogno di un riavvio
    (il programma ti avviserà),tu rispondi Si
    Al riavvio partirà la scansione
    Finita la scansione,il tool rilascia un rapporto in C:\gromozon_removal.log
    Per piacere posta il contenuto del file gromozon_removal.log

  3. #3
    Innanzi tutto grazie per la veloce risposta...
    Ecco il log:

    Removal tool loaded into memory
    ------------------------------------
    Executing rootkit removal engine....
    ------------------------------------
    Disabling rootkit file: \\?\C:\WINDOWS\system32\lpt8.qxp
    Resetting file permissions...
    Clearing attributes...
    Impossibile trovare il file - C:\_cleaned.tmp
    Removing file...
    Rootkit removed! Cleaning up...

    Removing temp files...
    Scanning: C:\WINDOWS
    Gromozon-Related Malicious Code Detected!
    FileName: C:\WINDOWS\pkdwp1.dll
    Removed!
    Scanning: C:\Programmi\File comuni
    Removing protected file: C:\Programmi\File comuni\Services\cvE.exe
    Removing directory: C:\Documents and Settings\\ZeHKc
    Removing protected file: C:\Programmi\File comuni\Services\FHE.exe
    Removing directory: C:\Documents and Settings\\ZeHKc
    Removing protected file: C:\Programmi\File comuni\Services\gaN.exe
    Removing directory: C:\Documents and Settings\\ZeHKc
    Removing protected file: C:\Programmi\File comuni\Services\hgp.exe
    Removing directory: C:\Documents and Settings\\ZeHKc
    Removing protected file: C:\Programmi\File comuni\Services\Kgp.exe
    Removing directory: C:\Documents and Settings\\ZeHKc
    Removing protected file: C:\Programmi\File comuni\Services\VBgj.exe
    Removing directory: C:\Documents and Settings\\ZeHKc
    Removing protected file: C:\Programmi\File comuni\Services\VTyF.exe
    Removing directory: C:\Documents and Settings\\ZeHKc
    Removing protected file: C:\Programmi\File comuni\Services\WqdBqF.exe
    Removing directory: C:\Documents and Settings\\ZeHKc


    Trojan.Gromozon Removed!

  4. #4
    Utente di HTML.it L'avatar di LUCASS
    Registrato dal
    May 2005
    Messaggi
    1,354
    Ok,facciamo un ulteriore controllo
    scarica sul desktop GMER http://www.gmer.net/gmer110.zip
    decomprimi sul desktop il file gmer.zip.
    Esegui gmer.exe
    Clicca sul Tab "Rootkit"
    Clicca su "Scan"
    finita la scansione clicca su "Copy"
    Apri il Blocco Note incolla il risultato (CTRL+V)

    Esegui gmer.exe
    Clicca sul Tab "Autostart"
    Spunta la casella "Show All"
    Clicca su "Scan"
    finita la scansione clicca su "Copy"
    Apri il Blocco Note incolla il risultato (CTRL+V)

    Copia in questa discussione entrambi i logs

  5. #5
    ora faccio la scansione.. nel frattempo norton mi sta continuamente avvisando che il file C:\WINDOWS\SYSTEM32\LPT8.QXP è infetto da trojan.LinkOptimizer....

    Impossibile rimuvere il file, l'accesso è stato negato..

  6. #6
    Utente di HTML.it L'avatar di LUCASS
    Registrato dal
    May 2005
    Messaggi
    1,354
    no problem, dopo lo disattiviamo il norton ,altrimenti da fastidio

    Ciao

  7. #7
    ok ecco i log...

    i files sono troppo lughi per essere postati, li separo in più post...



    ROOTKIT


    GMER 1.0.10.10122 - http://www.gmer.net
    Rootkit 2006-09-10 18:40:33
    Windows 5.1.2600 Service Pack 2


    ---- System - GMER 1.0.10 ----

    SSDT sptd.sys ZwCreateKey
    SSDT sptd.sys ZwEnumerateKey
    SSDT sptd.sys ZwEnumerateValueKey
    SSDT sptd.sys ZwOpenKey
    SSDT sptd.sys ZwQueryKey
    SSDT sptd.sys ZwQueryValueKey
    SSDT sptd.sys ZwSetValueKey

    ---- Devices - GMER 1.0.10 ----

    Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 8659B708
    Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 8659B0E8
    Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 8659B0E8
    Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 8659B0E8
    Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 8659B0E8
    Device \Driver\00000045 \Device\00000047 IRP_MJ_SYSTEM_CONTROL [F7416F68] sptd.sys
    Device \Driver\00000045 \Device\00000047 IRP_MJ_DEVICE_CHANGE [F742BA70] sptd.sys
    Device \Driver\00000045 \Device\00000047 IRP_MJ_PNP_POWER [F7424728] sptd.sys
    Device \Driver\USBSTOR \Device\00000070 IRP_MJ_CREATE 86271C30
    Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 8659C330
    Device \Driver\USBSTOR \Device\00000071 IRP_MJ_CREATE 86271C30
    Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 8659C330
    Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 862279E0
    Device \Driver\USBSTOR \Device\00000072 IRP_MJ_CREATE 86271C30
    Device \Driver\nvata \Device\00000065 IRP_MJ_CREATE 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_CREATE_NAMED_PIPE 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_CLOSEIRP_MJ_READ 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_WRITE 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_QUERY_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_SET_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_QUERY_EA 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_SET_EA 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_FLUSH_BUFFERS 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_QUERY_VOLUME_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_SET_VOLUME_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_DIRECTORY_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_FILE_SYSTEM_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_DEVICE_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_INTERNAL_DEVICE_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_SHUTDOWN 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_LOCK_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_CLEANUP 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_CREATE_MAILSLOT 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_QUERY_SECURITY 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_SET_SECURITY 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_POWER 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_SYSTEM_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_DEVICE_CHANGE 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_QUERY_QUOTA 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_SET_QUOTA 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_PNP 8659BC78
    Device \Driver\nvata \Device\00000065 IRP_MJ_PNP_POWER 8659BC78
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSEIRP_MJ_READ 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN

  8. #8
    8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 8627E2D0
    Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_PNP 8627E2D0
    Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 8659C330
    Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 862279E0
    Device \Driver\USBSTOR \Device\00000073 IRP_MJ_CREATE 86271C30
    Device \Driver\nvata \Device\00000066 IRP_MJ_CREATE 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_CREATE_NAMED_PIPE 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_CLOSEIRP_MJ_READ 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_WRITE 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_QUERY_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_SET_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_QUERY_EA 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_SET_EA 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_FLUSH_BUFFERS 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_QUERY_VOLUME_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_SET_VOLUME_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_DIRECTORY_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_FILE_SYSTEM_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_DEVICE_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_INTERNAL_DEVICE_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_SHUTDOWN 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_LOCK_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_CLEANUP 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_CREATE_MAILSLOT 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_QUERY_SECURITY 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_SET_SECURITY 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_POWER 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_SYSTEM_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_DEVICE_CHANGE 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_QUERY_QUOTA 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_SET_QUOTA 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_PNP 8659BC78
    Device \Driver\nvata \Device\00000066 IRP_MJ_PNP_POWER 8659BC78
    Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE 8659C330
    Device \Driver\nvata \Device\00000067 IRP_MJ_CREATE 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_CREATE_NAMED_PIPE 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_CLOSEIRP_MJ_READ 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_WRITE 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_QUERY_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_SET_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_QUERY_EA 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_SET_EA 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_FLUSH_BUFFERS 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_QUERY_VOLUME_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_SET_VOLUME_INFORMATION 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_DIRECTORY_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_FILE_SYSTEM_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_DEVICE_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_INTERNAL_DEVICE_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_SHUTDOWN 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_LOCK_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_CLEANUP 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_CREATE_MAILSLOT 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_QUERY_SECURITY 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_SET_SECURITY 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_POWER 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_SYSTEM_CONTROL 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_DEVICE_CHANGE 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_QUERY_QUOTA 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_SET_QUOTA 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_PNP 8659BC78
    Device \Driver\nvata \Device\00000067 IRP_MJ_PNP_POWER 8659BC78
    Device \Driver\Ftdisk \Device\HarddiskVolume5 IRP_MJ_CREATE 8659C330
    Device \Driver\NetBT \Device\NetBT_Tcpip_{B2E1E6B1-E8ED-4A15-85F6-8A0BEAAF62F7} IRP_MJ_CREATE 863C10E8
    Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 863C10E8
    Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 863C10E8
    Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 8659B9C0
    Device \Driver\Disk \Device\Harddisk1\DR1 IRP_MJ_CREATE 8659B9C0
    Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+a IRP_MJ_CREATE 8659B9C0
    Device \Driver\Disk \Device\Harddisk2\DR7 IRP_MJ_CREATE 8659B9C0
    Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+b IRP_MJ_CREATE 8659B9C0
    Device \Driver\Disk \Device\Harddisk3\DR8 IRP_MJ_CREATE 8659B9C0
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE_NAMED_PIPE 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_CLOSEIRP_MJ_READ 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_WRITE 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_INFORMATION

  9. #9
    8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_INFORMATION 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_EA 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_EA 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_FLUSH_BUFFERS 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_VOLUME_INFORMATION 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_VOLUME_INFORMATION 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_DIRECTORY_CONTROL 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_FILE_SYSTEM_CONTROL 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_DEVICE_CONTROL 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_SHUTDOWN 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_LOCK_CONTROL 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_CLEANUP 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE_MAILSLOT 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_SECURITY 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_SECURITY 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_POWER 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_SYSTEM_CONTROL 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_DEVICE_CHANGE 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_QUOTA 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_QUOTA 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_PNP 8659BC78
    Device \Driver\nvata \Device\NvAta0 IRP_MJ_PNP_POWER 8659BC78
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSEIRP_MJ_READ 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP_POWER 862C0D98
    Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+c IRP_MJ_CREATE 8659B9C0
    Device \Driver\Disk \Device\Harddisk4\DR9 IRP_MJ_CREATE 8659B9C0
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSEIRP_MJ_READ 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 862C0D98
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 862C0D98

  10. #10
    Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP_POWER 862C0D98
    Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 860D6350
    Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 860D6350
    Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSEIRP_MJ_READ 860D6350
    Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 860D6350
    Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 860D6350
    Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION 860D6350
    Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_EA 860D6350
    Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 8659C330
    Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE 862C50E8
    Device \Driver\dtscsi \Device\Scsi\dtscsi1Port1Path0Target0Lun0 IRP_MJ_CREATE 8625ECD8
    Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE 8625ECD8
    Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 86356498

    ---- Files - GMER 1.0.10 ----

    File C:\System Volume Information\MountPointManagerRemoteDatabase
    File C:\System Volume Information\tracking.log
    File C:\System Volume Information\_restore{7C46A53D-C215-426A-8804-408C2897E9D6}
    File D:\29ab4bf6a11fdebd30eb\sp1\spmsg.dll
    File D:\29ab4bf6a11fdebd30eb\sp1\spuninst.exe
    File D:\29ab4bf6a11fdebd30eb\sp1\update
    File D:\29ab4bf6a11fdebd30eb\sp1\update\eula.txt
    File D:\29ab4bf6a11fdebd30eb\sp1\update\spcustom.dll
    File D:\29ab4bf6a11fdebd30eb\sp1\update\update.exe
    File D:\29ab4bf6a11fdebd30eb\sp2\spmsg.dll
    File D:\29ab4bf6a11fdebd30eb\sp2\spuninst.exe
    File D:\29ab4bf6a11fdebd30eb\sp2\update
    File D:\29ab4bf6a11fdebd30eb\sp2\update\eula.txt
    File D:\29ab4bf6a11fdebd30eb\sp2\update\spcustom.dll
    File D:\29ab4bf6a11fdebd30eb\sp2\update\update.exe
    File D:\System Volume Information\MountPointManagerRemoteDatabase
    File D:\System Volume Information\tracking.log
    File D:\System Volume Information\_restore{1720F2F3-4028-4F57-9BB1-8BEFE18E8936}
    File D:\System Volume Information\_restore{36789080-5FEE-4928-926A-28F89BA0F386}
    File D:\System Volume Information\_restore{50A7CA68-03F0-42D8-9D68-655445418543}
    File D:\System Volume Information\_restore{64805253-2965-4452-9094-D507B7C9859B}
    File D:\System Volume Information\_restore{68AFD165-311E-4226-AF63-9643E17AD34A}
    File D:\System Volume Information\_restore{7C46A53D-C215-426A-8804-408C2897E9D6}
    File D:\System Volume Information\_restore{7C9050C3-714F-4B13-BA1D-16B9CD305E71}
    File D:\System Volume Information\_restore{8D7785C4-388B-4F0F-9011-FFB24BD0D156}
    File D:\System Volume Information\_restore{911DC40F-A491-4904-AF68-9D0660B580DE}
    File D:\System Volume Information\_restore{9123B653-6191-4E1D-9652-300A0357FEB4}
    File D:\System Volume Information\_restore{A7A8D407-5738-4552-B481-AF59C18353AC}
    File D:\System Volume Information\_restore{AC77AE03-CECF-4002-91B0-48034EF64F26}
    File D:\System Volume Information\_restore{B7D4A890-711A-4DAB-B372-BD1C50088775}
    File D:\System Volume Information\_restore{BC553CCB-4B7D-44B2-A69D-0873A7430039}
    File D:\System Volume Information\_restore{F162C272-DE14-495C-98DD-561E4F09B3FA}
    File E:\System Volume Information\MountPointManagerRemoteDatabase
    File E:\System Volume Information\tracking.log
    File E:\System Volume Information\_restore{68AFD165-311E-4226-AF63-9643E17AD34A}
    File E:\System Volume Information\_restore{7C46A53D-C215-426A-8804-408C2897E9D6}
    File E:\System Volume Information\_restore{911DC40F-A491-4904-AF68-9D0660B580DE}
    File E:\System Volume Information\_restore{F162C272-DE14-495C-98DD-561E4F09B3FA}
    File F:\System Volume Information\MountPointManagerRemoteDatabare
    File F:\System Volume Information\MountPointManagerRemoteDatabase
    File F:\System Volume Information\MOUNTP~1
    File F:\System Volume Information\tracking.log
    File F:\System Volume Information\_restore{50A7CA68-03F0-42D8-9D68-655445418543}
    File F:\System Volume Information\_restore{64805253-2965-4452-9094-D507B7C9859B}
    File F:\System Volume Information\_restore{68AFD165-311E-4226-AF63-9643E17AD34A}
    File F:\System Volume Information\_restore{7C46A53D-C215-426A-8804-408C2897E9D6}
    File F:\System Volume Information\_restore{911DC40F-A491-4904-AF68-9D0660B580DE}
    File F:\System Volume Information\_restore{BC553CCB-4B7D-44B2-A69D-0873A7430039}
    File F:\System Volume Information\_restore{F162C272-DE14-495C-98DD-561E4F09B3FA}
    File G:\System Volume Information\MountPointManagerRemoteDatabase
    File G:\System Volume Information\MountPointMan`gerRemoteDatabase
    File G:\System Volume Information\tracking.log
    File G:\System Volume Information\_restore{64805253-2965-4452-9094-D507B7C9859B}
    File G:\System Volume Information\_restore{68AFD165-311E-4226-AF63-9643E17AD34A}
    File G:\System Volume Information\_restore{7C46A53D-C215-426A-8804-408C2897E9D6}
    File G:\System Volume Information\_restore{911DC40F-A491-4904-AF68-9D0660B580DE}
    File G:\System Volume Information\_restore{F162C272-DE14-495C-98DD-561E4F09B3FA}

    ---- EOF - GMER 1.0.10 ----

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved.