|
|
|
|
Strumenti |
07-03-2009, 14:48 | #181 | |
Messaggi: n/a
|
Quote:
mi chiedevo come mai non aggiornassero in effetti |
|
22-03-2009, 13:02 | #182 |
Senior Member
Iscritto dal: Nov 2007
Città: Sicilia
Messaggi: 1643
|
Ecco il mio log, ci sono due voci che mi insospettiscono:
__________________
PC: O.S.: Microsoft Windows 10Pro - RAM: DDR3 1600Mhz PC12800 4GB G.Skill Ripjaws CL7 (2x2GB) - CPU: AMD Phenom II X4 965 3.4Ghz 4x512KB Black Edition - S.V.: ATI HD5870 XFX 1GB *** - S.M.: ASUS M4A89TD PRO/USB3 - Lettore: BD-RW LG BH10LS30 SATA - H.D.: SAMSUNG 250GB HD253GJ 7200rpm 16MB SpinPoint F3 + SAMSUNG 1TB HD103SJ 7200rpm 32MB Spinpoint F3 + NAS: QNAP 649 PRO |
22-03-2009, 13:52 | #183 |
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
Dal log non emerge nulla
__________________
Try again and you will be luckier.
|
22-03-2009, 14:48 | #184 |
Senior Member
Iscritto dal: Nov 2007
Città: Sicilia
Messaggi: 1643
|
__________________
PC: O.S.: Microsoft Windows 10Pro - RAM: DDR3 1600Mhz PC12800 4GB G.Skill Ripjaws CL7 (2x2GB) - CPU: AMD Phenom II X4 965 3.4Ghz 4x512KB Black Edition - S.V.: ATI HD5870 XFX 1GB *** - S.M.: ASUS M4A89TD PRO/USB3 - Lettore: BD-RW LG BH10LS30 SATA - H.D.: SAMSUNG 250GB HD253GJ 7200rpm 16MB SpinPoint F3 + SAMSUNG 1TB HD103SJ 7200rpm 32MB Spinpoint F3 + NAS: QNAP 649 PRO |
22-03-2009, 15:02 | #185 |
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
__________________
Try again and you will be luckier.
|
26-03-2009, 21:09 | #186 |
Senior Member
Iscritto dal: Aug 2006
Città: AS-ROMA
Messaggi: 976
|
Codice:
GMER 1.0.15.14944 - http://www.gmer.net Rootkit scan 2009-03-26 22:08:01 Windows 5.1.2600 Service Pack 3 ---- System - GMER 1.0.15 ---- SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwEnumerateKey [0x9F620E20] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwEnumerateValueKey [0x9F620E50] ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 8A6551F8 Device \Driver\Tcpip \Device\Ip OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd) Device \Driver\Tcpip \Device\Tcp OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd) Device \Driver\Tcpip \Device\Udp OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd) Device \Driver\Tcpip \Device\RawIp OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd) ---- EOF - GMER 1.0.15 ---- ragazzi io non ci capisco nulla, il vecchio gmer faceva logs lunghi 12 anni e questo qui solo ste poche righe? ho fatto tutto giusto? mi potete dire se vedete qlcosa di anomalo? grazie |
26-03-2009, 21:11 | #187 |
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
Nel Pannello di dx hai spuntato tutte le caselle?
__________________
Try again and you will be luckier.
|
26-03-2009, 21:30 | #188 |
Senior Member
Iscritto dal: Aug 2006
Città: AS-ROMA
Messaggi: 976
|
|
27-03-2009, 16:36 | #189 |
Senior Member
Iscritto dal: Aug 2006
Città: AS-ROMA
Messaggi: 976
|
posto solo ora il log, siccome durava secoli ho stoppato sulla sezione files sennò finiva domenica prossima...........righe rosse non ne ho però io so poco di gmer, me lo spiegò 3 anni fa xcdegasp ma poi non ricordo più nulla, ecco qui (l'ho messo su mediafire perchè è 47 k quindi eccede il max per gli allegati):
http://www.mediafire.com/?sharekey=2...5965eaa7bc68bc |
27-03-2009, 16:40 | #190 |
Senior Member
Iscritto dal: Aug 2006
Città: AS-ROMA
Messaggi: 976
|
ho paura di avere toppato ancora con l'invio, ragazzi è che quei tags non mi fungono cioè non so che url metterci
|
27-03-2009, 17:12 | #191 |
Senior Member
Iscritto dal: Aug 2006
Città: AS-ROMA
Messaggi: 976
|
forse così......
Codice:
GMER 1.0.15.14944 - http://www.gmer.net Rootkit scan 2009-03-27 17:20:47 Windows 5.1.2600 Service Pack 3 ---- System - GMER 1.0.15 ---- SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwAllocateVirtualMemory [0x9F9C10F0] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwAssignProcessToJobObject [0x9F9C16E0] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose [0x9FA1388E] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwConnectPort [0x9F9C0370] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0x9FA130EC] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0x9FA12DCE] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwCreatePort [0x9F9C01D0] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwCreateProcess [0x9F9BDA10] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwCreateProcessEx [0x9F9BDDE0] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0x9FA14938] SSDT BA7C9734 ZwCreateThread SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwDebugActiveProcess [0x9F9BF7B0] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwDeleteFile [0x9F9CE9C0] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0x9FA12ED8] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0x9FA12FC2] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwEnumerateKey [0x9F9CDE20] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwEnumerateValueKey [0x9F9CDE50] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0x9FA13BBC] SSDT BA7C9752 ZwLoadKey SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0x9FA133F4] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwOpenKey [0x9F9CC9A0] SSDT BA7C9720 ZwOpenProcess SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwOpenSection [0x9F9BD7A0] SSDT BA7C9725 ZwOpenThread SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwProtectVirtualMemory [0x9F9C1390] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwQueryKey [0x9F9CDDC0] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwQueryValueKey [0x9F9CDDF0] SSDT BA7C975C ZwReplaceKey SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwRequestWaitReplyPort [0x9F9C0750] SSDT BA7C9757 ZwRestoreKey SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwResumeThread [0x9F9BFE80] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSaveKey [0x9F9CDDA0] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSetContextThread [0x9F9BF5D0] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetInformationFile [0x9FA13526] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSetSystemInformation [0x9F9BF930] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0x9FA12BFC] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwShutdownSystem [0x9F9C0AC0] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSuspendProcess [0x9F9C0030] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSuspendThread [0x9F9BFCB0] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwSystemDebugControl [0x9F9BFB10] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0x9FA13B04] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwTerminateThread [0x9F9BF400] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwUnloadDriver [0x9F9C0DE0] SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0x9FA1370C] SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu Pty Ltd) ZwWriteVirtualMemory [0x9F9C1540] INT 0x62 ? 8A656BF8 INT 0x63 ? 8A45AF00 INT 0x73 ? 8A45AF00 INT 0x82 ? 8A656BF8 INT 0x83 ? 8A656BF8 ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 241C 80501C54 12 Bytes [D0, 01, 9C, 9F, 10, DA, 9B, ...] {ROL BYTE [ECX], 0x1; PUSHF ; LAHF ; ADC DL, BL; WAIT ; LAHF ; LOOPNZ 0xffffffffffffffe7; WAIT ; LAHF } .text ntkrnlpa.exe!ZwCallbackReturn + 245C 80501C94 8 Bytes JMP AF28BC35 .text ntkrnlpa.exe!ZwCallbackReturn + 2758 80501F90 12 Bytes [30, 00, 9C, 9F, B0, FC, 9B, ...] {XOR [EAX], AL; PUSHF ; LAHF ; MOV AL, 0xfc; WAIT ; LAHF ; ADC BL, BH; WAIT ; LAHF } ? sphk.sys Impossibile trovare il file specificato. ! .text USBPORT.SYS!DllUnload B92068AC 5 Bytes JMP 8A45A4E0 .text a2yj8q0e.SYS B4849384 1 Byte [20] .text a2yj8q0e.SYS B4849384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...] .text a2yj8q0e.SYS B48493AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...] .text a2yj8q0e.SYS B48493C4 3 Bytes [00, 00, 00] .text a2yj8q0e.SYS B48493C9 1 Byte [00] .text ... ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\CTsvcCDA.exe[208] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Spyware Terminator\SpywareTerminator.exe[216] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 018C0001 .text C:\Programmi\Spyware Terminator\SpywareTerminator.exe[216] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A .text C:\Programmi\Spyware Terminator\SpywareTerminator.exe[216] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A .text C:\Programmi\Spyware Terminator\SpywareTerminator.exe[216] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Spyware Terminator\SpywareTerminator.exe[216] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A .text C:\Programmi\Spyware Terminator\SpywareTerminator.exe[216] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A .text C:\Programmi\Spyware Terminator\SpywareTerminator.exe[216] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A .text C:\Programmi\Creative\Shared Files\CTDevSrv.exe[252] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Java\jre6\bin\jqs.exe[348] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\WINDOWS\system32\HPZipm12.exe[384] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\WINDOWS\system32\svchost.exe[440] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Tall Emu\Online Armor\oacat.exe[580] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00780001 .text C:\Programmi\Tall Emu\Online Armor\oacat.exe[580] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Tall Emu\Online Armor\oacat.exe[580] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0B001E .text C:\Programmi\Tall Emu\Online Armor\oacat.exe[580] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F05001E .text C:\WINDOWS\system32\csrss.exe[608] KERNEL32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\Programmi\Ashampoo\Ashampoo UnInstaller Platinum 2\UIWatcher.exe[632] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00CC0001 .text C:\Programmi\Ashampoo\Ashampoo UnInstaller Platinum 2\UIWatcher.exe[632] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A .text C:\Programmi\Ashampoo\Ashampoo UnInstaller Platinum 2\UIWatcher.exe[632] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A .text C:\Programmi\Ashampoo\Ashampoo UnInstaller Platinum 2\UIWatcher.exe[632] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Ashampoo\Ashampoo UnInstaller Platinum 2\UIWatcher.exe[632] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A .text C:\Programmi\Ashampoo\Ashampoo UnInstaller Platinum 2\UIWatcher.exe[632] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A .text C:\Programmi\Ashampoo\Ashampoo UnInstaller Platinum 2\UIWatcher.exe[632] user32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A .text C:\Programmi\CyberLink\Shared Files\RichVideo.exe[664] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\WINDOWS\system32\winlogon.exe[808] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\WINDOWS\system32\services.exe[864] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\WINDOWS\system32\lsass.exe[876] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\WINDOWS\system32\Ati2evxx.exe[1068] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text ... .text C:\WINDOWS\Explorer.EXE[1252] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D80001 .text C:\WINDOWS\Explorer.EXE[1252] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A .text C:\WINDOWS\Explorer.EXE[1252] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\Explorer.EXE[1252] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\WINDOWS\Explorer.EXE[1252] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\Explorer.EXE[1252] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A .text C:\WINDOWS\Explorer.EXE[1252] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A .text C:\Programmi\Spyware Terminator\sp_rsser.exe[1320] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\WINDOWS\System32\svchost.exe[1328] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\Programmi\Tall Emu\Online Armor\oasrv.exe[1536] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BE0001 .text C:\Programmi\Tall Emu\Online Armor\oasrv.exe[1536] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0B001E .text C:\Programmi\Tall Emu\Online Armor\oasrv.exe[1536] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F05001E .text C:\WINDOWS\system32\spoolsv.exe[1760] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\WINDOWS\system32\svchost.exe[1860] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\Programmi\a-squared Anti-Dialer\a2service.exe[1952] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\Programmi\a-squared Anti-Malware\a2service.exe[1972] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text C:\Programmi\a-squared Free\a2service.exe[2008] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 716F003D .text ... .text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[2736] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003F0001 .text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[2736] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F11001E .text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[2736] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0E001E .text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[2736] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[2736] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0B001E .text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[2736] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F05001E .text C:\Programmi\Tall Emu\Online Armor\oahlp.exe[2736] user32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F14001E .text C:\Programmi\Tall Emu\Online Armor\oaui.exe[3184] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01460001 .text C:\Programmi\Tall Emu\Online Armor\oaui.exe[3184] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Tall Emu\Online Armor\oaui.exe[3184] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0B001E .text C:\Programmi\Tall Emu\Online Armor\oaui.exe[3184] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F05001E .text C:\Documents and Settings\Paolo\Desktop\gmer e pavark\5zojzz1h.exe[3196] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00B90001 .text C:\Documents and Settings\Paolo\Desktop\gmer e pavark\5zojzz1h.exe[3196] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A .text C:\Documents and Settings\Paolo\Desktop\gmer e pavark\5zojzz1h.exe[3196] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A .text C:\Documents and Settings\Paolo\Desktop\gmer e pavark\5zojzz1h.exe[3196] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Documents and Settings\Paolo\Desktop\gmer e pavark\5zojzz1h.exe[3196] user32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A .text C:\Documents and Settings\Paolo\Desktop\gmer e pavark\5zojzz1h.exe[3196] user32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A .text C:\Documents and Settings\Paolo\Desktop\gmer e pavark\5zojzz1h.exe[3196] user32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\rundll32.exe[3352] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00BE0001 .text C:\WINDOWS\system32\rundll32.exe[3352] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\rundll32.exe[3352] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\rundll32.exe[3352] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\WINDOWS\system32\rundll32.exe[3352] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\rundll32.exe[3352] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\rundll32.exe[3352] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\wuauclt.exe[3496] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe[3568] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00CF0001 .text C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe[3568] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A .text C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe[3568] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A .text C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe[3568] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe[3568] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A .text C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe[3568] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A .text C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe[3568] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A .text C:\Programmi\Java\jre6\bin\jusched.exe[3668] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D40001 .text C:\Programmi\Java\jre6\bin\jusched.exe[3668] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A .text C:\Programmi\Java\jre6\bin\jusched.exe[3668] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A .text C:\Programmi\Java\jre6\bin\jusched.exe[3668] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Java\jre6\bin\jusched.exe[3668] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A .text C:\Programmi\Java\jre6\bin\jusched.exe[3668] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A .text C:\Programmi\Java\jre6\bin\jusched.exe[3668] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A .text C:\Programmi\Avira\AntiVir Desktop\avgnt.exe[3812] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00CB0001 .text C:\Programmi\Avira\AntiVir Desktop\avgnt.exe[3812] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A .text C:\Programmi\Avira\AntiVir Desktop\avgnt.exe[3812] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A .text C:\Programmi\Avira\AntiVir Desktop\avgnt.exe[3812] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Avira\AntiVir Desktop\avgnt.exe[3812] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A .text C:\Programmi\Avira\AntiVir Desktop\avgnt.exe[3812] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A .text C:\Programmi\Avira\AntiVir Desktop\avgnt.exe[3812] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A .text C:\WINDOWS\system32\ctfmon.exe[3932] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AF0001 .text C:\WINDOWS\system32\ctfmon.exe[3932] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A .text C:\WINDOWS\system32\ctfmon.exe[3932] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A .text C:\WINDOWS\system32\ctfmon.exe[3932] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\WINDOWS\system32\ctfmon.exe[3932] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A .text C:\WINDOWS\system32\ctfmon.exe[3932] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A .text C:\WINDOWS\system32\ctfmon.exe[3932] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01480001 .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F100F5A .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F0D0F5A .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!LoadResource 7C80A045 7 Bytes JMP 28001CC0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!FindResourceExW 7C80AD18 7 Bytes JMP 28001B00 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!FindResourceW 7C80BC5E 7 Bytes JMP 28001A80 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!SizeofResource 7C80BCF9 7 Bytes JMP 28001D80 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!FindResourceA 7C80BF19 7 Bytes JMP 28001B90 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!LockResource 7C80CD27 5 Bytes JMP 28001DF0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!CreateEventA 7C83089D 5 Bytes JMP 28001840 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!FindResourceExA 7C835F90 7 Bytes JMP 28001C20 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 5 Bytes JMP 0056DBBD C:\Programmi\Windows Live\Messenger\msnmsgr.exe (Windows Live Messenger/Microsoft Corporation) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] kernel32.dll!OutputDebugStringW 7C85B335 5 Bytes JMP 28001E50 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] ADVAPI32.dll!CryptDeriveKey 77F59FDD 7 Bytes JMP 28001000 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] ADVAPI32.dll!CryptDecrypt 77F5A109 7 Bytes JMP 28001060 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!PeekMessageW 7E39929B 5 Bytes JMP 28004090 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!LoadStringW 7E399E36 6 Bytes JMP 5F0A0F5A .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!SetWindowPlacement 7E39DE46 5 Bytes JMP 28005840 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!CreateDialogParamW 7E39EA3B 5 Bytes JMP 28005AC0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!LoadImageW 7E3A7B97 5 Bytes JMP 280060C0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!LoadStringA 7E3AC908 6 Bytes JMP 5F040F5A .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!CreateWindowExW 7E3AD0A3 5 Bytes JMP 28003820 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!SetWindowRgn 7E3AE528 7 Bytes JMP 28005980 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!LoadIconW 7E3AE8BC 5 Bytes JMP 280062B0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F130F5A .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!MessageBoxIndirectW 7E3E64D5 5 Bytes JMP 28005CB0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] USER32.dll!TrackPopupMenuEx 7E3ECF62 5 Bytes JMP 28004970 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] WS2_32.dll!closesocket 71A33E2B 5 Bytes JMP 2800A5A0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] WS2_32.dll!send 71A34C27 2 Bytes JMP 2800A180 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] WS2_32.dll!send + 3 71A34C2A 2 Bytes [5D, B6] .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] WS2_32.dll!WSARecv 71A34CB5 5 Bytes JMP 28009F60 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] WS2_32.dll!recv 71A3676F 5 Bytes JMP 28009DC0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] WS2_32.dll!WSASend 71A368FA 5 Bytes JMP 2800A360 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] SHELL32.dll!Shell_NotifyIconW 7CA3A5BF 5 Bytes JMP 28002FE0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] ole32.dll!CoInitializeEx 774CEF7B 5 Bytes JMP 28002100 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] ole32.dll!CoRegisterClassObject 774E7E90 5 Bytes JMP 28002200 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] WININET.dll!HttpOpenRequestA 630187BC 5 Bytes JMP 28008BE0 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] WININET.dll!InternetReadFile 6301AC9D 5 Bytes JMP 28008D70 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] WININET.dll!InternetCloseHandle 63020A61 5 Bytes JMP 28008F20 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) .text C:\Programmi\Windows Live\Messenger\msnmsgr.exe[4088] WININET.dll!HttpSendRequestA 6302E822 5 Bytes JMP 28008E50 C:\Programmi\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EAC040] sphk.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EAC13C] sphk.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EAC0BE] sphk.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EAC7FC] sphk.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EAC6D2] sphk.sys IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!KfAcquireSpinLock] 00000034 IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!READ_PORT_UCHAR] 0000008E IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!KeGetCurrentIrql] 00000043 IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!KfRaiseIrql] 00000044 IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!KfLowerIrql] 000000C4 IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!HalGetInterruptVector] 000000DE IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!HalTranslateBusAddress] 000000E9 IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!KeStallExecutionProcessor] 000000CB IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!KfReleaseSpinLock] 00000054 IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 0000007B IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!READ_PORT_USHORT] 00000094 IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000032 IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[HAL.dll!WRITE_PORT_UCHAR] 000000A6 IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[WMILIB.SYS!WmiSystemControl] 00000023 IAT \SystemRoot\System32\Drivers\a2yj8q0e.SYS[WMILIB.SYS!WmiCompleteRequest] 0000003D IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [B47CC3B0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd) IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [B47CC410] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd) IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [B47CC6C0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd) IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [B47CC700] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd) IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [B47CC6C0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd) IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [B47CC410] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd) IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [B47CC3B0] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 8A6551F8 Device \Driver\Tcpip \Device\Ip OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd) Device \Driver\NetBT \Device\NetBT_Tcpip_{F834E5B1-835A-4400-BA48-29E4999FF12A} 8983B1F8 Device \Driver\usbohci \Device\USBPDO-0 8A461500 Device \Driver\usbohci \Device\USBPDO-1 8A461500 Device \Driver\usbehci \Device\USBPDO-2 8A46C1F8 Device \Driver\Tcpip \Device\Tcp OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd) Device \Driver\Ftdisk \Device\HarddiskVolume1 8A6571F8 Device \Driver\Cdrom \Device\CdRom0 8A45B500 Device \Driver\Ftdisk \Device\HarddiskVolume2 8A6571F8 Device \Driver\Cdrom \Device\CdRom1 8A45B500 Device \Driver\Cdrom \Device\CdRom2 8A45B500 Device \Driver\Cdrom \Device\CdRom3 8A45B500 Device \Driver\NetBT \Device\NetBt_Wins_Export 8983B1F8 Device \Driver\sptd \Device\329099768 sphk.sys Device \Driver\NetBT \Device\NetbiosSmb 8983B1F8 Device \Driver\PCI_PNP4768 \Device\0000004c sphk.sys Device \Driver\Tcpip \Device\Udp OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd) Device \Driver\Tcpip \Device\RawIp OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd) Device \Driver\NetBT \Device\NetBT_Tcpip_{F97A2930-1297-4039-B664-AEB4B7E08634} 8983B1F8 Device \Driver\usbohci \Device\USBFDO-0 8A461500 Device \Driver\usbohci \Device\USBFDO-1 8A461500 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 897131F8 Device \Driver\Tcpip \Device\IPMULTICAST OAmon.sys (TDI Helper Driver/Tall Emu Pty Ltd) Device \Driver\usbehci \Device\USBFDO-2 8A46C1F8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 897131F8 Device \Driver\Ftdisk \Device\FtControl 8A6571F8 Device \Driver\a2yj8q0e \Device\Scsi\a2yj8q0e1Port2Path0Target1Lun0 8A2E2500 Device \Driver\a2yj8q0e \Device\Scsi\a2yj8q0e1Port2Path0Target0Lun0 8A2E2500 Device \Driver\a2yj8q0e \Device\Scsi\a2yj8q0e1 8A2E2500 Device \FileSystem\Cdfs \Cdfs 8A3821F8 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmi\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x92 0x04 0xA1 0x3C ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3F 0xF9 0x17 0x22 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x06 0x07 0x04 0xA3 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x1A 0xDD 0xD5 0x0C ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmi\DAEMON Tools\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x92 0x04 0xA1 0x3C ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x42 0x8D 0x91 0xF8 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEB 0xF8 0xEE 0xF9 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x7A 0x40 0x18 0xF2 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x1A 0xDD 0xD5 0x0C ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmi\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x92 0x04 0xA1 0x3C ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3F 0xF9 0x17 0x22 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x06 0x07 0x04 0xA3 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x1A 0xDD 0xD5 0x0C ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmi\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x92 0x04 0xA1 0x3C ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x42 0x8D 0x91 0xF8 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEB 0xF8 0xEE 0xF9 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x7A 0x40 0x18 0xF2 ... |
27-03-2009, 17:21 | #192 |
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
Così http://www.hwupgrade.it/forum/showpo...&postcount=190 andava benissimo, comunque non risulta nulla
__________________
Try again and you will be luckier.
|
27-03-2009, 19:20 | #193 | |
Senior Member
Iscritto dal: Aug 2006
Città: AS-ROMA
Messaggi: 976
|
Quote:
|
|
28-03-2009, 21:36 | #194 |
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
__________________
Try again and you will be luckier.
|
31-03-2009, 14:28 | #195 |
Senior Member
Iscritto dal: Feb 2009
Messaggi: 481
|
|
31-03-2009, 14:36 | #196 | |
Bannato
Iscritto dal: Nov 2008
Messaggi: 446
|
Quote:
ciao |
|
02-04-2009, 19:00 | #197 |
Senior Member
Iscritto dal: Feb 2009
Messaggi: 481
|
no...non succede niente...è come se fosse un'immagine...
|
29-04-2009, 22:53 | #198 |
Senior Member
Iscritto dal: Apr 2008
Messaggi: 1279
|
Disponibile la versione 1.0.15.14972 di GMER: buona analisi a Tutti
__________________
So di non sapere (cit.)... | Dichiarazione d'Amore | Usi creativi dell'ASUS Eee PC | Configurazione di Sicurezza e Note su Tor per MS Windows | Mail Provider: i più sicuri? | |
01-05-2009, 10:39 | #199 |
Senior Member
Iscritto dal: Jan 2009
Messaggi: 566
|
buongiorno a tutti..oggi gmer non ne vuole sapere di effettuare una scansione:
se lancio la scansione con i sw di sicurezza attivi (avira, online armor, prevx), smette di funzionare, disattivando o.a. o avira smette lo stesso di funzionare, disattivando prevx schermata blu e al riavvio questo messaggio.idee in proposito? |
01-05-2009, 10:48 | #200 |
Senior Member
Iscritto dal: Jan 2009
Messaggi: 566
|
altra parte della schermata di errore
|
Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 16:21.