PDA

View Full Version : problema con msn, media player, installazione applicazioni


Mailandre
21-10-2007, 18:43
ciao a tutti..
da un paio d giorni ho questi problemi..
msn logga e dopo 2 secondi si chiude da solo..
media player ha deciso di non aprirsi proprio..
in installazioni applicazioni la metà dei miei programmi è scomparsa e molti di quelli presenti non hanno il tasto cambia/rimuovi.. vabbè..
premetto ke ho appena rimosso il virus bagle ke non mi lasciava connettere con la rete senza fili..

vi posto il log d hjackthis..

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17.12.02, on 21/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
C:\Programmi\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\mdm.exe
D:\Software\3Ds Max\mentalray\satellite\raysat_3dsmax8server.exe
C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
D:\Software\Alcohol 120\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Symantec AntiVirus\Rtvscan.exe
C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ICO.EXE
C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe
C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
C:\Programmi\Sony\ISB Utility\ISBMgr.exe
C:\Programmi\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Programmi\Microsoft IntelliPoint\point32.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Programmi\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmi\Mozilla Firefox\firefox.exe
D:\Software\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 131.175.12.65:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Programmi\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Software\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Programmi\Google AFE\GoogleAFE.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Programmi\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [Apoint] C:\Programmi\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Programmi\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [Switcher.exe] C:\Programmi\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmi\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe
O4 - HKLM\..\Run: [euaio] C:\Documents and Settings\Andrea\Dati applicazioni\fareracito\sysvmrst.exe
O4 - HKLM\..\Run: [LClock] C:\Programmi\LClock\LClock.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SpeedOptimizer] D:\Software\DAP\SPEEDO~1\SPO.EXE -s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [VAIO Update 3] "C:\Programmi\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Ritaglio schermata e avvio di OneNote 2007.lnk = C:\Programmi\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: www.archivio.name
O15 - Trusted Zone: www.playitalia.com
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mailandrex.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {76A2A0AB-38B7-46DB-8E47-F10CDE4D7920} - http://www.cartografia.regione.lombardia.it/include/ecwplugins/ncs.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E85362EF-40D4-4E5D-BE07-D6B036CCA277} (GoPets Control) - https://secure.gopetslive.com/dev/gopets.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programmi\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - D:\Software\3Ds Max\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programmi\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Software\Alcohol 120\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programmi\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Programmi\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VideoAcceleratorEngine - Unknown owner - D:\Software\DAP\SPEEDB~1\VideoAcceleratorEngine.exe (file missing)
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

--
End of file - 15359 bytes

grazie a tutti

juninho85
21-10-2007, 19:04
fai analizare questo file
C:\WINDOWS\msnlogm.exe
qui (http://www.virustotal.com)

Mailandre
21-10-2007, 19:57
cavolo.. sai ke nn lo trovo dentro C:\windows.. w in + nn ho neanke la possibilità di cercarlo perchè la funzione cerca non va..

Gle89
21-10-2007, 20:01
cavolo.. sai ke nn lo trovo dentro C:\windows.. w in + nn ho neanke la possibilità di cercarlo perchè la funzione cerca non va..

Devi abilitare la visualizzazione dei file e cartelle nascoste. fai cosi:
RISORSE DEL PC- STRUMENTI -OPZIONI CARTELLA - VISUALIZZAZIONE e metti VISUALIZZA file o cartelel nascosti.

poi cercalo e fallo analizzare e dicci cosa ha rilevato! ti aspettiamo

Poi procediamo con pulizia...

Mailandre
21-10-2007, 20:11
si infatti quell'opzione era già abilitata.. mm.. sto pensando ke forse non lo trovo x' poco dopo la scansione hjack ho rimosso dal registro tutto ciò ke aveva a ke fare cn msn.. ora riavvio e vedo ke succede..

Gle89
21-10-2007, 20:15
si infatti quell'opzione era già abilitata.. mm.. sto pensando ke forse non lo trovo x' poco dopo la scansione hjack ho rimosso dal registro tutto ciò ke aveva a ke fare cn msn.. ora riavvio e vedo ke succede..

posta un nuovo log di HJT qui e vediamo, possibilmente con più programmi chiusi :D

Mailandre
21-10-2007, 20:26
ok.. ho fatto un nuovo scan.. cmq dopo il riavvio niente di nuovo..
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20.25.13, on 21/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
C:\Programmi\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\mdm.exe
D:\Software\3Ds Max\mentalray\satellite\raysat_3dsmax8server.exe
C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
D:\Software\Alcohol 120\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Symantec AntiVirus\Rtvscan.exe
C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
D:\SOFTWARE\VEXPLITE\viritsvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\ICO.EXE
C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe
C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
C:\Programmi\Sony\ISB Utility\ISBMgr.exe
C:\Programmi\Microsoft IntelliPoint\point32.exe
C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Programmi\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\System32\svchost.exe
D:\Software\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 131.175.12.65:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Programmi\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Software\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Programmi\Google AFE\GoogleAFE.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Programmi\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [Apoint] C:\Programmi\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Programmi\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [Switcher.exe] C:\Programmi\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmi\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [msnsyslog] C:\WINDOWS\msnlogm.exe
O4 - HKLM\..\Run: [LClock] C:\Programmi\LClock\LClock.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SpeedOptimizer] D:\Software\DAP\SPEEDO~1\SPO.EXE -s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [VAIO Update 3] "C:\Programmi\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [VIRIT LITE MONITOR] D:\SOFTWARE\VEXPLITE\MONLITE.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Ritaglio schermata e avvio di OneNote 2007.lnk = C:\Programmi\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: www.archivio.name
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mailandrex.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {76A2A0AB-38B7-46DB-8E47-F10CDE4D7920} - http://www.cartografia.regione.lombardia.it/include/ecwplugins/ncs.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E85362EF-40D4-4E5D-BE07-D6B036CCA277} (GoPets Control) - https://secure.gopetslive.com/dev/gopets.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programmi\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - D:\Software\3Ds Max\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programmi\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Software\Alcohol 120\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programmi\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Programmi\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VideoAcceleratorEngine - Unknown owner - D:\Software\DAP\SPEEDB~1\VideoAcceleratorEngine.exe (file missing)
O23 - Service: Virit eXplorer Lite (viritsvclite) - TG Soft Sas www.tgsoft.it - D:\SOFTWARE\VEXPLITE\viritsvc.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

--
End of file - 15184 bytes

juninho85
21-10-2007, 20:31
il recchione si rigenera
apri un thread qui (http://www.hwupgrade.it/forum/forumdisplay.php?f=125) dove spieghi il problema,postaci anche un log di gmer e findawf

Gle89
21-10-2007, 20:33
Se lo hai attivo, disabilita il ripristino di configurazione di sistema (start –
programmi – accessori – utilità di sistema – ripristino di configurazione di sistema).
Ora apri di nuovo HiJackThis con la seconda opzione “do a system scan” e seleziona le voci che ti riporterò qui sotto, mettendo il segno di spunta verde alla sinistra di ogni voce. Alla fine premi “Fix Checked”in fondo e dai la conferma. Chiudi pure HiJackThis.

Ecco le voci:

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpeedOptimizer] D:\Software\DAP\SPEEDO~1\SPO.EXE -s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmi\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Ritaglio schermata e avvio di OneNote 2007.lnk = C:\Programmi\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O15 - Trusted Zone: www.archivio.name
O16 - DPF: {E85362EF-40D4-4E5D-BE07-D6B036CCA277} (GoPets Control) - https://secure.gopetslive.com/dev/gopets.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
[quote]

ora esegui questi tool:

CCLEANER: clicca qui per il download (http://download.piriform.com/ccsetup141.exe)
una volta installato, lancia il programma, nel menu di sinistra portati alla voce Opzioni e nella finestra successiva clicca su:
● Impostazioni, e spunta la voce Cancellazione sicura (lenta)
poi su:
● Avanzate, togli la spunta alla voce Cancella solo file più vecchi di 48 ore
● alla voce Pulizia, spunta tutte le quelle comprese nella sezione Avanzate
● nel menu a sinistra, clicca sulla voce Pulizia, clicca su tasto Avvia Pulizia per eseguire la scansione
● sempre nel menu a sinistra, clicca sulla voce Problemi, clicca sul tasto Trova problemi ed avvia una scansione; al termine della scansione clicca sulla voce Ripara selezionati e prosegui

ASQUARED FREE: clicca qui per il download (http://download5.emsisoft.com/a2FreeSetup.exe)
una volta installato, scarica gli aggiornamenti e poi, esegui una scansione del sistema in modalità Deep Scan e rimuovi tutto ciò che viene rilevato con esclusione dei riferimenti a Software, MIrc, fotocamere digitali e/o scanner eventualmente installati.

PREVX CSI: clicca qui per il download (http://info.prevx.com/download.asp?grab=prevxcsi)
una volta installato, esegui una scansione

Aggiorna ACROBAT READER alla versione 8 (puoi trovarlo facilmente da google)

Alla fine di tutto questo dicci se ci sono sviluppi e quali.

P.S. :conosci questi link? li frequenti?
[quote]
www.archivio.name
*.sony-europe.com
*.sonystyle-europe.com
*.vaio-link.com

Gle89
21-10-2007, 20:34
il recchione si rigenera
apri un thread qui (http://www.hwupgrade.it/forum/forumdisplay.php?f=125) dove spieghi il problema,postaci anche un log di gmer e findawf

PErchè deve aprire un nuovo thread in aiuto sono infetto? :O

Mailandre
21-10-2007, 20:35
okok adesso faccio tutto.. grazie mille x l'aiuto cmq ripristino sistema è sempre stato disabilitato
ah volevo dire a juninho85 ke nn ho capito dove devo postare.. mi si apre la pagina del forum di aiuto sono infetto..

Mailandre
21-10-2007, 20:36
ah.. x i 3 link.. si li conosco.. sn dei link per il mio computer.. un vaio appunto.. cmq nn li visito mai..

Gle89
21-10-2007, 20:37
okok adesso faccio tutto.. grazie mille x l'aiuto cmq ripristino sistema è sempre stato disabilitato
ah volevo dire a juninho85 ke nn ho capito dove devo postare.. mi si apre la pagina del forum di aiuto sono infetto..

Infatti non capisco nemmeno io perchè ti vuole far postare di nuovo nella stessa sezione... forse si è sbagliato! Fai le cose consigliate sia da me che da lui :D

Mailandre
21-10-2007, 20:47
ho scaricato gmer ma nn ho capito cm fare ad utilizzarlo.. intanto sta andando ccleaner.. uff.. che casino.. spero di risolvere questa cosa..

Gle89
21-10-2007, 20:49
ho scaricato gmer ma nn ho capito cm fare ad utilizzarlo.. intanto sta andando ccleaner.. uff.. che casino.. spero di risolvere questa cosa..

con calma riuscirai a venirne fuori, intanto esegui le mie istruzioni, poi juninho85 ti spiegherà le sue :D

Mailandre
21-10-2007, 20:49
ok.. ccleaner ha cancellato 828mb di roba inutile.. benebene

juninho85
21-10-2007, 21:32
PErchè deve aprire un nuovo thread in aiuto sono infetto? :O

il problema pare che non si risolva con la semplice voce di hjt da fixare

xcdegasp
21-10-2007, 22:46
ok.. ccleaner ha cancellato 828mb di roba inutile.. benebene

dai una passata con msnfix -> http://sosvirus.changelog.fr/MSNFix.zip

e poi con a-squared-free -> http://download5.emsisoft.com/a2FreeSetup.exe
per la guida nelle impostazioni -> http://www.hwupgrade.it/forum/showthread.php?t=1564958

Mailandre
22-10-2007, 10:05
allora.. x adesso ho fatto tutto quello ke mi ha consigliato gle89..
ccleaner ha cancellato un bel po' di roba..
asquared mi ha rilevato una decina di cose sospette e le ho eliminate mentre prex csi ha detto ke sn pulito..

questo è il report di asquared:
a-squared Free - Version 3.0
Last update: 21/10/2007 20.55.15

Impostazioni scansione:

Oggetti: Memoria, Tracce, Cookies, C:\, D:\
Archivio scansioni: On
Scientifico: On
ADS Scan: On

Scansione avviata: 22/10/2007 0.07.36

c:\programmi\file comuni\totem shared rilevati: Trace.Directory.ISTbar
C:\Documents and Settings\LocalService\Dati applicazioni\Mozilla\Firefox\Profiles\aaqor9m9.default\cookies.txt:85 rilevati: Trace.TrackingCookie
C:\Documents and Settings\LocalService\Dati applicazioni\Mozilla\Firefox\Profiles\aaqor9m9.default\cookies.txt:99 rilevati: Trace.TrackingCookie
C:\Programmi\Yahoo!\Yahoo! Widget Engine\UnixUtils\usr\local\wbin\sleep.exe rilevati: Email-Worm.Win32.Runouce.b
C:\WINDOWS\Installer\{5783F2D7-5001-0410-0002-0060B0CE6BBA}\Acad162_icon.exe rilevati: Trojan-Clicker.Win32.Agent.jl
C:\WINDOWS\system32\closeapp.exe rilevati: Riskware.RiskTool.Win32.CloseApp.a
D:\Games\The Sims 2 Family Fun Stuff\TSBin\Sims2SP1.exe rilevati: Heuristic.Dialer.RAS
D:\Games\The Sims 2 Funky Business\TSBin\Sims2EP3.exe rilevati: Heuristic.Dialer.RAS
D:\Games\The Sims 2 Nightlife\TSBin\Sims2EP2.exe rilevati: Heuristic.Dialer.RAS
D:\Games\The Sims 2 Pets\TSBin\Sims2EP4.exe rilevati: Heuristic.Dialer.RAS

Scansionati

Files: 269765
Tracce: 335332
Cookies: 117
Processi: 52

Rilevato

Files: 7
Tracce: 1
Cookies: 2
Processi: 0
Chiavi registro: 0

Fine scansione: 22/10/2007 1.52.46
Tempo scansione: 1.45.10

C:\WINDOWS\system32\closeapp.exe Cancellato Riskware.RiskTool.Win32.CloseApp.a
C:\WINDOWS\Installer\{5783F2D7-5001-0410-0002-0060B0CE6BBA}\Acad162_icon.exe Cancellato Trojan-Clicker.Win32.Agent.jl
C:\Programmi\Yahoo!\Yahoo! Widget Engine\UnixUtils\usr\local\wbin\sleep.exe Cancellato Email-Worm.Win32.Runouce.b
C:\Documents and Settings\LocalService\Dati applicazioni\Mozilla\Firefox\Profiles\aaqor9m9.default\cookies.txt:85 Cancellato Trace.TrackingCookie
C:\Documents and Settings\LocalService\Dati applicazioni\Mozilla\Firefox\Profiles\aaqor9m9.default\cookies.txt:99 Cancellato Trace.TrackingCookie
c:\programmi\file comuni\totem shared Cancellato Trace.Directory.ISTbar

Cancellato

Files: 3
Tracce: 1
Cookies: 2

D:\Games\The Sims 2 Family Fun Stuff\TSBin\Sims2SP1.exe In quarantena Heuristic.Dialer.RAS
D:\Games\The Sims 2 Funky Business\TSBin\Sims2EP3.exe In quarantena Heuristic.Dialer.RAS
D:\Games\The Sims 2 Nightlife\TSBin\Sims2EP2.exe In quarantena Heuristic.Dialer.RAS
D:\Games\The Sims 2 Pets\TSBin\Sims2EP4.exe In quarantena Heuristic.Dialer.RAS

In quarantena

Files: 4
Tracce: 0
Cookies: 0

ora riavvio e vedo cosa succede.. in caso faccio anke tutto il resto.. eheh
GRAZIE A TUTTI PER L'AIUTO

Mailandre
22-10-2007, 10:36
boh..
spero di avere fatto giusto lo scan cn gmer.. il file log mi viene kilometrico.. mmm.. bhè io ve lo posto..

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-10-22 10:35:29
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.13 ----

SSDT 86F54438 ZwAlertResumeThread
SSDT 86EE9708 ZwAlertThread
SSDT 86C20EB0 ZwAllocateVirtualMemory
SSDT Vax347b.sys ZwClose
SSDT 86D2C240 ZwConnectPort
SSDT Vax347b.sys ZwCreateKey
SSDT 86F474E8 ZwCreateMutant
SSDT Vax347b.sys ZwCreatePagingFile
SSDT 86DBBDE0 ZwCreateThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteValueKey
SSDT Vax347b.sys ZwEnumerateKey
SSDT Vax347b.sys ZwEnumerateValueKey
SSDT 86E0BC90 ZwFreeVirtualMemory
SSDT 86CB2168 ZwImpersonateAnonymousToken
SSDT 86DEA1D8 ZwImpersonateThread
SSDT 86C3F1A8 ZwMapViewOfSection
SSDT 86DEA440 ZwOpenEvent
SSDT Vax347b.sys ZwOpenKey
SSDT 86DA5E20 ZwOpenProcessToken
SSDT 86C36E78 ZwOpenThreadToken
SSDT Vax347b.sys ZwQueryKey
SSDT 86DFC3A0 ZwQueryValueKey
SSDT 86DD4818 ZwResumeThread
SSDT 86C2CE78 ZwSetContextThread
SSDT 86CE9F48 ZwSetInformationProcess
SSDT 86CD1768 ZwSetInformationThread
SSDT Vax347b.sys ZwSetSystemPowerState
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwSetValueKey
SSDT 86DFBC90 ZwSuspendProcess
SSDT 86BE26F8 ZwSuspendThread
SSDT 86DAE8E8 ZwTerminateProcess
SSDT 86DD9EA8 ZwTerminateThread
SSDT 86C17108 ZwUnmapViewOfSection
SSDT 86C8D450 ZwWriteVirtualMemory

---- User IAT/EAT - GMER 1.0.13 ----

IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [018C7376] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL
IAT C:\Programmi\Mozilla Firefox\firefox.exe[1616] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [018C73CC] C:\Programmi\Mozilla Firefox\extensions\[email protected]\components\FULLSOFT.DLL

---- Devices - GMER 1.0.13 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 86F7D918

AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F73DD1DE] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F73DD1DE] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F73DD454] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F73DD1DE] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F73D0F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F46D08A0] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F46D0900] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F46D0810] SYMEVENT.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F46D0810] SYMEVENT.SYS

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 8441B898

AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_READ [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_WRITE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_POWER [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_READ [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_POWER [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA [F444EC60] SYMTDI.SYS

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 86BCB910
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 86BCB910
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 86E46480
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 86BCB910
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 86BCB910
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_NAMED_PIPE 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_READ 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_WRITE 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_EA 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_EA 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FLUSH_BUFFERS 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_VOLUME_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_VOLUME_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DIRECTORY_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FILE_SYSTEM_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SHUTDOWN 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_LOCK_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLEANUP 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_MAILSLOT 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_SECURITY 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_SECURITY 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CHANGE 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_QUOTA 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_QUOTA 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE_NAMED_PIPE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLOSE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_READ 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_WRITE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_EA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_EA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_FLUSH_BUFFERS 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_VOLUME_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_VOLUME_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DIRECTORY_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_FILE_SYSTEM_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_INTERNAL_DEVICE_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SHUTDOWN 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_LOCK_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLEANUP 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE_MAILSLOT 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_SECURITY 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_SECURITY 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_POWER 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SYSTEM_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CHANGE 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_QUOTA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_QUOTA 86BDE250
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_PNP 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CREATE 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CREATE_NAMED_PIPE 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CLOSE 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_READ 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_WRITE 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_QUERY_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SET_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_QUERY_EA 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SET_EA 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_FLUSH_BUFFERS 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_QUERY_VOLUME_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SET_VOLUME_INFORMATION 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_DIRECTORY_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_FILE_SYSTEM_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_DEVICE_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_INTERNAL_DEVICE_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SHUTDOWN 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_LOCK_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CLEANUP 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CREATE_MAILSLOT 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_QUERY_SECURITY 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SET_SECURITY 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_POWER 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SYSTEM_CONTROL 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_DEVICE_CHANGE 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_QUERY_QUOTA 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SET_QUOTA 86BDE250
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_PNP 86BDE250
Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 845245E0

AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_READ [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_WRITE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_POWER [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_READ [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_POWER [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA [F444EC60] SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA [F444EC60] SYMTDI.SYS

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 86DFAA78
Device \Device\LanmanRedirector IRP_MJ_CREATE [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_CLOSE [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_READ 86DFAA78
Device \Device\LanmanRedirector IRP_MJ_WRITE [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_SET_INFORMATION [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_QUERY_EA [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_SET_EA [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_SHUTDOWN [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_CLEANUP [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_SET_SECURITY [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_POWER [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_SET_QUOTA [F4255189] mrxsmb.sys
Device \Device\LanmanRedirector IRP_MJ_PNP [F4255189] mrxsmb.sys
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 86BF1CE0
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 86C6F5D8
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_CREATE 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_CREATE_NAMED_PIPE 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_CLOSE 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_READ 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_WRITE 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_QUERY_INFORMATION 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_SET_INFORMATION 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_QUERY_EA 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_SET_EA 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_FLUSH_BUFFERS 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_QUERY_VOLUME_INFORMATION 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_SET_VOLUME_INFORMATION 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_DIRECTORY_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_FILE_SYSTEM_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_DEVICE_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_SHUTDOWN 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_LOCK_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_CLEANUP 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_CREATE_MAILSLOT 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_QUERY_SECURITY 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_SET_SECURITY 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_POWER 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_SYSTEM_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_DEVICE_CHANGE 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_QUERY_QUOTA 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_SET_QUOTA 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1 IRP_MJ_PNP 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_CREATE 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_CLOSE 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_READ 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_WRITE 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_SET_INFORMATION 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_QUERY_EA 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_SET_EA 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_SHUTDOWN 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_CLEANUP 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_SET_SECURITY 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_POWER 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_SET_QUOTA 86CB8008
Device \Driver\Vax347s \Device\Scsi\Vax347s1Port3Path0Target0Lun0 IRP_MJ_PNP 86CB8008
Device \Fat IRP_MJ_CREATE [B9DB9C8A] Fastfat.SYS
Device \Fat IRP_MJ_CLOSE [B9DB67C8] Fastfat.SYS
Device \Fat IRP_MJ_READ 8441B898
Device \Fat IRP_MJ_WRITE [B9DB2AED] Fastfat.SYS
Device \Fat IRP_MJ_QUERY_INFORMATION [B9DBD958] Fastfat.SYS
Device \Fat IRP_MJ_SET_INFORMATION [B9DC0821] Fastfat.SYS
Device \Fat IRP_MJ_QUERY_EA [B9DC938A] Fastfat.SYS
Device \Fat IRP_MJ_SET_EA [B9DC8D49] Fastfat.SYS
Device \Fat IRP_MJ_FLUSH_BUFFERS [B9DC2BBE] Fastfat.SYS
Device \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [B9DC3331] Fastfat.SYS
Device \Fat IRP_MJ_SET_VOLUME_INFORMATION [B9DD14F4] Fastfat.SYS
Device \Fat IRP_MJ_DIRECTORY_CONTROL [B9DB9B37] Fastfat.SYS
Device \Fat IRP_MJ_FILE_SYSTEM_CONTROL [B9DB5948] Fastfat.SYS
Device \Fat IRP_MJ_DEVICE_CONTROL [B9DBF46B] Fastfat.SYS
Device \Fat IRP_MJ_SHUTDOWN [B9DD079D] Fastfat.SYS
Device \Fat IRP_MJ_LOCK_CONTROL [B9DCFC4A] Fastfat.SYS
Device \Fat IRP_MJ_CLEANUP [B9DB62FD] Fastfat.SYS
Device \Fat IRP_MJ_PNP [B9DD01DB] Fastfat.SYS
Device \Fat FastIoCheckIfPossible [B9DCB1F9] Fastfat.SYS
Device \Fat FastIoQueryBasicInfo [B9DBA646] Fastfat.SYS
Device \Fat FastIoQueryStandardInfo [B9DBA405] Fastfat.SYS
Device \Fat FastIoLock [B9DC09F3] Fastfat.SYS
Device \Fat FastIoUnlockSingle [B9DC3518] Fastfat.SYS
Device \Fat FastIoUnlockAll [B9DCF929] Fastfat.SYS
Device \Fat FastIoUnlockAllByKey [B9DCFA21] Fastfat.SYS
Device \Fat FastIoQueryNetworkOpenInfo [B9DCB28E] Fastfat.SYS
Device \Fat AcquireForCcFlush [B9DD04A6] Fastfat.SYS
Device \Fat ReleaseForCcFlush [B9DD051F] Fastfat.SYS

AttachedDevice \Fat IRP_MJ_CREATE [F73DD1DE] fltMgr.sys
AttachedDevice \Fat IRP_MJ_CREATE_NAMED_PIPE [F73DD1DE] fltMgr.sys
AttachedDevice \Fat IRP_MJ_CLOSE [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_READ [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_WRITE [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_QUERY_INFORMATION [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_SET_INFORMATION [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_QUERY_EA [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_SET_EA [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_FLUSH_BUFFERS [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_SET_VOLUME_INFORMATION [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_DIRECTORY_CONTROL [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_FILE_SYSTEM_CONTROL [F73DD454] fltMgr.sys
AttachedDevice \Fat IRP_MJ_DEVICE_CONTROL [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_SHUTDOWN [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_LOCK_CONTROL [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_CLEANUP [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_CREATE_MAILSLOT [F73DD1DE] fltMgr.sys
AttachedDevice \Fat IRP_MJ_QUERY_SECURITY [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_SET_SECURITY [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_POWER [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_SYSTEM_CONTROL [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_DEVICE_CHANGE [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_QUERY_QUOTA [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_SET_QUOTA [F73D0F4C] fltMgr.sys
AttachedDevice \Fat IRP_MJ_CREATE [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_CREATE_NAMED_PIPE [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_CLOSE [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_READ [F46D08A0] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_WRITE [F46D0900] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_QUERY_INFORMATION [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_SET_INFORMATION [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_QUERY_EA [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_SET_EA [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_FLUSH_BUFFERS [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_SET_VOLUME_INFORMATION [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_DIRECTORY_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_FILE_SYSTEM_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_DEVICE_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_SHUTDOWN [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_LOCK_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_CLEANUP [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_CREATE_MAILSLOT [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_QUERY_SECURITY [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_SET_SECURITY [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_POWER [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_SYSTEM_CONTROL [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_DEVICE_CHANGE [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_QUERY_QUOTA [F46D0810] SYMEVENT.SYS
AttachedDevice \Fat IRP_MJ_SET_QUOTA [F46D0810] SYMEVENT.SYS

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 86FD6B68
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 86FD6B68
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_READ 86FD6B68
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_READ 86FD6B68
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_READ 86FD6B68
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 86E0EAD0

---- Modules - GMER 1.0.13 ----

Module _________ F7416000-F742E000 (98304 bytes)

---- EOF - GMER 1.0.13 ----

Mailandre
22-10-2007, 10:43
e questo è msnfix

MSNFix 1.552

C:\Documents and Settings\Andrea\Documenti\Download\MSNFix\MSNFix
Fix effettuato il 22/10/2007 - 10.37.37,54 By Andrea
modalità normale

************************ Cercare i files presenti

... C:\Documents and Settings\Andrea\Dati applicazioni\addon.dat
... C:\WINDOWS\msnimport.exe

************************ MSNCHK ***** /!\ beta test /!\



************************ Ricerca le cartelle presenti

... C:\Temp\




************************ Eliminazione dei files

.. OK ... C:\Documents and Settings\Andrea\Dati applicazioni\addon.dat
.. OK ... C:\WINDOWS\msnimport.exe


************************ Eliminazione delle cartelle

.. OK ... C:\Temp\


************************ Pulizia del Registro



************************ Files sospetti

Nessun files trovato


I files e le chiavi di registro eliminati sono stati salvati nel file 22102007_10.42.3696.zip


------------------------------------------------------------------------
Auteur : !aur3n7 Contact: http://changelog.fr
------------------------------------------------------------------------

--------------------------------------------- END ---------------------------------------------

Mailandre
22-10-2007, 11:33
piccolo update:
ho installato msn 8.5 beta e funziona senza problemi.. nn so se perchè ho rimosso qualke virus o x' l'ha deciso lui.. inoltre è stato installato automaticamente windows live desktop che ha la funzione cerca.. quindi x quello nn c'è + problema.. mi rimane solo media player ke nn funzia e il problema di installazione applicazioni.. solo ke volevo provare a disintallare media player e installare una diversa versione ma nn riesco..

juninho85
22-10-2007, 11:45
media player non lo puoi disinstallare,aggiornalo semmai

Mailandre
22-10-2007, 14:11
è già aggiornato all'ultimissima versione..
volevo provare ad installare il 10.. un modo per farlo ci sarà di sicuro..

juninho85
22-10-2007, 15:50
hai già la 11?

xcdegasp
22-10-2007, 16:15
piccolo update:
ho installato msn 8.5 beta e funziona senza problemi.. nn so se perchè ho rimosso qualke virus o x' l'ha deciso lui.. inoltre è stato installato automaticamente windows live desktop che ha la funzione cerca.. quindi x quello nn c'è + problema.. mi rimane solo media player ke nn funzia e il problema di installazione applicazioni.. solo ke volevo provare a disintallare media player e installare una diversa versione ma nn riesco..

io proverai anche a visionare i software compatibili alla rete msn, tipo trillian, miranda, pidgin,...

Mailandre
22-10-2007, 16:24
si ho la versione 11 di media player.. e volevo dire ke pidgin l'avevo installato quando non funzionava + msn ed andava perfettamente..

Mailandre
22-10-2007, 17:17
ah.. ecco cosa volevo dire ke nn mi ricordavo..
ho dei problemi con emule.. nel senso ke si connette ma quando vaod su ricerca c mette mezz'ora prima d trovarmi i file.. e non mi è mai successo..

Mailandre
22-10-2007, 17:34
questo è un nuovo log di hjack..
cmq mi è anke venuto in mente ke dopo aver rimosso zone alarm e kasper ke avevo usato per fare la scansione virus, media player funzionava.. cioè prima non funzionava.. poi rimossi funzionava.. e adesso non va +.. strano no^

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17.30.26, on 22/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
d:\software\a-squared Free\a2service.exe
C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
C:\Programmi\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\mdm.exe
D:\Software\3Ds Max\mentalray\satellite\raysat_3dsmax8server.exe
C:\Programmi\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
D:\Software\Alcohol 120\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Symantec AntiVirus\Rtvscan.exe
C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ICO.EXE
C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe
C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Programmi\Sony\ISB Utility\ISBMgr.exe
C:\Programmi\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Programmi\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\WISPTIS.EXE
D:\Software\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 131.175.12.65:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Programmi\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Software\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Programmi\Google AFE\GoogleAFE.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Programmi\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [Apoint] C:\Programmi\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Programmi\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Programmi\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Programmi\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [Switcher.exe] C:\Programmi\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmi\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [VAIO Update 3] "C:\Programmi\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [ccApp] "C:\Programmi\File comuni\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Programmi\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mailandrex.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-UNO1/GAME_UNO1.cab
O16 - DPF: {76A2A0AB-38B7-46DB-8E47-F10CDE4D7920} - http://www.cartografia.regione.lombardia.it/include/ecwplugins/ncs.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - d:\software\a-squared Free\a2service.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Programmi\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programmi\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - D:\Software\3Ds Max\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programmi\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmi\File comuni\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Software\Alcohol 120\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programmi\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Programmi\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Programmi\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Programmi\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VideoAcceleratorEngine - Unknown owner - D:\Software\DAP\SPEEDB~1\VideoAcceleratorEngine.exe (file missing)
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Programmi\File comuni\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Programmi\Windows Live\installer\WLSetupSvc.exe

--
End of file - 13504 bytes

Gle89
22-10-2007, 18:08
Il log è pulito, perchè lo hai postato pure nel 3d Ufficiale di HJT?:eek:

Mailandre
22-10-2007, 18:14
mi han detto d postarlo anke lì.. vabbè..
ma allora a questo punto cosa devo fare media player ke nn funziona?? mi scoccia perchè non mi vanno gli streaming..

Gle89
22-10-2007, 18:19
mi han detto d postarlo anke lì.. vabbè..
ma allora a questo punto cosa devo fare media player ke nn funziona?? mi scoccia perchè non mi vanno gli streaming..

Disinstalla da pannello di controllo (installazioni/applicazioni) Media Player da MOD PROVVISORIA.

Rientra in modalità NORMALE e verifica se la versione 10 funziona. Se funziona riscarica la 11 e installa!

Mailandre
22-10-2007, 18:35
ho già provato.. il problema è ke da installazione applicazioni dico rimuovi e lui dice ke ristabilisce la versione precedente.. in verità rimane la 11.. ho anche provato a vedere se avevo un punto di ripristino ma quando apro mi rimane tutto bianco..

Mailandre
22-10-2007, 20:00
ok.. ho sistemato tutto e va tutto alla perfezione.. ho reinstallato media player ed ora funziona.. poi ho scaricato un aggiornamento per il pc e tutto va a meraviglia.. grazie a tutti della disponibilità dimostrata e scusate per la mia ingenuità in merito alla questione..
ciaooo

Gle89
22-10-2007, 20:38
Felice che tu abbia risolto!:D