GMER 1.0.14.14205 -
http://www.gmer.netRootkit scan 2008-03-13 20:05:41
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT \SystemRoot\system32\drivers\pctmp.sys (Memory Monitor Driver/PCTools Research Pty Ltd.) ZwAllocateVirtualMemory [0xF77D2EEC]
SSDT \SystemRoot\system32\drivers\pctmp.sys (Memory Monitor Driver/PCTools Research Pty Ltd.) ZwProtectVirtualMemory [0xF77D327E]
SSDT \SystemRoot\system32\drivers\pctmp.sys (Memory Monitor Driver/PCTools Research Pty Ltd.) ZwSetValueKey [0xF77D398A]
---- User code sections - GMER 1.0.14 ----
.text C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe[236] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe[236] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe[236] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\Programmi\Java\jre1.6.0_02\bin\jusched.exe[236] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\windows\system\hpsysdrv.exe[252] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 00EF200E
.text C:\windows\system\hpsysdrv.exe[252] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 00EF1DAF
.text C:\windows\system\hpsysdrv.exe[252] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 00EF1CF2
.text C:\windows\system\hpsysdrv.exe[252] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 00EF191B
.text C:\Programmi\ASUS\ASUS Remote\RemoteControlAppl.exe[304] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 00F3200E
.text C:\Programmi\ASUS\ASUS Remote\RemoteControlAppl.exe[304] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 00F31DAF
.text C:\Programmi\ASUS\ASUS Remote\RemoteControlAppl.exe[304] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 00F31CF2
.text C:\Programmi\ASUS\ASUS Remote\RemoteControlAppl.exe[304] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 00F3191B
.text C:\WINDOWS\system32\rundll32.exe[336] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 00CF200E
.text C:\WINDOWS\system32\rundll32.exe[336] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 00CF1DAF
.text C:\WINDOWS\system32\rundll32.exe[336] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 00CF1CF2
.text C:\WINDOWS\system32\rundll32.exe[336] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 00CF191B
.text C:\WINDOWS\system32\rundll32.exe[336] USER32.dll!DialogBoxParamW 7E3A555F 5 Bytes JMP 00D11050 C:\Programmi\Common Files\Sitecom Shared\PnP Universal Installer\signhook.dll
.text C:\WINDOWS\system32\rundll32.exe[336] USER32.dll!DialogBoxParamA 7E3BB10C 5 Bytes JMP 00D11000 C:\Programmi\Common Files\Sitecom Shared\PnP Universal Installer\signhook.dll
.text C:\WINDOWS\system32\ps2.exe[344] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 00A0200E
.text C:\WINDOWS\system32\ps2.exe[344] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 00A01DAF
.text C:\WINDOWS\system32\ps2.exe[344] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 00A01CF2
.text C:\WINDOWS\system32\ps2.exe[344] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 00A0191B
.text C:\Programmi\File comuni\Real\Update_OB\realsched.exe[352] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 0103200E
.text C:\Programmi\File comuni\Real\Update_OB\realsched.exe[352] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 01031DAF
.text C:\Programmi\File comuni\Real\Update_OB\realsched.exe[352] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 01031CF2
.text C:\Programmi\File comuni\Real\Update_OB\realsched.exe[352] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 0103191B
.text C:\Programmi\Windows Defender\MSASCui.exe[388] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 017B200E
.text C:\Programmi\Windows Defender\MSASCui.exe[388] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 017B1DAF
.text C:\Programmi\Windows Defender\MSASCui.exe[388] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 017B1CF2
.text C:\Programmi\Windows Defender\MSASCui.exe[388] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 017B191B
.text C:\Programmi\PC Tools Firewall Plus\FirewallGUI.exe[396] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 010E200E
.text C:\Programmi\PC Tools Firewall Plus\FirewallGUI.exe[396] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 010E1DAF
.text C:\Programmi\PC Tools Firewall Plus\FirewallGUI.exe[396] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 010E1CF2
.text C:\Programmi\PC Tools Firewall Plus\FirewallGUI.exe[396] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 010E191B
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[408] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 0178200E
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[408] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 01781DAF
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[408] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 01781CF2
.text C:\PROGRA~1\Grisoft\AVG7\avgcc.exe[408] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 0178191B
.text C:\WINDOWS\system32\ctfmon.exe[464] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\ctfmon.exe[464] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\ctfmon.exe[464] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\ctfmon.exe[464] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[476] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 012A200E
.text C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[476] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 012A1DAF
.text C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[476] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 012A1CF2
.text C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[476] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 012A191B
.text C:\documents and settings\compaq_proprietario\impostazioni locali\dati applicazioni\mpmwxd.exe[484] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 01E6200E
.text C:\documents and settings\compaq_proprietario\impostazioni locali\dati applicazioni\mpmwxd.exe[484] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 01E61DAF
.text C:\documents and settings\compaq_proprietario\impostazioni locali\dati applicazioni\mpmwxd.exe[484] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 01E61CF2
.text C:\documents and settings\compaq_proprietario\impostazioni locali\dati applicazioni\mpmwxd.exe[484] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 01E6191B
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[732] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[732] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[732] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe[732] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\csrss.exe[740] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\csrss.exe[740] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\csrss.exe[740] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\csrss.exe[740] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[784] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[784] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[784] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe[784] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\services.exe[808] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\services.exe[808] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\services.exe[808] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\services.exe[808] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[824] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 011B200E
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[824] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 011B1DAF
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[824] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 011B1CF2
.text C:\PROGRA~1\Grisoft\AVG7\avgemc.exe[824] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 011B191B
.text C:\WINDOWS\system32\svchost.exe[972] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[972] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[972] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[972] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\Programmi\PC Tools Firewall Plus\FWService.exe[1032] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 0204200E
.text C:\Programmi\PC Tools Firewall Plus\FWService.exe[1032] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 02041DAF
.text C:\Programmi\PC Tools Firewall Plus\FWService.exe[1032] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 02041CF2
.text C:\Programmi\PC Tools Firewall Plus\FWService.exe[1032] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 0204191B
.text C:\Programmi\Common Files\Sitecom Shared\PnP Universal Installer\DevNotifySvc.exe[1136] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 00A7200E
.text C:\Programmi\Common Files\Sitecom Shared\PnP Universal Installer\DevNotifySvc.exe[1136] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 00A71DAF
.text C:\Programmi\Common Files\Sitecom Shared\PnP Universal Installer\DevNotifySvc.exe[1136] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 00A71CF2
.text C:\Programmi\Common Files\Sitecom Shared\PnP Universal Installer\DevNotifySvc.exe[1136] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 00A7191B
.text C:\Programmi\Windows Defender\MsMpEng.exe[1200] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\Programmi\Windows Defender\MsMpEng.exe[1200] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\Programmi\Windows Defender\MsMpEng.exe[1200] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\Programmi\Windows Defender\MsMpEng.exe[1200] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\System32\svchost.exe[1240] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\System32\svchost.exe[1240] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\System32\svchost.exe[1240] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\System32\svchost.exe[1240] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\nvsvc32.exe[1300] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 008F200E
.text C:\WINDOWS\system32\nvsvc32.exe[1300] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 008F1DAF
.text C:\WINDOWS\system32\nvsvc32.exe[1300] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 008F1CF2
.text C:\WINDOWS\system32\nvsvc32.exe[1300] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 008F191B
.text C:\WINDOWS\system32\wuauclt.exe[1412] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 00CE200E
.text C:\WINDOWS\system32\wuauclt.exe[1412] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 00CE1DAF
.text C:\WINDOWS\system32\wuauclt.exe[1412] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 00CE1CF2
.text C:\WINDOWS\system32\wuauclt.exe[1412] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 00CE191B
.text C:\WINDOWS\system32\svchost.exe[1668] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\svchost.exe[1668] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\svchost.exe[1668] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\svchost.exe[1668] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\Explorer.EXE[1864] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 020C200E
.text C:\WINDOWS\Explorer.EXE[1864] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 020C1DAF
.text C:\WINDOWS\Explorer.EXE[1864] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 020C1CF2
.text C:\WINDOWS\Explorer.EXE[1864] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 020C191B
.text C:\WINDOWS\system32\spoolsv.exe[1900] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\spoolsv.exe[1900] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\spoolsv.exe[1900] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\spoolsv.exe[1900] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
.text C:\Programmi\7-Zip\7zFM.exe[3640] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 00E6200E
.text C:\Programmi\7-Zip\7zFM.exe[3640] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 00E61DAF
.text C:\Programmi\7-Zip\7zFM.exe[3640] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 00E61CF2
.text C:\Programmi\7-Zip\7zFM.exe[3640] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 00E6191B
.text C:\DOCUME~1\COMPAQ~1\IMPOST~1\Temp\7zO1.tmp\gmer.exe[3672] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 00EA200E
.text C:\DOCUME~1\COMPAQ~1\IMPOST~1\Temp\7zO1.tmp\gmer.exe[3672] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 00EA1DAF
.text C:\DOCUME~1\COMPAQ~1\IMPOST~1\Temp\7zO1.tmp\gmer.exe[3672] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 00EA1CF2
.text C:\DOCUME~1\COMPAQ~1\IMPOST~1\Temp\7zO1.tmp\gmer.exe[3672] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 00EA191B
.text C:\WINDOWS\system32\wuauclt.exe[3724] ntdll.dll!NtEnumerateKey 7C91D94C 5 Bytes JMP 1000200E
.text C:\WINDOWS\system32\wuauclt.exe[3724] ntdll.dll!NtEnumerateValueKey 7C91D976 5 Bytes JMP 10001DAF
.text C:\WINDOWS\system32\wuauclt.exe[3724] ntdll.dll!NtQueryDirectoryFile 7C91DF5E 5 Bytes JMP 10001CF2
.text C:\WINDOWS\system32\wuauclt.exe[3724] ntdll.dll!NtQuerySystemInformation 7C91E1AA 5 Bytes JMP 1000191B
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Ip pctfw2.sys (PC Tools TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\pctfw2 \Device\PcaTcpFilter avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp pctfw2.sys (PC Tools TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp pctfw2.sys (PC Tools TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp pctfw2.sys (PC Tools TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\pctfw2 \Device\PCTFWPL avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\pctfw2 \Device\PcaRawIpFilter avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\pctfw2 \Device\PcaUdpFilter avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\pctfw2 \Device\PCTFW2 avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)
---- Processes - GMER 1.0.14 ----
Process C:\documents and settings\compaq_proprietario\impostazioni locali\dati applicazioni\mpmwxd.exe (*** hidden *** ) 484
Library C:\documents and settings\compaq_proprietario\impostazioni locali\dati applicazioni\mpmwxd.exe (*** hidden *** ) @ C:\documents and settings\compaq_proprietario\impostazioni locali\dati applicazioni\mpmwxd.exe [484] 0x00400000
---- Registry - GMER 1.0.14 ----
Reg HKLM\SOFTWARE\Classes\Software\BigFishGames\MahjongTowersII\author@forfun\3 Wiepie
Reg HKLM\SOFTWARE\Classes\Software\BigFishGames\MahjongTowersII\Boards@forfun\3 0,0,0,0,0,0,0,65536,0,698368,0,698368,0,8192,0,0,0,0,0,0,0,0,0,0,0,65536,0,698368,0,698368,0,8192,0,0,0,0,0,0,0,0,0,0,0,65536,0,698368,0,698368,0,8192,0,0,0,0,0,0,0,0,0,0,0,8388736,0,8388736,0,8388736,0,8388736,0,0,0,0,0,0,0,0,0,0,0,8388736,0,8388736,0,8388736,0,8388736,0,0,0,0,0,0,35652128,0,68158480,0,134744072,0,134744072,0,134744072,0,134744072,0,134744072,0,68157968,0,0,0,0,20971840,0,20971840,0,35652128,0,35652128,0,20971840,0,20971840,0,35651872,0,35651872,0,0,0,18874656,0,18874656,0,34603536,0,34603536,0,18874656,0,18874656,0,34603536,0,34603536,0,0,0,17826064,0,17826064,0,34079240,0,34079240,0,17826064,0,17826064,0,34079240,0,34079240
Reg HKLM\SOFTWARE\Classes\Software\BigFishGames\MahjongTowersII\Descriptions@forfun\3 NA
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@mpmwxd c:\documents and settings\compaq_proprietario\impostazioni locali\dati applicazioni\mpmwxd.exe mpmwxd
---- Files - GMER 1.0.14 ----
File C:\Documents and Settings\Compaq_Proprietario\Impostazioni locali\Dati applicazioni\mpmwxd.dat 4945 bytes
File C:\Documents and Settings\Compaq_Proprietario\Impostazioni locali\Dati applicazioni\mpmwxd.exe 364544 bytes
File C:\Documents and Settings\Compaq_Proprietario\Impostazioni locali\Dati applicazioni\mpmwxd_nav.dat 396721 bytes
File C:\Documents and Settings\Compaq_Proprietario\Impostazioni locali\Dati applicazioni\mpmwxd_navps.dat 806 bytes
---- EOF - GMER 1.0.14 ----
SCUSA P2 SCUSA è che sono molto ignorante in materia e non so come fare a riportarti solo quei file in rosso!!!!