Ciao Luke, allora ecco i risultati di virit:
VirIT eXplorer Lite Log
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK
--------------------------------------------------------
04/03/2007 - 15:24:01
[SCANSIONE DEL REGISTRO]
OK
[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
C:\Documents and Settings\Alberto\Impostazioni locali\Temp\RarSFX1\catchme.exe Possibile variante da Trojan.SoundMx
C:\Documents and Settings\Alberto\Impostazioni locali\Temp\RarSFX0\catchme.exe Possibile variante da Trojan.SoundMx
C:\Documents and Settings\Alberto\Impostazioni locali\Temp\RarSFX2\catchme.exe Possibile variante da Trojan.SoundMx
Chiavi Registro infette: 0.
Files Infetti: 3.
Files Sospetti: 0.
Files Analizzati: 58521.
Files Totali: 58521.
Chiavi Registro rimosse: 0.
Virus Rimossi: 0.
[SCANSIONE DELLA MEMORIA]
OK
--------------------------------------------------------
Ecco il log in modalità provvisoria:
04/03/2007 - 15:46:32
[SCANSIONE DEL REGISTRO]
OK
[C:]
MASTER BOOT RECORD: OK
BOOT SECTOR: OK
C:\Documents and Settings\Alberto\Impostazioni locali\Temp\RarSFX1\catchme.exe Possibile variante da Trojan.SoundMx
C:\Documents and Settings\Alberto\Impostazioni locali\Temp\RarSFX0\catchme.exe Possibile variante da Trojan.SoundMx
C:\Documents and Settings\Alberto\Impostazioni locali\Temp\RarSFX2\catchme.exe Possibile variante da Trojan.SoundMx
[SCANSIONE DELLA MEMORIA]
OK
[SCANSIONE DELLA MEMORIA]
OK
--------------------------------------------------------
ecco i risultati con gmer
GMER 1.0.12.12027 -
http://www.gmer.net
Rootkit scan 2007-03-04 17:21:17
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwClose
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateProcessEx
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSection
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSymbolicLinkObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDeleteKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDeleteValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDuplicateObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwFlushKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwInitializeRegistry
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey2
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwNotifyChangeKey
SSDT kl1.sys ZwOpenFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenSection
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryMultipleValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQuerySystemInformation
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwReplaceKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwRestoreKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwResumeThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSaveKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetContextThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSuspendThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwUnloadKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwWriteVirtualMemory
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[284]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[285]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[286]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[287]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[288]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[289]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[290]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[291]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[292]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[293]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[294]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[295]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[296]
Code \??\C:\WINDOWS\system32\drivers\klif.sys FsRtlCheckLockForReadAccess
Code \??\C:\WINDOWS\system32\drivers\klif.sys IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.12 ----
.text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804EAF2E 5 Bytes JMP B738A6C0 \??\C:\WINDOWS\system32\drivers\klif.sys
.text ntkrnlpa.exe!IoIsOperationSynchronous 804EF718 5 Bytes JMP B738AB50 \??\C:\WINDOWS\system32\drivers\klif.sys
.text ntkrnlpa.exe!KiDispatchInterrupt + 100 80544C20 7 Bytes JMP B738CE10 \??\C:\WINDOWS\system32\drivers\klif.sys
.text USBPORT.SYS!DllUnload B9E6C7AE 5 Bytes JMP 8A5051B8
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 8A5371D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 8A5371D8
Device \Driver\NetBT \Device\NetBT_Tcpip_{585D92EE-3F6B-4BEB-9110-43AB0AA379F8} IRP_MJ_CREATE 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{585D92EE-3F6B-4BEB-9110-43AB0AA379F8} IRP_MJ_CLOSE 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{585D92EE-3F6B-4BEB-9110-43AB0AA379F8} IRP_MJ_DEVICE_CONTROL 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{585D92EE-3F6B-4BEB-9110-43AB0AA379F8} IRP_MJ_INTERNAL_DEVICE_CONTROL 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{585D92EE-3F6B-4BEB-9110-43AB0AA379F8} IRP_MJ_CLEANUP 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{585D92EE-3F6B-4BEB-9110-43AB0AA379F8} IRP_MJ_PNP 89819690
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 8A3DE1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 8A55A1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 8A55A1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CREATE 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CLOSE 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_POWER 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_PNP 8A3DE1D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CREATE 8A3B71D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CLOSE 8A3B71D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_DEVICE_CONTROL 8A3B71D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A3B71D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_POWER 8A3B71D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_SYSTEM_CONTROL 8A3B71D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_PNP 8A3B71D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 8A55B1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE [B9E0A012] OsaFsLoc.sys
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 8A47C980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 8A47C980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 8A47C980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 8A47C980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 8A47C980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A47C980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 8A47C980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 8A47C980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 8A47C980
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 8A47C980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE [B9E0A012] OsaFsLoc.sys
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 8A47C980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 8A47C980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 8A47C980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 8A47C980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 8A47C980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A47C980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 8A47C980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 8A47C980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 8A47C980
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 8A47C980
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 8A55B1D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CREATE 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CLOSE 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_DEVICE_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_INTERNAL_DEVICE_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_POWER 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SYSTEM_CONTROL 8A5581D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_PNP 8A5581D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 89819690
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 89819690
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 89819690
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 89819690
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 89819690
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 89819690
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 89819690
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 89819690
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 89819690
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 89819690
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 89819690
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 89819690
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CREATE 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CLOSE 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_POWER 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_PNP 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CREATE 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CLOSE 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_POWER 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_PNP 8A3DE1D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 89806600
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 89806600
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CREATE 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CLOSE 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_POWER 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_PNP 8A3DE1D8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 89806600
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 89806600
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CREATE 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CLOSE 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_POWER 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_SYSTEM_CONTROL 8A3DE1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_PNP 8A3DE1D8
Device \Driver\NetBT \Device\NetBT_Tcpip_{E20A791B-319C-45E7-B1F1-9E76E0237F6F} IRP_MJ_CREATE 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{E20A791B-319C-45E7-B1F1-9E76E0237F6F} IRP_MJ_CLOSE 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{E20A791B-319C-45E7-B1F1-9E76E0237F6F} IRP_MJ_DEVICE_CONTROL 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{E20A791B-319C-45E7-B1F1-9E76E0237F6F} IRP_MJ_INTERNAL_DEVICE_CONTROL 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{E20A791B-319C-45E7-B1F1-9E76E0237F6F} IRP_MJ_CLEANUP 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{E20A791B-319C-45E7-B1F1-9E76E0237F6F} IRP_MJ_PNP 89819690
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 8A55B1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 8A55B1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 8A55B1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 8A55B1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 8A55B1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 8A55B1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 8A55B1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 8A55B1D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 8A55B1D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CREATE 8A3B71D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CLOSE 8A3B71D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_DEVICE_CONTROL 8A3B71D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A3B71D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_POWER 8A3B71D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_SYSTEM_CONTROL 8A3B71D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_PNP 8A3B71D8
Device \Driver\00000133 \Device\0000007f IRP_MJ_POWER [BA6DFD74] sptd.sys
Device \Driver\00000133 \Device\0000007f IRP_MJ_SYSTEM_CONTROL [BA6F92A2] sptd.sys
Device \Driver\00000133 \Device\0000007f IRP_MJ_PNP [BA6FA228] sptd.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{A9CEABE6-9768-4B64-8DCF-FBE5565FA345} IRP_MJ_CREATE 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{A9CEABE6-9768-4B64-8DCF-FBE5565FA345} IRP_MJ_CLOSE 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{A9CEABE6-9768-4B64-8DCF-FBE5565FA345} IRP_MJ_DEVICE_CONTROL 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{A9CEABE6-9768-4B64-8DCF-FBE5565FA345} IRP_MJ_INTERNAL_DEVICE_CONTROL 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{A9CEABE6-9768-4B64-8DCF-FBE5565FA345} IRP_MJ_CLEANUP 89819690
Device \Driver\NetBT \Device\NetBT_Tcpip_{A9CEABE6-9768-4B64-8DCF-FBE5565FA345} IRP_MJ_PNP 89819690
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1Port2Path0Target0Lun0 IRP_MJ_CREATE 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1Port2Path0Target0Lun0 IRP_MJ_CLOSE 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1Port2Path0Target0Lun0 IRP_MJ_POWER 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1Port2Path0Target0Lun0 IRP_MJ_PNP 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1 IRP_MJ_CREATE 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1 IRP_MJ_CLOSE 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1 IRP_MJ_DEVICE_CONTROL 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1 IRP_MJ_POWER 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1 IRP_MJ_SYSTEM_CONTROL 8A514980
Device \Driver\abee4x8x \Device\Scsi\abee4x8x1 IRP_MJ_PNP 8A514980
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_READ 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 8A5371D8
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 8A5371D8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [B5C18756] DLAIFS_M.SYS
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 89511980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 89511980
---- Threads - GMER 1.0.12 ----
Thread 4:168 8A41C8E0
Thread 4:172 8A41C8E0
Thread 4:176 8A3F48D0
Thread 4:180 8A3F48D0
Thread 4:184 8A3F48D0
Thread 4:532 8A41C8E0
Thread 4:784 8A41C8E0
Thread 4:920 8A41C8E0
---- EOF - GMER 1.0.12 ----
GMER 1.0.12.12027 -
http://www.gmer.net
Autostart scan 2007-03-04 17:23:11
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\SYSTEM32\Userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
igfxcui@DLLName = igfxdev.dll
klogon@DLLName = C:\WINDOWS\system32\klogon.dll
WgaLogon@DLLName = WgaLogon.dll
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs = C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
AVP /*Kaspersky Internet Security 6.0*/@ = "C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r
AWService /*AdminWorks Agent X6*/@ = "C:\Acer\Empowering Technology\admServ.exe"
ehRecvr /*Media Center Receiver Service*/@ = C:\WINDOWS\eHome\ehRecvr.exe
ehSched /*Media Center Scheduler Service*/@ = C:\WINDOWS\eHome\ehSched.exe
EvtEng /*Intel(R) PROSet/Wireless Event Log*/@ = C:\Programmi\Intel\Wireless\Bin\EvtEng.exe
Fax /*Fax*/@ = %systemroot%\system32\fxssvc.exe
LightScribeService /*LightScribeService Direct Disc Labeling Service*/@ = "C:\Programmi\File comuni\LightScribe\LSSrvc.exe"
LVPrcSrv /*Logitech Process Monitor*/@ = c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
McrdSvc /*Media Center Extender Service*/@ = C:\WINDOWS\ehome\mcrdsvc.exe
NVSvc /*NVIDIA Display Driver Service*/@ = %SystemRoot%\system32\nvsvc32.exe
RegSrvc /*Intel(R) PROSet/Wireless Registry Service*/@ = C:\Programmi\Intel\Wireless\Bin\RegSrvc.exe
Roxio Upnp Server 9 /*Roxio Upnp Server 9*/@ = "C:\Programmi\File comuni\Sonic Shared\RoxioUpnpService9.exe"
RoxLiveShare9 /*LiveShare P2P Server 9*/@ = "C:\Programmi\File comuni\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe"
RoxWatch9 /*Roxio Hard Drive Watcher 9*/@ = "C:\Programmi\File comuni\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe"
S24EventMonitor /*Intel(R) PROSet/Wireless Service*/@ = C:\Programmi\Intel\Wireless\Bin\S24EvMon.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
viritsvclite /*Virit eXplorer Lite*/@ = C:\VEXPLITE\viritsvc.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@igfxtrayC:\WINDOWS\system32\igfxtray.exe = C:\WINDOWS\system32\igfxtray.exe
@igfxhkcmdC:\WINDOWS\system32\hkcmd.exe = C:\WINDOWS\system32\hkcmd.exe
@igfxpersC:\WINDOWS\system32\igfxpers.exe = C:\WINDOWS\system32\igfxpers.exe
@BluetoothAuthenticationAgentrundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent = rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
@ehTrayC:\WINDOWS\ehome\ehtray.exe = C:\WINDOWS\ehome\ehtray.exe
@LaunchAppAlaunch = Alaunch
@RTHDCPLRTHDCPL.EXE = RTHDCPL.EXE
@SkyTelSkyTel.EXE = SkyTel.EXE
@AlcmtrALCMTR.EXE = ALCMTR.EXE
@AzMixerSelC:\Programmi\Realtek\InstallShield\AzMixerSel.exe = C:\Programmi\Realtek\InstallShield\AzMixerSel.exe
@SynTPEnhC:\Programmi\Synaptics\SynTP\SynTPEnh.exe = C:\Programmi\Synaptics\SynTP\SynTPEnh.exe
@ntiMUIC:\Programmi\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe = C:\Programmi\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
@ /*file not found*/ = /*file not found*/
@ADMTray.exe"C:\Acer\Empowering Technology\admtray.exe" = "C:\Acer\Empowering Technology\admtray.exe"
@eDataSecurity LoaderC:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe = C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
@IMJPMIG8.1"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
@MSPY2002C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC = C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
@PHIME2002ASyncC:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
@PHIME2002AC:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
@nwiznwiz.exe /install = nwiz.exe /install
@NvMediaCenterRUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
@ePower_DMCC:\Acer\Empowering Technology\ePower\ePower_DMC.exe = C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
@Acer ePower ManagementC:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot /*file not found*/ = C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot /*file not found*/
@LManagerC:\PROGRA~1\LAUNCH~1\LManager.exe = C:\PROGRA~1\LAUNCH~1\LManager.exe
@eRecoveryServiceC:\Acer\Empowering Technology\eRecovery\Monitor.exe = C:\Acer\Empowering Technology\eRecovery\Monitor.exe
@LVCOMSXC:\WINDOWS\system32\LVCOMSX.EXE = C:\WINDOWS\system32\LVCOMSX.EXE
@LogitechCameraAssistantC:\Programmi\Acer\OrbiCam\CameraAssistant.exe = C:\Programmi\Acer\OrbiCam\CameraAssistant.exe
@LogitechVideo[inspector]C:\Programmi\Acer\OrbiCam\InstallHelper.exe /inspect = C:\Programmi\Acer\OrbiCam\InstallHelper.exe /inspect
@LogitechCameraService(E)C:\WINDOWS\system32\ElkCtrl.exe /automation = C:\WINDOWS\system32\ElkCtrl.exe /automation
@SunJavaUpdateSched"C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe" = "C:\Programmi\Java\jre1.5.0_10\bin\jusched.exe"
@DAEMON Tools"C:\Programmi\eMule\Incoming\DAEMON Tools\daemon.exe" -lang 1033 = "C:\Programmi\eMule\Incoming\DAEMON Tools\daemon.exe" -lang 1033
@RoxWatchTray"C:\Programmi\File comuni\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" = "C:\Programmi\File comuni\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
@DMXLauncher"C:\Programmi\Roxio\Media Experience\DMXLauncher.exe" = "C:\Programmi\Roxio\Media Experience\DMXLauncher.exe"
@RoxioDragToDisc"C:\Programmi\Roxio\Drag-to-Disc\DrgToDsc.exe" = "C:\Programmi\Roxio\Drag-to-Disc\DrgToDsc.exe"
@kis"C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" = "C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
@KernelFaultCheck%systemroot%\system32\dumprep 0 -k = %systemroot%\system32\dumprep 0 -k
@mlvshb.exeC:\WINDOWS\TEMP\mlvshb.exe /*file not found*/ = C:\WINDOWS\TEMP\mlvshb.exe /*file not found*/
@zihzda.exeC:\WINDOWS\TEMP\zihzda.exe /*file not found*/ = C:\WINDOWS\TEMP\zihzda.exe /*file not found*/
@ozxzta.exeC:\WINDOWS\TEMP\ozxzta.exe /*file not found*/ = C:\WINDOWS\TEMP\ozxzta.exe /*file not found*/
@lpzvgb.exeC:\WINDOWS\TEMP\lpzvgb.exe /*file not found*/ = C:\WINDOWS\TEMP\lpzvgb.exe /*file not found*/
@jzgtaa.exeC:\WINDOWS\TEMP\jzgtaa.exe /*file not found*/ = C:\WINDOWS\TEMP\jzgtaa.exe /*file not found*/
@txteba.exeC:\WINDOWS\TEMP\txteba.exe /*file not found*/ = C:\WINDOWS\TEMP\txteba.exe /*file not found*/
@VIRIT LITE MONITORC:\VEXPLITE\MONLITE.EXE = C:\VEXPLITE\MONLITE.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run@compaq-speed = "c:\windows\system32\compaq-speed.exe" /*file not found*/
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@CTFMON.EXEC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@MSMSGS"C:\Programmi\Messenger\msmsgs.exe" /background = "C:\Programmi\Messenger\msmsgs.exe" /background
@Skype"C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized = "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
@swgC:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe = C:\Programmi\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Pagina proprietà versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{2F603045-309F-11CF-9774-0020AFD0CFF6} /*Synaptics Control Panel*/C:\Programmi\Synaptics\SynTP\SynTPCpl.dll = C:\Programmi\Synaptics\SynTP\SynTPCpl.dll
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{2b45bd21-71f8-4c8c-a87a-7eeb25a1a3e0} /*EPM-PO Shell Extension*/epm-po.dll = epm-po.dll
@{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} /*OpenOffice.org Column Handler*/"C:\Programmi\OpenOffice.org 2.0\program\shlxthdl.dll" = "C:\Programmi\OpenOffice.org 2.0\program\shlxthdl.dll"
@{087B3AE3-E237-4467-B8DB-5A38AB959AC9} /*OpenOffice.org Infotip Handler*/"C:\Programmi\OpenOffice.org 2.0\program\shlxthdl.dll" = "C:\Programmi\OpenOffice.org 2.0\program\shlxthdl.dll"
@{63542C48-9552-494A-84F7-73AA6A7C99C1} /*OpenOffice.org Property Sheet Handler*/"C:\Programmi\OpenOffice.org 2.0\program\shlxthdl.dll" = "C:\Programmi\OpenOffice.org 2.0\program\shlxthdl.dll"
@{3B092F0C-7696-40E3-A80F-68D74DA84210} /*OpenOffice.org Thumbnail Viewer*/"C:\Programmi\OpenOffice.org 2.0\program\shlxthdl.dll" = "C:\Programmi\OpenOffice.org 2.0\program\shlxthdl.dll"
@{CA5FEE26-14C1-4B5A-86E9-233FC0EE2682} /*IZArc DragDrop Menu*/C:\Programmi\IZArc\IZArcCM.dll = C:\Programmi\IZArc\IZArcCM.dll
@{8D9D4D0D-FDDD-44CB-AAB2-6161FA0757C5} /*IZArc Shell Context Menu*/C:\Programmi\