fatto, eccolo:
GMER 1.0.12.12086 -
http://www.gmer.net
Rootkit scan 2007-03-09 22:38:36
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT \??\C:\WINDOWS\System32\drivers\wpsdrvnt.sys ZwAllocateVirtualMemory
SSDT sptd.sys ZwCreateKey
SSDT \??\C:\WINDOWS\System32\drivers\wpsdrvnt.sys ZwCreateThread
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\System32\drivers\wpsdrvnt.sys ZwMapViewOfSection
SSDT sptd.sys ZwOpenKey
SSDT \??\C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\WINDOWS\System32\drivers\wpsdrvnt.sys ZwProtectVirtualMemory
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
SSDT \??\C:\WINDOWS\System32\drivers\wpsdrvnt.sys ZwShutdownSystem
SSDT \??\C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\System32\drivers\wpsdrvnt.sys ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.12 ----
? C:\WINDOWS\system32\drivers\sptd.sys Impossibile accedere al file. Il file è utilizzato da un altro processo.
? C:\WINDOWS\System32\Drivers\SPTD3261.SYS Impossibile accedere al file. Il file è utilizzato da un altro processo.
? C:\WINDOWS\System32\Drivers\dtscsi.sys Impossibile accedere al file. Il file è utilizzato da un altro processo.
.text tcpip.sys!IPTransmit + 10BC BAE8ACFA 6 Bytes CALL F8306CE0 Teefer.sys
.text tcpip.sys!IPTransmit + 2810 BAE8C44E 6 Bytes CALL F8306CE0 Teefer.sys
.text tcpip.sys!ARPRcv + 506D BAE914E0 6 Bytes CALL F8306CE0 Teefer.sys
.text wanarp.sys F7BE93FD 7 Bytes CALL F8306E30 Teefer.sys
---- User code sections - GMER 1.0.12 ----
.text C:\WINDOWS\EXPLORER.EXE[1024] SHELL32.dll!SHFileOperationW 7CA7FD0A 5 Bytes JMP 10001102 C:\Programmi\Unlocker\UnlockerHook.dll
.text C:\WINDOWS\EXPLORER.EXE[3052] SHELL32.dll!SHFileOperationW 7CA7FD0A 5 Bytes JMP 00AC1102 C:\Programmi\Unlocker\UnlockerHook.dll
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 823E0218
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 823E0218
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F8737220] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F8737480] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F87375A0] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F87375D0] wpsdrvnt.sys
Device \Driver\00000042 \Device\00000050 IRP_MJ_POWER [F844EA26] sptd.sys
Device \Driver\00000042 \Device\00000050 IRP_MJ_SYSTEM_CONTROL [F8462BD8] sptd.sys
Device \Driver\00000042 \Device\00000050 IRP_MJ_PNP [F845B54E] sptd.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{1FF3C553-5BEC-4A41-B5EC-C85A6304DAA7} IRP_MJ_CREATE 820A19A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1FF3C553-5BEC-4A41-B5EC-C85A6304DAA7} IRP_MJ_CLOSE 820A19A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1FF3C553-5BEC-4A41-B5EC-C85A6304DAA7} IRP_MJ_DEVICE_CONTROL 820A19A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1FF3C553-5BEC-4A41-B5EC-C85A6304DAA7} IRP_MJ_INTERNAL_DEVICE_CONTROL 820A19A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1FF3C553-5BEC-4A41-B5EC-C85A6304DAA7} IRP_MJ_CLEANUP 820A19A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1FF3C553-5BEC-4A41-B5EC-C85A6304DAA7} IRP_MJ_PNP 820A19A0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F8737220] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F8737480] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F87375A0] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F87375D0] wpsdrvnt.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 823E09C0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 823E09C0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 823E09C0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 823E09C0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 823E09C0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 823E09C0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 823E09C0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 823E09C0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 823E09C0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 823E09C0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 823E09C0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 8209A0E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 8209A0E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 8209A0E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 8209A0E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 8209A0E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 8209A0E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8209A0E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 8209A0E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 8209A0E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 8209A0E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 8209A0E8
Device \Driver\usbstor \Device\00000072 IRP_MJ_CREATE 820B90E8
Device \Driver\usbstor \Device\00000072 IRP_MJ_CLOSE 820B90E8
Device \Driver\usbstor \Device\00000072 IRP_MJ_READ 820B90E8
Device \Driver\usbstor \Device\00000072 IRP_MJ_WRITE 820B90E8
Device \Driver\usbstor \Device\00000072 IRP_MJ_DEVICE_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000072 IRP_MJ_INTERNAL_DEVICE_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000072 IRP_MJ_POWER 820B90E8
Device \Driver\usbstor \Device\00000072 IRP_MJ_SYSTEM_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000072 IRP_MJ_PNP 820B90E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSE 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 81FB66D0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 81FB66D0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 8209A0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 8209A0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 8209A0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 8209A0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 8209A0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 8209A0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8209A0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 8209A0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 8209A0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 8209A0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 8209A0E8
Device \Driver\usbstor \Device\00000073 IRP_MJ_CREATE 820B90E8
Device \Driver\usbstor \Device\00000073 IRP_MJ_CLOSE 820B90E8
Device \Driver\usbstor \Device\00000073 IRP_MJ_READ 820B90E8
Device \Driver\usbstor \Device\00000073 IRP_MJ_WRITE 820B90E8
Device \Driver\usbstor \Device\00000073 IRP_MJ_DEVICE_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000073 IRP_MJ_INTERNAL_DEVICE_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000073 IRP_MJ_POWER 820B90E8
Device \Driver\usbstor \Device\00000073 IRP_MJ_SYSTEM_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000073 IRP_MJ_PNP 820B90E8
Device \Driver\usbstor \Device\00000074 IRP_MJ_CREATE 820B90E8
Device \Driver\usbstor \Device\00000074 IRP_MJ_CLOSE 820B90E8
Device \Driver\usbstor \Device\00000074 IRP_MJ_READ 820B90E8
Device \Driver\usbstor \Device\00000074 IRP_MJ_WRITE 820B90E8
Device \Driver\usbstor \Device\00000074 IRP_MJ_DEVICE_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000074 IRP_MJ_INTERNAL_DEVICE_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000074 IRP_MJ_POWER 820B90E8
Device \Driver\usbstor \Device\00000074 IRP_MJ_SYSTEM_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000074 IRP_MJ_PNP 820B90E8
Device \Driver\usbstor \Device\00000075 IRP_MJ_CREATE 820B90E8
Device \Driver\usbstor \Device\00000075 IRP_MJ_CLOSE 820B90E8
Device \Driver\usbstor \Device\00000075 IRP_MJ_READ 820B90E8
Device \Driver\usbstor \Device\00000075 IRP_MJ_WRITE 820B90E8
Device \Driver\usbstor \Device\00000075 IRP_MJ_DEVICE_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000075 IRP_MJ_INTERNAL_DEVICE_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000075 IRP_MJ_POWER 820B90E8
Device \Driver\usbstor \Device\00000075 IRP_MJ_SYSTEM_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000075 IRP_MJ_PNP 820B90E8
Device \Driver\usbstor \Device\00000076 IRP_MJ_CREATE 820B90E8
Device \Driver\usbstor \Device\00000076 IRP_MJ_CLOSE 820B90E8
Device \Driver\usbstor \Device\00000076 IRP_MJ_READ 820B90E8
Device \Driver\usbstor \Device\00000076 IRP_MJ_WRITE 820B90E8
Device \Driver\usbstor \Device\00000076 IRP_MJ_DEVICE_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000076 IRP_MJ_INTERNAL_DEVICE_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000076 IRP_MJ_POWER 820B90E8
Device \Driver\usbstor \Device\00000076 IRP_MJ_SYSTEM_CONTROL 820B90E8
Device \Driver\usbstor \Device\00000076 IRP_MJ_PNP 820B90E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 820A19A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 820A19A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 820A19A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 820A19A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 820A19A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 820A19A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 820A19A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 820A19A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 820A19A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 820A19A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 820A19A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 820A19A0
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F8737220] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F8737480] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F87375A0] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F87375D0] wpsdrvnt.sys
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 823E0450
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CLOSE 823E0450
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_READ 823E0450
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_WRITE 823E0450
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_FLUSH_BUFFERS 823E0450
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_INTERNAL_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SHUTDOWN 823E0450
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_POWER 823E0450
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SYSTEM_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_PNP 823E0450
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F8737220] wpsdrvnt.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F8737480] wpsdrvnt.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F87375A0] wpsdrvnt.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F87375D0] wpsdrvnt.sys
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_CREATE 823E0450
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_CLOSE 823E0450
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_READ 823E0450
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_WRITE 823E0450
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_FLUSH_BUFFERS 823E0450
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_INTERNAL_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_SHUTDOWN 823E0450
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_POWER 823E0450
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_SYSTEM_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk1\DR2 IRP_MJ_PNP 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_CREATE 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_CLOSE 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_READ 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_WRITE 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_FLUSH_BUFFERS 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_INTERNAL_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_SHUTDOWN 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_POWER 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_SYSTEM_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+6 IRP_MJ_PNP 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_CREATE 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_CLOSE 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_READ 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_WRITE 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_FLUSH_BUFFERS 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_INTERNAL_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_SHUTDOWN 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_POWER 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_SYSTEM_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk2\DR3 IRP_MJ_PNP 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_CREATE 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_CLOSE 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_READ 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_WRITE 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_FLUSH_BUFFERS 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_INTERNAL_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_SHUTDOWN 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_POWER 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_SYSTEM_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+7 IRP_MJ_PNP 823E0450
Device \Driver\NetBT \Device\NetBT_Tcpip_{1CEBF783-17A6-4ABC-94A5-03F176FF1C89} IRP_MJ_CREATE 820A19A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1CEBF783-17A6-4ABC-94A5-03F176FF1C89} IRP_MJ_CLOSE 820A19A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1CEBF783-17A6-4ABC-94A5-03F176FF1C89} IRP_MJ_DEVICE_CONTROL 820A19A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1CEBF783-17A6-4ABC-94A5-03F176FF1C89} IRP_MJ_INTERNAL_DEVICE_CONTROL 820A19A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1CEBF783-17A6-4ABC-94A5-03F176FF1C89} IRP_MJ_CLEANUP 820A19A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{1CEBF783-17A6-4ABC-94A5-03F176FF1C89} IRP_MJ_PNP 820A19A0
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_CREATE 823E0450
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_CLOSE 823E0450
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_READ 823E0450
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_WRITE 823E0450
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_FLUSH_BUFFERS 823E0450
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_INTERNAL_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_SHUTDOWN 823E0450
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_POWER 823E0450
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_SYSTEM_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk3\DR4 IRP_MJ_PNP 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_CREATE 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_CLOSE 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_READ 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_WRITE 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_FLUSH_BUFFERS 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_INTERNAL_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_SHUTDOWN 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_POWER 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_SYSTEM_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+8 IRP_MJ_PNP 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_CREATE 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_CLOSE 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_READ 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_WRITE 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_FLUSH_BUFFERS 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_INTERNAL_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_SHUTDOWN 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_POWER 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_SYSTEM_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk4\DR5 IRP_MJ_PNP 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_CREATE 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_CLOSE 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_READ 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_WRITE 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_FLUSH_BUFFERS 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_INTERNAL_DEVICE_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_SHUTDOWN 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_POWER 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_SYSTEM_CONTROL 823E0450
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+9 IRP_MJ_PNP 823E0450
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 820B80E8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F8737220] wpsdrvnt.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [F8737480] wpsdrvnt.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F87375A0] wpsdrvnt.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F87375D0] wpsdrvnt.sys
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 820B80E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 820B80E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSE 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_FLUSH_BUFFERS 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_VOLUME_INFORMATION 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_DIRECTORY_CONTROL 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_FILE_SYSTEM_CONTROL 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLEANUP 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_SECURITY 81F3C870
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_SECURITY 81F3C870
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 823E09C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 823E09C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 823E09C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 823E09C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 823E09C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 823E09C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 823E09C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 823E09C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 823E09C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 823E09C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 823E09C0
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CLOSE 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_WRITE 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_INFORMATION 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_SET_INFORMATION 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_VOLUME_INFORMATION 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_DIRECTORY_CONTROL 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_FILE_SYSTEM_CONTROL 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CLEANUP 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE_MAILSLOT 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_SECURITY 81F720E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_SET_SECURITY 81F720E8
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CREATE 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CLOSE 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_POWER 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_PNP 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CLOSE 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_DEVICE_CONTROL 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_POWER 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SYSTEM_CONTROL 81F446C0
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_PNP 81F446C0
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_READ 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 823E0218
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 823E0218
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 81E6A0E8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 81E6A0E8
---- EOF - GMER 1.0.12 ----
GMER 1.0.12.12086 -
http://www.gmer.net
Autostart scan 2007-03-09 22:40:07
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
AtiExtEvent@DLLName = Ati2evxx.dll
WgaLogon@DLLName = WgaLogon.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
Ati HotKey Poller@ = %SystemRoot%\system32\Ati2evxx.exe
ATI Smart /*ATI Smart*/@ = C:\WINDOWS\system32\ati2sgag.exe
AVG Anti-Spyware Guard /*AVG Anti-Spyware Guard*/@ = C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
bdss /*BitDefender Scan Server*/@ = "C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdss.exe" /service
CiSvc /*Servizio di indicizzazione*/@ = %SystemRoot%\system32\cisvc.exe
Fax /*Fax*/@ = %systemroot%\system32\fxssvc.exe
KodakCCS /*Kodak Camera Connection Software*/@ = %SystemRoot%\system32\drivers\KodakCCS.exe
myAgtSvc /*McAfee Total Protection Agent Service*/@ = C:\Programmi\McAfee\Managed VirusScan\Agent\myAgtSvc.exe /ServiceStart /*file not found*/
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
SmcService /*Sygate Personal Firewall*/@ = C:\Programmi\Sygate\SPF\smc.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
UserAccess7 /*SecuROM User Access Service (V7)*/@ = C:\WINDOWS\system32\UAService7.exe
viritsvclite /*Virit eXplorer Lite*/@ = C:\VEXPLITE\viritsvc.exe
WMPNetworkSvc /*Servizio di condivisione in rete Windows Media Player*/@ = "C:\Programmi\Windows Media Player\WMPNetwk.exe"
XCOMM /*BitDefender Communicator*/@ = "C:\Programmi\File comuni\Softwin\BitDefender Communicator\xcommsvr.exe" /service
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@Disk MonitorC:\Programmi\Generic\USB Card Reader Driver v1.9e3\Disk_Monitor.exe = C:\Programmi\Generic\USB Card Reader Driver v1.9e3\Disk_Monitor.exe
@SmcServiceC:\PROGRA~1\Sygate\SPF\smc.exe -startgui = C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
@HPDJ Taskbar UtilityC:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe = C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
@KernelFaultCheck%systemroot%\system32\dumprep 0 -k = %systemroot%\system32\dumprep 0 -k
@ATICCC"C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay = "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
@UnlockerAssistant"C:\Programmi\Unlocker\UnlockerAssistant.exe" = "C:\Programmi\Unlocker\UnlockerAssistant.exe"
@TkBellExe"C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot = "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
@FCPAgentC:\Programmi\Everstrike Software\Folder Crypto Password\fppservice.exe = C:\Programmi\Everstrike Software\Folder Crypto Password\fppservice.exe
@QuickTime Task"C:\Programmi\QuickTime\qttask.exe" -atboottime = "C:\Programmi\QuickTime\qttask.exe" -atboottime
@MVS SplashC:\Programmi\McAfee\Managed VirusScan\Agent\Splash.exe = C:\Programmi\McAfee\Managed VirusScan\Agent\Splash.exe
@McAfee Managed Services Tray"C:\Programmi\McAfee\Managed VirusScan\Agent\myagttry.exe" = "C:\Programmi\McAfee\Managed VirusScan\Agent\myagttry.exe"
@BDNewsAgent"c:\programmi\softwin\bitdefender8\bdnagent.exe" = "c:\programmi\softwin\bitdefender8\bdnagent.exe"
RunOnceEx@ = /*file not found*/
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@IncrediMailC:\Programmi\IncrediMail\bin\IncMail.exe /c = C:\Programmi\IncrediMail\bin\IncMail.exe /c
@MSMSGS"C:\Programmi\Messenger\Msmsgs.exe" /background = "C:\Programmi\Messenger\Msmsgs.exe" /background
@CTFMON.EXEC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@WMPNSCFGC:\Programmi\Windows Media Player\WMPNSCFG.exe = C:\Programmi\Windows Media Player\WMPNSCFG.exe
@VirtualVillagers.exeC:\DOCUME~1\PAPIEM~1\Desktop\VIRTUA~1.EXE /r /*file not found*/ = C:\DOCUME~1\PAPIEM~1\Desktop\VIRTUA~1.EXE /r /*file not found*/
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WPDShServiceObj = C:\WINDOWS\system32\WPDShServiceObj.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{57B86673-276A-48B2-BAE7-C6DBB3020EB8} = C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{63542C48-9552-494A-84F7-73AA6A7C99C1} /*OpenOffice Property Sheet Handler*/C:\Programmi\OpenOffice.org1.1.1\program\shlxthdl.dll = C:\Programmi\OpenOffice.org1.1.1\program\shlxthdl.dll
@{acb4a560-3606-11d3-aef4-00104bd0f92d} /*KodakShellExtension*/C:\Programmi\File comuni\KODAK\IFSCore\kodakshx.dll = C:\Programmi\File comuni\KODAK\IFSCore\kodakshx.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\System32\extmgr.dll = C:\WINDOWS\System32\extmgr.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Programmi\Real\RealPlayer\rpshell.dll = C:\Programmi\Real\RealPlayer\rpshell.dll
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/(null) =
@{8DB493EA-B2AD-42EC-AC53-3D95A528A3B3} /*FppIconOverlay extension*/C:\PROGRA~1\EVERST~1\FOLDER~1\FPP_IC~1.DLL = C:\PROGRA~1\EVERST~1\FOLDER~1\FPP_IC~1.DLL
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{5E2121EE-0300-11D4-8D3B-444553540000} /*Catalyst Context Menu extension*/C:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll = C:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll
@{40950107-FEA6-4d53-A65F-B2DCBA57DD58} /*Nokia Phone Browser*/C:\Programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll = C:\Programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
@{FBFE7864-D495-41f0-B7DC-4BB601CC295E} /*Contact View*/C:\Programmi\Nokia\Nokia PC Suite 6\ContactView.dll = C:\Programmi\Nokia\Nokia PC Suite 6\ContactView.dll
@{C0C4375A-5B72-4efe-929D-3B848C3A1E91} /*Message View*/C:\Programmi\Nokia\Nokia PC Suite 6\MessageView.dll = C:\Programmi\Nokia\Nokia PC Suite 6\MessageView.dll
@{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} /*UnlockerShellExtension*/C:\Programmi\Unlocker\UnlockerCOM.dll = C:\Programmi\Unlocker\UnlockerCOM.dll
@{D653647D-D607-4DF6-A5B8-48D2BA195F7B} /*BitDefender Antivirus v8*/C:\Programmi\Softwin\BitDefender8\bdshelxt.dll = C:\Programmi\Softwin\BitDefender8\bdshelxt.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/C:\Programmi\iTunes\iTunesMiniPlayer.dll = C:\Programmi\iTunes\iTunesMiniPlayer.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Programmi\WinRAR\rarext.dll = C:\Programmi\WinRAR\rarext.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\context.dll
BitDefender Antivirus v8@{D653647D-D607-4DF6-A5B8-48D2BA195F7B} = C:\Programmi\Softwin\BitDefender8\bdshelxt.dll
IMMenuShellExt@{F8984111-38B6-11D5-8725-0050DA2761C4} = C:\PROGRA~1\INCRED~1\bin\ImShExt.dll
MyPictures3D@{AA7A03E6-7FA5-42E7-9D7A-9A2A4E344B3F} = C:\Programmi\MyPictures3D\Bin\MyPicContext.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\context.dll
FppShellExtension@{8DB493EA-B2AD-42EC-AC53-3D95A528A3B3} = C:\PROGRA~1\EVERST~1\FOLDER~1\FPP_IC~1.DLL
MyPictures3D@{AA7A03E6-7FA5-42E7-9D7A-9A2A4E344B3F} = C:\Programmi\MyPictures3D\Bin\MyPicContext.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
BitDefender Antivirus v8@{D653647D-D607-4DF6-A5B8-48D2BA195F7B} = C:\Programmi\Softwin\BitDefender8\bdshelxt.dll
UnlockerShellExtension@{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} = C:\Programmi\Unlocker\UnlockerCOM.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Programmi\WinRAR\rarext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll = C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
@{22BF413B-C6D2-4d91-82A9-A0F997BA588C}C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL = C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\System32\ssmypics.scr
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
@Start
Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local PageC:\windows\system32\blank.htm = C:\windows\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start
Pagehttp://www.microsoft.com/isapi/redi ... ar=msnhome =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\System32\itss.dll
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\System32\itss.dll
ms-itss@CLSID = C:\Programmi\File comuni\Microsoft Shared\Information Retrieval\msitss.dll
myrm@CLSID = C:\Programmi\McAfee\Managed VirusS