Grazie della risposta Luke. Allora, dopo aver perso 3 ore circa spero di aver sconfitto il worm. Ho eliminato la cartella, il fantomatico filE.
Ho reinstallato Antivir e Spyware terminator, ho riavviato ben 4 volte. E sono ancorà lì, il centrosicurezza pc funge.
In ogni caso ho eseguito i tuoi consigli alla lettera.
Ecco il rootkit di Gmer:
GMER 1.0.13.12551 -
http://www.gmer.net
Rootkit scan 2007-09-12 16:50:41
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.13 ----
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwConnectPort
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwCreatePort
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection
SSDT F8BD8F5C ZwCreateThread
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwDeleteFile
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile
SSDT sptd.sys ZwOpenKey
SSDT F8BD8F48 ZwOpenProcess
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwOpenSection
SSDT F8BD8F4D ZwOpenThread
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwSetContextThread
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwSetInformationFile
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwShutdownSystem
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile
SSDT \SystemRoot\System32\DRIVERS\cmdmon.sys ZwWriteFileGather
SSDT F8BD8F52 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.13 ----
? C:\WINDOWS\system32\drivers\sptd.sys Impossibile accedere al file. Il file è utilizzato da un altro processo.
.text USBPORT.SYS!DllUnload F813762C 5 Bytes JMP 821221B8
? C:\WINDOWS\System32\Drivers\dtscsi.sys Impossibile accedere al file. Il file è utilizzato da un altro processo.
---- User code sections - GMER 1.0.13 ----
.text C:\Programmi\Comodo\Firewall\CPF.exe[1844] ntdll.dll!LdrLoadDll 7C9261CA 3 Bytes [ FF, 25, 1E ]
.text C:\Programmi\Comodo\Firewall\CPF.exe[1844] ntdll.dll!LdrLoadDll + 4 7C9261CE 2 Bytes [ 05, 5F ]
.text C:\Programmi\Comodo\Firewall\CPF.exe[1844] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F08001E
---- Kernel IAT/EAT - GMER 1.0.13 ----
IAT \WINDOWS\System32\Drivers\SPTDDRV1.SYS[ntoskrnl.exe!IoConnectInterrupt] [F845D718] sptd.sys
IAT \WINDOWS\System32\Drivers\SPTDDRV1.SYS[ntoskrnl.exe!IofCompleteRequest] [F8472656] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F845D6C4] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F8473394] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F845D718] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F844DAB6] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F844DBEE] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F844DB76] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F844E71C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F844E5F2] sptd.sys
IAT disk.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F84734E8] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F84727AE] sptd.sys
IAT \SystemRoot\system32\DRIVERS\cdrom.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F84734E8] sptd.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [F85886D0] inspect.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F8588730] inspect.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [F8588950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F8588910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F8588910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F8588730] inspect.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F85886D0] inspect.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F8588950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F8588950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F8588910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F8588730] inspect.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F85886D0] inspect.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F8588910] inspect.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F85886D0] inspect.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F8588730] inspect.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F8588950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F85886D0] inspect.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F8588910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F8588730] inspect.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [F8588950] inspect.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F8588910] inspect.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F8588730] inspect.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [F85886D0] inspect.sys
---- User IAT/EAT - GMER 1.0.13 ----
IAT C:\Documents and Settings\francesco\Impostazioni locali\Temp\gmer.exe[1348] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [10002DF0] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Documents and Settings\francesco\Impostazioni locali\Temp\gmer.exe[1348] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [10002C50] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Documents and Settings\francesco\Impostazioni locali\Temp\gmer.exe[1348] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [10002C10] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Documents and Settings\francesco\Impostazioni locali\Temp\gmer.exe[1348] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [10002C60] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\WINDOWS\Explorer.EXE[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [10002DF0] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\WINDOWS\Explorer.EXE[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [10002C50] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\WINDOWS\Explorer.EXE[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [10002C10] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\WINDOWS\Explorer.EXE[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [10002C60] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Programmi\Messenger\msmsgs.exe[1976] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [10002DF0] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Programmi\Messenger\msmsgs.exe[1976] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [10002C50] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Programmi\Messenger\msmsgs.exe[1976] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [10002C10] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Programmi\Messenger\msmsgs.exe[1976] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [10002C60] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\PROGRA~1\WINZIP\winzip32.exe[3000] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [10002DF0] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\PROGRA~1\WINZIP\winzip32.exe[3000] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [10002C50] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\PROGRA~1\WINZIP\winzip32.exe[3000] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [10002C10] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\PROGRA~1\WINZIP\winzip32.exe[3000] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [10002C60] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Programmi\Internet Explorer\iexplore.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [10002DF0] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Programmi\Internet Explorer\iexplore.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [10002C50] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Programmi\Internet Explorer\iexplore.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [10002C10] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
IAT C:\Programmi\Internet Explorer\iexplore.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [10002C60] C:\Programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 823D71D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 823D71D8
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F8388F70] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F8388F70] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F8389160] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F8388F70] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F837CF08] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F837CF08] fltMgr.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [B2F3AA6A] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [B2F3AA16] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_READ [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_WRITE [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [B2F3A94A] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [B2F3A85E] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [B2F3A9B8] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_POWER [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA [B2F3AB12] cmdmon.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{8C92B039-F941-4843-A37E-B8156310E454} IRP_MJ_CREATE 8201D990
Device \Driver\NetBT \Device\NetBT_Tcpip_{8C92B039-F941-4843-A37E-B8156310E454} IRP_MJ_CLOSE 8201D990
Device \Driver\NetBT \Device\NetBT_Tcpip_{8C92B039-F941-4843-A37E-B8156310E454} IRP_MJ_DEVICE_CONTROL 8201D990
Device \Driver\NetBT \Device\NetBT_Tcpip_{8C92B039-F941-4843-A37E-B8156310E454} IRP_MJ_INTERNAL_DEVICE_CONTROL 8201D990
Device \Driver\NetBT \Device\NetBT_Tcpip_{8C92B039-F941-4843-A37E-B8156310E454} IRP_MJ_CLEANUP 8201D990
Device \Driver\NetBT \Device\NetBT_Tcpip_{8C92B039-F941-4843-A37E-B8156310E454} IRP_MJ_PNP 8201D990
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 820571D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 820571D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 820571D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 820571D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 823721D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 823721D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 823721D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 823721D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 823721D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 823721D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 823721D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 823721D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 823721D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 820571D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 820571D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 820571D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 820571D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE 820571D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE 820571D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER 820571D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP 820571D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CREATE 820571D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CLOSE 820571D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_POWER 820571D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 820571D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_PNP 820571D8
Device \Driver\00000036 \Device\00000047 IRP_MJ_POWER [F8459DB6] sptd.sys
Device \Driver\00000036 \Device\00000047 IRP_MJ_SYSTEM_CONTROL [F846F73C] sptd.sys
Device \Driver\00000036 \Device\00000047 IRP_MJ_PNP [F846877E] sptd.sys
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CREATE 820401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CLOSE 820401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_DEVICE_CONTROL 820401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 820401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_POWER 820401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_SYSTEM_CONTROL 820401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_PNP 820401D8
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [B2F3AA6A] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [B2F3AA16] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_READ [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [B2F3A94A] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [B2F3A85E] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [B2F3A9B8] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_POWER [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA [B2F3AB12] cmdmon.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA [B2F3AB12] cmdmon.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 823D91D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 823D91D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 823D91D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 823D91D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 823D91D8
Device \Drive