1.
GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-03-15 22:20:31
Windows 5.1.2600 Dodatek Service Pack 2
---- Services - GMER 1.0.12 ----
Service .NET CLR Data
Service .NET CLR Networking
Service .NETFramework
Service [DISABLED] Abiosdsk
Service [DISABLED] abp480n5
Service C:\WINDOWS\system32\drivers\ACEDRV07.sys [AUTO] ACEDRV07
Service C:\WINDOWS\System32\DRIVERS\ACPI.sys [BOOT] ACPI
Service [DISABLED] ACPIEC
Service C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [MANUAL] Adobe LM Service
Service [DISABLED] adpu160m
Service C:\WINDOWS\system32\drivers\aec.sys [MANUAL] aec
Service C:\WINDOWS\System32\drivers\afd.sys [SYSTEM] AFD
Service [DISABLED] Aha154x
Service [DISABLED] aic78u2
Service [DISABLED] aic78xx
Service C:\WINDOWS\system32\drivers\ALCXWDM.SYS [MANUAL] ALCXWDM
Service C:\WINDOWS\System32\svchost.exe [DISABLED] Alerter
Service C:\WINDOWS\System32\alg.exe [MANUAL] ALG
Service [DISABLED] AliIde
Service C:\WINDOWS\System32\DRIVERS\amdk7.sys [SYSTEM] AmdK7
Service [DISABLED] amsint
Service C:\WINDOWS\system32\svchost.exe [MANUAL] AppMgmt
Service [DISABLED] asc
Service [DISABLED] asc3350p
Service [DISABLED] asc3550
Service ASP.NET
Service ASP.NET_1.1.4322
Service C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [MANUAL] aspnet_state
Service C:\WINDOWS\System32\DRIVERS\asyncmac.sys [MANUAL] AsyncMac
Service C:\WINDOWS\System32\DRIVERS\atapi.sys [BOOT] atapi
Service [DISABLED] Atdisk
Service C:\WINDOWS\System32\Ati2evxx.exe [AUTO] Ati HotKey Poller
Service C:\WINDOWS\system32\ati2sgag.exe [AUTO] ATI Smart
Service C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [MANUAL] ati2mtag
Service C:\WINDOWS\System32\DRIVERS\atmarpc.sys [MANUAL] Atmarpc
Service C:\WINDOWS\System32\svchost.exe [AUTO] AudioSrv
Service C:\WINDOWS\System32\DRIVERS\audstub.sys [MANUAL] audstub
Service C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys [SYSTEM] AVG Anti-Spyware Driver
Service C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe [AUTO] AVG Anti-Spyware Guard
Service C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys [SYSTEM] AvgAsCln
Service BattC
Service [SYSTEM] Beep
Service C:\WINDOWS\System32\svchost.exe [AUTO] BITS
Service C:\WINDOWS\System32\svchost.exe [AUTO] Browser
Service [DISABLED] cbidf2k
Service [DISABLED] cd20xrnt
Service [SYSTEM] Cdaudio
Service [DISABLED] Cdfs
Service C:\WINDOWS\System32\DRIVERS\cdrom.sys [SYSTEM] Cdrom
Service [SYSTEM] Changer
Service C:\WINDOWS\System32\cisvc.exe [MANUAL] cisvc
Service C:\WINDOWS\system32\svchosts.exe [DISABLED] Client IP-IPX
Service C:\WINDOWS\system32\clipsrv.exe [DISABLED] ClipSrv
Service [DISABLED] CmdIde
Service C:\WINDOWS\System32\dllhost.exe [MANUAL] COMSysApp
Service ContentFilter
Service ContentIndex
Service [DISABLED] Cpqarray
Service C:\WINDOWS\system32\svchost.exe [AUTO] CryptSvc
Service [DISABLED] dac2w2k
Service [DISABLED] dac960nt
Service C:\WINDOWS\system32\svchost.exe [AUTO] DcomLaunch
Service C:\WINDOWS\System32\svchost.exe [AUTO] Dhcp
Service C:\WINDOWS\System32\DRIVERS\disk.sys [BOOT] Disk
Service C:\WINDOWS\System32\dmadmin.exe [MANUAL] dmadmin
Service C:\WINDOWS\System32\drivers\dmboot.sys [DISABLED] dmboot
Service C:\WINDOWS\System32\drivers\dmio.sys [BOOT] dmio
Service C:\WINDOWS\System32\drivers\dmload.sys [BOOT] dmload
Service C:\WINDOWS\System32\svchost.exe [AUTO] dmserver
Service C:\WINDOWS\system32\drivers\DMusic.sys [MANUAL] DMusic
Service C:\WINDOWS\System32\svchost.exe [AUTO] Dnscache
Service [DISABLED] dpti2o
Service C:\WINDOWS\system32\drivers\drmkaud.sys [MANUAL] drmkaud
Service System32\Drivers\dtscsi.sys [MANUAL] dtscsi
Service C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [MANUAL] ElbyCDFL
Service C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [AUTO] ElbyCDIO
Service C:\WINDOWS\System32\svchost.exe [DISABLED] ERSvc
Service C:\WINDOWS\system32\services.exe [AUTO] Eventlog
Service C:\WINDOWS\System32\svchost.exe [MANUAL] EventSystem
Service [DISABLED] Fastfat
Service C:\WINDOWS\System32\svchost.exe [MANUAL] FastUserSwitchingCompatibility
Service C:\WINDOWS\System32\DRIVERS\fdc.sys [MANUAL] Fdc
Service [SYSTEM] Fips
Service [SYSTEM] Flpydisk
Service C:\WINDOWS\system32\drivers\fltmgr.sys [BOOT] FltMgr
Service [SYSTEM] Fs_Rec
Service C:\WINDOWS\System32\DRIVERS\ftdisk.sys [BOOT] Ftdisk
Service fwdrv
Service C:\WINDOWS\System32\DRIVERS\gameenum.sys [MANUAL] gameenum
Service C:\WINDOWS\System32\DRIVERS\gmer.sys [MANUAL] gmer
Service G:\INSTALL\GMSIPCI.SYS [MANUAL] GMSIPCI
Service C:\WINDOWS\System32\DRIVERS\msgpc.sys [MANUAL] Gpc
Service C:\WINDOWS\system32\DRIVERS\hamachi.sys [MANUAL] hamachi
Service C:\WINDOWS\System32\svchost.exe [AUTO] helpsvc
Service C:\WINDOWS\System32\svchost.exe [DISABLED] HidServ
Service C:\WINDOWS\system32\DRIVERS\hidusb.sys [MANUAL] HidUsb
Service [DISABLED] hpn
Service [DISABLED] hpt3xx
Service C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [MANUAL] HSFHWBS2
Service C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [MANUAL] HSF_DP
Service C:\WINDOWS\System32\Drivers\HTTP.sys [MANUAL] HTTP
Service C:\WINDOWS\System32\svchost.exe [MANUAL] HTTPFilter
Service [SYSTEM] i2omgmt
Service [DISABLED] i2omp
Service C:\WINDOWS\System32\DRIVERS\i8042prt.sys [SYSTEM] i8042prt
Service C:\WINDOWS\system32\DRIVERS\imapi.sys [SYSTEM] Imapi
Service C:\WINDOWS\System32\imapi.exe [MANUAL] ImapiService
Service inetaccs
Service [DISABLED] ini910u
Service Inport
Service [DISABLED] IntelIde
Service C:\WINDOWS\system32\drivers\ip6fw.sys [MANUAL] ip6fw
Service C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys [MANUAL] IpFilterDriver
Service C:\WINDOWS\System32\DRIVERS\ipinip.sys [MANUAL] IpInIp
Service C:\WINDOWS\System32\DRIVERS\ipnat.sys [MANUAL] IpNat
Service C:\WINDOWS\System32\DRIVERS\ipsec.sys [SYSTEM] IPSec
Service C:\WINDOWS\System32\DRIVERS\irenum.sys [MANUAL] IRENUM
Service ISAPISearch
Service C:\WINDOWS\System32\DRIVERS\isapnp.sys [BOOT] isapnp
Service C:\WINDOWS\System32\DRIVERS\kbdclass.sys [SYSTEM] Kbdclass
Service khips
Service C:\WINDOWS\system32\drivers\kmixer.sys [MANUAL] kmixer
Service [BOOT] KSecDD
Service C:\WINDOWS\System32\svchost.exe [AUTO] lanmanserver
Service C:\WINDOWS\System32\svchost.exe [AUTO] lanmanworkstation
Service [SYSTEM] lbrtfdc
Service ldap
Service LicenseService
Service C:\Program Files\Common Files\LightScribe\LSSrvc.exe [AUTO] LightScribeService
Service C:\WINDOWS\System32\svchost.exe [AUTO] LmHosts
Service C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [AUTO] mdmxsdk
Service C:\WINDOWS\System32\svchost.exe [DISABLED] Messenger
Service [SYSTEM] mnmdd
Service C:\WINDOWS\System32\mnmsrvc.exe [MANUAL] mnmsrvc
Service [MANUAL] Modem
Service C:\WINDOWS\System32\DRIVERS\mouclass.sys [SYSTEM] Mouclass
Service [BOOT] MountMgr
Service [DISABLED] mraid35x
Service C:\WINDOWS\System32\DRIVERS\mrxdav.sys [MANUAL] MRxDAV
Service C:\WINDOWS\System32\DRIVERS\mrxsmb.sys [SYSTEM] MRxSmb
Service C:\WINDOWS\System32\msdtc.exe [MANUAL] MSDTC
Service [SYSTEM] Msfs
Service C:\WINDOWS\system32\msiexec.exe [MANUAL] MSIServer
Service C:\WINDOWS\system32\drivers\MSKSSRV.sys [MANUAL] MSKSSRV
Service C:\WINDOWS\system32\drivers\MSPCLOCK.sys [MANUAL] MSPCLOCK
Service C:\WINDOWS\system32\drivers\MSPQM.sys [MANUAL] MSPQM
Service C:\WINDOWS\System32\DRIVERS\mssmbios.sys [MANUAL] mssmbios
Service [BOOT] Mup
Service [BOOT] NDIS
Service C:\WINDOWS\System32\DRIVERS\ndistapi.sys [MANUAL] NdisTapi
Service C:\WINDOWS\System32\DRIVERS\ndisuio.sys [MANUAL] Ndisuio
Service C:\WINDOWS\System32\DRIVERS\ndiswan.sys [MANUAL] NdisWan
Service [MANUAL] NDProxy
Service C:\WINDOWS\System32\DRIVERS\netbios.sys [SYSTEM] NetBIOS
Service C:\WINDOWS\System32\DRIVERS\netbt.sys [MANUAL] NetBT
Service C:\WINDOWS\system32\netdde.exe [DISABLED] NetDDE
Service C:\WINDOWS\system32\netdde.exe [DISABLED] NetDDEdsdm
Service C:\WINDOWS\System32\lsass.exe [MANUAL] Netlogon
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Netman
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Nla
Service nm
Service [SYSTEM] Npfs
Service [DISABLED] Ntfs
Service C:\WINDOWS\system32\ntio256.sys [AUTO] ntio256
Service C:\WINDOWS\System32\lsass.exe [MANUAL] NtLmSsp
Service C:\WINDOWS\system32\svchost.exe [MANUAL] NtmsSvc
Service [SYSTEM] Null
Service C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys [MANUAL] NwlnkFlt
Service C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys [MANUAL] NwlnkFwd
Service C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [AUTO] NwlnkIpx
Service C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [AUTO] NwlnkNb
Service C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [AUTO] NwlnkSpx
Service C:\WINDOWS\System32\DRIVERS\parport.sys [MANUAL] Parport
Service [BOOT] PartMgr
Service [AUTO] ParVdm
Service C:\WINDOWS\System32\DRIVERS\pci.sys [BOOT] PCI
Service [SYSTEM] PCIDump
Service [DISABLED] PCIIde
Service [DISABLED] Pcmcia
Service System32\Drivers\Pcouffin.sys [MANUAL] Pcouffin
Service [MANUAL] PDCOMP
Service [MANUAL] PDFRAME
Service [MANUAL] PDRELI
Service [MANUAL] PDRFRAME
Service [DISABLED] perc2
Service [DISABLED] perc2hib
Service PerfDisk
Service PerfNet
Service PerfOS
Service PerfProc
Service C:\WINDOWS\system32\services.exe [AUTO] PlugPlay
Service C:\WINDOWS\System32\lsass.exe [AUTO] PolicyAgent
Service C:\WINDOWS\System32\DRIVERS\raspptp.sys [MANUAL] PptpMiniport
Service PQNTDrv
Service C:\WINDOWS\System32\DRIVERS\processr.sys [SYSTEM] Processor
Service C:\WINDOWS\system32\drivers\pnwbd.sys [MANUAL] Pronaut_WBD
Service C:\WINDOWS\system32\lsass.exe [AUTO] ProtectedStorage
Service C:\WINDOWS\System32\DRIVERS\psched.sys [MANUAL] PSched
Service C:\WINDOWS\System32\DRIVERS\ptilink.sys [MANUAL] Ptilink
Service C:\WINDOWS\System32\Drivers\PxHelp20.sys [BOOT] PxHelp20
Service [DISABLED] ql1080
Service [DISABLED] Ql10wnt
Service [DISABLED] ql12160
Service [DISABLED] ql1240
Service [DISABLED] ql1280
Service C:\WINDOWS\System32\DRIVERS\rasacd.sys [SYSTEM] RasAcd
Service C:\WINDOWS\System32\svchost.exe [MANUAL] RasAuto
Service C:\WINDOWS\System32\DRIVERS\rasl2tp.sys [MANUAL] Rasl2tp
Service C:\WINDOWS\System32\svchost.exe [MANUAL] RasMan
Service C:\WINDOWS\System32\DRIVERS\raspppoe.sys [MANUAL] RasPppoe
Service C:\WINDOWS\System32\DRIVERS\raspti.sys [MANUAL] Raspti
Service C:\WINDOWS\System32\DRIVERS\rdbss.sys [SYSTEM] Rdbss
Service C:\WINDOWS\System32\DRIVERS\RDPCDD.sys [SYSTEM] RDPCDD
Service RDPDD
Service C:\WINDOWS\System32\DRIVERS\rdpdr.sys [MANUAL] rdpdr
Service RDPNP
Service [MANUAL] RDPWD
Service C:\WINDOWS\system32\sessmgr.exe [MANUAL] RDSessMgr
Service C:\WINDOWS\System32\DRIVERS\redbook.sys [SYSTEM] redbook
Service C:\WINDOWS\System32\svchost.exe [DISABLED] RemoteAccess
Service C:\WINDOWS\system32\svchost.exe [AUTO] RemoteRegistry
Service C:\WINDOWS\System32\locator.exe [MANUAL] RpcLocator
Service C:\WINDOWS\system32\svchost.exe [AUTO] RpcSs
Service C:\WINDOWS\System32\rsvp.exe [MANUAL] RSVP
Service C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [MANUAL] rtl8139
Service C:\WINDOWS\system32\lsass.exe [AUTO] SamSs
Service C:\WINDOWS\System32\SCardSvr.exe [MANUAL] SCardSvr
Service C:\WINDOWS\System32\svchost.exe [AUTO] Schedule
Service ScsiPort
Service C:\WINDOWS\System32\DRIVERS\secdrv.sys [AUTO] Secdrv
Service C:\WINDOWS\System32\svchost.exe [AUTO] seclogon
Service C:\WINDOWS\system32\svchost.exe [AUTO] SENS
Service C:\WINDOWS\System32\DRIVERS\serenum.sys [MANUAL] serenum
Service C:\WINDOWS\System32\DRIVERS\serial.sys [SYSTEM] Serial
Service C:\WINDOWS\System32\drivers\sfdrv01.sys [BOOT] sfdrv01
Service C:\WINDOWS\System32\drivers\sfhlp02.sys [BOOT] sfhlp02
Service [SYSTEM] Sfloppy
Service C:\WINDOWS\System32\drivers\sfsync04.sys [BOOT] sfsync04
Service SharedAccess
Service C:\WINDOWS\System32\svchost.exe [AUTO] ShellHWDetection
Service [DISABLED] Simbad
Service [DISABLED] Sparrow
Service C:\WINDOWS\system32\drivers\splitter.sys [MANUAL] splitter
Service C:\WINDOWS\system32\spoolsv.exe [AUTO] Spooler
Service C:\WINDOWS\System32\Drivers\sptd.sys [BOOT] sptd
Service System32\Drivers\spyemrg.sys [SYSTEM] SpyEmrg
Service C:\WINDOWS\System32\DRIVERS\sr.sys [BOOT] sr
Service C:\WINDOWS\System32\svchost.exe [AUTO] srservice
Service C:\WINDOWS\System32\DRIVERS\srv.sys [MANUAL] Srv
Service C:\WINDOWS\System32\svchost.exe [MANUAL] SSDPSRV
Service C:\Program Files\Alcohol 120\StarWind\StarWindService.exe [AUTO] StarWindService
Service C:\WINDOWS\System32\svchost.exe [AUTO] stisvc
Service C:\WINDOWS\System32\DRIVERS\swenum.sys [MANUAL] swenum
Service C:\WINDOWS\system32\drivers\swmidi.sys [MANUAL] swmidi
Service C:\WINDOWS\System32\dllhost.exe [MANUAL] SwPrv
Service swwd
Service [DISABLED] symc810
Service [DISABLED] symc8xx
Service [DISABLED] sym_hi
Service [DISABLED] sym_u3
Service C:\WINDOWS\system32\drivers\sysaudio.sys [MANUAL] sysaudio
Service C:\WINDOWS\system32\smlogsvc.exe [MANUAL] SysmonLog
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TapiSrv
Service C:\WINDOWS\System32\DRIVERS\tcpip.sys [SYSTEM] Tcpip
Service [MANUAL] TDPIPE
Service [MANUAL] TDTCP
Service C:\WINDOWS\System32\DRIVERS\termdd.sys [SYSTEM] TermDD
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TermService
Service C:\WINDOWS\System32\svchost.exe [AUTO] Themes
Service C:\WINDOWS\System32\tlntsvr.exe [MANUAL] TlntSvr
Service [DISABLED] TosIde
Service C:\WINDOWS\system32\svchost.exe [AUTO] TrkWks
Service TSDDD
Service [DISABLED] Udfs
Service [DISABLED] ultra
Service C:\WINDOWS\system32\wdfmgr.exe [AUTO] UMWdf
Service C:\WINDOWS\System32\DRIVERS\update.sys [MANUAL] Update
Service C:\WINDOWS\System32\svchost.exe [MANUAL] upnphost
Service C:\WINDOWS\System32\ups.exe [MANUAL] UPS
Service C:\WINDOWS\system32\drivers\usbaudio.sys [MANUAL] usbaudio
Service C:\WINDOWS\system32\DRIVERS\usbccgp.sys [MANUAL] usbccgp
Service C:\WINDOWS\System32\DRIVERS\usbhub.sys [MANUAL] usbhub
Service C:\WINDOWS\system32\DRIVERS\usbprint.sys [MANUAL] usbprint
Service C:\WINDOWS\system32\DRIVERS\usbscan.sys [MANUAL] usbscan
Service C:\WINDOWS\system32\DRIVERS\usbser.sys [MANUAL] usbser
Service C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [MANUAL] USBSTOR
Service C:\WINDOWS\System32\DRIVERS\usbuhci.sys [MANUAL] usbuhci
Service C:\WINDOWS\System32\Drivers\vaxscsi.sys [MANUAL] vaxscsi
Service C:\WINDOWS\System32\drivers\vga.sys [SYSTEM] VgaSave
Service C:\WINDOWS\System32\DRIVERS\viaagp.sys [BOOT] viaagp
Service C:\WINDOWS\System32\DRIVERS\viaide.sys [BOOT] ViaIde
Service [BOOT] VolSnap
Service C:\WINDOWS\System32\vssvc.exe [MANUAL] VSS
Service VXD
Service C:\WINDOWS\System32\svchost.exe [AUTO] W32Time
Service W3SVC
Service C:\WINDOWS\System32\DRIVERS\wanarp.sys [MANUAL] Wanarp
Service [MANUAL] WDICA
Service C:\WINDOWS\system32\drivers\wdmaud.sys [MANUAL] wdmaud
Service C:\WINDOWS\System32\svchost.exe [AUTO] WebClient
Service C:\WINDOWS\SYSTEM32\DRIVERS\Wibukey.sys [AUTO] WIBUKEY
Service C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [MANUAL] winachsf
Service C:\WINDOWS\system32\wincom32.sys [AUTO] wincom32
Service C:\WINDOWS\system32\svchost.exe [AUTO] winmgmt
Service [MANUAL] Winsock
Service WinSock2
Service WinTrust
Service C:\WINDOWS\System32\svchost.exe [MANUAL] WmdmPmSN
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Wmi
Service WmiApRpl
Service C:\WINDOWS\System32\wbem\wmiapsrv.exe [MANUAL] WmiApSrv
Service C:\WINDOWS\System32\svchost.exe [DISABLED] wscsvc
Service C:\WINDOWS\System32\svchost.exe [DISABLED] wuauserv
Service C:\WINDOWS\System32\svchost.exe [AUTO] WZCSVC
Service C:\WINDOWS\System32\svchost.exe [MANUAL] xmlprov
Service C:\WINDOWS\system32\zntport.sys [AUTO] zntport
Service ZoomoutScope
Service {6EA1532D-AFE4-4734-A343-3F6743CF5C2A}
Service {FA78D867-62FB-47FA-A563-5672917FD99F}
Service [MANUAL] amxlg3pa
---- EOF - GMER 1.0.12 ----
2.
[quote]GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-03-15 22:31:08
Windows 5.1.2600 Dodatek Service Pack 2
---- System - GMER 1.0.12 ----
SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
---- Kernel code sections - GMER 1.0.12 ----
? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
.text USBPORT.SYS!DllUnload F6DDF62C 5 Bytes JMP 82CC7960
? C:\WINDOWS\System32\Drivers\vaxscsi.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
? System32\Drivers\amxlg3pa.SYS Nie można odnaleźć określonego pliku.
.text ntdll.dll!NtClose 7C90D586 5 Bytes JMP 720342BA
.text ntdll.dll!NtCreateProcess 7C90D754 5 Bytes JMP 72034445
.text ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes JMP 72034329
.text ntdll.dll!NtCreateSection 7C90D793 5 Bytes JMP 720342D8
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 82F521D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 82F521D8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6EA1532D-AFE4-4734-A343-3F6743CF5C2A} IRP_MJ_CREATE 82C72980
Device \Driver\NetBT \Device\NetBT_Tcpip_{6EA1532D-AFE4-4734-A343-3F6743CF5C2A} IRP_MJ_CLOSE 82C72980
Device \Driver\NetBT \Device\NetBT_Tcpip_{6EA1532D-AFE4-4734-A343-3F6743CF5C2A} IRP_MJ_DEVICE_CONTROL 82C72980
Device \Driver\NetBT \Device\NetBT_Tcpip_{6EA1532D-AFE4-4734-A343-3F6743CF5C2A} IRP_MJ_INTERNAL_DEVICE_CONTROL 82C72980
Device \Driver\NetBT \Device\NetBT_Tcpip_{6EA1532D-AFE4-4734-A343-3F6743CF5C2A} IRP_MJ_CLEANUP 82C72980
Device \Driver\NetBT \Device\NetBT_Tcpip_{6EA1532D-AFE4-4734-A343-3F6743CF5C2A} IRP_MJ_PNP 82C72980
Device \Driver\00000050 \Device\00000051 IRP_MJ_POWER [F7446C7E] sptd.sys
Device \Driver\00000050 \Device\00000051 IRP_MJ_SYSTEM_CONTROL [F74602A2] sptd.sys
Device \Driver\00000050 \Device\00000051 IRP_MJ_PNP [F7461228] sptd.sys
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 82CCF980
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 82CCF980
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 82CCF980
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82CCF980
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 82CCF980
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 82CCF980
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 82CCF980
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 82FC01D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 82FC01D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 82FC01D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 82FC01D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 82FC01D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 82FC01D8
Device \Driver\00000050 \Device\00000052 IRP_MJ_POWER [F7446C7E] sptd.sys
Device \Driver\00000050 \Device\00000052 IRP_MJ_SYSTEM_CONTROL [F74602A2] sptd.sys
Device \Driver\00000050 \Device\00000052 IRP_MJ_PNP [F7461228] sptd.sys
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 82CCF980
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 82CCF980
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 82CCF980
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82CCF980
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 82CCF980
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 82CCF980
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 82CCF980
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE 82CCF980
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE 82CCF980
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 82CCF980
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 82CCF980
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER 82CCF980
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 82CCF980
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP 82CCF980
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 82F541D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 82D0A1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 82D0A1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 82D0A1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 82D0A1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 82D0A1D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 82F541D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 82F531D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 82F531D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 82F531D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82FC0B48
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 82F531D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 82F531D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLOSE 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CONTROL 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 82FC0B48
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_POWER 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SYSTEM_CONTROL 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_PNP 82F531D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 82F531D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 82F531D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 82F531D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82FC0B48
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 82F531D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 82F531D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLOSE 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DEVICE_CONTROL 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_INTERNAL_DEVICE_CONTROL 82FC0B48
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_POWER 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SYSTEM_CONTROL 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_PNP 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_CREATE 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_CLOSE 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_DEVICE_CONTROL 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_INTERNAL_DEVICE_CONTROL 82FC0B48
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_POWER 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_SYSTEM_CONTROL 82F531D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 IRP_MJ_PNP 82F531D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 82D0A1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 82D0A1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 82D0A1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 82D0A1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 82D0A1D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_READ 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_WRITE 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_FLUSH_BUFFERS 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_DEVICE_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SHUTDOWN 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CLEANUP 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_POWER 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SYSTEM_CONTROL 82F541D8
Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_PNP 82F541D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CLOSE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_READ 82D0A1D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_WRITE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_FLUSH_BUFFERS 82D0A1D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_DEVICE_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SHUTDOWN 82D0A1D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_POWER 82D0A1D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SYSTEM_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_PNP 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_CREATE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_CLOSE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_READ 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_WRITE 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_FLUSH_BUFFERS 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_DEVICE_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SHUTDOWN 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_POWER 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SYSTEM_CONTROL 82D0A1D8
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_PNP 82D0A1D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 82C72980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 82C72980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 82C72980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 82C72980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 82C72980
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 82C72980
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CREATE 82CCF980
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CLOSE 82CCF980
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 82CCF980
Device \D