- Kod: Zaznacz wszystko
GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-04-01 19:24:15
Windows 5.1.2600 Dodatek Service Pack 2
---- Services - GMER 1.0.12 ----
Service [DISABLED] Abiosdsk
Service [DISABLED] abp480n5
Service C:\WINDOWS\system32\DRIVERS\ACPI.sys [BOOT] ACPI
Service [DISABLED] ACPIEC
Service C:\WINDOWS\system32\drivers\actser.sys [MANUAL] actser
Service [DISABLED] adpu160m
Service C:\WINDOWS\system32\drivers\aec.sys [MANUAL] aec
Service C:\WINDOWS\System32\drivers\afd.sys [SYSTEM] AFD
Service [DISABLED] Aha154x
Service [DISABLED] aic78u2
Service [DISABLED] aic78xx
Service C:\WINDOWS\system32\svchost.exe [DISABLED] Alerter
Service C:\WINDOWS\System32\alg.exe [MANUAL] ALG
Service [DISABLED] AliIde
Service C:\WINDOWS\system32\DRIVERS\AmdK8.sys [SYSTEM] AmdK8
Service [DISABLED] amsint
Service C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [MANUAL] ApfiltrService
Service C:\WINDOWS\system32\svchost.exe [MANUAL] AppMgmt
Service C:\WINDOWS\system32\DRIVERS\arp1394.sys [MANUAL] Arp1394
Service [DISABLED] asc
Service [DISABLED] asc3350p
Service [DISABLED] asc3550
Service C:\WINDOWS\system32\DRIVERS\asyncmac.sys [MANUAL] AsyncMac
Service C:\WINDOWS\system32\DRIVERS\atapi.sys [BOOT] atapi
Service [DISABLED] Atdisk
Service C:\WINDOWS\system32\DRIVERS\atmarpc.sys [MANUAL] Atmarpc
Service C:\WINDOWS\System32\svchost.exe [AUTO] AudioSrv
Service C:\WINDOWS\system32\DRIVERS\audstub.sys [MANUAL] audstub
Service E:\Program Files\KasperskyAV6.0.2.614\polish\avp.exe [AUTO] AVP
Service BattC
Service [SYSTEM] Beep
Service C:\WINDOWS\system32\svchost.exe [AUTO] BITS
Service C:\WINDOWS\system32\brsvc01a.exe [AUTO] Brother XP spl Service
Service C:\WINDOWS\system32\svchost.exe [AUTO] Browser
Service C:\WINDOWS\System32\Drivers\BrScnUsb.sys [MANUAL] BrScnUsb
Service [DISABLED] cbidf2k
Service [DISABLED] cd20xrnt
Service [SYSTEM] Cdaudio
Service [DISABLED] Cdfs
Service C:\WINDOWS\system32\DRIVERS\cdrom.sys [SYSTEM] Cdrom
Service [SYSTEM] Changer
Service C:\WINDOWS\system32\cisvc.exe [MANUAL] CiSvc
Service C:\WINDOWS\system32\clipsrv.exe [DISABLED] ClipSrv
Service [DISABLED] CmdIde
Service C:\WINDOWS\system32\DRIVERS\CnxTrLan.sys [MANUAL] CnxTrLan
Service C:\WINDOWS\system32\DRIVERS\CnxTrUsb.sys [MANUAL] CnxTrUsb
Service C:\WINDOWS\system32\dllhost.exe [MANUAL] COMSysApp
Service ContentFilter
Service ContentIndex
Service [DISABLED] Cpqarray
Service C:\WINDOWS\system32\svchost.exe [AUTO] CryptSvc
Service [DISABLED] dac2w2k
Service [DISABLED] dac960nt
Service C:\WINDOWS\system32\svchost.exe [AUTO] DcomLaunch
Service C:\WINDOWS\system32\svchost.exe [AUTO] Dhcp
Service C:\WINDOWS\system32\DRIVERS\disk.sys [BOOT] Disk
Service C:\WINDOWS\System32\dmadmin.exe [MANUAL] dmadmin
Service C:\WINDOWS\System32\drivers\dmboot.sys [DISABLED] dmboot
Service C:\WINDOWS\System32\drivers\dmio.sys [BOOT] dmio
Service C:\WINDOWS\System32\drivers\dmload.sys [BOOT] dmload
Service C:\WINDOWS\System32\svchost.exe [AUTO] dmserver
Service C:\WINDOWS\system32\drivers\DMusic.sys [MANUAL] DMusic
Service C:\WINDOWS\system32\svchost.exe [AUTO] Dnscache
Service [DISABLED] dpti2o
Service C:\WINDOWS\system32\drivers\drmkaud.sys [MANUAL] drmkaud
Service C:\WINDOWS\System32\svchost.exe [AUTO] ERSvc
Service C:\WINDOWS\system32\services.exe [AUTO] Eventlog
Service C:\WINDOWS\system32\svchost.exe [MANUAL] EventSystem
Service C:\WINDOWS\System32\Drivers\ezplay.sys [MANUAL] ezplay
Service [DISABLED] Fastfat
Service C:\WINDOWS\System32\svchost.exe [MANUAL] FastUserSwitchingCompatibility
Service [SYSTEM] Fdc
Service [SYSTEM] Fips
Service [SYSTEM] Flpydisk
Service C:\WINDOWS\system32\DRIVERS\fltMgr.sys [BOOT] FltMgr
Service [SYSTEM] Fs_Rec
Service C:\WINDOWS\system32\DRIVERS\ftdisk.sys [BOOT] Ftdisk
Service C:\WINDOWS\System32\DRIVERS\gmer.sys [MANUAL] gmer
Service C:\WINDOWS\system32\DRIVERS\msgpc.sys [MANUAL] Gpc
Service C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [MANUAL] HDAudBus
Service C:\WINDOWS\System32\svchost.exe [AUTO] helpsvc
Service C:\WINDOWS\System32\svchost.exe [DISABLED] HidServ
Service [DISABLED] hpn
Service C:\WINDOWS\System32\Drivers\HTTP.sys [MANUAL] HTTP
Service C:\WINDOWS\System32\svchost.exe [MANUAL] HTTPFilter
Service [SYSTEM] i2omgmt
Service [DISABLED] i2omp
Service C:\WINDOWS\system32\DRIVERS\i8042prt.sys [SYSTEM] i8042prt
Service C:\WINDOWS\system32\DRIVERS\imapi.sys [SYSTEM] Imapi
Service C:\WINDOWS\system32\imapi.exe [MANUAL] ImapiService
Service inetaccs
Service [DISABLED] ini910u
Service Inport
Service C:\WINDOWS\system32\drivers\RtkHDAud.sys [MANUAL] IntcAzAudAddService
Service [DISABLED] IntelIde
Service C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys [MANUAL] Ip6Fw
Service C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys [MANUAL] IpFilterDriver
Service C:\WINDOWS\system32\DRIVERS\ipinip.sys [MANUAL] IpInIp
Service C:\WINDOWS\system32\DRIVERS\ipnat.sys [MANUAL] IpNat
Service C:\WINDOWS\system32\DRIVERS\ipsec.sys [SYSTEM] IPSec
Service C:\WINDOWS\system32\DRIVERS\irenum.sys [MANUAL] IRENUM
Service ISAPISearch
Service C:\WINDOWS\system32\DRIVERS\isapnp.sys [BOOT] isapnp
Service C:\WINDOWS\system32\DRIVERS\kbdclass.sys [SYSTEM] Kbdclass
Service C:\WINDOWS\system32\drivers\kl1.sys [BOOT] kl1
Service C:\WINDOWS\system32\drivers\klif.sys [SYSTEM] klif
Service C:\WINDOWS\system32\drivers\kmixer.sys [MANUAL] kmixer
Service [BOOT] KSecDD
Service C:\WINDOWS\system32\svchost.exe [AUTO] lanmanserver
Service C:\WINDOWS\system32\svchost.exe [AUTO] lanmanworkstation
Service [SYSTEM] lbrtfdc
Service ldap
Service LicenseService
Service C:\WINDOWS\system32\svchost.exe [AUTO] LmHosts
Service C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [AUTO] MDM
Service C:\WINDOWS\system32\svchost.exe [DISABLED] Messenger
Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [MANUAL] Microsoft Office Groove Audit Service
Service [SYSTEM] mnmdd
Service C:\WINDOWS\system32\mnmsrvc.exe [MANUAL] mnmsrvc
Service [MANUAL] Modem
Service C:\WINDOWS\system32\DRIVERS\mouclass.sys [SYSTEM] Mouclass
Service [BOOT] MountMgr
Service [DISABLED] mraid35x
Service C:\WINDOWS\system32\DRIVERS\mrxdav.sys [MANUAL] MRxDAV
Service C:\WINDOWS\system32\DRIVERS\mrxsmb.sys [SYSTEM] MRxSmb
Service C:\WINDOWS\system32\msdtc.exe [MANUAL] MSDTC
Service [SYSTEM] Msfs
Service C:\WINDOWS\system32\msiexec.exe [MANUAL] MSIServer
Service C:\WINDOWS\system32\drivers\MSKSSRV.sys [MANUAL] MSKSSRV
Service C:\WINDOWS\system32\drivers\MSPCLOCK.sys [MANUAL] MSPCLOCK
Service C:\WINDOWS\system32\drivers\MSPQM.sys [MANUAL] MSPQM
Service C:\WINDOWS\system32\DRIVERS\mssmbios.sys [MANUAL] mssmbios
Service [BOOT] Mup
Service C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [MANUAL] NBService
Service [BOOT] NDIS
Service C:\WINDOWS\system32\DRIVERS\ndistapi.sys [MANUAL] NdisTapi
Service C:\WINDOWS\system32\DRIVERS\ndisuio.sys [MANUAL] Ndisuio
Service C:\WINDOWS\system32\DRIVERS\ndiswan.sys [MANUAL] NdisWan
Service [MANUAL] NDProxy
Service C:\WINDOWS\system32\DRIVERS\netbios.sys [SYSTEM] NetBIOS
Service C:\WINDOWS\system32\DRIVERS\netbt.sys [SYSTEM] NetBT
Service C:\WINDOWS\system32\netdde.exe [DISABLED] NetDDE
Service C:\WINDOWS\system32\netdde.exe [DISABLED] NetDDEdsdm
Service C:\WINDOWS\system32\lsass.exe [MANUAL] Netlogon
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Netman
Service C:\WINDOWS\system32\DRIVERS\nic1394.sys [MANUAL] NIC1394
Service C:\WINDOWS\system32\svchost.exe [MANUAL] Nla
Service C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [MANUAL] NMIndexingService
Service [SYSTEM] Npfs
Service [DISABLED] Ntfs
Service C:\WINDOWS\system32\lsass.exe [MANUAL] NtLmSsp
Service C:\WINDOWS\system32\svchost.exe [MANUAL] NtmsSvc
Service [SYSTEM] Null
Service C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [MANUAL] nv
Service C:\WINDOWS\system32\DRIVERS\nvata.sys [BOOT] nvata
Service C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [MANUAL] NVENETFD
Service C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [MANUAL] nvnetbus
Service C:\WINDOWS\system32\nvsvc32.exe [AUTO] NVSvc
Service C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys [MANUAL] NwlnkFlt
Service C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys [MANUAL] NwlnkFwd
Service C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [MANUAL] odserv
Service C:\WINDOWS\system32\DRIVERS\ohci1394.sys [BOOT] ohci1394
Service C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [MANUAL] ose
Service Outlook
Service C:\WINDOWS\system32\DRIVERS\parport.sys [MANUAL] Parport
Service [BOOT] PartMgr
Service [AUTO] ParVdm
Service C:\WINDOWS\system32\DRIVERS\pci.sys [BOOT] PCI
Service [SYSTEM] PCIDump
Service C:\WINDOWS\system32\DRIVERS\pciide.sys [BOOT] PCIIde
Service [DISABLED] Pcmcia
Service C:\WINDOWS\System32\Drivers\pcouffin.sys [MANUAL] pcouffin
Service [MANUAL] PDCOMP
Service [MANUAL] PDFRAME
Service [MANUAL] PDRELI
Service [MANUAL] PDRFRAME
Service [DISABLED] perc2
Service [DISABLED] perc2hib
Service PerfDisk
Service PerfNet
Service PerfOS
Service PerfProc
Service C:\WINDOWS\system32\drivers\pfc.sys [MANUAL] pfc
Service C:\WINDOWS\system32\services.exe [AUTO] PlugPlay
Service C:\WINDOWS\system32\lsass.exe [AUTO] PolicyAgent
Service C:\WINDOWS\system32\DRIVERS\raspptp.sys [MANUAL] PptpMiniport
Service C:\WINDOWS\system32\DRIVERS\processr.sys [SYSTEM] Processor
Service C:\WINDOWS\system32\lsass.exe [AUTO] ProtectedStorage
Service C:\WINDOWS\system32\DRIVERS\psched.sys [MANUAL] PSched
Service C:\WINDOWS\system32\DRIVERS\ptilink.sys [MANUAL] Ptilink
Service [DISABLED] ql1080
Service [DISABLED] Ql10wnt
Service [DISABLED] ql12160
Service [DISABLED] ql1240
Service [DISABLED] ql1280
Service C:\WINDOWS\system32\DRIVERS\rasacd.sys [SYSTEM] RasAcd
Service C:\WINDOWS\system32\svchost.exe [MANUAL] RasAuto
Service C:\WINDOWS\system32\DRIVERS\rasl2tp.sys [MANUAL] Rasl2tp
Service C:\WINDOWS\system32\svchost.exe [MANUAL] RasMan
Service C:\WINDOWS\system32\DRIVERS\raspppoe.sys [MANUAL] RasPppoe
Service C:\WINDOWS\system32\DRIVERS\raspti.sys [MANUAL] Raspti
Service C:\WINDOWS\system32\DRIVERS\rdbss.sys [SYSTEM] Rdbss
Service C:\WINDOWS\System32\DRIVERS\RDPCDD.sys [SYSTEM] RDPCDD
Service RDPDD
Service C:\WINDOWS\system32\DRIVERS\rdpdr.sys [MANUAL] rdpdr
Service RDPNP
Service [MANUAL] RDPWD
Service C:\WINDOWS\system32\sessmgr.exe [MANUAL] RDSessMgr
Service C:\WINDOWS\system32\DRIVERS\redbook.sys [SYSTEM] redbook
Service C:\WINDOWS\system32\svchost.exe [DISABLED] RemoteAccess
Service C:\WINDOWS\system32\svchost.exe [AUTO] RemoteRegistry
Service C:\WINDOWS\system32\locator.exe [MANUAL] RpcLocator
Service C:\WINDOWS\system32\svchost.exe [AUTO] RpcSs
Service C:\WINDOWS\system32\rsvp.exe [MANUAL] RSVP
Service C:\WINDOWS\system32\lsass.exe [AUTO] SamSs
Service C:\WINDOWS\System32\SCardSvr.exe [MANUAL] SCardSvr
Service C:\WINDOWS\System32\svchost.exe [AUTO] Schedule
Service C:\WINDOWS\system32\DRIVERS\secdrv.sys [AUTO] Secdrv
Service C:\WINDOWS\System32\svchost.exe [AUTO] seclogon
Service C:\WINDOWS\system32\svchost.exe [AUTO] SENS
Service C:\WINDOWS\system32\DRIVERS\serenum.sys [MANUAL] serenum
Service C:\WINDOWS\system32\DRIVERS\serial.sys [SYSTEM] Serial
Service [SYSTEM] Sfloppy
Service C:\WINDOWS\system32\svchost.exe [AUTO] SharedAccess
Service C:\WINDOWS\System32\svchost.exe [AUTO] ShellHWDetection
Service [DISABLED] Simbad
Service C:\WINDOWS\system32\DRIVERS\siusbmod.sys [MANUAL] siusbmod
Service [DISABLED] Sparrow
Service C:\WINDOWS\system32\drivers\splitter.sys [MANUAL] splitter
Service C:\WINDOWS\system32\spoolsv.exe [AUTO] Spooler
Service C:\WINDOWS\System32\Drivers\sptd.sys [BOOT] sptd
Service C:\WINDOWS\system32\DRIVERS\sr.sys [BOOT] sr
Service C:\WINDOWS\system32\svchost.exe [AUTO] srservice
Service C:\WINDOWS\system32\DRIVERS\srv.sys [MANUAL] Srv
Service C:\WINDOWS\system32\svchost.exe [MANUAL] SSDPSRV
Service C:\WINDOWS\system32\svchost.exe [AUTO] stisvc
Service C:\WINDOWS\system32\DRIVERS\swenum.sys [MANUAL] swenum
Service C:\WINDOWS\system32\drivers\swmidi.sys [MANUAL] swmidi
Service C:\WINDOWS\system32\dllhost.exe [MANUAL] SwPrv
Service [DISABLED] symc810
Service [DISABLED] symc8xx
Service [DISABLED] sym_hi
Service [DISABLED] sym_u3
Service C:\WINDOWS\system32\drivers\sysaudio.sys [MANUAL] sysaudio
Service C:\WINDOWS\system32\smlogsvc.exe [MANUAL] SysmonLog
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TapiSrv
Service C:\WINDOWS\system32\DRIVERS\tcpip.sys [SYSTEM] Tcpip
Service [MANUAL] TDPIPE
Service [MANUAL] TDTCP
Service C:\WINDOWS\system32\DRIVERS\termdd.sys [SYSTEM] TermDD
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TermService
Service C:\WINDOWS\System32\svchost.exe [AUTO] Themes
Service C:\WINDOWS\system32\tlntsvr.exe [DISABLED] TlntSvr
Service [DISABLED] TosIde
Service C:\WINDOWS\system32\svchost.exe [AUTO] TrkWks
Service TSDDD
Service [DISABLED] Udfs
Service [DISABLED] ultra
Service C:\WINDOWS\system32\wdfmgr.exe [AUTO] UMWdf
Service C:\WINDOWS\system32\DRIVERS\update.sys [MANUAL] Update
Service C:\WINDOWS\system32\svchost.exe [MANUAL] upnphost
Service C:\WINDOWS\System32\ups.exe [MANUAL] UPS
Service C:\WINDOWS\system32\DRIVERS\usbccgp.sys [MANUAL] usbccgp
Service C:\WINDOWS\system32\DRIVERS\usbehci.sys [MANUAL] usbehci
Service C:\WINDOWS\system32\DRIVERS\usbhub.sys [MANUAL] usbhub
Service C:\WINDOWS\system32\DRIVERS\usbohci.sys [MANUAL] usbohci
Service C:\WINDOWS\system32\DRIVERS\usbprint.sys [MANUAL] usbprint
Service C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [MANUAL] USBSTOR
Service C:\WINDOWS\System32\drivers\vga.sys [SYSTEM] VgaSave
Service [DISABLED] ViaIde
Service [BOOT] VolSnap
Service C:\WINDOWS\system32\DRIVERS\vsb.sys [MANUAL] vsbus
Service C:\WINDOWS\System32\DRIVERS\vserial.sys [MANUAL] vserial
Service C:\WINDOWS\System32\vssvc.exe [MANUAL] VSS
Service C:\WINDOWS\System32\svchost.exe [AUTO] W32Time
Service W3SVC
Service C:\WINDOWS\system32\DRIVERS\wanarp.sys [MANUAL] Wanarp
Service [MANUAL] WDICA
Service C:\WINDOWS\system32\drivers\wdmaud.sys [MANUAL] wdmaud
Service C:\WINDOWS\system32\svchost.exe [AUTO] WebClient
Service C:\WINDOWS\system32\svchost.exe [AUTO] winmgmt
Service [MANUAL] Winsock
Service WinSock2
Service WinTrust
Service C:\WINDOWS\System32\svchost.exe [MANUAL] WmdmPmSN
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Wmi
Service WmiApRpl
Service C:\WINDOWS\system32\wbem\wmiapsrv.exe [MANUAL] WmiApSrv
Service [SYSTEM] WS2IFSL
Service C:\WINDOWS\System32\svchost.exe [AUTO] wscsvc
Service C:\WINDOWS\system32\svchost.exe [AUTO] wuauserv
Service C:\WINDOWS\System32\svchost.exe [AUTO] WZCSVC
Service C:\WINDOWS\System32\svchost.exe [MANUAL] xmlprov
Service {7CDAF98D-F456-4B03-9703-63B5748BA212}
Service {83A2A176-6303-4330-A8A6-52C5B7AEA805}
Service {F76D5FEC-1FED-4E97-95E3-CECE5FD76528}
---- EOF - GMER 1.0.12 ----
[quote]GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-04-01 19:37:53
Windows 5.1.2600 Dodatek Service Pack 2
---- System - GMER 1.0.12 ----
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwClose
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateProcessEx
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSection
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSymbolicLinkObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDeleteKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDeleteValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDuplicateObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwFlushKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwInitializeRegistry
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey2
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwNotifyChangeKey
SSDT kl1.sys ZwOpenFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenSection
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryMultipleValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQuerySystemInformation
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwReplaceKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwRestoreKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwResumeThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSaveKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetContextThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetSecurityObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSuspendThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwUnloadKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwWriteVirtualMemory
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[284]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[285]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[286]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[287]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[288]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[289]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[290]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[291]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[292]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[293]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[294]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[295]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[296]
Code \??\C:\WINDOWS\system32\drivers\klif.sys FsRtlCheckLockForReadAccess
Code \??\C:\WINDOWS\system32\drivers\klif.sys IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.12 ----
.text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804EAE80 5 Bytes JMP F1A56F00 \??\C:\WINDOWS\system32\drivers\klif.sys
.text ntkrnlpa.exe!IoIsOperationSynchronous 804EF808 5 Bytes JMP F1A57400 \??\C:\WINDOWS\system32\drivers\klif.sys
.text ntkrnlpa.exe!KiDispatchInterrupt + 102 80544D02 5 Bytes [ 56, 51, 71, 90, 90 ]
? C:\WINDOWS\system32\drivers\sptd.sys Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
.text USBPORT.SYS!DllUnload F729E62C 5 Bytes JMP 82CC05F0
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 82DD41D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 82DD41D8
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CREATE 82BA3980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CLOSE 82BA3980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 82BA3980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82BA3980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_POWER 82BA3980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 82BA3980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_PNP 82BA3980
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_CREATE 82B8C918
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_CLOSE 82B8C918
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 82B8C918
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B8C918
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_POWER 82B8C918
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 82B8C918
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_PNP 82B8C918
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 82DD61D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 82DD61D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 82DD61D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 82DD61D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 82DD61D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 82DD61D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 82D661D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 82B471D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 82B471D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 82B471D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 82B471D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 82B471D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 82B471D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B471D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 82B471D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 82B471D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 82B471D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 82B471D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 82D661D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 82D661D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 82D651D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 82D651D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 82D651D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D651D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 82D651D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 82D651D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 82D651D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 82D651D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 82D651D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 82D651D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D651D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 82D651D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 82D651D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 82D651D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 82D651D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 82D651D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 82D651D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D651D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 82D651D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 82D651D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 82D651D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 829F51D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 829F51D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 829F51D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 829F51D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 829F51D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 829F51D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 829F51D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 829F51D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 829F51D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 829F51D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 829F51D8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 829F51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_CREATE 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_CREATE_NAMED_PIPE 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_CLOSE 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_READ 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_WRITE 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_QUERY_INFORMATION 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_SET_INFORMATION 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_QUERY_EA 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_SET_EA 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_FLUSH_BUFFERS 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_QUERY_VOLUME_INFORMATION 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_SET_VOLUME_INFORMATION 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_DIRECTORY_CONTROL 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_FILE_SYSTEM_CONTROL 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_DEVICE_CONTROL 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_INTERNAL_DEVICE_CONTROL 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_SHUTDOWN 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_LOCK_CONTROL 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_CLEANUP 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_CREATE_MAILSLOT 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_QUERY_SECURITY 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_SET_SECURITY 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_POWER 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_SYSTEM_CONTROL 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_DEVICE_CHANGE 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_QUERY_QUOTA 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_SET_QUOTA 82DD51D8
Device \Driver\nvata \Device\0000005f IRP_MJ_PNP 82DD51D8
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_CREATE 82BA3980
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_CLOSE 82BA3980
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 82BA3980
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82BA3980
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_POWER 82BA3980
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 82BA3980
Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_PNP 82BA3980
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE_NAMED_PIPE 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_CLOSE 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_READ 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_WRITE 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_INFORMATION 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_INFORMATION 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_EA 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_EA 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_FLUSH_BUFFERS 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_VOLUME_INFORMATION 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_VOLUME_INFORMATION 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_DIRECTORY_CONTROL 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_FILE_SYSTEM_CONTROL 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_DEVICE_CONTROL 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82DD51D8
Device \Driver\nvata \Device\NvAta0 IRP