SergioH 0 Denunciar post Postado Dezembro 28, 2006 Aconteceu a alguns dias o mantispm.exe (acho que é um processo so zonealarm) começou a ser fechado, bem como o iexplorer. Encontrei entre os processos abertos um jusched.exe. Não sei o que fazer se possível me dá uma ajuda. Logfile of HijackThis v1.99.1 Scan saved at 15:14:58, on 28/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\ZoneLabs\isafe.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe C:\Arquivos de programas\Saitek\Software\Profiler.exe C:\Arquivos de programas\Saitek\Software\SaiSmart.exe C:\WINDOWS\system32\taskmngr.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\PowerArchiver\POWERARC.EXE D:\hijack\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tst.gov.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.terra.com.br/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [Zone Labs Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKLM\..\Run: [Profiler] C:\Arquivos de programas\Saitek\Software\Profiler.exe O4 - HKLM\..\Run: [saiSmart] C:\Arquivos de programas\Saitek\Software\SaiSmart.exe O4 - HKLM\..\Run: [Windows] taskmngr.exe O4 - HKLM\..\RunServices: [Windows] taskmngr.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=about:blank O20 - Winlogon Notify: ldr64 - C:\WINDOWS\SYSTEM32\ldr64.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Obrigado pelo seu tempo Sergio Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Dezembro 29, 2006 Olá SergioH! O jusched.exe é da Sun Java e está no seu log: O4 - HKLM\..\Run: [sunJavaUpdateSched]"C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe" É legítimo, mas desnecessário. Veja aqui. Se quiser, pode incluí-lo nas entradas que irá marcar no HijackThis. Baixe > KillBox Salve ou imprima estas instruções, pois vai segui-las desconectado e sem acesso a esta página: 1 - Rode o KillBox, marque Delete on Reboot e coloque em Full Path of File to Delete: C:\WINDOWS\system32\taskmngr.exe Clique no botão . Responda Não à pergunta. Coloque agora: C:\WINDOWS\SYSTEM32\ldr64.dll Clique no botão . Desta vez, responda Sim à pergunta. Ao reiniciar o PC, aperte F8 intermitentemente. No menu escolha: modo seguro. 2 - Faça um scan com o HijackThis, marque as entradas abaixo, que ainda encontrar e clique em O4 - HKLM\..\Run: [Windows] taskmngr.exe O4 - HKLM\..\RunServices: [Windows] taskmngr.exe O20 - Winlogon Notify: ldr64 - C:\WINDOWS\SYSTEM32\ldr64.dll 3 - Reinicie em modo normal, faça um scan com o HijackThis e salve/poste o log. Informe se acabou o problema. Compartilhar este post Link para o post Compartilhar em outros sites
SergioH 0 Denunciar post Postado Dezembro 30, 2006 Olá, Muito obrigado pela análise do log e pela sua ajuda Sam Spade. Realizei os procedimentos, muito bem explicados, e até agora o iexplorer não fechou nem o mantispm. Estou postando o log e vou continuar a monitorar o computador. Se não for inconveniente gostaria de postar o resultado final após algumas horas. Se for possível, gostaria de saber se isso que aconteceu com meu computador pode ter passado para um computador de rede residencial. Não há compartilhamento de impressoraq nem de arquivos apenas acesso à internet. Abaixo segue o log: Logfile of HijackThis v1.99.1 Scan saved at 23:15:20, on 29/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\ZoneLabs\isafe.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe C:\Arquivos de programas\Saitek\Software\Profiler.exe C:\Arquivos de programas\Saitek\Software\SaiSmart.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe D:\hijack\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tst.gov.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.terra.com.br/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [Zone Labs Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKLM\..\Run: [Profiler] C:\Arquivos de programas\Saitek\Software\Profiler.exe O4 - HKLM\..\Run: [saiSmart] C:\Arquivos de programas\Saitek\Software\SaiSmart.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=about:blank O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Sam spade, muito obriago pelo seu tempo e cooperação. Desejo a você e toda equipe do imasters um excelente 2007 com a realização de todos os seus sonhos. :natal_biggrin: Até agora sem problemas. Com certeza resolvido. Mais uma vez muito obrigado. SergioH Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Dezembro 30, 2006 Ok, o log está limpo. Alguns malwares podem se propagar para outras máquinas que estejam em rede. Rode o HijackThis no outro PC e poste o log para verificarmos.Desejo um Feliz 2007 para você também. Abraço. :natal_smile: Compartilhar este post Link para o post Compartilhar em outros sites
SergioH 0 Denunciar post Postado Dezembro 30, 2006 Olá, Sam Spade, segue o log do outro computador: Logfile of HijackThis v1.99.1 Scan saved at 13:37:11, on 30/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Arquivos de programas\Java\jre1.6.0\bin\jusched.exe C:\Arquivos de programas\MSN Messenger\msnmsgr.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\svchost.exe C:\hijack\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.terra.com.br/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=192.168.0.1:21;gopher=192.168.0.1:1080;http=192.168.0.1:6588;https=192.168.0 .1:6588 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background O8 - Extra context menu item: &Google Search - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=about:blank O17 - HKLM\System\CCS\Services\Tcpip\..\{986AB80F-37B6-4892-8636-5C78FCDF77B6}: NameServer = 192.168.0.1,200.246.46.132 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe Sam Spade mais uma vez muito obrigado pelo seu tempo e cooperação. Abração :natal_biggrin: SergioH Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Janeiro 1, 2007 Olá, ao gerar o log não pode haver ítens desabilitados da inicialização, pois não aparecem. Siga estas instruções: Vá em Iniciar > Executar > digite msconfig Na aba Geral marque: Inicialização normal - Carregar todos os drivers de dispositivo e serviços.Aplicar > Ok Reinicie o PC, gere um novo log e poste. Compartilhar este post Link para o post Compartilhar em outros sites
SergioH 0 Denunciar post Postado Janeiro 3, 2007 Olá, Putz desculpa; segue o novo log: Logfile of HijackThis v1.99.1 Scan saved at 14:19:33, on 3/1/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Arquivos de programas\Java\jre1.6.0\bin\jusched.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\SlySoft\AnyDVD\AnyDVD.exe C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\hijack\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.terra.com.br/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=192.168.0.1:21;gopher=192.168.0.1:1080;http=192.168.0.1:6588;https=192.168.0 .1:6588 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [CloneCDTray] "C:\Arquivos de programas\SlySoft\CloneCD\CloneCDTray.exe" /s O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [AnyDVD] "C:\Arquivos de programas\SlySoft\AnyDVD\AnyDVD.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background O4 - Startup: K-Lite2006.lnk = C:\Arquivos de programas\K-Lite2006\klrun.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &Google Search - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=about:blank O17 - HKLM\System\CCS\Services\Tcpip\..\{986AB80F-37B6-4892-8636-5C78FCDF77B6}: NameServer = 192.168.0.1,200.246.46.132 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe Obrigado pelo seu tempo Sam Spade. * Sam, desculpa o incômodo, mas o anti-virus do zone alarm detectou isto: W32.Trojan.Spy.Banker.Bai (no pc que deu o primeiro prblema que você resolveu) C:\WINDOWS\system32\drivers\oreans32.sys O zone deixou em quarentena. Você pode me dar uma dica sobre o que fazer?? Dei uma checada nos posts anteriores e não encontrei nenhum trojanspy -bankerbai. Obrigado e desculpa o incômodo. Sergio Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Janeiro 4, 2007 O log está limpo. Sobre isso: mas o anti-virus do zone alarm detectou isto: W32.Trojan.Spy.Banker.Bai (no pc que deu o primeiro prblema que você resolveu) C:\WINDOWS\system32\drivers\oreans32.sysO zone deixou em quarentena. Você pode me dar uma dica sobre o que fazer?? Dei uma checada nos posts anteriores e não encontrei nenhum trojanspy -bankerbai. Tudo indica ser um bot e não um banker: http://www.avira.com/pt/threats/section/fu...ot.1234944.html Poste um log do HijackThis deste PC. Compartilhar este post Link para o post Compartilhar em outros sites
SergioH 0 Denunciar post Postado Janeiro 4, 2007 Olá Sam, Obrigado quanto ao log da outra máquina já fico mais traqüilo. Quanto ao outro pc (que apareceu o trojan) segue o log. Isso tem alguma coisa a ver com o problema anterior??? Como uma volta dos mortos vivos??? :upset: Logfile of HijackThis v1.99.1 Scan saved at 14:08:45, on 4/1/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\ZoneLabs\isafe.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe C:\Arquivos de programas\Saitek\Software\Profiler.exe C:\Arquivos de programas\Saitek\Software\SaiSmart.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe D:\hijack\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tst.gov.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.terra.com.br/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [Zone Labs Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKLM\..\Run: [Profiler] C:\Arquivos de programas\Saitek\Software\Profiler.exe O4 - HKLM\..\Run: [saiSmart] C:\Arquivos de programas\Saitek\Software\SaiSmart.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=about:blank O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Obrigado pela força Sam. E pelo seu tempo. Tenha um bom dia. Sergio Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Janeiro 5, 2007 Provavelmente é uma nova infecção. Baixe > GMER Extraia os seus arquivos para o desktop. Dê um duplo-clique no gmer.exe. Clique na aba Rootkit e depois no botão Scan. IMPORTANTE: Não marque a caixa Show All. Quando o scan acabar, clique em Copy e poste o resultado. Compartilhar este post Link para o post Compartilhar em outros sites
SergioH 0 Denunciar post Postado Janeiro 5, 2007 Olá, Nova infecção!!! Esse zone alarm sei não :unsure: Sam fui fazer o scan e a opção show all estava em branco porque todas as opções já estavam marcadas. Quais destas opções eu devo marcar (desmarcar) para fazer o scan System Sections Devices Modules Processes Threads Libraries Services Registry FilesObrigado e um abraço.SergioH Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Janeiro 6, 2007 Olá, o que está marcado são os setores que serão examinados. O Show All é para mostrar todos os resultados. Como só queremos os rootkits, a caixa Show All estando desmarcada, o resultado fica limitado ao da aba que selecionar, no caso, Rootkit. Compartilhar este post Link para o post Compartilhar em outros sites
SergioH 0 Denunciar post Postado Janeiro 6, 2007 Olá, Agora entendi!!!!! Leigo é complicado :upset: Bom sem delongas segue o resultado do Gmer. Obrigado e tenha um bom fim de semana :thumbsup: GMER 1.0.12.12011 - http://www.gmer.net Rootkit scan 2007-01-06 16:25:21 Windows 5.1.2600 Service Pack 2 ---- System - GMER 1.0.12 ---- SSDT d347bus.sys ZwClose SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile SSDT \SystemRoot\System32\vsdatant.sys ZwCreateKey SSDT d347bus.sys ZwCreatePagingFile SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcess SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcessEx SSDT \SystemRoot\System32\vsdatant.sys ZwCreateSection SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey SSDT \SystemRoot\System32\vsdatant.sys ZwDuplicateObject SSDT d347bus.sys ZwEnumerateKey SSDT d347bus.sys ZwEnumerateValueKey SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey SSDT \SystemRoot\System32\vsdatant.sys ZwMapViewOfSection SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile SSDT d347bus.sys ZwOpenKey SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess SSDT \SystemRoot\System32\vsdatant.sys ZwOpenThread SSDT d347bus.sys ZwQueryKey SSDT d347bus.sys ZwQueryValueKey SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey SSDT \SystemRoot\System32\vsdatant.sys ZwRequestWaitReplyPort SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort SSDT \SystemRoot\System32\vsdatant.sys ZwSetInformationFile SSDT \SystemRoot\System32\vsdatant.sys ZwSetSystemInformation SSDT d347bus.sys ZwSetSystemPowerState SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey SSDT \SystemRoot\System32\vsdatant.sys ZwTerminateProcess ---- Kernel code sections - GMER 1.0.12 ---- .text ntoskrnl.exe!ZwYieldExecution + 12A 804E4964 16 Bytes [ 20, 8A, 4C, F7, 60, AC, 07, ... ] .text ntoskrnl.exe!ZwYieldExecution + 16E 804E49A8 8 Bytes [ 50, 79, 07, A3, B0, 30, 08, ... ] .text ntoskrnl.exe!ZwYieldExecution + 200 804E4A3A 2 Bytes [ 08, A3 ] .text ntoskrnl.exe!ZwYieldExecution + 436 804E4C70 8 Bytes [ 80, 4F, 07, A3, B0, 40, 4D, ... ] .text ntoskrnl.exe!ZwYieldExecution + 12A 804E4964 16 Bytes [ 20, 8A, 4C, F7, 60, AC, 07, ... ] .text ... ---- Devices - GMER 1.0.12 ---- Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 89BC33F0 Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 89BC10E8 Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 89BC10E8 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 897C8CA8 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 89982C58 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 89982C58 Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [A308C2A0] vsdatant.sys Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 89C0DEB0 Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 89C0DEB0 Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_CREATE 898788A8 Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_CLOSE 898788A8 Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_DEVICE_CONTROL 898788A8 Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_INTERNAL_DEVICE_CONTROL 898788A8 Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_CLEANUP 898788A8 Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_PNP 898788A8 Device \Driver000072 \Device000047 IRP_MJ_POWER [F7511F68] sptd.sys Device \Driver000072 \Device000047 IRP_MJ_SYSTEM_CONTROL [F7526A70] sptd.sys Device \Driver000072 \Device000047 IRP_MJ_PNP [F751F728] sptd.sys Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_CREATE 898788A8 Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_CLOSE 898788A8 Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_DEVICE_CONTROL 898788A8 Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_INTERNAL_DEVICE_CONTROL 898788A8 Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_CLEANUP 898788A8 Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_PNP 898788A8 Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [A308C2A0] vsdatant.sys Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 89C0D0E8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 89C0D0E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 896901A0 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 896901A0 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSE 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 89ADFFB0 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 8965E3D8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 8965E3D8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 896901A0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 896901A0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_NAMED_PIPE 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_READ 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_WRITE 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_EA 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_EA 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FLUSH_BUFFERS 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_VOLUME_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_VOLUME_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DIRECTORY_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FILE_SYSTEM_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SHUTDOWN 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_LOCK_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLEANUP 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_MAILSLOT 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_SECURITY 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_SECURITY 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CHANGE 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_QUOTA 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_QUOTA 89936008 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 89936008 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 89936008 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 89936008 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 896901A0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 896901A0 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 898788A8 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 898788A8 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 898788A8 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 898788A8 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 898788A8 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 898788A8 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 898788A8 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 898788A8 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 898788A8 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 898788A8 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 898788A8 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 898788A8 Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 89686270 Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [A308C2A0] vsdatant.sys Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 89C0D5D0 Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CLOSE 89C0D5D0 Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_READ 89C0D5D0 Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_WRITE 89C0D5D0 Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_FLUSH_BUFFERS 89C0D5D0 Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_DEVICE_CONTROL 89C0D5D0 Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0D5D0 Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SHUTDOWN 89C0D5D0 Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_POWER 89C0D5D0 Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SYSTEM_CONTROL 89C0D5D0 Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_PNP 89C0D5D0 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 899434C8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 89628488 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 89628488 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [A308C2A0] vsdatant.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [A308C2A0] vsdatant.sys Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 899434C8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 89628488 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 89628488 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSE 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 89B4D2A8 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_FLUSH_BUFFERS 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_VOLUME_INFORMATION 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_DIRECTORY_CONTROL 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_FILE_SYSTEM_CONTROL 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLEANUP 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_SECURITY 89925420 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_SECURITY 89925420 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 89C0D0E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 89C0D0E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 89C0D0E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 89C0D0E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 89C0D0E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0D0E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 89C0D0E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 89C0D0E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 89C0D0E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 89C0D0E8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 89C0D0E8 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CLOSE 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 8997C370 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_WRITE 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_INFORMATION 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_SET_INFORMATION 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_VOLUME_INFORMATION 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_DIRECTORY_CONTROL 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_FILE_SYSTEM_CONTROL 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CLEANUP 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE_MAILSLOT 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_SECURITY 898523C0 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_SET_SECURITY 898523C0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CREATE 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CREATE_NAMED_PIPE 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CLOSE 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_READ 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_WRITE 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_QUERY_INFORMATION 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SET_INFORMATION 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_QUERY_EA 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SET_EA 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_FLUSH_BUFFERS 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_QUERY_VOLUME_INFORMATION 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SET_VOLUME_INFORMATION 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_DIRECTORY_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_FILE_SYSTEM_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_DEVICE_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SHUTDOWN 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_LOCK_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CLEANUP 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CREATE_MAILSLOT 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_QUERY_SECURITY 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SET_SECURITY 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_POWER 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SYSTEM_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_DEVICE_CHANGE 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_QUERY_QUOTA 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SET_QUOTA 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_PNP 897DF2E0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_CREATE 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_CLOSE 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_READ 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_WRITE 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SET_INFORMATION 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_QUERY_EA 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SET_EA 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SHUTDOWN 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_CLEANUP 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SET_SECURITY 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_POWER 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SET_QUOTA 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_PNP 896771D0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CREATE 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CLOSE 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_READ 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_WRITE 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SET_INFORMATION 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_QUERY_EA 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SET_EA 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SHUTDOWN 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CLEANUP 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SET_SECURITY 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_POWER 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SET_QUOTA 897DF2E0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_PNP 897DF2E0 Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_CREATE 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_CLOSE 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_DEVICE_CONTROL 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_POWER 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_SYSTEM_CONTROL 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_PNP 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_CREATE 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_CLOSE 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_POWER 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 89C0DA40 Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_PNP 89C0DA40 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CREATE 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CREATE_NAMED_PIPE 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CLOSE 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_READ 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_WRITE 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_INFORMATION 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_INFORMATION 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_EA 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_EA 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_FLUSH_BUFFERS 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_VOLUME_INFORMATION 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_VOLUME_INFORMATION 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_DIRECTORY_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_FILE_SYSTEM_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_DEVICE_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_INTERNAL_DEVICE_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SHUTDOWN 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_LOCK_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CLEANUP 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CREATE_MAILSLOT 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_SECURITY 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_SECURITY 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_POWER 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SYSTEM_CONTROL 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_DEVICE_CHANGE 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_QUOTA 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_QUOTA 896771D0 Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_PNP 896771D0 Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_READ 897C8CA8 Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 89982C58 Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 89982C58 Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 897E4300 Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_READ 897E4300 Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 897E4300 Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_READ 897E4300 Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_READ 897E4300 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 8985C9B0 Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 897CC318 Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 897CC318 ---- Modules - GMER 1.0.12 ---- Module _________ F782A000 ---- EOF - GMER 1.0.12 ---- Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Janeiro 8, 2007 Olá, não chegou a infectar o PC. O GMER deu OK.Está sendo detectada mais alguma infecção? Compartilhar este post Link para o post Compartilhar em outros sites
SergioH 0 Denunciar post Postado Janeiro 8, 2007 Opa!!! Então posso mandar o Antivirús apagar esse malware??? Vou dar mais uma checada pra ver se tem algo mais e posto. Abração Sérgio Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Janeiro 13, 2007 Ok, pode excluir o arquivo da quarentena. Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Fevereiro 12, 2007 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto é necessário enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites