Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

SergioH

[Resolvido!]Alguém pode analisar meu log ; HijackThis

Recommended Posts

Aconteceu a alguns dias o mantispm.exe (acho que é um processo so zonealarm) começou a ser fechado, bem como o iexplorer. Encontrei entre os processos abertos um jusched.exe. Não sei o que fazer se possível me dá uma ajuda.

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 15:14:58, on 28/12/2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\ZoneLabs\isafe.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe

C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe

C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe

C:\Arquivos de programas\Saitek\Software\Profiler.exe

C:\Arquivos de programas\Saitek\Software\SaiSmart.exe

C:\WINDOWS\system32\taskmngr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\PowerArchiver\POWERARC.EXE

D:\hijack\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tst.gov.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.terra.com.br/

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [Zone Labs Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe"

O4 - HKLM\..\Run: [Profiler] C:\Arquivos de programas\Saitek\Software\Profiler.exe

O4 - HKLM\..\Run: [saiSmart] C:\Arquivos de programas\Saitek\Software\SaiSmart.exe

O4 - HKLM\..\Run: [Windows] taskmngr.exe

O4 - HKLM\..\RunServices: [Windows] taskmngr.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=about:blank

O20 - Winlogon Notify: ldr64 - C:\WINDOWS\SYSTEM32\ldr64.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

 

Obrigado pelo seu tempo

 

Sergio

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá SergioH! O jusched.exe é da Sun Java e está no seu log:

 

O4 - HKLM\..\Run: [sunJavaUpdateSched]"C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe"

É legítimo, mas desnecessário. Veja aqui. Se quiser, pode incluí-lo nas entradas que irá marcar no HijackThis.

 

Baixe > KillBox

 

Salve ou imprima estas instruções, pois vai segui-las desconectado e sem acesso a esta página:

 

1 - Rode o KillBox, marque Delete on Reboot e coloque em Full Path of File to Delete:

 

C:\WINDOWS\system32\taskmngr.exe

 

Clique no botão killbox.png. Responda Não à pergunta.

 

Coloque agora:

 

C:\WINDOWS\SYSTEM32\ldr64.dll

 

Clique no botão killbox.png. Desta vez, responda Sim à pergunta.

 

Ao reiniciar o PC, aperte F8 intermitentemente. No menu escolha: modo seguro.

 

2 - Faça um scan com o HijackThis, marque as entradas abaixo, que ainda encontrar e clique em ht-fix.png

 

O4 - HKLM\..\Run: [Windows] taskmngr.exe

 

O4 - HKLM\..\RunServices: [Windows] taskmngr.exe

 

O20 - Winlogon Notify: ldr64 - C:\WINDOWS\SYSTEM32\ldr64.dll

 

3 - Reinicie em modo normal, faça um scan com o HijackThis e salve/poste o log. Informe se acabou o problema.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá,

 

Muito obrigado pela análise do log e pela sua ajuda Sam Spade. Realizei os procedimentos, muito bem explicados, e até agora o iexplorer não fechou nem o mantispm. Estou postando o log e vou continuar a monitorar o computador. Se não for inconveniente gostaria de postar o resultado final após algumas horas.

 

Se for possível, gostaria de saber se isso que aconteceu com meu computador pode ter passado para um computador de rede residencial. Não há compartilhamento de impressoraq nem de arquivos apenas acesso à internet.

 

Abaixo segue o log:

 

Logfile of HijackThis v1.99.1

Scan saved at 23:15:20, on 29/12/2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\ZoneLabs\isafe.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe

C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe

C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe

C:\Arquivos de programas\Saitek\Software\Profiler.exe

C:\Arquivos de programas\Saitek\Software\SaiSmart.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\wuauclt.exe

D:\hijack\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tst.gov.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.terra.com.br/

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [Zone Labs Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe"

O4 - HKLM\..\Run: [Profiler] C:\Arquivos de programas\Saitek\Software\Profiler.exe

O4 - HKLM\..\Run: [saiSmart] C:\Arquivos de programas\Saitek\Software\SaiSmart.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=about:blank

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

 

Sam spade, muito obriago pelo seu tempo e cooperação. Desejo a você e toda equipe do imasters um excelente 2007 com a realização de todos os seus sonhos. :natal_biggrin:

Até agora sem problemas. Com certeza resolvido. Mais uma vez muito obrigado.

SergioH

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ok, o log está limpo. Alguns malwares podem se propagar para outras máquinas que estejam em rede. Rode o HijackThis no outro PC e poste o log para verificarmos.Desejo um Feliz 2007 para você também. Abraço. :natal_smile:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá,

 

Sam Spade, segue o log do outro computador:

 

Logfile of HijackThis v1.99.1

Scan saved at 13:37:11, on 30/12/2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Arquivos de programas\Java\jre1.6.0\bin\jusched.exe

C:\Arquivos de programas\MSN Messenger\msnmsgr.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\System32\svchost.exe

C:\hijack\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.terra.com.br/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=192.168.0.1:21;gopher=192.168.0.1:1080;http=192.168.0.1:6588;https=192.168.0

.1:6588

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background

O8 - Extra context menu item: &Google Search - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmsearch.html

O8 - Extra context menu item: &Translate English Word - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmwordtrans.html

O8 - Extra context menu item: Backward Links - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmcache.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmsimilar.html

O8 - Extra context menu item: Translate Page into English - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmtrans.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=about:blank

O17 - HKLM\System\CCS\Services\Tcpip\..\{986AB80F-37B6-4892-8636-5C78FCDF77B6}: NameServer = 192.168.0.1,200.246.46.132

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

 

Sam Spade mais uma vez muito obrigado pelo seu tempo e cooperação. Abração :natal_biggrin:

 

SergioH

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá, ao gerar o log não pode haver ítens desabilitados da inicialização, pois não aparecem. Siga estas instruções:

 

Vá em Iniciar > Executar > digite msconfig

 

Na aba Geral marque: Inicialização normal - Carregar todos os drivers de dispositivo e serviços.Aplicar > Ok

 

Reinicie o PC, gere um novo log e poste.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá,

 

 

Putz desculpa; segue o novo log:

 

 

Logfile of HijackThis v1.99.1

Scan saved at 14:19:33, on 3/1/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Arquivos de programas\Java\jre1.6.0\bin\jusched.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\SlySoft\AnyDVD\AnyDVD.exe

C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe

C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\hijack\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.terra.com.br/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=192.168.0.1:21;gopher=192.168.0.1:1080;http=192.168.0.1:6588;https=192.168.0

.1:6588

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [CloneCDTray] "C:\Arquivos de programas\SlySoft\CloneCD\CloneCDTray.exe" /s

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [AnyDVD] "C:\Arquivos de programas\SlySoft\AnyDVD\AnyDVD.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - Startup: K-Lite2006.lnk = C:\Arquivos de programas\K-Lite2006\klrun.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: &Google Search - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmsearch.html

O8 - Extra context menu item: &Translate English Word - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmwordtrans.html

O8 - Extra context menu item: Backward Links - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmcache.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmsimilar.html

O8 - Extra context menu item: Translate Page into English - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmtrans.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=about:blank

O17 - HKLM\System\CCS\Services\Tcpip\..\{986AB80F-37B6-4892-8636-5C78FCDF77B6}: NameServer = 192.168.0.1,200.246.46.132

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

 

Obrigado pelo seu tempo Sam Spade.

* Sam, desculpa o incômodo, mas o anti-virus do zone alarm detectou isto: W32.Trojan.Spy.Banker.Bai (no pc que deu o primeiro prblema que você resolveu) C:\WINDOWS\system32\drivers\oreans32.sys

O zone deixou em quarentena. Você pode me dar uma dica sobre o que fazer?? Dei uma checada nos posts anteriores e não encontrei nenhum trojanspy -bankerbai.

Obrigado e desculpa o incômodo.

Sergio

Compartilhar este post


Link para o post
Compartilhar em outros sites

O log está limpo. Sobre isso:

 

mas o anti-virus do zone alarm detectou isto: W32.Trojan.Spy.Banker.Bai (no pc que deu o primeiro prblema que você resolveu) C:\WINDOWS\system32\drivers\oreans32.sys

O zone deixou em quarentena. Você pode me dar uma dica sobre o que fazer?? Dei uma checada nos posts anteriores e não encontrei nenhum trojanspy -bankerbai.

Tudo indica ser um bot e não um banker:

 

http://www.avira.com/pt/threats/section/fu...ot.1234944.html

 

Poste um log do HijackThis deste PC.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Sam,

 

 

Obrigado quanto ao log da outra máquina já fico mais traqüilo.

 

Quanto ao outro pc (que apareceu o trojan) segue o log. Isso tem alguma coisa a ver com o problema anterior??? Como uma volta dos mortos vivos??? :upset:

 

Logfile of HijackThis v1.99.1

Scan saved at 14:08:45, on 4/1/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\ZoneLabs\isafe.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe

C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe

C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe

C:\Arquivos de programas\Saitek\Software\Profiler.exe

C:\Arquivos de programas\Saitek\Software\SaiSmart.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe

C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

D:\hijack\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tst.gov.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.terra.com.br/

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [Zone Labs Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.5.0_10\bin\jusched.exe"

O4 - HKLM\..\Run: [Profiler] C:\Arquivos de programas\Saitek\Software\Profiler.exe

O4 - HKLM\..\Run: [saiSmart] C:\Arquivos de programas\Saitek\Software\SaiSmart.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=about:blank

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

 

 

Obrigado pela força Sam. E pelo seu tempo. Tenha um bom dia.

 

Sergio

Compartilhar este post


Link para o post
Compartilhar em outros sites

Provavelmente é uma nova infecção. Baixe > GMER

 

Extraia os seus arquivos para o desktop.

 

Dê um duplo-clique no gmer.exe. Clique na aba Rootkit e depois no botão Scan.

 

IMPORTANTE: Não marque a caixa Show All.

 

Quando o scan acabar, clique em Copy e poste o resultado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá, Nova infecção!!! Esse zone alarm sei não :unsure: Sam fui fazer o scan e a opção show all estava em branco porque todas as opções já estavam marcadas. Quais destas opções eu devo marcar (desmarcar) para fazer o scan System Sections Devices Modules Processes Threads Libraries Services Registry FilesObrigado e um abraço.SergioH

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá, o que está marcado são os setores que serão examinados. O Show All é para mostrar todos os resultados. Como só queremos os rootkits, a caixa Show All estando desmarcada, o resultado fica limitado ao da aba que selecionar, no caso, Rootkit.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá,

 

Agora entendi!!!!! Leigo é complicado :upset: Bom sem delongas segue o resultado do Gmer. Obrigado e tenha um bom fim de semana :thumbsup:

 

 

 

 

GMER 1.0.12.12011 - http://www.gmer.net

Rootkit scan 2007-01-06 16:25:21

Windows 5.1.2600 Service Pack 2

 

 

---- System - GMER 1.0.12 ----

 

SSDT d347bus.sys ZwClose

SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort

SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile

SSDT \SystemRoot\System32\vsdatant.sys ZwCreateKey

SSDT d347bus.sys ZwCreatePagingFile

SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort

SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcess

SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcessEx

SSDT \SystemRoot\System32\vsdatant.sys ZwCreateSection

SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort

SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile

SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey

SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey

SSDT \SystemRoot\System32\vsdatant.sys ZwDuplicateObject

SSDT d347bus.sys ZwEnumerateKey

SSDT d347bus.sys ZwEnumerateValueKey

SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey

SSDT \SystemRoot\System32\vsdatant.sys ZwMapViewOfSection

SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile

SSDT d347bus.sys ZwOpenKey

SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess

SSDT \SystemRoot\System32\vsdatant.sys ZwOpenThread

SSDT d347bus.sys ZwQueryKey

SSDT d347bus.sys ZwQueryValueKey

SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey

SSDT \SystemRoot\System32\vsdatant.sys ZwRequestWaitReplyPort

SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey

SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort

SSDT \SystemRoot\System32\vsdatant.sys ZwSetInformationFile

SSDT \SystemRoot\System32\vsdatant.sys ZwSetSystemInformation

SSDT d347bus.sys ZwSetSystemPowerState

SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey

SSDT \SystemRoot\System32\vsdatant.sys ZwTerminateProcess

 

---- Kernel code sections - GMER 1.0.12 ----

 

.text ntoskrnl.exe!ZwYieldExecution + 12A 804E4964 16 Bytes [ 20, 8A, 4C, F7, 60, AC, 07, ... ]

.text ntoskrnl.exe!ZwYieldExecution + 16E 804E49A8 8 Bytes [ 50, 79, 07, A3, B0, 30, 08, ... ]

.text ntoskrnl.exe!ZwYieldExecution + 200 804E4A3A 2 Bytes [ 08, A3 ]

.text ntoskrnl.exe!ZwYieldExecution + 436 804E4C70 8 Bytes [ 80, 4F, 07, A3, B0, 40, 4D, ... ]

.text ntoskrnl.exe!ZwYieldExecution + 12A 804E4964 16 Bytes [ 20, 8A, 4C, F7, 60, AC, 07, ... ]

.text ...

 

---- Devices - GMER 1.0.12 ----

 

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 89BC33F0

Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 89BC10E8

Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 89BC10E8

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 897C8CA8

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 89982C58

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 89982C58

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [A308C2A0] vsdatant.sys

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 89C0DEB0

Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 89C0DEB0

Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_CREATE 898788A8

Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_CLOSE 898788A8

Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_DEVICE_CONTROL 898788A8

Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_INTERNAL_DEVICE_CONTROL 898788A8

Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_CLEANUP 898788A8

Device \Driver\NetBT \Device\NetBT_Tcpip_{DE1B69E4-95C2-43F4-8D17-B4E7A417C07A} IRP_MJ_PNP 898788A8

Device \Driver000072 \Device000047 IRP_MJ_POWER [F7511F68] sptd.sys

Device \Driver000072 \Device000047 IRP_MJ_SYSTEM_CONTROL [F7526A70] sptd.sys

Device \Driver000072 \Device000047 IRP_MJ_PNP [F751F728] sptd.sys

Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_CREATE 898788A8

Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_CLOSE 898788A8

Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_DEVICE_CONTROL 898788A8

Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_INTERNAL_DEVICE_CONTROL 898788A8

Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_CLEANUP 898788A8

Device \Driver\NetBT \Device\NetBT_Tcpip_{447DEF50-828B-4687-BC41-EDA354A81248} IRP_MJ_PNP 898788A8

Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [A308C2A0] vsdatant.sys

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 89C0D0E8

Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 89C0D0E8

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 896901A0

Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 896901A0

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSE 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 89ADFFB0

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 8965E3D8

Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 8965E3D8

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 896901A0

Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 896901A0

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_NAMED_PIPE 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_READ 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_WRITE 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_EA 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_EA 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FLUSH_BUFFERS 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_VOLUME_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_VOLUME_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DIRECTORY_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FILE_SYSTEM_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SHUTDOWN 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_LOCK_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLEANUP 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_MAILSLOT 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_SECURITY 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_SECURITY 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CHANGE 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_QUOTA 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_QUOTA 89936008

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 89936008

Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 89936008

Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 89936008

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 896901A0

Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 896901A0

Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 898788A8

Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 898788A8

Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 898788A8

Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 898788A8

Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 898788A8

Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 898788A8

Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 898788A8

Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 898788A8

Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 898788A8

Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 898788A8

Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 898788A8

Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 898788A8

Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 89686270

Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [A308C2A0] vsdatant.sys

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 89C0D5D0

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CLOSE 89C0D5D0

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_READ 89C0D5D0

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_WRITE 89C0D5D0

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_FLUSH_BUFFERS 89C0D5D0

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_DEVICE_CONTROL 89C0D5D0

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0D5D0

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SHUTDOWN 89C0D5D0

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_POWER 89C0D5D0

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SYSTEM_CONTROL 89C0D5D0

Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_PNP 89C0D5D0

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 899434C8

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 89628488

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 89628488

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [A308C2A0] vsdatant.sys

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [A308C2A0] vsdatant.sys

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 899434C8

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 89628488

Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 89628488

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSE 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 89B4D2A8

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_FLUSH_BUFFERS 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_VOLUME_INFORMATION 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_DIRECTORY_CONTROL 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_FILE_SYSTEM_CONTROL 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLEANUP 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_SECURITY 89925420

Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_SECURITY 89925420

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 89C0D0E8

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 89C0D0E8

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 89C0D0E8

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 89C0D0E8

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 89C0D0E8

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0D0E8

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 89C0D0E8

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 89C0D0E8

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 89C0D0E8

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 89C0D0E8

Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 89C0D0E8

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CLOSE 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 8997C370

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_WRITE 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_INFORMATION 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_SET_INFORMATION 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_VOLUME_INFORMATION 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_DIRECTORY_CONTROL 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_FILE_SYSTEM_CONTROL 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CLEANUP 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE_MAILSLOT 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_SECURITY 898523C0

Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_SET_SECURITY 898523C0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CREATE 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CREATE_NAMED_PIPE 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CLOSE 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_READ 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_WRITE 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_QUERY_INFORMATION 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SET_INFORMATION 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_QUERY_EA 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SET_EA 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_FLUSH_BUFFERS 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_QUERY_VOLUME_INFORMATION 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SET_VOLUME_INFORMATION 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_DIRECTORY_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_FILE_SYSTEM_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_DEVICE_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SHUTDOWN 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_LOCK_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CLEANUP 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CREATE_MAILSLOT 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_QUERY_SECURITY 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SET_SECURITY 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_POWER 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SYSTEM_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_DEVICE_CHANGE 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_QUERY_QUOTA 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SET_QUOTA 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_PNP 897DF2E0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_CREATE 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_CLOSE 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_READ 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_WRITE 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SET_INFORMATION 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_QUERY_EA 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SET_EA 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SHUTDOWN 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_CLEANUP 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SET_SECURITY 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_POWER 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_SET_QUOTA 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1Port3Path0Target0Lun0 IRP_MJ_PNP 896771D0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CREATE 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CLOSE 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_READ 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_WRITE 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SET_INFORMATION 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_QUERY_EA 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SET_EA 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SHUTDOWN 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CLEANUP 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SET_SECURITY 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_POWER 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_SET_QUOTA 897DF2E0

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 IRP_MJ_PNP 897DF2E0

Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_CREATE 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_CLOSE 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_DEVICE_CONTROL 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_POWER 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_SYSTEM_CONTROL 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_PNP 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_CREATE 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_CLOSE 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_POWER 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 89C0DA40

Device \Driver\viamraid \Device\Scsi\viamraid1Port2Path0Target0Lun0 IRP_MJ_PNP 89C0DA40

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CREATE 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CREATE_NAMED_PIPE 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CLOSE 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_READ 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_WRITE 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_INFORMATION 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_INFORMATION 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_EA 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_EA 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_FLUSH_BUFFERS 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_VOLUME_INFORMATION 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_VOLUME_INFORMATION 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_DIRECTORY_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_FILE_SYSTEM_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_DEVICE_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_INTERNAL_DEVICE_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SHUTDOWN 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_LOCK_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CLEANUP 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_CREATE_MAILSLOT 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_SECURITY 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_SECURITY 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_POWER 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SYSTEM_CONTROL 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_DEVICE_CHANGE 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_QUERY_QUOTA 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_SET_QUOTA 896771D0

Device \Driver\d347prt \Device\Scsi\d347prt1 IRP_MJ_PNP 896771D0

Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_READ 897C8CA8

Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 89982C58

Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 89982C58

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 897E4300

Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_READ 897E4300

Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 897E4300

Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_READ 897E4300

Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_READ 897E4300

Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 8985C9B0

Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 897CC318

Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 897CC318

 

---- Modules - GMER 1.0.12 ----

 

Module _________ F782A000

 

---- EOF - GMER 1.0.12 ----

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa!!! Então posso mandar o Antivirús apagar esse malware??? Vou dar mais uma checada pra ver se tem algo mais e posto. Abração Sérgio

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto é necessário enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.