GMER 1.0.12.12011 -
http://www.gmer.net
Rootkit scan 2006-12-05 19:28:22
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT 86EB3100 ZwAlertResumeThread
SSDT 86DAC360 ZwAlertThread
SSDT 86F9B590 ZwAllocateVirtualMemory
SSDT 86D93A98 ZwConnectPort
SSDT \??\C:\Programmer\Symantec\SYMEVENT.SYS ZwCreateKey
SSDT 86E0A7B0 ZwCreateMutant
SSDT 86F9BC48 ZwCreateThread
SSDT \??\C:\Programmer\Symantec\SYMEVENT.SYS ZwDeleteKey
SSDT \??\C:\Programmer\Symantec\SYMEVENT.SYS ZwDeleteValueKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT 86D3F340 ZwFreeVirtualMemory
SSDT 86E0A870 ZwImpersonateAnonymousToken
SSDT 86EFF300 ZwImpersonateThread
SSDT 86D5F980 ZwMapViewOfSection
SSDT 86CE0B18 ZwOpenEvent
SSDT sptd.sys ZwOpenKey
SSDT \??\C:\Programmer\ewido\security suite\guard.sys ZwOpenProcess
SSDT 86F56360 ZwOpenProcessToken
SSDT 86DA8478 ZwOpenThreadToken
SSDT sptd.sys ZwQueryKey
SSDT 86FCC9D8 ZwQueryValueKey
SSDT 86F56318 ZwResumeThread
SSDT 86DA8440 ZwSetContextThread
SSDT 86ECF4F8 ZwSetInformationProcess
SSDT 86DCD528 ZwSetInformationThread
SSDT \??\C:\Programmer\Symantec\SYMEVENT.SYS ZwSetValueKey
SSDT 86CE0AE0 ZwSuspendProcess
SSDT 8703A8E8 ZwSuspendThread
SSDT \??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\FiltNt.sys ZwTerminateProcess
SSDT 86DCD4A8 ZwTerminateThread
SSDT 86D5F948 ZwUnmapViewOfSection
SSDT \??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\FiltNt.sys ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.12 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 235C 80501060 8 Bytes [ 00, 31, EB, 86, 60, C3, DA, ... ]
.text ntkrnlpa.exe!ZwCallbackReturn + 2514 80501218 8 Bytes [ 8C, 26, CF, F7, 60, 63, F5, ... ]
.text ntkrnlpa.exe!ZwCallbackReturn + 26BC 805013C0 8 Bytes [ F8, F4, EC, 86, 28, D5, DC, ... ]
.text ntkrnlpa.exe!ZwCallbackReturn + 2720 80501424 8 Bytes [ E0, 0A, CE, 86, E8, A8, 03, ... ]
.text ntkrnlpa.exe!ZwCallbackReturn + 2730 80501434 8 Bytes [ 30, A3, 3A, EE, A8, D4, DC, ... ]
---- User code sections - GMER 1.0.12 ----
.text C:\PROGRAMMER\BULLGUARD SOFTWARE\BULLGUARD\BULLGUARD.EXE[540] USER32.dll!SetScrollInfo 77D39056 7 Bytes JMP 00DC6250 C:\Programmer\BullGuard Software\BullGuard\gui\BgScrollHookDll.dll
.text C:\PROGRAMMER\BULLGUARD SOFTWARE\BULLGUARD\BULLGUARD.EXE[540] USER32.dll!GetScrollInfo 77D417F8 7 Bytes JMP 00DC61A0 C:\Programmer\BullGuard Software\BullGuard\gui\BgScrollHookDll.dll
.text C:\PROGRAMMER\BULLGUARD SOFTWARE\BULLGUARD\BULLGUARD.EXE[540] USER32.dll!ShowScrollBar 77D4F2CA 5 Bytes JMP 00DC6320 C:\Programmer\BullGuard Software\BullGuard\gui\BgScrollHookDll.dll
.text C:\PROGRAMMER\BULLGUARD SOFTWARE\BULLGUARD\BULLGUARD.EXE[540] USER32.dll!GetScrollPos 77D4F6DC 1 Byte [ E9 ]
.text C:\PROGRAMMER\BULLGUARD SOFTWARE\BULLGUARD\BULLGUARD.EXE[540] USER32.dll!GetScrollPos + 2 77D4F6DE 3 Bytes [ 6A, 07, 89 ]
.text C:\PROGRAMMER\BULLGUARD SOFTWARE\BULLGUARD\BULLGUARD.EXE[540] USER32.dll!SetScrollPos 77D4F728 5 Bytes JMP 00DC6290 C:\Programmer\BullGuard Software\BullGuard\gui\BgScrollHookDll.dll
.text C:\PROGRAMMER\BULLGUARD SOFTWARE\BULLGUARD\BULLGUARD.EXE[540] USER32.dll!GetScrollRange 77D4F75F 5 Bytes JMP 00DC6210 C:\Programmer\BullGuard Software\BullGuard\gui\BgScrollHookDll.dll
.text C:\PROGRAMMER\BULLGUARD SOFTWARE\BULLGUARD\BULLGUARD.EXE[540] USER32.dll!SetScrollRange 77D4F973 5 Bytes JMP 00DC62D0 C:\Programmer\BullGuard Software\BullGuard\gui\BgScrollHookDll.dll
.text C:\PROGRAMMER\BULLGUARD SOFTWARE\BULLGUARD\BULLGUARD.EXE[540] USER32.dll!EnableScrollBar 77D87BC5 7 Bytes JMP 00DC6160 C:\Programmer\BullGuard Software\BullGuard\gui\BgScrollHookDll.dll
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 871CA608
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 871CA608
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CREATE 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CLOSE 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_READ 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_WRITE 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_QUERY_INFORMATION 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_SET_INFORMATION 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_QUERY_VOLUME_INFORMATION 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_DIRECTORY_CONTROL 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_FILE_SYSTEM_CONTROL 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_DEVICE_CONTROL 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_LOCK_CONTROL 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CLEANUP 86DAA560
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_PNP 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CREATE 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CLOSE 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_READ 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_WRITE 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_QUERY_INFORMATION 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_SET_INFORMATION 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_QUERY_VOLUME_INFORMATION 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_DIRECTORY_CONTROL 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_FILE_SYSTEM_CONTROL 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_DEVICE_CONTROL 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_LOCK_CONTROL 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CLEANUP 86DAA560
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_PNP 86DAA560
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 871CD4F0
Device \Driver\NetBT \Device\NetBT_Tcpip_{C2019C6C-A5C0-4A24-BA75-26CC1BCB3CF4} IRP_MJ_CREATE 86FFDEB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{C2019C6C-A5C0-4A24-BA75-26CC1BCB3CF4} IRP_MJ_CLOSE 86FFDEB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{C2019C6C-A5C0-4A24-BA75-26CC1BCB3CF4} IRP_MJ_DEVICE_CONTROL 86FFDEB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{C2019C6C-A5C0-4A24-BA75-26CC1BCB3CF4} IRP_MJ_INTERNAL_DEVICE_CONTROL 86FFDEB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{C2019C6C-A5C0-4A24-BA75-26CC1BCB3CF4} IRP_MJ_CLEANUP 86FFDEB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{C2019C6C-A5C0-4A24-BA75-26CC1BCB3CF4} IRP_MJ_PNP 86FFDEB0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 86EF2A30
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 86EF2A30
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 86EF2A30
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 86EF2A30
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 86EF2A30
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 86EF2A30
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 86EF2A30
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 86EF2A30
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSE 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 86E98598
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 86E98598
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 871CD4F0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 86EF2A30
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 86EF2A30
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 86EF2A30
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 86EF2A30
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 86EF2A30
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 86EF2A30
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 86EF2A30
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 86EF2A30
Device \Driver\NetBT \Device\NetBT_Tcpip_{7A2BF1FF-F883-4ABE-96B6-1A6547CDEB65} IRP_MJ_CREATE 86FFDEB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{7A2BF1FF-F883-4ABE-96B6-1A6547CDEB65} IRP_MJ_CLOSE 86FFDEB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{7A2BF1FF-F883-4ABE-96B6-1A6547CDEB65} IRP_MJ_DEVICE_CONTROL 86FFDEB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{7A2BF1FF-F883-4ABE-96B6-1A6547CDEB65} IRP_MJ_INTERNAL_DEVICE_CONTROL 86FFDEB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{7A2BF1FF-F883-4ABE-96B6-1A6547CDEB65} IRP_MJ_CLEANUP 86FFDEB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{7A2BF1FF-F883-4ABE-96B6-1A6547CDEB65} IRP_MJ_PNP 86FFDEB0
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 86EF2A30
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 86EF2A30
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 86EF2A30
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 86EF2A30
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 86EF2A30
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 86EF2A30
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 86EF2A30
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CLOSE 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_READ 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_WRITE 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_FLUSH_BUFFERS 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_DEVICE_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_INTERNAL_DEVICE_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SHUTDOWN 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_POWER 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SYSTEM_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_PNP 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_CREATE 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_CLOSE 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_READ 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_WRITE 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_FLUSH_BUFFERS 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_DEVICE_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_INTERNAL_DEVICE_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SHUTDOWN 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_POWER 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_SYSTEM_CONTROL 86EF2A30
Device \Driver\Cdrom \Device\CdRom4 IRP_MJ_PNP 86EF2A30
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 86FFDEB0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 86FFDEB0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 86FFDEB0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 86FFDEB0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 86FFDEB0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 86FFDEB0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 86FFDEB0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 86FFDEB0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 86FFDEB0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 86FFDEB0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 86FFDEB0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 86FFDEB0
Device \Driver\00000052 \Device\00000094 IRP_MJ_POWER [F744CF68] sptd.sys
Device \Driver\00000052 \Device\00000094 IRP_MJ_SYSTEM_CONTROL [F7461A70] sptd.sys
Device \Driver\00000052 \Device\00000094 IRP_MJ_PNP [F745A728] sptd.sys
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 871CA8C0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CLOSE 871CA8C0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_READ 871CA8C0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_WRITE 871CA8C0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_FLUSH_BUFFERS 871CA8C0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_DEVICE_CONTROL 871CA8C0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_INTERNAL_DEVICE_CONTROL 871CA8C0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SHUTDOWN 871CA8C0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_POWER 871CA8C0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SYSTEM_CONTROL 871CA8C0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_PNP 871CA8C0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 86F7C598
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 86F7C598
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSE 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_FLUSH_BUFFERS 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_VOLUME_INFORMATION 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_DIRECTORY_CONTROL 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_FILE_SYSTEM_CONTROL 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLEANUP 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_SECURITY 86CF70E8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_SECURITY 86CF70E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 871CD4F0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 871CD4F0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 871CD4F0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 871CD4F0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 871CD4F0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 871CD4F0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 871CD4F0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 871CD4F0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 871CD4F0
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CLOSE 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_WRITE 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_INFORMATION 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_SET_INFORMATION 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_VOLUME_INFORMATION 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_DIRECTORY_CONTROL 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_FILE_SYSTEM_CONTROL 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CLEANUP 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE_MAILSLOT 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_SECURITY 86DE60E8
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_SET_SECURITY 86DE60E8
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_CREATE 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_CLOSE 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_DEVICE_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_POWER 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_SYSTEM_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_PNP 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CREATE 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CLOSE 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_POWER 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_PNP 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target2Lun0 IRP_MJ_CREATE 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target2Lun0 IRP_MJ_CLOSE 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target2Lun0 IRP_MJ_DEVICE_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target2Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target2Lun0 IRP_MJ_POWER 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target2Lun0 IRP_MJ_SYSTEM_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target2Lun0 IRP_MJ_PNP 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CLOSE 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_DEVICE_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_POWER 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SYSTEM_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_PNP 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target3Lun0 IRP_MJ_CREATE 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target3Lun0 IRP_MJ_CLOSE 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target3Lun0 IRP_MJ_DEVICE_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target3Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target3Lun0 IRP_MJ_POWER 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target3Lun0 IRP_MJ_SYSTEM_CONTROL 86F46828
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target3Lun0 IRP_MJ_PNP 86F46828
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_READ 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 871CA608
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 871CA608
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 86DC7730
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 86DC7730
---- EOF - GMER 1.0.12 ----