Trojan Will Not Delete
21 min read
Welcome to Tom Coyote Forums
Please observe these rules while we work:
- Perform all actions in the order given.
- If you don't know, stop and ask! Don't keep going on.
- Please reply to this thread. Do not start a new topic.
- Since there may be other issues with your system besides your original symptoms, please continue to follow this thread until I have given you an "All Clean.".
c:windows\iasrecst.exe, i do find information on. C:\WINDOWS\fmideploy.exe I find nothing. Let's have it looked at.
Ready? Let's go.
*=========================*
Download Hijackthis from here
- Save HJTsetup.exe to your desktop.
- Double click on the HJTsetup.exe icon on your desktop.
- By default it will install to C:\Program Files\Hijack This.
- Continue to click Next in the setup dialogue boxes until you get to the Select Additional Tasks dialogue.
- Put a check by Create a desktop icon then click Next again.
- Continue to follow the rest of the prompts from there.
- At the final dialogue box click Finish and it will launch Hijack This.
- Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
- Click Save to save the log file and then the log will open in notepad.
- Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
- Come back here to this thread and Paste the log in your next reply.
- DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
Create Uninstall List with Hijackthis
This is how you do that:
Open HiJackThis
Click on the tab "Open the Misc Tools Session"
Click on the Box that says "Uninstall Manager"
Click on the button "Save list"
Copy and past the List from notepad into your post
*=========================*
Please Submit File to VirusTotal for analysis.
Click Virus Total Site
Use the "Browse" button and locate the following file on your computer:
C:\WINDOWS\fmideploy.exe
Click the "Submit" button.
Please copy and post (reply) with the results
Do the above steps for each file listed
*=========================*
Please post the following;
Hijackthis log
Uninstall list
VirusTotal results
Thanks,
Rogue
Logfile of HijackThis v1.99.1
Scan saved at 12:24:28 PM, on 6/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\iasrecst.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.exe -on
O4 - HKLM\..\Run: [LtcyCfgApply] "C:\Documents and Settings\Vincenzo\Desktop\latency tool pci\LtcyCfg.exe" /a
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] "C:\Program Files\ATI Multimedia\main\ATIDtct.EXE"
O4 - HKCU\..\Run: [Microsoft Keyboard Enhance V2.0] C:\WINDOWS\iasrecst.exe
O4 - HKCU\..\Run: [Intel Audio Studio V2.0] C:\WINDOWS\fmideploy.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab53083.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab53083.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab53083.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37680.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (ZPA_TexasHoldem Object) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab53083.cab
O16 - DPF: {AFAB176A-0D25-436A-8555-286F6D7AA388} (CRegFreezeScanModule Object) - http://www.actualresearch.com/files/rfscanax.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab53083.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab53852.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
Uninstall list
3Com NIC Diagnostics
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Download Manager 1.2 (Remove Only)
Adobe Flash Player 9 ActiveX
Airliners Env 5.1
ALi USB2.0 Driver
Apple Software Update
ASRC
ASUS Probe V2.20.07
AsusUpdate
ATI - Software Uninstall Utility
ATI Control Panel
ATI Decoder
ATI Display Driver
ATI HYDRAVISION
ATI Multimedia Center 9.03
ATI Problem Report Wizard
ATI Remote Wonder 2.5
avi2divx
BitTorrent 3.4.2
CCleaner (remove only)
CH Gameport Devices
DAO
DeepSight Extractor
DivX 4.12 Codec
Driver Cleaner 3
EVEREST Home Edition v1.51
HijackThis 1.99.1
InCD (Ahead Software)
InstallWatch Pro 2.5
InterVideo Installer
InterVideo WinDVD 4
InterVideo WinDVD Creator
InterVideo WinRip
iPod for Windows 2005-06-26
iPod for Windows 2005-10-12
iPod for Windows 2006-01-10
iTunes
Java 2 Runtime Environment, SE v1.4.2_01
Java 2 Runtime Environment, SE v1.4.2_05
Kaspersky Anti-Virus 6.0
Kaspersky Anti-Virus 6.0
LDB ClockXP 2.00 Beta 3
Logitech Gaming Software
Logitech MouseWare 9.76
Macromedia Shockwave Player
Mafia
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft Data Access Components KB870669
Microsoft Dictation
Microsoft Speech Recognition Engine 4.0 (English)
Microsoft Speech SDK 4.0
Microsoft Speech SDK 4.0 ActiveX Components
Microsoft Speech SDK 4.0 Suite
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft Voice
MSN Messenger 7.5
MSN Music Assistant
MUSICMATCH Jukebox
Natural Color
Nero - Burning Rom
Outlook Express Q823353
PC Connectivity Solution
PCFriendly
PowerDVD
QuickTime
Roger Wilco
Shockwave
SiSoftware Sandra Standard 2004.SP2b (Win32 x86)
Sound Blaster Live!
SoundMAX
Spider-Man 2
Spybot - Search & Destroy 1.4
SpywareBlaster v3.5.1
SpywareGuard v2.2
SquawkBox
SUPER © Version 2007.bld.22 (Mar 14, 2007)
Super Audio Converter 5.0
Symantec KB-DocID:2003093015493306
TeamSpeak 2 RC2
Tranquillity 1.0
TTS_Technology
Voice Editor
VPN v1.4us
Winamp (remove only)
Window Washer
Windows Installer 3.0 (KB884016)
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player Hotfix [See wm828026 for more information]
Windows XP Application Compatibility Update[Q319580]
Windows XP Hotfix - KB821557
Windows XP Hotfix - KB823182
Windows XP Hotfix - KB823559
Windows XP Hotfix - KB824105
Windows XP Hotfix - KB824141
Windows XP Hotfix - KB824146
Windows XP Hotfix - KB825119
Windows XP Hotfix - KB828028
Windows XP Hotfix - KB828035
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB833987
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB837001
Windows XP Hotfix - KB840315
Windows XP Hotfix - KB840374
Windows XP Hotfix - KB840987
Windows XP Hotfix - KB841356
Windows XP Hotfix - KB841533
Windows XP Hotfix - KB841873
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB873376
Windows XP Hotfix - KB887822
Windows XP Hotfix (SP1) [See Q309521 for more information]
Windows XP Hotfix (SP1) [See Q311889 for more information]
Windows XP Hotfix (SP1) [See Q311967 for more information]
Windows XP Hotfix (SP1) [See Q313450 for more information]
Windows XP Hotfix (SP1) [See Q314862 for more information]
Windows XP Hotfix (SP1) [See Q315000 for more information]
Windows XP Hotfix (SP1) [See Q315403 for more information]
Windows XP Hotfix (SP1) [See Q317277 for more information]
Windows XP Hotfix (SP1) [See Q318138 for more information]
Windows XP Hotfix (SP1) [See Q323172 for more information]
Windows XP Hotfix (SP1) [See Q324096 for more information]
Windows XP Hotfix (SP1) [See Q324380 for more information]
Windows XP Hotfix (SP1) [See Q326830 for more information]
Windows XP Hotfix (SP1) [See Q328940 for more information]
Windows XP Hotfix (SP1) [See Q329048 for more information]
Windows XP Hotfix (SP1) [See Q329390 for more information]
Windows XP Hotfix (SP1) [See Q329441 for more information]
Windows XP Hotfix (SP1) [See Q329834 for more information]
Windows XP Hotfix (SP1) Q328310
Windows XP Hotfix (SP1) Q329170
Windows XP Hotfix (SP1) Q810577
Windows XP Hotfix (SP1) Q810833
Windows XP Hotfix (SP1) Q811493
Windows XP Hotfix (SP1) Q815021
Windows XP Hotfix (SP1) Q817606
Windows XP Hotfix (SP2) [See Q329115 for more information]
WinMX
WinRAR archiver
XviD MPEG-4 Video Codec
Yahoo! Messenger
ZoneAlarm
///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
STATUS: FINISHEDComplete scanning result of "fmideploy.exe", received in VirusTotal at 06.20.2007, 05:31:36 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.6.16.0 06.19.2007 no virus found
AntiVir 7.4.0.34 06.19.2007 HEUR/Malware
Authentium 4.93.8 06.19.2007 W32/Downloader2.AILI
Avast 4.7.997.0 06.19.2007 no virus found
AVG 7.5.0.467 06.19.2007 BackDoor.Generic7.GTE
BitDefender 7.2 06.20.2007 no virus found
CAT-QuickHeal 9.00 06.19.2007 no virus found
ClamAV devel-20070416 06.20.2007 no virus found
DrWeb 4.33 06.19.2007 no virus found
eSafe 7.0.15.0 06.19.2007 no virus found
eTrust-Vet 30.7.3727 06.19.2007 no virus found
Ewido 4.0 06.19.2007 no virus found
FileAdvisor 1 06.20.2007 Not analyzed yet
Fortinet 2.91.0.0 06.19.2007 W32/DROPPER.CHB!tr
F-Prot 4.3.2.48 06.19.2007 W32/Downloader2.AILI
F-Secure 6.70.13030.0 06.19.2007 W32/Malware.WTA
Ikarus T3.1.1.8 06.19.2007 Trojan-Dropper.Win32.Agent.AIY
Kaspersky 4.0.2.24 06.19.2007 no virus found
McAfee 5056 06.19.2007 no virus found
Microsoft 1.2607 06.19.2007 no virus found
NOD32v2 2340 06.20.2007 no virus found
Norman 5.80.02 06.19.2007 W32/Malware.WTA
Panda 9.0.0.4 06.20.2007 Generic Trojan
Prevx1 V2 06.20.2007 no virus found
Sophos 4.18.0 06.12.2007 no virus found
Sunbelt 2.2.907.0 06.16.2007 no virus found
Symantec 10 06.20.2007 no virus found
TheHacker [removed] 06.18.2007 no virus found
VBA32 [removed] 06.19.2007 Trojan.Win32.Bifrose.ADR
VirusBuster 4.3.23:9 06.19.2007 no virus found
Webwasher-Gateway 6.0.1 06.19.2007 Heuristic.Malware
Aditional Information
File size: 70656 bytes
MD5: 369992870bcfffbf6b874a95e32cb68d
SHA1: 589052d9711ae1689caed5a6ed3cbd6fa2ee68e0
Bit9 info: http://fileadvisor.bit9.com/services/extin…b874a95e32cb68d
/////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
Other detections found today as a risk (invader) by kaspersky program and i beleive avast too………….
C:\Windows\gmflpr.dll
C:\WINDOWS\drmclient32.dll
Also I scanned with virustotal the iasrecst.exe file and kapersky says no virus found, yet that is the program that detected it, just to let you know. :/
STATUS: FINISHEDComplete scanning result of "iasrecst.exe", received in VirusTotal at 06.20.2007, 06:02:51 (CET).
Antivirus Version Update Result
AhnLab-V3 2007.6.16.0 06.19.2007 no virus found
AntiVir 7.4.0.34 06.19.2007 DR/Spy.Agent.RM
Authentium 4.93.8 06.19.2007 no virus found
Avast 4.7.997.0 06.19.2007 no virus found
AVG 7.5.0.467 06.19.2007 Dropper.Generic.MSP
BitDefender 7.2 06.20.2007 Dropped:Trojan.Spy.Agent.RM
CAT-QuickHeal 9.00 06.19.2007 no virus found
ClamAV devel-20070416 06.20.2007 no virus found
DrWeb 4.33 06.19.2007 no virus found
eSafe 7.0.15.0 06.19.2007 Win32.Trojan
eTrust-Vet 30.7.3727 06.19.2007 no virus found
Ewido 4.0 06.19.2007 Backdoor.Small.or
FileAdvisor 1 06.20.2007 No threat detected
Fortinet 2.91.0.0 06.19.2007 Multidr.JD!tr
F-Prot 4.3.2.48 06.19.2007 no virus found
F-Secure 6.70.13030.0 06.19.2007 no virus found
Ikarus T3.1.1.8 06.19.2007 MalwareScope.Trojan-Spy.BZub.1
Kaspersky 4.0.2.24 06.19.2007 no virus found
McAfee 5056 06.19.2007 MultiDropper-JD
Microsoft 1.2607 06.19.2007 no virus found
NOD32v2 2340 06.20.2007 probably unknown NewHeur_PE virus
Norman 5.80.02 06.19.2007 no virus found
Panda 9.0.0.4 06.20.2007 Trj/FireByPass.BA
Prevx1 V2 06.20.2007 no virus found
Sophos 4.18.0 06.12.2007 Mal/Behav-116
Sunbelt 2.2.907.0 06.16.2007 no virus found
Symantec 10 06.20.2007 Backdoor.Trojan
TheHacker 6.1.6.134 06.18.2007 no virus found
VBA32 [removed] 06.20.2007 suspected of Embedded.Backdoor.Win32.Small.or
VirusBuster 4.3.23:9 06.19.2007 no virus found
Webwasher-Gateway 6.0.1 06.19.2007 Trojan.Spy.Agent.RM
Aditional Information
File size: 51200 bytes
MD5: e10382f5de164a1204a3e635863ed16d
SHA1: f57905226aed7144ab9ccb145e766979150396c2
Bit9 info: http://fileadvisor.bit9.com/services/extin…4a3e635863ed16d
Here you go!
I noticed you are running XP's SP1, it is critical that you be able to update to SP2. Many exploits are patched with SP2 and many security features are added. Namely a firewall.
Do not update yet as updating an infected PC could cause problems. Once clean are you able to update? I'll provide a link.
Download and install AVG Anti-Spyware v7.5
- After download, double click on the file to launch the install process.
- Choose a language, click "OK" and then click "Next".
- Read the "License Agreement" and click "I Agree".
- Accept default installation path: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5, click "Next", then click "Install".
- After setup completes, click "Finish" to start the program automatically or launch AVG Anti-Spyware by double-clicking its icon on your desktop or in the system tray.
- The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. As AVG Anti-Spyware may interfere with some of our other fixes, we are temporarily disabling it's active protection features until your system is clean, then you can reenable them.
- Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".
- Go to Start > Run and type: services.msc
- Press "OK".
- Click the "Extended tab" and scroll down the list to find AVG Anti-Spyware guard.
- When you find the guard service, double-click on it.
- In the Properties Window > General Tab that opens, click the "Stop" button.
- From the drop-down menu next to "Startup Type", click on "Manual".
- Now click "Apply", then "OK" and close the Services window.
- Connect to the Internet, go back to AVG Anti-Spyware, select the "Update" button and click "Start update". Wait until you see the "Update successful" message. If you are having problems with the updater, manually update with the AVG Anti-Spyware Full database installer from here.
- Exit AVG Anti-Spyware when done - DO NOT perform a scan yet.
Download ATF Cleaner by Atribune and save it to your Desktop.
*=========================*
Now, enable the Show Hidden Folders option, like this:
Click Start.
Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.
*=========================*
Open Task Manger by pressing ctrl + alt + delete keys simultaneously
- Click Processes
- Click Image Name to Alphabetize the list
- Find
iasrecst.exe << and click on it - Click End Process
- Repeat steps for each process listed above
Close Task Manager
*========================*
Remove Programs
Please Click Start > Control Panel > Add/Remove Programs
Remove these programs by clicking Remove
Java 2 Runtime Environment, SE v1.4.2_01
Java 2 Runtime Environment, SE v1.4.2_05 ,,,, We'll update these later
If some programs listed are not present, please do not panic
*=========================*
Start HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O4 - HKCU\..\Run: [Microsoft Keyboard Enhance V2.0] C:\WINDOWS\iasrecst.exe
O4 - HKCU\..\Run: [Intel Audio Studio V2.0] C:\WINDOWS\fmideploy.exe
CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked
*=========================*
Start in Safe Mode
Please print the instructions below or copy and paste to Notepad since you will not have internet access while in Safe Mode.
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, continually press F8.
- Instead of Windows loading as normal, a menu should appear
- Select the first option, to run Windows in Safe Mode.
Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to and find the following files: if found, delete the following (some may not be present after previous steps):
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\fmideploy.exe0
*=========================*
Double-click ATF-Cleaner.exe to run the program.
Make sure that all browser windows are closed
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit to close ATF-Cleaner.
*=========================*
Scan with AVG Anti-Spyware as follows:
- Click on the "Scanner" button and choose the "Settings" tab.
- Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.
- Under "How to Scan?", "Possibly unwanted software", and What to Scan?" leave all the default settings.
- Under "Reports" select "Automatically generate report after every scan" and UNcheck "Only if threats were found".
- Click the "Scan" tab to return to scanning options.
- Click "Complete System Scan" to start.
- When the scan has finished you will be presented with a list of infected objects found. Click "Apply all actions" to place the files in Quarantine.
- Click on "Report" button to view all completed scans.
- Click on the most recent scan you just performed and select "Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt.
- Save to your desktop. A copy of each report will also be saved in C:\Documents and Settings\Your User Name\Application Data\Grisoft\AVG Antispyware 7.5\Reports
- Exit AVG Anti-Spyware when done, reboot normally and submit the log report in your next response.
Restart your PC in Normal Mode
*=========================*
Please update Java Runtime Environment
You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of perceived vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6.1 Update
- The current version can be downloaded from Sun here: http://java.sun.com/javase/downloads/index.jsp Scroll down the page to 'Java Runtime Environment (JRE) 6u1'
Selcted either Windows Online or Windows Offline download and press the 'Download' button. On the new web page, click the 'Accept License Agreement' button. Then select 'Windows Offline Installation, Multi-language' in the Windows Platform area just below the Accept button.
Please post the following;
New hijackthis log
AVG AntiSpyware log
If you are prepared to download SP2
Thanks,
Rogue
Scan saved at 3:36:00 PM, on 6/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer SP1 v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\wwSecure.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.exe -on
O4 - HKLM\..\Run: [LtcyCfgApply] "C:\Documents and Settings\Vincenzo\Desktop\latency tool pci\LtcyCfg.exe" /a
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] "C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] "C:\Program Files\ATI Multimedia\main\ATIDtct.EXE"
O4 - HKCU\..\Run: [Microsoft Keyboard Enhance V2.0] C:\WINDOWS\iasrecst.exe
O4 - HKCU\..\Run: [Intel Audio Studio V2.0] C:\WINDOWS\fmideploy.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab53083.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab53083.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab53083.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37680.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {AFAB176A-0D25-436A-8555-286F6D7AA388} (CRegFreezeScanModule Object) - http://www.actualresearch.com/files/rfscanax.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab53083.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab53852.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\System32\wwSecure.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
AVG scan looks like all boxes computer writing and i cant paste its contents. Report on desktop
Also one trace is left of this malware, shield has detected a dll file that was caused by the backdoor trojan.
Yes you can do this as yourself.Can you just clarify if its safe to work in safe mode as myself as the user and not as administrator? I started working on it and then realized it.
Do you have the AVG Antispyware report?
This sounds like a false positive. Can you give me the exact warning Spyware Guard is giving you? If so I can report it to the developer.Also spyware guard is asking me to keep or remove the BHO browser help object for the java you had me install, what do I do?
I'm not familiar with all of it's functions. There may be an option to disregard.
Other than that logs are looking better. How is the PC running now?
Rogue
Hi Marco25,
This sounds like a false positive. Can you give me the exact warning Spyware Guard is giving you? If so I can report it to the developer.Also spyware guard is asking me to keep or remove the BHO browser help object for the java you had me install, what do I do?
I'm not familiar with all of it's functions. There may be an option to disregard.
Other than that logs are looking better. How is the PC running now?
Rogue
Warning! A BHO HAS been added.
The following bho has been added to your system
(761497bb-d6f0-462c-b6eb-d4daf1d92d43)
Prog id N/A
File location C:\program files\java\ire1.6.0_01\bin\ssv.dll
Keep bho or remove bho (push buttons)
As for the pc it seems to be running smoother, a few detections by the shield which i removed and they never came back.
Can i uninstall avg or should i keep it, also file in quarantine what happens if i uninstall program, should i first remove all items from quarantine?
A few steps back there was some options you had me change example show os hidden system files, should i go back and re put these settings to default, or do i leave everything as is?
Press the option to keep the BHO since it is a legit entry. Spyware Guard will monitor your registry for changes and prompt you when they appear. Looks like it’s workingKeep bho or remove bho (push buttons)
It’s in your system restore and we will clear that shortly.New threat detection
C:\System Volume Information\_restore{DB404D20-85F2-4DCA-84EA-CF82EA31E3F0}\RP1060\A0158572.dll
As for the previous steps, we’ll do those shortly when we’re all done.
Before we do that I need you to now update from XP’s SP1 to SP2 using the link below. After updating I would like to see a new hijackthis log just to make sure nothing has found it’s way in due to the unpatched exploits in SP1.
http://www.microsoft.com/windowsxp/sp2/default.mspx
Rogue
Scan saved at 3:08:03 PM, on 6/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer SP2 v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\wwSecure.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.msn.ca
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.exe -on
O4 - HKLM\..\Run: [LtcyCfgApply] "C:\Documents and Settings\Vincenzo\Desktop\latency tool pci\LtcyCfg.exe" /a
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] "C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] "C:\Program Files\ATI Multimedia\main\ATIDtct.EXE"
O4 - HKCU\..\Run: [Microsoft Keyboard Enhance V2.0] C:\WINDOWS\iasrecst.exe
O4 - HKCU\..\Run: [Intel Audio Studio V2.0] C:\WINDOWS\fmideploy.exe
O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "Vincenzo"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
015 - Trusted Zone: memberservices.passport.net
O15 - Trusted Zone: www.screensavers.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab53083.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab53083.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab53083.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37680.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {AFAB176A-0D25-436A-8555-286F6D7AA388} (CRegFreezeScanModule Object) - http://www.actualresearch.com/files/rfscanax.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab53083.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab53852.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\System32\wwSecure.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
Not sure what happened but you have reinfected yourself. Please keep the surfing to a minimum until we get you all cleaned up and secure. This is just an example of how fast an unpatched system can become infected again.
Please run a GMER Rootkit scan:
Download GMER's application from here:
http://www.gmer.net/gmer.zip
Unzip it and start the GMER.exe
Click the Rootkit tab and click the Scan button.
Once done, click the Copy button.
This will copy the results to your clipboard.
Paste the results in your next reply.
Warning ! Please, do not select the "Show all" checkbox during the scan.
If you're having problems with running GMER.exe, try it in safe mode.
This tools works in safe mode. Other rootkitrevealers don't.
*=========================*
Open AVG AntiSpyware and update the definitions database
*=========================*
Start HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:
O4 - HKCU\..\Run: [Microsoft Keyboard Enhance V2.0] C:\WINDOWS\iasrecst.exe
O4 - HKCU\..\Run: [Intel Audio Studio V2.0] C:\WINDOWS\fmideploy.exe
015 - Trusted Zone: memberservices.passport.net
O15 - Trusted Zone: www.screensavers.com
CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked
*=========================*
Start in Safe Mode
Please print the instructions below or copy and paste to Notepad since you will not have internet access while in Safe Mode.
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, continually press F8.
- Instead of Windows loading as normal, a menu should appear
- Select the first option, to run Windows in Safe Mode.
Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to and find the following files: if found, delete the following (some may not be present after previous steps):
C:\WINDOWS\iasrecst.exe
C:\WINDOWS\fmideploy.exe
*=========================*
Scan with AVG Anti-Spyware as follows:
- Click on the "Scanner" button and choose the "Settings" tab.
- Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.
- Under "How to Scan?", "Possibly unwanted software", and What to Scan?" leave all the default settings.
- Under "Reports" select "Automatically generate report after every scan" and UNcheck "Only if threats were found".
- Click the "Scan" tab to return to scanning options.
- Click "Complete System Scan" to start.
- When the scan has finished you will be presented with a list of infected objects found. Click "Apply all actions" to place the files in Quarantine.
- Click on "Report" button to view all completed scans.
- Click on the most recent scan you just performed and select "Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt.
- Save to your desktop. A copy of each report will also be saved in C:\Documents and Settings\Your User Name\Application Data\Grisoft\AVG Antispyware 7.5\Reports
- Exit AVG Anti-Spyware when done, reboot normally and submit the log report in your next response.
Restart your PC in Normal Mode
*=========================*
Run Kapersky Online AV Scanner
Using Internet Explore Go to http://www.kaspersky.com/virusscanner and click the Kaspersky Online Scanner button.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
- Read the Requirements and limitations before you click Accept.
- Allow the ActiveX download if necessary.
- Once the database has downloaded, click Next.
- Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
- Click on "My Computer" and then put the kettle on!
- When the scan has completed, click Save Report As…
- Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
- Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
*=========================*
Create Uninstall List with Hijackthis
This is how you do that:
Open HiJackThis
Click on the tab "Open the Misc Tools Session"
Click on the Box that says "Uninstall Manager"
Click on the button "Save list"
Copy and past the List from notepad into your post
*=========================*
Please post the following;
GMER Log
AVG AntiSpware log
New hijackthis log
New uninstall list
Thanks,
Rogue
GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-06-22 13:59:11
Windows 5.1.2600
—- System - GMER 1.0.12 —-
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwClose
SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwCreateKey
SSDT d346bus.sys ZwCreatePagingFile
SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcessEx
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateSection
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwCreateSymbolicLinkObject
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwCreateThread
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwDeleteKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwDeleteValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDuplicateObject
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwFlushKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwInitializeRegistry
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwLoadKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwLoadKey2
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwNotifyChangeKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwOpenKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwOpenSection
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenThread
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwQueryKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwQueryMultipleValueKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwQuerySystemInformation
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwQueryValueKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRequestWaitReplyPort
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwRestoreKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwResumeThread
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwSaveKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwSetContextThread
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwSetInformationFile
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwSetInformationKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwSetInformationProcess
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwSetSecurityObject
SSDT d346bus.sys ZwSetSystemPowerState
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwSetValueKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwSuspendThread
SSDT \SystemRoot\System32\vsdatant.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwUnloadKey
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys ZwWriteVirtualMemory
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[284]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[285]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[286]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[287]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[288]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[289]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[290]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[291]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[292]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[293]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[294]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[295]
SSDT \??\C:\WINDOWS\System32\drivers\klif.sys SSDT[296]
—- Kernel code sections - GMER 1.0.12 —-
.text ntoskrnl.exe!KiDispatchInterrupt + 100 8052F950 7 Bytes JMP A9CB83C0 \??\C:\WINDOWS\System32\drivers\klif.sys
? srescan.sys The system cannot find the file specified.
.text ntoskrnl.exe!KiDispatchInterrupt + 100 8052F950 7 Bytes JMP A9CB83C0 \??\C:\WINDOWS\System32\drivers\klif.sys
—- User code sections - GMER 1.0.12 —-
.text C:\WINDOWS\explorer.exe[1924] SHELL32.dll!StrStrW + FFE6AB34 773E85A8 4 Bytes [ 40, 02, 85, 71 ]
—- Devices - GMER 1.0.12 —-
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 8673E910
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_READ 86462E50
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_READ 86462E50
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [A9D9E8A0] vsdatant.sys
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 86415390
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 86415390
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 864BBEF0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 86415390
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 86415390
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE_NAMED_PIPE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CLOSE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_READ 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_WRITE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_EA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_EA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_FLUSH_BUFFERS 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_VOLUME_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_VOLUME_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DIRECTORY_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_FILE_SYSTEM_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DEVICE_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_INTERNAL_DEVICE_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SHUTDOWN 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_LOCK_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CLEANUP 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE_MAILSLOT 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_SECURITY 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_SECURITY 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_POWER 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SYSTEM_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DEVICE_CHANGE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_QUOTA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_QUOTA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_PNP 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_NAMED_PIPE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_READ 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_WRITE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_EA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_EA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FLUSH_BUFFERS 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_VOLUME_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_VOLUME_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DIRECTORY_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FILE_SYSTEM_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SHUTDOWN 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_LOCK_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLEANUP 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_MAILSLOT 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_SECURITY 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_SECURITY 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CHANGE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_QUOTA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_QUOTA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 8640F5F0
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE_NAMED_PIPE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CLOSE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_READ 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_WRITE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_EA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_EA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_FLUSH_BUFFERS 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_VOLUME_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_VOLUME_INFORMATION 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DIRECTORY_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_FILE_SYSTEM_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DEVICE_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_INTERNAL_DEVICE_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SHUTDOWN 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_LOCK_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CLEANUP 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE_MAILSLOT 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_SECURITY 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_SECURITY 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_POWER 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SYSTEM_CONTROL 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DEVICE_CHANGE 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_QUOTA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_QUOTA 8640F5F0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_PNP 8640F5F0
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 86415390
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 86415390
Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 86227A60
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [A9D9E8A0] vsdatant.sys
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 86469C88
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [A9D9E8A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [A9D9E8A0] vsdatant.sys
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 86469C88
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 86346170
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 862E9E98
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_CREATE 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_CLOSE 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_READ 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_WRITE 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_SET_INFORMATION 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_QUERY_EA 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_SET_EA 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_SHUTDOWN 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_CLEANUP 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_SET_SECURITY 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_POWER 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_SET_QUOTA 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1Port2Path0Target0Lun0 IRP_MJ_PNP 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_CREATE 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_CREATE_NAMED_PIPE 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_CLOSE 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_READ 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_WRITE 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_QUERY_INFORMATION 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_SET_INFORMATION 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_QUERY_EA 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_SET_EA 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_FLUSH_BUFFERS 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_QUERY_VOLUME_INFORMATION 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_SET_VOLUME_INFORMATION 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_DIRECTORY_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_FILE_SYSTEM_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_DEVICE_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_INTERNAL_DEVICE_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_SHUTDOWN 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_LOCK_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_CLEANUP 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_CREATE_MAILSLOT 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_QUERY_SECURITY 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_SET_SECURITY 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_POWER 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_SYSTEM_CONTROL 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_DEVICE_CHANGE 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_QUERY_QUOTA 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_SET_QUOTA 86397E30
Device \Driver\d346prt \Device\Scsi\d346prt1 IRP_MJ_PNP 86397E30
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 861F6DA8
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 861F6DA8
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_READ 861F6DA8
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_READ 861F6DA8
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_READ 861F6DA8
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 8647BBD8
—- Modules - GMER 1.0.12 —-
Module _________ F7796000-F77AC000 (90112 bytes)
—- Threads - GMER 1.0.12 —-
Thread 4:136 865FED00
Thread 4:140 865FED00
Thread 4:144 865CF430
Thread 4:148 865CF430
Thread 4:152 865CF430
Thread 4:412 865FED00
Thread 4:568 865FED00
—- EOF - GMER 1.0.12 —-
Other reports to follow
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI