This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Slow and sometimes useless computer

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently my PC has been moving much slower, internet pages almost always need to be refreshed in order to fully load, attempts at downloads are fruitless, and sometimes I am redirected to unwanted websites when trying to access intended ones. My CPU usage spikes from 2% to 68% and back down frequently. I regularly run AdAware, Spybot S&D, EZ Trust Anti-Virus and Pest Patrol. The only thing found recently on those scans was CiD Help and WinZix found and quarantined by Pest Patrol.

Help!?

Here is my Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 6:05:50 PM, on 10/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\V0330Mon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
O4 - HKLM\..\Run: [V0330Mon.exe] C:\WINDOWS\V0330Mon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15031/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hi mnemenya,

Please open HijackThis, choose Do a system scan only and place a checkmark next to the following line:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Download Deckard's System Scanner (DSS)
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply
Once complete, please post both DSS logs, you won't need to produce a new HijackThis log as DSS produces one for you.
Thanks for your attention to this! Here goes…

Deckard's System Scanner v20071014.68
Run by [removed] on 2007-10-25 23:03:58
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
47: 2007-10-26 03:04:07 UTC - RP124 - Deckard's System Scanner Restore Point
46: 2007-10-26 02:52:42 UTC - RP123 - Removed MSXML 4.0 SP2 (KB927978)
45: 2007-10-26 02:52:12 UTC - RP122 - Removed MSXML 4.0 SP2 (KB936181)
44: 2007-10-26 02:51:45 UTC - RP121 - Removed MSXML 4.0 SP2 Parser and SDK
43: 2007-10-26 02:41:57 UTC - RP120 - Removed Adobe Reader 8


– First Restore Point –
1: 2007-09-19 14:48:45 UTC - RP78 - Installed resident evil 4


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as Josh.exe) ————————————————

Unable to find log (file not found); running clone.
– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-10-25 23:06:05
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\iSafe.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Common Files\stardock\SDMCP.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRid.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
C:\WINDOWS\V0330Mon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Josh\Local Settings\Temporary Internet Files\Content.IE5\7S11JW4S\dss[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?hl=en
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar3.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
O4 - HKLM\..\Run: [V0330Mon.exe] C:\WINDOWS\V0330Mon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} () - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab Class) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/flash…ent/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15031/CTPID.cab
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\Program Files\Common Files\stardock\MCPCore.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\iSafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


–
End of file - 7757 bytes

– HijackThis Fixed Entries (C:\PROGRA~1\HIJACK~1\backups\) ——————–

backup-20070708-093655-308 O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/…login-devel.cab
backup-20070709-181633-211 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
backup-20070709-181633-222 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
backup-20070709-181633-242 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
backup-20070709-181633-397 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
backup-20070908-201245-701 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
backup-20070908-201245-908 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
backup-20071025-230032-597 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 OMCI - c:\windows\system32\drivers\omci.sys
Hi mnemenya,

Please do an online scan with Kaspersky:

Open Kaspersky Online Scanner in Internet Explorer

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save as Text button and save the file to your desktop
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

————————————————————————

Download Gmer to your Desktop from here:
http://www.gmer.net/gmer.zip
  • Unzip the program onto your Desktop
  • Disconnect from internet and close all running programs
  • Double click gmer.exe, let the gmer.sys driver load if asked
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say OK
  • If there is no warning, then check that the Rootkit tab is selected and click the Scan button - don't change any settings before you do so
  • Once the scan is complete, click the Copy button
  • Open Notepad and hit Ctrl+V to paste the log and then save the log to your desktop
————————————————————————

Once complete, please post the Kaspersky report, the GMER log and a new HijackThis log.
Ok - here's what you asked for:

Logfile of HijackThis v1.99.1
Scan saved at 12:33:05 AM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\V0330Mon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
O4 - HKLM\..\Run: [V0330Mon.exe] C:\WINDOWS\V0330Mon.exe
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15031/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, October 26, 2007 11:37:36 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/10/2007
Kaspersky Anti-Virus database records: 446899
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\

Scan Statistics:
Total number of scanned objects: 52579
Number of viruses found: 3
Number of infected objects: 3
Number of suspicious objects: 0
Duration of the scan process: 01:07:43

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Josh\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Josh\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Josh\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Josh\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Josh\Local Settings\History\History.IE5\MSHist012007102620071027\index.dat Object is locked skipped
C:\Documents and Settings\Josh\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Josh\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Josh\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2007-10-26.21-42-03.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{C89FE2A1-5F73-4CF8-A636-823D8790CC5B}\RP126\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\JOSH-MHV5BSW1V2.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{D0AED90F-66AD-4508-AFE1-D9198397D0C8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT02158.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\_OTMoveIt\MovedFiles\Documents and Settings\Owner\Desktop\uninstall6_90.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\_OTMoveIt\MovedFiles\WINDOWS\Downloaded Program Files\gsda.dll Infected: not-a-virus:Downloader.Win32.SpyGame skipped
C:\_OTMoveIt\MovedFiles\WINDOWS\Temp\kdcfk.ren Infected: Packed.Win32.PolyCrypt.b skipped

Scan process completed.


GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-10-27 00:28:10
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.13 —-

SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort
SSDT sptd.sys ZwCreateKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey
SSDT sptd.sys ZwOpenKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey

—- Kernel code sections - GMER 1.0.13 —-

? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload F83E962C 5 Bytes JMP 829BE780
? System32\Drivers\aeq2fq2l.SYS The system cannot find the file specified.
? System32\Drivers\ah0z06qy.SYS The system cannot find the file specified.

—- Kernel IAT/EAT - GMER 1.0.13 —-

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F8AF3886] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F8AF3832] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F8B15892] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F8AF3886] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F8ADDAD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F8ADDC1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F8ADDB9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F8ADE748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F8ADE61E] sptd.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F8AF2ACA] sptd.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [EFD47160] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [EFD47160] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [EFD47160] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateFile] [EFD61ED0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [EFD47160] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [EFD47160] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys

—- Devices - GMER 1.0.13 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 82B691E8

AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F88B4F1C] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F88B50A4] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F88B5240] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F88B5010] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F88B4FF0] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F88B4EB6] VET-REC.SYS

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 8294F7A0
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [EFD61800] vsdatant.sys
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 8290C1E8
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_CREATE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_CREATE_NAMED_PIPE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_CLOSE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_READ [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_WRITE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_QUERY_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SET_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_QUERY_EA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SET_EA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_FLUSH_BUFFERS [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_QUERY_VOLUME_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SET_VOLUME_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_DIRECTORY_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_FILE_SYSTEM_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_DEVICE_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_INTERNAL_DEVICE_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SHUTDOWN [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_LOCK_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_CLEANUP [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_CREATE_MAILSLOT [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_QUERY_SECURITY [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SET_SECURITY [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_POWER [F8AEC712] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SYSTEM_CONTROL [F8B0F2C8] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_DEVICE_CHANGE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_QUERY_QUOTA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SET_QUOTA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_PNP [F8B10238] sptd.sys
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 8290C1E8
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_CREATE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_CREATE_NAMED_PIPE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_CLOSE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_READ [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_WRITE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_QUERY_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SET_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_QUERY_EA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SET_EA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_FLUSH_BUFFERS [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_QUERY_VOLUME_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SET_VOLUME_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_DIRECTORY_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_FILE_SYSTEM_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_DEVICE_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_INTERNAL_DEVICE_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SHUTDOWN [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_LOCK_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_CLEANUP [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_CREATE_MAILSLOT [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_QUERY_SECURITY [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SET_SECURITY [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_POWER [F8AEC712] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SYSTEM_CONTROL [F8B0F2C8] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_DEVICE_CHANGE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_QUERY_QUOTA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SET_QUOTA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_PNP [F8B10238] sptd.sys
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP 8290C1E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_CREATE 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_CLOSE 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_POWER 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_PNP 829871E8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [EFD61800] vsdatant.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 82BD71E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 829725D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CLOSE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_POWER 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SYSTEM_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_PNP 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CLOSE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_INTERNAL_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_POWER 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SYSTEM_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_PNP 82B6A1E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CLOSE 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_READ 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_WRITE 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_FLUSH_BUFFERS 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_INTERNAL_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SHUTDOWN 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_POWER 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SYSTEM_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_PNP 829725D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 829B17A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 829B17A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 829B17A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 829B17A0
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [EFD61800] vsdatant.sys
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_PNP 8290C1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_CREATE 829B17A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_CLOSE 829B17A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_INTERNAL_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_CLEANUP 829B17A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_PNP 829B17A0
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_PNP 8290C1E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 829B21E8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [EFD61800] vsdatant.sys
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_PNP 8290C1E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 829B21E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_CREATE 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_CLOSE 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_DEVICE_CONTROL 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_POWER 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_SYSTEM_CONTROL 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_PNP 829871E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 82BD71E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_CREATE 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_CLOSE 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_DEVICE_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_INTERNAL_DEVICE_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_POWER 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_SYSTEM_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_PNP 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_CREATE 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_CLOSE 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_POWER 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_PNP 829211E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_CREATE 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_CLOSE 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_DEVICE_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_INTERNAL_DEVICE_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_POWER 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_SYSTEM_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_PNP 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_CREATE 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_CLOSE 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_POWER 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_PNP 828511E8
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_READ 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 8294F7A0

AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [F88B4F1C] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [F88B50A4] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [F88B5240] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [F88B5010] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [F88B4FF0] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [F88B4EB6] VET-REC.SYS

Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 829A9568

—- EOF - GMER 1.0.13 —-
Here you go:

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-10-27 00:28:10
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.13 —-

SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort
SSDT sptd.sys ZwCreateKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey
SSDT sptd.sys ZwOpenKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey

—- Kernel code sections - GMER 1.0.13 —-

? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload F83E962C 5 Bytes JMP 829BE780
? System32\Drivers\aeq2fq2l.SYS The system cannot find the file specified.
? System32\Drivers\ah0z06qy.SYS The system cannot find the file specified.

—- Kernel IAT/EAT - GMER 1.0.13 —-

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F8AF3886] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F8AF3832] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F8B15892] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F8AF3886] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F8ADDAD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F8ADDC1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F8ADDB9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F8ADE748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F8ADE61E] sptd.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F8AF2ACA] sptd.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [EFD47160] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [EFD47160] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [EFD47160] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateFile] [EFD61ED0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [EFD47160] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [EFD47000] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [EFD47160] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [EFD47390] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [EFD47250] \SystemRoot\System32\vsdatant.sys

—- Devices - GMER 1.0.13 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 82B691E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 82B691E8

AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F88B4F1C] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F88B50A4] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F88B5240] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F88B5010] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F88B4FF0] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F88B4EB6] VET-REC.SYS

Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 8294F7A0
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 8294F7A0
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [EFD61800] vsdatant.sys
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 8290C1E8
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_CREATE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_CREATE_NAMED_PIPE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_CLOSE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_READ [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_WRITE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_QUERY_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SET_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_QUERY_EA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SET_EA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_FLUSH_BUFFERS [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_QUERY_VOLUME_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SET_VOLUME_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_DIRECTORY_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_FILE_SYSTEM_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_DEVICE_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_INTERNAL_DEVICE_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SHUTDOWN [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_LOCK_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_CLEANUP [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_CREATE_MAILSLOT [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_QUERY_SECURITY [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SET_SECURITY [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_POWER [F8AEC712] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SYSTEM_CONTROL [F8B0F2C8] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_DEVICE_CHANGE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_QUERY_QUOTA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_SET_QUOTA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000044 IRP_MJ_PNP [F8B10238] sptd.sys
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 8290C1E8
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_CREATE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_CREATE_NAMED_PIPE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_CLOSE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_READ [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_WRITE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_QUERY_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SET_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_QUERY_EA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SET_EA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_FLUSH_BUFFERS [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_QUERY_VOLUME_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SET_VOLUME_INFORMATION [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_DIRECTORY_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_FILE_SYSTEM_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_DEVICE_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_INTERNAL_DEVICE_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SHUTDOWN [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_LOCK_CONTROL [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_CLEANUP [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_CREATE_MAILSLOT [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_QUERY_SECURITY [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SET_SECURITY [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_POWER [F8AEC712] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SYSTEM_CONTROL [F8B0F2C8] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_DEVICE_CHANGE [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_QUERY_QUOTA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_SET_QUOTA [F8B12AD2] sptd.sys
Device \Driver\PCI_NTPNP9822 \Device\000045 IRP_MJ_PNP [F8B10238] sptd.sys
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP 8290C1E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_CREATE 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_CLOSE 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_POWER 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 829871E8
Device \Driver\usbehci \Device\USBPDO-3 IRP_MJ_PNP 829871E8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [EFD61800] vsdatant.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 82BD71E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 829725D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CLOSE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_POWER 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SYSTEM_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_PNP 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CLOSE 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_INTERNAL_DEVICE_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_POWER 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SYSTEM_CONTROL 82B6A1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_PNP 82B6A1E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CREATE 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_CLOSE 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_READ 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_WRITE 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_FLUSH_BUFFERS 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_INTERNAL_DEVICE_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SHUTDOWN 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_POWER 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_SYSTEM_CONTROL 829725D8
Device \Driver\Cdrom \Device\CdRom3 IRP_MJ_PNP 829725D8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 829B17A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 829B17A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 829B17A0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 829B17A0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 829B17A0
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [EFD61800] vsdatant.sys
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_PNP 8290C1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_CREATE 829B17A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_CLOSE 829B17A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_INTERNAL_DEVICE_CONTROL 829B17A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_CLEANUP 829B17A0
Device \Driver\NetBT \Device\NetBT_Tcpip_{70F7F137-8C9B-46CF-B906-808F2C162261} IRP_MJ_PNP 829B17A0
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_PNP 8290C1E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 829B21E8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [EFD61800] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [EFD61800] vsdatant.sys
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CREATE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CLOSE 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_POWER 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL 8290C1E8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_PNP 8290C1E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 829B21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 829B21E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_CREATE 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_CLOSE 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_DEVICE_CONTROL 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_POWER 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_SYSTEM_CONTROL 829871E8
Device \Driver\usbehci \Device\USBFDO-3 IRP_MJ_PNP 829871E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 82BD71E8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 82BD71E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_CREATE 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_CLOSE 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_DEVICE_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_INTERNAL_DEVICE_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_POWER 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_SYSTEM_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1 IRP_MJ_PNP 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_CREATE 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_CLOSE 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_POWER 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 829211E8
Device \Driver\aeq2fq2l \Device\Scsi\aeq2fq2l1Port3Path0Target0Lun0 IRP_MJ_PNP 829211E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_CREATE 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_CLOSE 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_DEVICE_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_INTERNAL_DEVICE_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_POWER 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_SYSTEM_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1 IRP_MJ_PNP 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_CREATE 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_CLOSE 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_POWER 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 828511E8
Device \Driver\ah0z06qy \Device\Scsi\ah0z06qy1Port2Path0Target0Lun0 IRP_MJ_PNP 828511E8
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_READ 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 8294F7A0
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 8294F7A0

AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [F88B4F1C] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [F88B50A4] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [F88B5240] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [F88B5010] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [F88B4FF0] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [F88B4EB6] VET-REC.SYS
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [F88B4EB6] VET-REC.SYS

Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 829A9568
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 829A9568

—- EOF - GMER 1.0.13 —-

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, October 26, 2007 11:37:36 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/10/2007
Kaspersky Anti-Virus database records: 446899
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\

Scan Statistics:
Total number of scanned objects: 52579
Number of viruses found: 3
Number of infected objects: 3
Number of suspicious objects: 0
Duration of the scan process: 01:07:43

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Josh\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Josh\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Josh\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Josh\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Josh\Local Settings\History\History.IE5\MSHist012007102620071027\index.dat Object is locked skipped
C:\Documents and Settings\Josh\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Josh\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Josh\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2007-10-26.21-42-03.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{C89FE2A1-5F73-4CF8-A636-823D8790CC5B}\RP126\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\JOSH-MHV5BSW1V2.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{D0AED90F-66AD-4508-AFE1-D9198397D0C8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT02158.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\_OTMoveIt\MovedFiles\Documents and Settings\Owner\Desktop\uninstall6_90.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\_OTMoveIt\MovedFiles\WINDOWS\Downloaded Program Files\gsda.dll Infected: not-a-virus:Downloader.Win32.SpyGame skipped
C:\_OTMoveIt\MovedFiles\WINDOWS\Temp\kdcfk.ren Infected: Packed.Win32.PolyCrypt.b skipped

Scan process completed.

Logfile of HijackThis v1.99.1
Scan saved at 12:33:05 AM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\V0330Mon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
O4 - HKLM\..\Run: [V0330Mon.exe] C:\WINDOWS\V0330Mon.exe
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15031/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hi mnemenya,

Please open HijackThis, choose Do a system scan only and place a checkmark next to the following lines:

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Then please delete this folder:

C:\_OTMoveIt


Your Java is out of date and is now a security risk. Please remove this program via Add/Remove Programs:
Java™ 6 Update 2
You can get the latest update (version 6 update 3) from here

Your version of Spybot S&D is now outdated. You can get the latest version from here:
http://www.safer-networking.org/en/download/

I haven't seen anything which indicates a malware infection on your machine, please try the following to see if we can discover the cause of the CPU usage problem:

Try using Process Explorer to monitor resources on your system. Run Process Explorer minimized and when a slowdown occurs, switch to the Process Explorer window to see which process is using a high percentage of CPU.

The other symptoms you report sound like web browsing issues. Please make a note of any redirections that occur and what unwanted websites you are sent to - this may help narrow down the problem. Please try downloading something (like the newer versions of Java or Spybot) and note exactly what happens.

Once complete, please post a new HijackThis log, let me know if you found anything with Process Explorer and if you have any further information about the browsing issues. If you have any other symptoms to report, please post them too.
In Add/Remove Programs I did see Java 6 Update 2 and deleted it, but I also saw that I already had Java 6 Update 3 listed as well, so I did not download it again. I did download the new version of Spybot S&D, and found that when I tried to save it, instead of run it, the progress would quickly go to 5% or 50% done, and then just freeze up. At one point it was aborted because it said the connection to the server was reset. I have been trying to download Skype software as well, and always Run it, but can never get past more than 7% done. It looks like the redirection to other websites has stopped at this point, but I did try to access OldNavy.com and an error came up immediately saying that my cookies needed to be enabled. I did enable them, but still came up with the same message afterward and was unable to fully load the site.

When looking at Process Explorer, I see that System Idle Process stays at about 95%, until every 2 or 3 seconds it decreases to about 40% when the process vsmon.exe (TrueVector Service from Zone Labs Inc) spikes to anywhere from 25% to 65%. Not sure if any of this is helpful, but its all I can see at this point. Here's my newest HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 10:26:15 AM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\V0330Mon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
O4 - HKLM\..\Run: [V0330Mon.exe] C:\WINDOWS\V0330Mon.exe
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15031/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hi mnemenya,

As you can see the Process Explorer results show that Zone Alarm is pretty busy, I suggest you try removing the program temporarily to see if that resolves the CPU and/or the connection issues.

A software firewall is important for security but as long as the Windows firewall is active you can safely access the internet for testing purposes. If you find that it is the cause then you should consider using a different product such as Comodo.

If you choose to try removing Zone Alarm and you have paid for the product, you should check you have your product key so you can reinstall it. Also, after it has been removed and before connecting to the internet make sure the Windows firewall is active as follows:
  • Press Start->Run, type wscui.cpl and press OK
  • Click Windows Firewall, make sure On is selected and press OK
As this does not appear to be a malware problem, for further assistance I recommend you post in the Browsers, Internet and email forum here at WhatTheTech - the experts there specialize in these types of problems and I'm sure they'll resolve the problems swiftly for you.

Here are some tips to help you keep your computer clean:

Operating system vulnerabilities can easily be exploited by malware so please ensure your operating system is automatically kept up to date by using Windows Update:
Go to Start->Control Panel->Automatic Updates
Select Automatic and select a suitable schedule
Also, check that your antivirus and antispyware programs are set to automatically update daily.

You have a good antivirus program installed, however I recommend you also install antispyware software with real-time capabilities - this will protect you from a wider range of malware and also that it will protect you from system changes and spyware while you are working, not just removing malware after it has been installed. There are a range of paid-for and free packages available, a free one I can recommend is Windows Defender, available here:
http://www.microsoft.com/athome/security/s…re/default.mspx

Spywareblaster is a free program which prevents the download and installation of Internet Explorer ActiveX based malware by immunizing your system against it. You can download Spywareblaster from here and a tutorial to help you get started is available here.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins orActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
I will definitely take your advice and post my browser problems in another forum. Before we finish here though, I was surprised to see that it was Zone Alarm running so often, especially because I didn't think I had been using it at all! I switched over to EZ Trust Armor for all of my antivirus and firewall needs over a year ago, and thought I had removed Zone Alarm from my pc. I just went into Add/Remove Programs to remove it now, and it is not listed. So then I ran a search for it and found 2 file folders but no applications. Any advice on how to track it down and get rid of it once and for all?
Hi mnemenya,

Looking into it, it appears that the EZ Trust uses the Zone Alarm program for it's firewall, so although vsmon.exe is a Zone Alarm process, when we see it working it's actually is the EZ Trust firewall working. I should have seen this so I'm sorry about that. In this case you could try temporarily de-activating the EZ Trust firewall to see if that helps, however please make sure the Windows firewall is active while you are testing.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI