Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Großes Problem mit W32.Myzor.FK@yf (https://www.trojaner-board.de/45403-grosses-problem-w32-myzor-fk-yf.html)

Sunny 04.11.2007 19:44

Zitat:

Zitat von Hannibal252 (Beitrag 303125)
Ich habs geschaft mit diesem Gmer Programm n Scan vorzunehmen. Doch der ist zu lang. Der Passt hier nicht rein -.-

Dann teile den Report auf 2-3 Beiträge auf, ich suche mir das dann zusammen. ;)


Zitat:

Zu den einträgen in den Internetoptionen. Da Steht definitiv nix mehr von dieser DNS. Ich habe keine Ahnung wo das her kommen soll.
Diese Einträge kommen von dem Trojaner, dieser hat eine zusätzlich Verbindung bzw. Umleitung eingerichtet.
Meist ist der o.g. Trojaner mit Rootkit-Technologie ausgestattet und versteckt sich tief im System.

Es wird sehr schwierig dieses wieder zu entfernen, unter XP würde das schneller gehen, aber unter VISTA ist es für alle Helfer hier an Board noch Neuland. :schmoll:

Hannibal252 04.11.2007 19:50

Hmm und was kan das jetzt genau anrichten?

Hier der scan. Muss ihn in 5 Teile teilen.

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-11-04 19:39:14
Windows 6.0.6000

---- System - GMER 1.0.13 ----
SSDT 9C4B41E0 ZwAlertResumeThread
SSDT A1291460 ZwAlertThread
SSDT 8E021320 ZwAllocateVirtualMemory
SSDT 8888EF30 ZwConnectPort
SSDT 9F7EEE28 ZwCreateMutant
SSDT 8E021368 ZwCreateThread
SSDT A1223B20 ZwFreeVirtualMemory
SSDT 9877D428 ZwImpersonateAnonymousToken
SSDT 9C5EC090 ZwImpersonateThread
SSDT 9AD88EB8 ZwMapViewOfSection
SSDT 9C51E070 ZwOpenEvent
SSDT 9AB58190 ZwOpenProcess
SSDT 9AC71A68 ZwOpenProcessToken
SSDT 9AB58195 ZwOpenThread
SSDT 9F7D4608 ZwOpenThreadToken
SSDT 9F6808B8 ZwResumeThread
SSDT A122A3F8 ZwSetContextThread
SSDT 9AD88D60 ZwSetInformationProcess
SSDT 9F7D44B0 ZwSetInformationThread
SSDT 9C40EDE0 ZwSuspendProcess
SSDT 9AD1CDC8 ZwSuspendThread
SSDT 8890ED90 ZwTerminateProcess
SSDT A122BEC0 ZwTerminateThread
SSDT 9AC0EA98 ZwUnmapViewOfSection
SSDT 8E021290 ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.13 ----

? C:\Windows\System32\Drivers\sptd.sys Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
.text USBPORT.SYS!DllUnload 8B9F2ACF 5 Bytes JMP 861F11C8
? C:\Windows\system32\Drivers\RKREVEAL150.SYS Das System kann die angegebene Datei nicht finden.

---- Kernel IAT/EAT - GMER 1.0.13 ----

IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [8071A61E] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80719AD4] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [8071A748] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [80719B9C] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [80719C1A] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [8072EACA] \SystemRoot\System32\Drivers\sptd.sys

---- User IAT/EAT - GMER 1.0.13 ----

IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [6F3B1923] C:\Windows\AppPatch\AcLayers.DLL
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\System32\USERENV.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\System32\Secur32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4524] @ C:\Windows\System32\SAMLIB.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [6F3B1923] C:\Windows\AppPatch\AcLayers.DLL
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\System32\USERENV.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\System32\Secur32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Windows\System32\rundll32.exe[4768] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW] [6C5E88F6] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW] [6C5E8B2F] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW] [6C5E8A65] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [6C5EA391] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [6C5E9815] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [6C5E9639] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegSetValueExW] [6C5E9BA7] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW] [6C5E88F6] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [6C5EA391] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] [6C5E8A65] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!OpenFile] [6C5E8C84] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!CopyFileW] [6C5E88F6] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!DeleteFileW] [6C5E8A65] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!MoveFileW] [6C5E8B2F] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!CreateFileW] [6C5EA391] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!CreateFileW] [6C5EA391] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegCreateKeyExA] [6C5E952A] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegSetValueExA] [6C5E9AFB] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExA] [6C5E9741] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExW] [6C5E9815] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [6C5E2E2C] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW] [6C5E8A65] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] [6C5E2C16] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] [6C5EA391] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] [6C5E2A18] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!AccessCheck] [6C5E883A] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW] [6C5E9A53] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteValueW] [6C5E9CF9] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [6C5E9815] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueExW] [6C5E9BA7] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [6C5E9639] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [6C5E9741] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] [6C5E8A65] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW] [6C5E8FA6] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [6C5EA391] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA] [6C5E8F4E] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [6C5EA275] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegSetValueExA] [6C5E9AFB] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [6C5E952A] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [6C5E9741] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteValueA] [6C5E9C57] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [6C5E9639] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [6C5E9815] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegSetValueExW] [6C5E9BA7] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteValueW] [6C5E9CF9] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\NETAPI32.dll [ADVAPI32.dll!RegSetValueExW] [6C5E9BA7] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\NETAPI32.dll [ADVAPI32.dll!SetFileSecurityW] [6C5E9DF4] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\NETAPI32.dll [ADVAPI32.dll!RegOpenKeyExA] [6C5E9741] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\NETAPI32.dll [ADVAPI32.dll!RegCreateKeyExW] [6C5E9639] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\NETAPI32.dll [ADVAPI32.dll!RegOpenKeyExW] [6C5E9815] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\NETAPI32.dll [ADVAPI32.dll!AccessCheck] [6C5E883A] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!CreateFileW] [6C5EA391] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!MoveFileExW] [6C5E8C14] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] [6C5E88F6] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] [6C5E8B2F] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] [6C5E8A65] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW] [6C5E8FA6] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] [6C5E8C14] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [6C5EA391] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [6C5E9815] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueExW] [6C5E9BA7] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [6C5E9639] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteValueW] [6C5E9CF9] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW] [6C5E9A53] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW] [6C5E9498] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!SetFileSecurityW] [6C5E9DF4] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!AccessCheck] [6C5E883A] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [6C5E9741] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!PrivCopyFileExW] [6C5E8EEA] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!MoveFileExW] [6C5E8C14] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!DeleteFileW] [6C5E8A65] C:\Windows\AppPatch\AcGenral.DLL

Hannibal252 04.11.2007 19:51

IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!CreateFileW] [6C5EA391] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!SetFileAttributesW] [6C5E8FA6] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!SetFileSecurityW] [6C5E9DF4] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegCreateKeyExW] [6C5E9639] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegSetValueExW] [6C5E9BA7] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegOpenKeyExW] [6C5E9815] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!CreateFileW] [6C5EA391] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [6FE74618] C:\Windows\system32\ShimEng.dll
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegCreateKeyExW] [6C5E9639] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegSetValueExW] [6C5E9BA7] C:\Windows\AppPatch\AcGenral.DLL
IAT C:\Users\Rafael\Desktop\gmer\gmer.exe[6772] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegOpenKeyExW] [6C5E9815] C:\Windows\AppPatch\AcGenral.DLL

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 84A581E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 84A581E8

AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys

Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_CREATE 84A531E8
Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_READ 84A531E8
Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_WRITE 84A531E8
Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_FLUSH_BUFFERS 84A531E8
Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_DEVICE_CONTROL 84A531E8
Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_INTERNAL_DEVICE_CONTROL 84A531E8
Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_SHUTDOWN 84A531E8
Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_CLEANUP 84A531E8
Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_POWER 84A531E8
Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_SYSTEM_CONTROL 84A531E8
Device \Driver\volmgr \Device\VolMgrControl IRP_MJ_PNP 84A531E8

AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys

Hannibal252 04.11.2007 19:52

AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys

Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 870AE1E8

AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys

Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 870AE1E8

AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys

Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_CREATE 870727A0
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_CLOSE 870727A0
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 870727A0
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 870727A0
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_POWER 870727A0
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 870727A0
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_PNP 870727A0

AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys

Hannibal252 04.11.2007 19:54

AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys

Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CREATE 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CLOSE 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_POWER 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_PNP 870AE1E8

AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys

Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_CREATE 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_CLOSE 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_POWER 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_SYSTEM_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-4 IRP_MJ_PNP 870AE1E8

AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_CREATE [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_CLOSE [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_READ [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_WRITE [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_QUERY_INFORMATION [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_SET_INFORMATION [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_QUERY_EA [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_SET_EA [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_FLUSH_BUFFERS [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_DIRECTORY_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_DEVICE_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_SHUTDOWN [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_LOCK_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_CLEANUP [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_CREATE_MAILSLOT [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_QUERY_SECURITY [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_SET_SECURITY [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_POWER [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_SYSTEM_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_DEVICE_CHANGE [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_QUERY_QUOTA [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp IRP_MJ_SET_QUOTA [8D4251D0] SYMTDI.SYS

Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_CREATE 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_CLOSE 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_INTERNAL_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_POWER 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_SYSTEM_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBPDO-5 IRP_MJ_PNP 870AE1E8
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_CREATE 870727A0
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_CLOSE 870727A0
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_DEVICE_CONTROL 870727A0
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_INTERNAL_DEVICE_CONTROL 870727A0
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_POWER 870727A0
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_SYSTEM_CONTROL 870727A0
Device \Driver\usbehci \Device\USBPDO-6 IRP_MJ_PNP 870727A0
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_CREATE 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_READ 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_WRITE 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_CLEANUP 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_POWER 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume1 IRP_MJ_PNP 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_CREATE 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_READ 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_WRITE 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 84A531E8

Hannibal252 04.11.2007 19:56

Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_CLEANUP 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_POWER 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume2 IRP_MJ_PNP 84A531E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_CREATE 871DB1E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_CLOSE 871DB1E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_READ 871DB1E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_WRITE 871DB1E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 871DB1E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 871DB1E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 871DB1E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 871DB1E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_POWER 871DB1E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 871DB1E8
Device \Driver\cdrom \Device\CdRom0 IRP_MJ_PNP 871DB1E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_CREATE 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_READ 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_WRITE 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_CLEANUP 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_POWER 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume3 IRP_MJ_PNP 84A531E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 IRP_MJ_CREATE 84A571E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 IRP_MJ_CLOSE 84A571E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 IRP_MJ_DEVICE_CONTROL 84A571E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 84A571E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 IRP_MJ_POWER 84A571E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 IRP_MJ_SYSTEM_CONTROL 84A571E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 IRP_MJ_PNP 84A571E8
Device \Driver\iaStor \Device\Ide\iaStor0 IRP_MJ_CREATE 84A561E8
Device \Driver\iaStor \Device\Ide\iaStor0 IRP_MJ_CLOSE 84A561E8
Device \Driver\iaStor \Device\Ide\iaStor0 IRP_MJ_DEVICE_CONTROL 84A561E8
Device \Driver\iaStor \Device\Ide\iaStor0 IRP_MJ_INTERNAL_DEVICE_CONTROL 84A561E8
Device \Driver\iaStor \Device\Ide\iaStor0 IRP_MJ_POWER 84A561E8
Device \Driver\iaStor \Device\Ide\iaStor0 IRP_MJ_SYSTEM_CONTROL 84A561E8
Device \Driver\iaStor \Device\Ide\iaStor0 IRP_MJ_PNP 84A561E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 84A571E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 84A571E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 84A571E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 84A571E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 84A571E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 84A571E8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 84A571E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 84A571E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 84A571E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 84A571E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 84A571E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 84A571E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 84A571E8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 84A571E8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 IRP_MJ_CREATE 84A561E8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 IRP_MJ_CLOSE 84A561E8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 IRP_MJ_DEVICE_CONTROL 84A561E8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 84A561E8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 IRP_MJ_POWER 84A561E8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 IRP_MJ_SYSTEM_CONTROL 84A561E8
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 IRP_MJ_PNP 84A561E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_CREATE 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_READ 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_WRITE 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_FLUSH_BUFFERS 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_DEVICE_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_INTERNAL_DEVICE_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_SHUTDOWN 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_CLEANUP 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_POWER 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_SYSTEM_CONTROL 84A531E8
Device \Driver\volmgr \Device\HarddiskVolume4 IRP_MJ_PNP 84A531E8

AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_CREATE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_CREATE_NAMED_PIPE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_CLOSE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_READ [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_WRITE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_QUERY_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_SET_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_QUERY_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_SET_EA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_FLUSH_BUFFERS [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_QUERY_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_SET_VOLUME_INFORMATION [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_DIRECTORY_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_FILE_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_INTERNAL_DEVICE_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_SHUTDOWN [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_LOCK_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_CLEANUP [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_CREATE_MAILSLOT [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_QUERY_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_SET_SECURITY [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_POWER [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_SYSTEM_CONTROL [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_DEVICE_CHANGE [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_QUERY_QUOTA [8288BB02] symsnap.sys
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 IRP_MJ_SET_QUOTA [8288BB02] symsnap.sys

Device \Driver\netbt \Device\NetBt_Wins_Export IRP_MJ_CREATE 887C31E8
Device \Driver\netbt \Device\NetBt_Wins_Export IRP_MJ_CLOSE 887C31E8
Device \Driver\netbt \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 887C31E8
Device \Driver\netbt \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 887C31E8
Device \Driver\netbt \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 887C31E8
Device \Driver\netbt \Device\NetBt_Wins_Export IRP_MJ_PNP 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{920B322A-E7C9-4528-9995-B0F9EABDB1CD} IRP_MJ_CREATE 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{920B322A-E7C9-4528-9995-B0F9EABDB1CD} IRP_MJ_CLOSE 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{920B322A-E7C9-4528-9995-B0F9EABDB1CD} IRP_MJ_DEVICE_CONTROL 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{920B322A-E7C9-4528-9995-B0F9EABDB1CD} IRP_MJ_INTERNAL_DEVICE_CONTROL 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{920B322A-E7C9-4528-9995-B0F9EABDB1CD} IRP_MJ_CLEANUP 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{920B322A-E7C9-4528-9995-B0F9EABDB1CD} IRP_MJ_PNP 887C31E8
Device \Driver\iScsiPrt \Device\RaidPort0 IRP_MJ_CREATE 871741E8
Device \Driver\iScsiPrt \Device\RaidPort0 IRP_MJ_CLOSE 871741E8
Device \Driver\iScsiPrt \Device\RaidPort0 IRP_MJ_DEVICE_CONTROL 871741E8
Device \Driver\iScsiPrt \Device\RaidPort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 871741E8
Device \Driver\iScsiPrt \Device\RaidPort0 IRP_MJ_POWER 871741E8
Device \Driver\iScsiPrt \Device\RaidPort0 IRP_MJ_SYSTEM_CONTROL 871741E8
Device \Driver\iScsiPrt \Device\RaidPort0 IRP_MJ_PNP 871741E8

AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_CREATE [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_CREATE_NAMED_PIPE [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_CLOSE [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_READ [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_WRITE [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_QUERY_INFORMATION [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_SET_INFORMATION [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_QUERY_EA [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_SET_EA [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_FLUSH_BUFFERS [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_DIRECTORY_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_DEVICE_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_SHUTDOWN [8D4251D0] SYMTDI.SYS

Hannibal252 04.11.2007 19:57

So das is der letze Teil.





AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_LOCK_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_CLEANUP [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_CREATE_MAILSLOT [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_QUERY_SECURITY [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_SET_SECURITY [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_POWER [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_SYSTEM_CONTROL [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_DEVICE_CHANGE [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_QUERY_QUOTA [8D4251D0] SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp IRP_MJ_SET_QUOTA [8D4251D0] SYMTDI.SYS

Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CREATE 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_CLOSE 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_POWER 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_PNP 870AE1E8
Device \Driver\netbt \Device\NetBT_Tcpip_{031ECDCD-A5F4-4794-9D2F-271ADE06D3F4} IRP_MJ_CREATE 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{031ECDCD-A5F4-4794-9D2F-271ADE06D3F4} IRP_MJ_CLOSE 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{031ECDCD-A5F4-4794-9D2F-271ADE06D3F4} IRP_MJ_DEVICE_CONTROL 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{031ECDCD-A5F4-4794-9D2F-271ADE06D3F4} IRP_MJ_INTERNAL_DEVICE_CONTROL 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{031ECDCD-A5F4-4794-9D2F-271ADE06D3F4} IRP_MJ_CLEANUP 887C31E8
Device \Driver\netbt \Device\NetBT_Tcpip_{031ECDCD-A5F4-4794-9D2F-271ADE06D3F4} IRP_MJ_PNP 887C31E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CREATE 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CLOSE 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_POWER 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_PNP 870AE1E8
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_CREATE 870727A0
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_CLOSE 870727A0
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL 870727A0
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 870727A0
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_POWER 870727A0
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL 870727A0
Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_PNP 870727A0
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CREATE 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CLOSE 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_POWER 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_SYSTEM_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_PNP 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_CREATE 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_CLOSE 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_POWER 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_SYSTEM_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-4 IRP_MJ_PNP 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_CREATE 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_CLOSE 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_INTERNAL_DEVICE_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_POWER 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_SYSTEM_CONTROL 870AE1E8
Device \Driver\usbuhci \Device\USBFDO-5 IRP_MJ_PNP 870AE1E8
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_CREATE 870727A0
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_CLOSE 870727A0
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_DEVICE_CONTROL 870727A0
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_INTERNAL_DEVICE_CONTROL 870727A0
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_POWER 870727A0
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_SYSTEM_CONTROL 870727A0
Device \Driver\usbehci \Device\USBFDO-6 IRP_MJ_PNP 870727A0

---- EOF - GMER 1.0.13 ----

Sunny 04.11.2007 20:24

Hannibal, seit wann tritt denn das Problem auf mit den falschen Links bei Google?

Ich habe nun in 2 anderen Foren "Kollegen" um Rat gebeten, keiner konnte mir genaueres zu deinem Problem sagen bzw. helfen! :schmoll:

Es gibt die Möglichkeit einer Systemwiederherstellung, d.h. dein System sieht dann so aus wie es an diesem Tag (automatisch!) abgesichert wurde.
Somit würde dein Problem eventuell gelöst werden.

Hannibal252 04.11.2007 20:41

Zitat:

Zitat von [Gc]Sunny (Beitrag 303152)
Hannibal, seit wann tritt denn das Problem auf mit den falschen Links bei Google?

welche falschen Links bei Google ? oO

Ich habe gerade n HiJackthis für Vista gefunden. Könnte das mein Problem lösen ?

Sunny 04.11.2007 20:52

Zitat:

Zitat von Hannibal252 (Beitrag 303156)
welche falschen Links bei Google ? oO


Sorry, falscher Thread!


Zitat:

Ich habe gerade n HiJackthis für Vista gefunden. Könnte das mein Problem lösen ?
Du meinst sicherlich die Version 2.0.2... versuch es mal ... ;)
Jedoch wird diese auch die DNS-Umleitung erkennen.
Und leider auch nicht bereinigen/entfernen. :schmoll:

Hannibal252 04.11.2007 20:57

da steht das ich das manuell entfernen muss. Dazu soll ich in Notepad C:\Windows\System32\drivers\etc\hosts öffnen und die linien finden die Hijackthis mir angegeben hat und diese löschen.

Sunny 04.11.2007 20:59

Zitat:

Zitat von Hannibal252 (Beitrag 303161)
da steht das ich das manuell entfernen muss. Dazu soll ich in Notepad C:\Windows\System32\drivers\etc\hosts öffnen und die linien finden die Hijackthis mir angegeben hat und diese löschen.

Mach das mal bitte, in der hosts Datei werden diese Daten immer gespeichert:

es darf unter dem Beispiel Text nur das stehen:

Zitat:

127.0.0.1 localhost

Hannibal252 04.11.2007 21:04

bei mir steht folgendes unter dem beispieltext:

127.0.0.1 localhost
::1 localhost

Wenn ich die untere Zele lösche und neu speichern will meint der PC aber dass die datei nicht gespeichert werden kann. Ich soll dateipfad und namen überprüfen -.-

Sunny 04.11.2007 21:09

Zitat:

Zitat von Hannibal252 (Beitrag 303166)
bei mir steht folgendes unter dem beispieltext:

127.0.0.1 localhost
::1 localhost

Wenn ich die untere Zele lösche und neu speichern will meint der PC aber dass die datei nicht gespeichert werden kann. Ich soll dateipfad und namen überprüfen -.-

Also bei allen XP-Windows-Versionen steht nur der erste Eintrag drinnen, was der 2.te zu bedeuten hat kann ich dir leider nicht sagen. :mad:
Wichtig ist eigentlich nur das dort nichts mit 85.255.x.x steht!


Ansonsten versuch mal eine Systemwiederherstellung, das wäre das einzige was mir dazu jetzt noch einfällt.
Fakt ist: Die DNS-Umleitung muss raus, deine Verbindung wird so abgefangen und (eventuell!) missbraucht, und die gesamte Geschwindigkeit nimmt auch mit der Zeit ab.

Hannibal252 04.11.2007 21:12

Dann bleibt wohl oder übel keine andere Möglichkeit.
Trotzdem danke die Hilfe hier ist wirklich gut. Dafür hast du n dickes Lob verdient ;)
mfg Hannibal

PS ich melde mich nach der Systemwiederherstellung wieder.


Alle Zeitangaben in WEZ +1. Es ist jetzt 15:11 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131