it's pretty long so here goes:
GMER 1.0.11.11390 -
http://www.gmer.netRootkit 2006-10-25 08:51:11
Windows 5.1.2600
---- System - GMER 1.0.11 ----
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
INT 0x00 \WINDOWS\system32\ntoskrnl.exe 804D59B2
INT 0x01 \WINDOWS\system32\ntoskrnl.exe 804D5B06
INT 0x03 \WINDOWS\system32\ntoskrnl.exe 804D5E2E
INT 0x04 \WINDOWS\system32\ntoskrnl.exe 804D5F96
INT 0x05 \WINDOWS\system32\ntoskrnl.exe 804D60DE
INT 0x06 \WINDOWS\system32\ntoskrnl.exe 804D6242
INT 0x07 \WINDOWS\system32\ntoskrnl.exe 804D681E
INT 0x09 \WINDOWS\system32\ntoskrnl.exe 804D6C41
INT 0x0A \WINDOWS\system32\ntoskrnl.exe 804D6D49
INT 0x0B \WINDOWS\system32\ntoskrnl.exe 804D6E75
INT 0x0C \WINDOWS\system32\ntoskrnl.exe 804D7042
INT 0x0D \WINDOWS\system32\ntoskrnl.exe 804D7310
INT 0x0E \WINDOWS\system32\ntoskrnl.exe 804D79A4
INT 0x0F \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x10 \WINDOWS\system32\ntoskrnl.exe 804D7E58
INT 0x11 \WINDOWS\system32\ntoskrnl.exe 804D7F78
INT 0x12 \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x13 \WINDOWS\system32\ntoskrnl.exe 804D80C8
INT 0x14 \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x15 \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x16 \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x17 \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x18 \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x19 \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x1A \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x1B \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x1C \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x1D \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x1E \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x1F \WINDOWS\system32\hal.dll 806B6150
INT 0x2A \WINDOWS\system32\ntoskrnl.exe 804D525E
INT 0x2B \WINDOWS\system32\ntoskrnl.exe 804D5354
INT 0x2C \WINDOWS\system32\ntoskrnl.exe 804D54C4
INT 0x2D \WINDOWS\system32\ntoskrnl.exe 804D5D1E
INT 0x2E \WINDOWS\system32\ntoskrnl.exe 804D4DCD
INT 0x2F \WINDOWS\system32\ntoskrnl.exe 804D7D50
INT 0x30 \WINDOWS\system32\ntoskrnl.exe 804D44B0
INT 0x31 \WINDOWS\system32\ntoskrnl.exe 804D44BA
INT 0x32 \WINDOWS\system32\ntoskrnl.exe 804D44C4
INT 0x33 \WINDOWS\system32\ntoskrnl.exe 804D44CE
INT 0x34 \WINDOWS\system32\ntoskrnl.exe 804D44D8
INT 0x35 \WINDOWS\system32\ntoskrnl.exe 804D44E2
INT 0x36 \WINDOWS\system32\ntoskrnl.exe 804D44EC
INT 0x37 \WINDOWS\system32\hal.dll 806B5900
INT 0x38 \WINDOWS\system32\ntoskrnl.exe 804D4500
INT 0x39 \WINDOWS\system32\ntoskrnl.exe 804D450A
INT 0x3A \WINDOWS\system32\ntoskrnl.exe 804D4514
INT 0x3B \WINDOWS\system32\ntoskrnl.exe 804D451E
INT 0x3C \WINDOWS\system32\ntoskrnl.exe 804D4528
INT 0x3D \WINDOWS\system32\hal.dll 806B6C94
INT 0x3E \WINDOWS\system32\ntoskrnl.exe 804D453C
INT 0x3F \WINDOWS\system32\ntoskrnl.exe 804D4546
INT 0x40 \WINDOWS\system32\ntoskrnl.exe 804D4550
INT 0x41 \WINDOWS\system32\hal.dll 806B6B08
INT 0x42 \WINDOWS\system32\ntoskrnl.exe 804D4564
INT 0x43 \WINDOWS\system32\ntoskrnl.exe 804D456E
INT 0x44 \WINDOWS\system32\ntoskrnl.exe 804D4578
INT 0x45 \WINDOWS\system32\ntoskrnl.exe 804D4582
INT 0x46 \WINDOWS\system32\ntoskrnl.exe 804D458C
INT 0x47 \WINDOWS\system32\ntoskrnl.exe 804D4596
INT 0x48 \WINDOWS\system32\ntoskrnl.exe 804D45A0
INT 0x49 \WINDOWS\system32\ntoskrnl.exe 804D45AA
INT 0x4A \WINDOWS\system32\ntoskrnl.exe 804D45B4
INT 0x4B \WINDOWS\system32\ntoskrnl.exe 804D45BE
INT 0x4C \WINDOWS\system32\ntoskrnl.exe 804D45C8
INT 0x4D \WINDOWS\system32\ntoskrnl.exe 804D45D2
INT 0x4E \WINDOWS\system32\ntoskrnl.exe 804D45DC
INT 0x4F \WINDOWS\system32\ntoskrnl.exe 804D45E6
INT 0x50 \WINDOWS\system32\hal.dll 806B59D8
INT 0x51 \WINDOWS\system32\ntoskrnl.exe 804D45FA
INT 0x52 \WINDOWS\system32\ntoskrnl.exe 804D4604
INT 0x53 \WINDOWS\system32\ntoskrnl.exe 804D460E
INT 0x54 \WINDOWS\system32\ntoskrnl.exe 804D4618
INT 0x55 \WINDOWS\system32\ntoskrnl.exe 804D4622
INT 0x56 \WINDOWS\system32\ntoskrnl.exe 804D462C
INT 0x57 \WINDOWS\system32\ntoskrnl.exe 804D4636
INT 0x58 \WINDOWS\system32\ntoskrnl.exe 804D4640
INT 0x59 \WINDOWS\system32\ntoskrnl.exe 804D464A
INT 0x5A \WINDOWS\system32\ntoskrnl.exe 804D4654
INT 0x5B \WINDOWS\system32\ntoskrnl.exe 804D465E
INT 0x5C \WINDOWS\system32\ntoskrnl.exe 804D4668
INT 0x5D \WINDOWS\system32\ntoskrnl.exe 804D4672
INT 0x5E \WINDOWS\system32\ntoskrnl.exe 804D467C
INT 0x5F \WINDOWS\system32\ntoskrnl.exe 804D4686
INT 0x60 \WINDOWS\system32\ntoskrnl.exe 804D4690
INT 0x61 \WINDOWS\system32\ntoskrnl.exe 804D469A
INT 0x64 \WINDOWS\system32\ntoskrnl.exe 804D46B8
INT 0x65 \WINDOWS\system32\ntoskrnl.exe 804D46C2
INT 0x66 \WINDOWS\system32\ntoskrnl.exe 804D46CC
INT 0x67 \WINDOWS\system32\ntoskrnl.exe 804D46D6
INT 0x68 \WINDOWS\system32\ntoskrnl.exe 804D46E0
INT 0x69 \WINDOWS\system32\ntoskrnl.exe 804D46EA
INT 0x6A \WINDOWS\system32\ntoskrnl.exe 804D46F4
INT 0x6B \WINDOWS\system32\ntoskrnl.exe 804D46FE
INT 0x6C \WINDOWS\system32\ntoskrnl.exe 804D4708
INT 0x6D \WINDOWS\system32\ntoskrnl.exe 804D4712
INT 0x6E \WINDOWS\system32\ntoskrnl.exe 804D471C
INT 0x6F \WINDOWS\system32\ntoskrnl.exe 804D4726
INT 0x70 \WINDOWS\system32\ntoskrnl.exe 804D4730
INT 0x71 \WINDOWS\system32\ntoskrnl.exe 804D473A
INT 0x72 \WINDOWS\system32\ntoskrnl.exe 804D4744
INT 0x73 \WINDOWS\system32\ntoskrnl.exe 804D474E
INT 0x74 \WINDOWS\system32\ntoskrnl.exe 804D4758
INT 0x75 \WINDOWS\system32\ntoskrnl.exe 804D4762
INT 0x76 \WINDOWS\system32\ntoskrnl.exe 804D476C
INT 0x77 \WINDOWS\system32\ntoskrnl.exe 804D4776
INT 0x78 \WINDOWS\system32\ntoskrnl.exe 804D4780
INT 0x79 \WINDOWS\system32\ntoskrnl.exe 804D478A
INT 0x7A \WINDOWS\system32\ntoskrnl.exe 804D4794
INT 0x7B \WINDOWS\system32\ntoskrnl.exe 804D479E
INT 0x7C \WINDOWS\system32\ntoskrnl.exe 804D47A8
INT 0x7D \WINDOWS\system32\ntoskrnl.exe 804D47B2
INT 0x7E \WINDOWS\system32\ntoskrnl.exe 804D47BC
INT 0x7F \WINDOWS\system32\ntoskrnl.exe 804D47C6
INT 0x80 \WINDOWS\system32\ntoskrnl.exe 804D47D0
INT 0x81 \WINDOWS\system32\ntoskrnl.exe 804D47DA
INT 0x84 \WINDOWS\system32\ntoskrnl.exe 804D47F8
INT 0x85 \WINDOWS\system32\ntoskrnl.exe 804D4802
INT 0x86 \WINDOWS\system32\ntoskrnl.exe 804D480C
INT 0x87 \WINDOWS\system32\ntoskrnl.exe 804D4816
INT 0x88 \WINDOWS\system32\ntoskrnl.exe 804D4820
INT 0x89 \WINDOWS\system32\ntoskrnl.exe 804D482A
INT 0x8A \WINDOWS\system32\ntoskrnl.exe 804D4834
INT 0x8B \WINDOWS\system32\ntoskrnl.exe 804D483E
INT 0x8C \WINDOWS\system32\ntoskrnl.exe 804D4848
INT 0x8D \WINDOWS\system32\ntoskrnl.exe 804D4852
INT 0x8E \WINDOWS\system32\ntoskrnl.exe 804D485C
INT 0x8F \WINDOWS\system32\ntoskrnl.exe 804D4866
INT 0x90 \WINDOWS\system32\ntoskrnl.exe 804D4870
INT 0x91 \WINDOWS\system32\ntoskrnl.exe 804D487A
INT 0x94 \WINDOWS\system32\ntoskrnl.exe 804D4898
INT 0x95 \WINDOWS\system32\ntoskrnl.exe 804D48A2
INT 0x96 \WINDOWS\system32\ntoskrnl.exe 804D48AC
INT 0x97 \WINDOWS\system32\ntoskrnl.exe 804D48B6
INT 0x98 \WINDOWS\system32\ntoskrnl.exe 804D48C0
INT 0x99 \WINDOWS\system32\ntoskrnl.exe 804D48CA
INT 0x9A \WINDOWS\system32\ntoskrnl.exe 804D48D4
INT 0x9B \WINDOWS\system32\ntoskrnl.exe 804D48DE
INT 0x9C \WINDOWS\system32\ntoskrnl.exe 804D48E8
INT 0x9D \WINDOWS\system32\ntoskrnl.exe 804D48F2
INT 0x9E \WINDOWS\system32\ntoskrnl.exe 804D48FC
INT 0x9F \WINDOWS\system32\ntoskrnl.exe 804D4906
INT 0xA0 \WINDOWS\system32\ntoskrnl.exe 804D4910
INT 0xA1 \WINDOWS\system32\ntoskrnl.exe 804D491A
INT 0xA2 \WINDOWS\system32\ntoskrnl.exe 804D4924
INT 0xA4 \WINDOWS\system32\ntoskrnl.exe 804D4938
INT 0xA5 \WINDOWS\system32\ntoskrnl.exe 804D4942
INT 0xA6 \WINDOWS\system32\ntoskrnl.exe 804D494C
INT 0xA7 \WINDOWS\system32\ntoskrnl.exe 804D4956
INT 0xA8 \WINDOWS\system32\ntoskrnl.exe 804D4960
INT 0xA9 \WINDOWS\system32\ntoskrnl.exe 804D496A
INT 0xAA \WINDOWS\system32\ntoskrnl.exe 804D4974
INT 0xAB \WINDOWS\system32\ntoskrnl.exe 804D497E
INT 0xAC \WINDOWS\system32\ntoskrnl.exe 804D4988
INT 0xAD \WINDOWS\system32\ntoskrnl.exe 804D4992
INT 0xAE \WINDOWS\system32\ntoskrnl.exe 804D499C
INT 0xAF \WINDOWS\system32\ntoskrnl.exe 804D49A6
INT 0xB0 \WINDOWS\system32\ntoskrnl.exe 804D49B0
INT 0xB3 \WINDOWS\system32\ntoskrnl.exe 804D49CE
INT 0xB5 \WINDOWS\system32\ntoskrnl.exe 804D49E2
INT 0xB6 \WINDOWS\system32\ntoskrnl.exe 804D49EC
INT 0xB7 \WINDOWS\system32\ntoskrnl.exe 804D49F6
INT 0xB8 \WINDOWS\system32\ntoskrnl.exe 804D4A00
INT 0xB9 \WINDOWS\system32\ntoskrnl.exe 804D4A0A
INT 0xBA \WINDOWS\system32\ntoskrnl.exe 804D4A14
INT 0xBB \WINDOWS\system32\ntoskrnl.exe 804D4A1E
INT 0xBC \WINDOWS\system32\ntoskrnl.exe 804D4A28
INT 0xBD \WINDOWS\system32\ntoskrnl.exe 804D4A32
INT 0xBE \WINDOWS\system32\ntoskrnl.exe 804D4A3C
INT 0xBF \WINDOWS\system32\ntoskrnl.exe 804D4A46
INT 0xC0 \WINDOWS\system32\ntoskrnl.exe 804D4A50
INT 0xC1 \WINDOWS\system32\hal.dll 806B5B44
INT 0xC2 \WINDOWS\system32\ntoskrnl.exe 804D4A64
INT 0xC3 \WINDOWS\system32\ntoskrnl.exe 804D4A6E
INT 0xC4 \WINDOWS\system32\ntoskrnl.exe 804D4A78
INT 0xC5 \WINDOWS\system32\ntoskrnl.exe 804D4A82
INT 0xC6 \WINDOWS\system32\ntoskrnl.exe 804D4A8C
INT 0xC7 \WINDOWS\system32\ntoskrnl.exe 804D4A96
INT 0xC8 \WINDOWS\system32\ntoskrnl.exe 804D4AA0
INT 0xC9 \WINDOWS\system32\ntoskrnl.exe 804D4AAA
INT 0xCA \WINDOWS\system32\ntoskrnl.exe 804D4AB4
INT 0xCB \WINDOWS\system32\ntoskrnl.exe 804D4ABE
INT 0xCC \WINDOWS\system32\ntoskrnl.exe 804D4AC8
INT 0xCD \WINDOWS\system32\ntoskrnl.exe 804D4AD2
INT 0xCE \WINDOWS\system32\ntoskrnl.exe 804D4ADC
INT 0xCF \WINDOWS\system32\ntoskrnl.exe 804D4AE6
INT 0xD0 \WINDOWS\system32\ntoskrnl.exe 804D4AF0
INT 0xD1 \WINDOWS\system32\hal.dll 806B4EE4
INT 0xD2 \WINDOWS\system32\ntoskrnl.exe 804D4B04
INT 0xD3 \WINDOWS\system32\ntoskrnl.exe 804D4B0E
INT 0xD4 \WINDOWS\system32\ntoskrnl.exe 804D4B18
INT 0xD5 \WINDOWS\system32\ntoskrnl.exe 804D4B22
INT 0xD6 \WINDOWS\system32\ntoskrnl.exe 804D4B2C
INT 0xD7 \WINDOWS\system32\ntoskrnl.exe 804D4B36
INT 0xD8 \WINDOWS\system32\ntoskrnl.exe 804D4B40
INT 0xD9 \WINDOWS\system32\ntoskrnl.exe 804D4B4A
INT 0xDA \WINDOWS\system32\ntoskrnl.exe 804D4B54
INT 0xDB \WINDOWS\system32\ntoskrnl.exe 804D4B5E
INT 0xDC \WINDOWS\system32\ntoskrnl.exe 804D4B68
INT 0xDD \WINDOWS\system32\ntoskrnl.exe 804D4B72
INT 0xDE \WINDOWS\system32\ntoskrnl.exe 804D4B7C
INT 0xDF \WINDOWS\system32\ntoskrnl.exe 804D4B86
INT 0xE0 \WINDOWS\system32\ntoskrnl.exe 804D4B90
INT 0xE1 \WINDOWS\system32\hal.dll 806B60A0
INT 0xE2 \WINDOWS\system32\ntoskrnl.exe 804D4BA4
INT 0xE3 \WINDOWS\system32\hal.dll 806B5E1C
INT 0xE4 \WINDOWS\system32\ntoskrnl.exe 804D4BB8
INT 0xE5 \WINDOWS\system32\ntoskrnl.exe 804D4BC2
INT 0xE6 \WINDOWS\system32\ntoskrnl.exe 804D4BCC
INT 0xE7 \WINDOWS\system32\ntoskrnl.exe 804D4BD6
INT 0xE8 \WINDOWS\system32\ntoskrnl.exe 804D4BE0
INT 0xE9 \WINDOWS\system32\ntoskrnl.exe 804D4BEA
INT 0xEA \WINDOWS\system32\ntoskrnl.exe 804D4BF4
INT 0xEB \WINDOWS\system32\ntoskrnl.exe 804D4BFE
INT 0xEC \WINDOWS\system32\ntoskrnl.exe 804D4C08
INT 0xED \WINDOWS\system32\ntoskrnl.exe 804D4C12
INT 0xEE \WINDOWS\system32\ntoskrnl.exe 804D4C19
INT 0xEF \WINDOWS\system32\ntoskrnl.exe 804D4C20
INT 0xF0 \WINDOWS\system32\ntoskrnl.exe 804D4C27
INT 0xF1 \WINDOWS\system32\ntoskrnl.exe 804D4C2E
INT 0xF2 \WINDOWS\system32\ntoskrnl.exe 804D4C35
INT 0xF3 \WINDOWS\system32\ntoskrnl.exe 804D4C3C
INT 0xF4 \WINDOWS\system32\ntoskrnl.exe 804D4C43
INT 0xF5 \WINDOWS\system32\ntoskrnl.exe 804D4C4A
INT 0xF6 \WINDOWS\system32\ntoskrnl.exe 804D4C51
INT 0xF7 \WINDOWS\system32\ntoskrnl.exe 804D4C58
INT 0xF8 \WINDOWS\system32\ntoskrnl.exe 804D4C5F
INT 0xF9 \WINDOWS\system32\ntoskrnl.exe 804D4C66
INT 0xFA \WINDOWS\system32\ntoskrnl.exe 804D4C6D
INT 0xFB \WINDOWS\system32\ntoskrnl.exe 804D4C74
INT 0xFC \WINDOWS\system32\ntoskrnl.exe 804D4C7B
INT 0xFD \WINDOWS\system32\hal.dll 806B65CC
INT 0xFE \WINDOWS\system32\hal.dll 806B6754
INT 0xFF \WINDOWS\system32\ntoskrnl.exe 804D4C90
SYSENTER \WINDOWS\system32\ntoskrnl.exe 804D4DA0
---- Devices - GMER 1.0.11 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F9151200] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [804F2529] ntoskrnl.exe
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F9151DA5] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F9137687] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F9138428] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F915353F] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F91390B1] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F915353F] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F915353F] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F9162A23] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F91524E2] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F91524E2] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F9157595] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F91568D4] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F91524E2] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [804F2529] ntoskrnl.exe
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F9149476] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F91679E3] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F91514DA] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [804F2529] ntoskrnl.exe
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F91524E2] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F91524E2] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [804F2529] ntoskrnl.exe
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [804F2529] ntoskrnl.exe
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [804F2529] ntoskrnl.exe
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F915353F] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F915353F] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP [F91A03FC] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs FastIoCheckIfPossible [F9167BBB] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs FastIoRead [F91544CE] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs FastIoWrite [F9164898] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs FastIoQueryBasicInfo [F9159DB0] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs FastIoQueryStandardInfo [F9159C14] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs FastIoLock [F9167E66] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs FastIoUnlockSingle [F9167F26] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs FastIoUnlockAll [F919E1B9] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs FastIoUnlockAllByKey [F919E2FD] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs AcquireFileForNtCreateSection [F91526F4] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs ReleaseFileForNtCreateSection [F9152721] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs FastIoQueryNetworkOpenInfo [F9164FC6] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs AcquireForModWrite [F91A3918] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs MdlRead [F9165233] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs MdlReadComplete [8051E58F] ntoskrnl.exe
Device \FileSystem\Ntfs \Ntfs PrepareMdlWrite [F916436D] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs MdlWriteComplete [805F28AA] ntoskrnl.exe
Device \FileSystem\Ntfs \Ntfs FastIoQueryOpen [F9159EC5] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs AcquireForCcFlush [F91523DB] Ntfs.sys
Device \FileSystem\Ntfs \Ntfs ReleaseForCcFlush [F915239C] Ntfs.sys
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE [F472FF08] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE_NAMED_PIPE [804F2529] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE [F472FC3E] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ [F472CCA8] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE [F472C6F4] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION [F473201C] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION [F4732612] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA [F4744988] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA [F474435C] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS [F4741C58] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION [F4730A26] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION [F474BB64] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL [F47342B2] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL [F4735E8B] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL [F474140C] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_INTERNAL_DEVICE_CONTROL [804F2529] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN [F474B0C7] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL [F474A844] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP [F4730882] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE_MAILSLOT [804F2529] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_SECURITY [804F2529] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_SECURITY [804F2529] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_POWER [804F2529] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SYSTEM_CONTROL [804F2529] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CHANGE [804F2529] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_QUOTA [804F2529] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_QUOTA [804F2529] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP [F4739477] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom FastIoCheckIfPossible [F4746888] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom FastIoRead [805F28D2] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom FastIoWrite [805BE91F] ntoskrnl.exe
Device \FileSystem\Fastfat \FatCdrom FastIoQueryBasicInfo [F47337D7] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom FastIoQueryStandardInfo [F4736F5A] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom FastIoLock [F473A2E1] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom FastIoUnlockSingle [F473AA0E] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom FastIoUnlockAll [F474A546] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom FastIoUnlockAllByKey [F474A634] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom FastIoQueryNetworkOpenInfo [F4746916] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom AcquireForCcFlush [F4731A74] Fastfat.SYS
Device \FileSystem\Fastfat \FatCdrom ReleaseForCcFlush [F4731ADE] Fastfat.SYS
Device \FileSystem\Mup \Dfs IRP_MJ_CREATE [F90F95D3] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_CREATE_NAMED_PIPE [F90F95D3] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_CLOSE [F90F9CC6] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_READ [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_WRITE [F9105A0B] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_QUERY_INFORMATION [F90FC031] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_SET_INFORMATION [F910764A] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_QUERY_EA [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_SET_EA [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_FLUSH_BUFFERS [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_QUERY_VOLUME_INFORMATION [F910A671] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_SET_VOLUME_INFORMATION [F910A74A] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_DIRECTORY_CONTROL [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_FILE_SYSTEM_CONTROL [F90F9971] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_DEVICE_CONTROL [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_SHUTDOWN [F9106E81] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_LOCK_CONTROL [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_CLEANUP [F90F9C88] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_CREATE_MAILSLOT [F90F95D3] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_QUERY_SECURITY [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_SET_SECURITY [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_POWER [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_SYSTEM_CONTROL [F90F5ABC] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_DEVICE_CHANGE [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_QUERY_QUOTA [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_SET_QUOTA [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs IRP_MJ_PNP [F90F576D] Mup.sys
Device \FileSystem\Mup \Dfs FastIoCheckIfPossible [F9106FCA] Mup.sys
Device \FileSystem\Mup \Dfs FastIoRead [F910700E] Mup.sys
Device \FileSystem\Mup \Dfs FastIoWrite [F9107052] Mup.sys
Device \FileSystem\Mup \Dfs FastIoQueryBasicInfo [F9107096] Mup.sys
Device \FileSystem\Mup \Dfs FastIoQueryStandardInfo [F90FBBB6] Mup.sys
Device \FileSystem\Mup \Dfs FastIoLock [F90FBFA4] Mup.sys
Device \FileSystem\Mup \Dfs FastIoUnlockSingle [F90FBFD0] Mup.sys
Device \FileSystem\Mup \Dfs FastIoUnlockAll [F91070D1] Mup.sys
Device \FileSystem\Mup \Dfs FastIoUnlockAllByKey [F9107109] Mup.sys
Device \FileSystem\Mup \Dfs AcquireFileForNtCreateSection [F9107144] Mup.sys
Device \FileSystem\Mup \Dfs ReleaseFileForNtCreateSection [F91071CF] Mup.sys
Device \FileSystem\Mup \Dfs FastIoDetachDevice [F9107243] Mup.sys
Device \FileSystem\Mup \Dfs FastIoQueryNetworkOpenInfo [F90FBFFC] Mup.sys
Device \FileSystem\Mup \Dfs AcquireForModWrite [F9107384] Mup.sys
Device \FileSystem\Mup \Dfs MdlRead [F9107246] Mup.sys
Device \FileSystem\Mup \Dfs MdlReadComplete [F91072A0] Mup.sys
Device \FileSystem\Mup \Dfs PrepareMdlWrite [F91072E2] Mup.sys
Device \FileSystem\Mup \Dfs MdlWriteComplete [F910733C] Mup.sys
Device \FileSystem\Mup \Dfs FastIoReadCompressed [F91073F7] Mup.sys
Device \FileSystem\Mup \Dfs FastIoWriteCompressed [F910744A] Mup.sys
Device \FileSystem\Mup \Dfs MdlReadCompleteCompressed [F910749D] Mup.sys
Device \FileSystem\Mup \Dfs MdlWriteCompleteCompressed [F91074D2] Mup.sys
Device \FileSystem\Mup \Dfs ReleaseForModWrite [F91073BF] Mup.sys
Device \FileSystem\Mup \Dfs AcquireForCcFlush [F90FC211] Mup.sys
Device \FileSystem\Mup \Dfs ReleaseForCcFlush [F90FC24D] Mup.sys
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_CREATE [F91BF718] KSecDD.sys
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_CREATE_NAMED_PIPE [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_CLOSE [F91BF718] KSecDD.sys
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_READ [F91BF718] KSecDD.sys
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_WRITE [F91BF718] KSecDD.sys
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_QUERY_INFORMATION [F91BF718] KSecDD.sys
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_SET_INFORMATION [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_QUERY_EA [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_SET_EA [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_FLUSH_BUFFERS [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_QUERY_VOLUME_INFORMATION [F91BF718] KSecDD.sys
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_SET_VOLUME_INFORMATION [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_DIRECTORY_CONTROL [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_FILE_SYSTEM_CONTROL [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_DEVICE_CONTROL [F91BF718] KSecDD.sys
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_INTERNAL_DEVICE_CONTROL [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_SHUTDOWN [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_LOCK_CONTROL [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_CLEANUP [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_CREATE_MAILSLOT [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_QUERY_SECURITY [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_SET_SECURITY [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_POWER [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_SYSTEM_CONTROL [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_DEVICE_CHANGE [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_QUERY_QUOTA [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_SET_QUOTA [804F2529] ntoskrnl.exe
Device \Driver\KSecDD \Device\KsecDD IRP_MJ_PNP [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_CREATE [F404B4A0] fsksnt.sys
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_CREATE_NAMED_PIPE [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_CLOSE [F404B4A0] fsksnt.sys
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_READ [F404B4A0] fsksnt.sys
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_WRITE [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_QUERY_INFORMATION [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_SET_INFORMATION [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_QUERY_EA [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_SET_EA [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_FLUSH_BUFFERS [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_QUERY_VOLUME_INFORMATION [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_SET_VOLUME_INFORMATION [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_DIRECTORY_CONTROL [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_FILE_SYSTEM_CONTROL [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_DEVICE_CONTROL [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_INTERNAL_DEVICE_CONTROL [804F2529] ntoskrnl.exe
Device \Driver\Fsks \Device\FSKS0 IRP_MJ_SHUTDOWN [804F2529] ntoskrnl.exe
Device \Driver\Fsks