hijackthis log, blbeta, and gmer logs in that order(not sure if i did the blbeta one right but..)
Logfile of HijackThis v1.99.1
Scan saved at 1:23:34 AM, on 10/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\System32\sistray.EXE
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\AOL\1145397178\ee\AOLSoftware.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Ares\Ares.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ryan\My Documents\HJT\hijackthis.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1145397178\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Cookie Washer\washidx.exe "ryan"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
http://www.kaspersky.com/kos/english/kavwebscan_unicode.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
10/07/06 01:07:33 [Info]: BlackLight Engine 1.0.47 initialized
10/07/06 01:07:33 [Info]: OS: 5.1 build 2600 (Service Pack 2)
10/07/06 01:07:41 [Note]: 7019 4
10/07/06 01:07:41 [Note]: 7005 0
10/07/06 01:09:25 [Note]: 7006 0
10/07/06 01:09:25 [Note]: 7011 1456
10/07/06 01:09:25 [Note]: 7026 0
10/07/06 01:09:25 [Note]: 7026 0
10/07/06 01:09:49 [Note]: FSRAW library version 1.7.1020
10/07/06 01:10:06 [Note]: 2000 1012
10/07/06 01:10:31 [Note]: 7007 0
GMER 1.0.11.11390 -
http://www.gmer.netRootkit 2006-10-07 01:22:34
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.11 ----
SSDT 81ABE1D0 ZwAllocateVirtualMemory
SSDT 81AD2C60 ZwCreateKey
SSDT 81ABE6F8 ZwCreateProcess
SSDT 81ABE680 ZwCreateProcessEx
SSDT 81ABE4A0 ZwCreateThread
SSDT 81B09D00 ZwDeleteKey
SSDT 81ABE770 ZwDeleteValueKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT 81ABE248 ZwQueueApcThread
SSDT 81ABD020 ZwReadVirtualMemory
SSDT 81AC4148 ZwRenameKey
SSDT 81ABE338 ZwSetContextThread
SSDT 81ABE860 ZwSetInformationKey
SSDT 81ABE590 ZwSetInformationProcess
SSDT 81ABE3B0 ZwSetInformationThread
SSDT 81ABE7E8 ZwSetValueKey
SSDT 81ABE518 ZwSuspendProcess
SSDT 81ABE2C0 ZwSuspendThread
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
SSDT 81ABE428 ZwTerminateThread
SSDT 81ABE158 ZwWriteVirtualMemory
Code \SystemRoot\system32\DRIVERS\css-dvp.sys ZwClose
Code \SystemRoot\system32\DRIVERS\css-dvp.sys ZwCreateSection
Code \SystemRoot\system32\DRIVERS\css-dvp.sys ZwSetInformationFile
Code \SystemRoot\system32\DRIVERS\css-dvp.sys ZwWriteFile
Code \SystemRoot\system32\DRIVERS\css-dvp.sys IoCreateFile
Code \SystemRoot\system32\DRIVERS\css-dvp.sys NtClose
Code \SystemRoot\system32\DRIVERS\css-dvp.sys NtCreateSection
Code \SystemRoot\system32\DRIVERS\css-dvp.sys NtSetInformationFile
Code \SystemRoot\system32\DRIVERS\css-dvp.sys NtWriteFile
---- Devices - GMER 1.0.11 ----
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE FFA0E1C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE FFA10120
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE 819DF1C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_READ 819A51E8
Device \Driver\Tcpip \Device\Ip IRP_MJ_WRITE 819E1120
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION 819F81C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION FFA36120
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA FFA191C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA 819831C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS 819821E8
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION FFA0B1C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION FFA071C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL FFA081C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL FFA1D1C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL FFA331C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [FB07485A] avgtdi.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN FFA4F1C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL FFA251C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP FFA2E1C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT FFA4B120
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY FFA3C120
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY FFA011C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_POWER FFA691C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL FFA6B120
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE FFA51120
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA FFA5C1C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA FFA5D1C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP FFA3B120
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE FFA0E1C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE FFA10120
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE 819DF1C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_READ 819A51E8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE 819E1120
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION 819F81C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION FFA36120
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA FFA191C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA 819831C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS 819821E8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION FFA0B1C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION FFA071C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL FFA081C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL FFA1D1C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL FFA331C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [FB07485A] avgtdi.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN FFA4F1C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL FFA251C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP FFA2E1C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT FFA4B120
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY FFA3C120
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY FFA011C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_POWER FFA691C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL FFA6B120
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE FFA51120
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA FFA5C1C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA FFA5D1C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP FFA3B120
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE FFA0E1C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE FFA10120
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE 819DF1C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_READ 819A51E8
Device \Driver\Tcpip \Device\Udp IRP_MJ_WRITE 819E1120
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION 819F81C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION FFA36120
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA FFA191C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA 819831C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS 819821E8
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION FFA0B1C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION FFA071C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL FFA081C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL FFA1D1C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL FFA331C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [FB07485A] avgtdi.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN FFA4F1C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL FFA251C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP FFA2E1C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT FFA4B120
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY FFA3C120
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY FFA011C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_POWER FFA691C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL FFA6B120
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE FFA51120
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA FFA5C1C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA FFA5D1C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_PNP FFA3B120
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE FFA0E1C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE FFA10120
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE 819DF1C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_READ 819A51E8
Device \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE 819E1120
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION 819F81C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION FFA36120
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA FFA191C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA 819831C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS 819821E8
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION FFA0B1C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION FFA071C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL FFA081C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL FFA1D1C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL FFA331C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [FB07485A] avgtdi.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN FFA4F1C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL FFA251C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP FFA2E1C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT FFA4B120
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY FFA3C120
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY FFA011C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_POWER FFA691C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL FFA6B120
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE FFA51120
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA FFA5C1C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA FFA5D1C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_PNP FFA3B120
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE FFA0E1C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_NAMED_PIPE FFA10120
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE 819DF1C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_READ 819A51E8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_WRITE 819E1120
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_INFORMATION 819F81C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_INFORMATION FFA36120
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_EA FFA191C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_EA 819831C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FLUSH_BUFFERS 819821E8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_VOLUME_INFORMATION FFA0B1C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_VOLUME_INFORMATION FFA071C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DIRECTORY_CONTROL FFA081C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FILE_SYSTEM_CONTROL FFA1D1C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL FFA331C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [FB07485A] avgtdi.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SHUTDOWN FFA4F1C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_LOCK_CONTROL FFA251C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP FFA2E1C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_MAILSLOT FFA4B120
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_SECURITY FFA3C120
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_SECURITY FFA011C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_POWER FFA691C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SYSTEM_CONTROL FFA6B120
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CHANGE FFA51120
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_QUOTA FFA5C1C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_QUOTA FFA5D1C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_PNP FFA3B120
---- EOF - GMER 1.0.11 ----