offline
- Pridružio: 17 Jan 2009
- Poruke: 49
|
mycity.rs/must-login.png
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/01/18 00:30
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: catchme.sys
Image Path: C:\ComboFix\catchme.sys
Address: 0xF7BE7000 Size: 30592 File Visible: No
Status: -
Name: Combo-Fix.sys
Image Path: Combo-Fix.sys
Address: 0xF788F000 Size: 60416 File Visible: No
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF481F000 Size: 98304 File Visible: No
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7D61000 Size: 8192 File Visible: No
Status: -
Name: giveio.sys
Image Path: giveio.sys
Address: 0xF7DF8000 Size: 1664 File Visible: No
Status: -
Name: PCI_PNP6430
Image Path: \Driver\PCI_PNP6430
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: PROCEXP90.SYS
Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Address: 0xF7DBF000 Size: 6464 File Visible: No
Status: -
Name: RecAgent.sys
Image Path: RecAgent.sys
Address: 0xF7C43000 Size: 14432 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xBA324000 Size: 45056 File Visible: No
Status: -
Name: speedfan.sys
Image Path: speedfan.sys
Address: 0xF7D35000 Size: 5248 File Visible: No
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: spvg.sys
Image Path: spvg.sys
Address: 0xF770E000 Size: 1048576 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Nesa Savkovic\Local Settings\temp\etilqs_Nj5VCuzWnZXKIWgwLBRo
Status: Allocation size mismatch (API: 32768, Raw: 0)
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "spvg.sys" at address 0xf770f0e0
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spvg.sys" at address 0xf772dca2
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spvg.sys" at address 0xf772e030
#: 119 Function Name: NtOpenKey
Status: Hooked by "spvg.sys" at address 0xf770f0c0
#: 160 Function Name: NtQueryKey
Status: Hooked by "spvg.sys" at address 0xf772e108
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spvg.sys" at address 0xf772df88
#: 247 Function Name: NtSetValueKey
Status: Hooked by "spvg.sys" at address 0xf772e19a
Stealth Objects
-------------------
Object: Hidden Module [Name: AnonServiceLib.dll]
Process: AnonMgmtSvc.exe (PID: 1988-) Address: 0x01360000 Size: 53248
Object: Hidden Module [Name: System.Runtime.Remoting.dll]
Process: AnonMgmtSvc.exe (PID: 1988-) Address: 0x01590000 Size: 307200
Object: Hidden Module [Name: App4R.DevMons.NetworkCardDevMon.dll]
Process: lxddamon.exe (PID: 3592) Address: 0x010e0000 Size: 28672
Object: Hidden Module [Name: App4R.Monitor.Common.dll]
Process: lxddamon.exe (PID: 3592) Address: 0x00f60000 Size: 36864
Object: Hidden Module [Name: App4R.Monitor.Core.dll]
Process: lxddamon.exe (PID: 3592) Address: 0x00d30000 Size: 53248
Object: Hidden Module [Name: App4R.DevMons.MCMDevMon.dll]
Process: lxddamon.exe (PID: 3592) Address: 0x010b0000 Size: 69632
Object: Hidden Module [Name: App4R.DevMons.ScanDevMon.dll]
Process: lxddamon.exe (PID: 3592) Address: 0x01100000 Size: 28672
Object: Hidden Module [Name: System.Runtime.Remoting.dll]
Process: lxddamon.exe (PID: 3592) Address: 0x01240000 Size: 307200
Object: Hidden Module [Name: Skins.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x045a0000 Size: 290816
Object: Hidden Module [Name: AnonServiceLib.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x016d0000 Size: 53248
Object: Hidden Module [Name: AnxCommonLib.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x017f0000 Size: 512000
Object: Hidden Module [Name: DevExpress.Utils.v6.3.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x03b40000 Size: 2600960
Object: Hidden Module [Name: DevExpress.Data.v6.3.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x047e0000 Size: 462848
Object: Hidden Module [Name: AnonNyms.Anx]
Process: Anonymizer.exe (PID: 4020) Address: 0x053f0000 Size: 847872
Object: Hidden Module [Name: AnonHome.Anx]
Process: Anonymizer.exe (PID: 4020) Address: 0x05260000 Size: 348160
Object: Hidden Module [Name: DevExpress.XtraNavBar.v6.3.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x05780000 Size: 307200
Object: Hidden Module [Name: DevExpress.XtraEditors.v6.3.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x05640000 Size: 1273856
Object: Hidden Module [Name: AnonSurf.Anx]
Process: Anonymizer.exe (PID: 4020) Address: 0x05580000 Size: 733184
Object: Hidden Module [Name: System.Data.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x063a0000 Size: 2961408
Object: Hidden Module [Name: DevExpress.XtraGrid.v6.3.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x066d0000 Size: 1363968
Object: Hidden Module [Name: DevExpress.XtraTreeList.v6.3.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x06aa0000 Size: 684032
Object: Hidden Module [Name: DevExpress.XtraBars.v6.3.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x06850000 Size: 1396736
Object: Hidden Module [Name: NymsInterface.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x06fe0000 Size: 184320
Object: Hidden Module [Name: System.Web.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x07a50000 Size: 5246976
Object: Hidden Module [Name: System.Transactions.dll]
Process: Anonymizer.exe (PID: 4020) Address: 0x08350000 Size: 270336
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8676a1f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x8676b1f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x8676b1f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8676b1f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8676b1f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x8676b1f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8676b1f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x8676b1f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x864c1500 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_CREATE]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_CLOSE]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_READ]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_WRITE]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_QUERY_EA]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_SET_EA]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_SHUTDOWN]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_CLEANUP]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_SET_SECURITY]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_POWER]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_SET_QUOTA]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: Imagedrv, IRP_MJ_PNP]
Process: System Address: 0x867da1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x8676c1f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x865241f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x865241f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x865241f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x865241f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x865241f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x865241f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x865241f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x867db1f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x85d421f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x85d421f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x85d421f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x85d421f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x85d421f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x85d421f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x8643e1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x8643e1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8643e1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8643e1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x8643e1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8643e1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x8643e1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x8613c1f8 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_CREATE]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_CLOSE]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_READ]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_CLEANUP]
Process: System Address: 0x8654a500 Size: -
Object: Hidden Code [Driver: CdfsЅఐ卆浩, IRP_MJ_PNP]
Process: System Address: 0x8654a500 Size: -
Dopuna: 18 Jan 2009 0:57
Sta sada?
Jel je ovo gotovo ili ima jos...
|