offline
- Pridružio: 24 Apr 2007
- Poruke: 31
|
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/04/03 23:22
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: 00000080
Image Path: \Driver\00000080
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB74C4000 Size: 98304 File Visible: No
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79C9000 Size: 8192 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x8C044000 Size: 45056 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Guza\Local Settings\Application Data\Microsoft\Messenger\bokac1984@hotmail.com\SharingMetadata\lilithmarionette@hotmail.com\DFSR\Staging\CS{47746DCE-C8E2-3DA5-A1FE-D81499BD06D5}\01\10-{47746DCE-C8E2-3DA5-A1FE-D81499BD06D5}-v1-{21BEE76B-8F7A-4B70-8C7E-6D270DEE02ED}-v10-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Xilinx\10.1\ISE\coregen\ip\xilinx\gip1\com\xilinx\ip\mac_fir_v4_0\data\hdlif\C_MAC_FIR_V4_0.hif:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "sptd.sys" at address 0xf750ac04
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf750ad48
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf750b0c0
#: 119 Function Name: NtOpenKey
Status: Hooked by "sptd.sys" at address 0xf750aae2
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf750b18a
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "sptd.sys" at address 0xf750b022
#: 247 Function Name: NtSetValueKey
Status: Hooked by "sptd.sys" at address 0xf750b212
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8a5cd0e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x898e4550 Size: -
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CREATE]
Process: System Address: 0x8a511bd8 Size: -
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CLOSE]
Process: System Address: 0x8a511bd8 Size: -
Object: Hidden Code [Driver: dtscsi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a511bd8 Size: -
Object: Hidden Code [Driver: dtscsi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a511bd8 Size: -
Object: Hidden Code [Driver: dtscsi, IRP_MJ_POWER]
Process: System Address: 0x8a511bd8 Size: -
Object: Hidden Code [Driver: dtscsi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a511bd8 Size: -
Object: Hidden Code [Driver: dtscsi, IRP_MJ_PNP]
Process: System Address: 0x8a511bd8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8a50bb30 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_CREATE]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_CLOSE]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_READ]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_WRITE]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_POWER]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_PNP]
Process: System Address: 0x8a5ce5d0 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_CREATE]
Process: System Address: 0x8a5ce808 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_CLOSE]
Process: System Address: 0x8a5ce808 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a5ce808 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a5ce808 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_POWER]
Process: System Address: 0x8a5ce808 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a5ce808 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_PNP]
Process: System Address: 0x8a5ce808 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x8a5cec78 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8a5ceeb0 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x89fe50e8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x89fe50e8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89fe50e8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89fe50e8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x89fe50e8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x89fe50e8 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLOSE]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_WRITE]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_EA]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_EA]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLEANUP]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_POWER]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89fbe7b0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x89fb9970 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_CREATE]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_CLOSE]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_READ]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_WRITE]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_CLEANUP]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Npfsం扏济D:, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a0f80e8 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_CREATE]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_CLOSE]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_READ]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_WRITE]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_CLEANUP]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Msfsఆ剒敬, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89ff38d0 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_CREATE]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_CLOSE]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_READ]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_CLEANUP]
Process: System Address: 0x89f7d7c8 Size: -
Object: Hidden Code [Driver: Cdfsȅ瑎䙦܂Èш, IRP_MJ_PNP]
Process: System Address: 0x89f7d7c8 Size: -
|