offline
- Pridružio: 18 Jan 2009
- Poruke: 205
|
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/01/31 15:50
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name:
Image Path:
Address: 0xF7473000 Size: 98304 File Visible: No
Status: -
Name:
Image Path:
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: catchme.sys
Image Path: C:\ComboFix\catchme.sys
Address: 0xF779F000 Size: 30592 File Visible: No
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAFCEA000 Size: 98304 File Visible: No
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79EB000 Size: 8192 File Visible: No
Status: -
Name: PROCEXP90.SYS
Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Address: 0xF79FB000 Size: 6464 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAEE2B000 Size: 45056 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\sccfg.sys
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\1\Local Settings\Application Data\Microsoft\Messenger\eva78bor@hotmail.com\SharingMetadata\nuhi-25@live.de\DFSR\Staging\CS{7A2029D7-D139-336D-8736-DC37BC732EB8}\01\29-{7A2029D7-D139-336D-8736-DC37BC732EB8}-v1-{64B3F9FB-6EB3-46AB-9FD3-F785A85A509D}-v29-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\1\Local Settings\Application Data\Microsoft\Messenger\eva78bor@hotmail.com\SharingMetadata\ssalijevic@hotmail.com\DFSR\Staging\CS{446DDD9C-0C81-A53E-8D4A-BF586EFD3FDB}\01\24-{446DDD9C-0C81-A53E-8D4A-BF586EFD3FDB}-v1-{64B3F9FB-6EB3-46AB-9FD3-F785A85A509D}-v24-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\1\Local Settings\Application Data\Microsoft\Messenger\eva78bor@hotmail.com\SharingMetadata\veljko_lazar@hotmail.com\DFSR\Staging\CS{74913BEC-DAC6-09A3-EB44-C911C1D20AB7}\01\25-{74913BEC-DAC6-09A3-EB44-C911C1D20AB7}-v1-{64B3F9FB-6EB3-46AB-9FD3-F785A85A509D}-v25-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\1\Application Data\Macromedia\Flash Player\#SharedObjects\N2SCP9HU\image.com.com\gamespot\images\cne_flash\production\media_player\proteus\gs:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\1\Application Data\Macromedia\Flash Player\#SharedObjects\N2SCP9HU\image.com.com\gamespot\images\cne_flash\production\media_player\proteus\gs:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\1\Application Data\Macromedia\Flash Player\#SharedObjects\N2SCP9HU\image.com.com\gamespot\images\cne_flash\production\media_player\proteus\gs:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
SSDT
-------------------
#: 025 Function Name: NtClose
Status: Hooked by "vax347b.sys" at address 0xf75bcbb8
#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\system32\windrvNT.sys" at address 0xf77db36a
#: 041 Function Name: NtCreateKey
Status: Hooked by "vax347b.sys" at address 0xf75bcb70
#: 045 Function Name: NtCreatePagingFile
Status: Hooked by "vax347b.sys" at address 0xf75b0c70
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "vax347b.sys" at address 0xf75b14fe
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "vax347b.sys" at address 0xf75bccb0
#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\WINDOWS\system32\windrvNT.sys" at address 0xf77dbcd8
#: 119 Function Name: NtOpenKey
Status: Hooked by "vax347b.sys" at address 0xf75bcb34
#: 145 Function Name: NtQueryDirectoryFile
Status: Hooked by "C:\WINDOWS\system32\windrvNT.sys" at address 0xf77db842
#: 154 Function Name: NtQueryInformationProcess
Status: Hooked by "C:\WINDOWS\system32\windrvNT.sys" at address 0xf77d81e0
#: 160 Function Name: NtQueryKey
Status: Hooked by "vax347b.sys" at address 0xf75b151e
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "vax347b.sys" at address 0xf75bcc06
#: 224 Function Name: NtSetInformationFile
Status: Hooked by "C:\WINDOWS\system32\windrvNT.sys" at address 0xf77dc142
#: 241 Function Name: NtSetSystemPowerState
Status: Hooked by "vax347b.sys" at address 0xf75bc450
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x89721b60 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x86e2de18 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_READ]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_WRITE]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_EA]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_EA]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SHUTDOWN]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CLEANUP]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_SECURITY]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_QUOTA]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x892f8008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_EA]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_EA]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLEANUP]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8936c918 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_CREATE]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_CLOSE]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_READ]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_WRITE]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_EA]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_EA]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_CLEANUP]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_POWER]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_PNP]
Process: System Address: 0x8931c9b8 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x893f9c88 Size: -
Object: Hidden Code [Driver: Srv, IRP_MJ_READ]
Process: System Address: 0x895eeb98 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x894058a0 Size: -
Object: Hidden Code [Driver: Npfsȅ瑎てȁఅ瑎獆晀, IRP_MJ_READ]
Process: System Address: 0x8941c588 Size: -
Object: Hidden Code [Driver: Msfsȅ瑎てȁః瑎て, IRP_MJ_READ]
Process: System Address: 0x893e5ce0 Size: -
Object: Hidden Code [Driver: Fs_Rec, IRP_MJ_READ]
Process: System Address: 0x89418190 Size: -
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭䃐h쁨܀SysLin, IRP_MJ_READ]
Process: System Address: 0x89786ea0 Size: -
|