offline
- DreamingStar
- Ugledni građanin
- Pridružio: 16 Mar 2010
- Poruke: 481
- Gde živiš: ...pod zvezdanim krakom...
|
Opet propust
Hvala na strpljenju evo izveštaja :
https://www.mycity.rs/must-login.png
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/06/26 16:58
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: 000007F5
Image Path: 000007F5
Address: 0xAB124000 Size: 73472 File Visible: No Signed: -
Status: -
Name: 000009EE
Image Path: 000009EE
Address: 0xAAC73000 Size: 73472 File Visible: No Signed: -
Status: -
Name: 00000A27
Image Path: 00000A27
Address: 0xAAC39000 Size: 73472 File Visible: No Signed: -
Status: -
Name: PCI_PNP1386
Image Path: \Driver\PCI_PNP1386
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: pxtdypow.sys
Image Path: C:\DOCUME~1\MAJAJO~1\LOCALS~1\Temp\pxtdypow.sys
Address: 0xAA43C000 Size: 93056 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAB276000 Size: 49152 File Visible: No Signed: -
Status: -
Name: spnt.sys
Image Path: spnt.sys
Address: 0xF7373000 Size: 995328 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\WINDOWS\Prefetch\ROOTREPEAL.EXE-238DD849.pf
Status: Could not get file information (Error 0xc0000008-)
Path: C:\WINDOWS\Temp\NOD5AD1.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\NOD5AD3.tmp
Status: Invisible to the Windows API!
Path: C:\System Volume Information\_restore{B29903ED-0CEB-457B-8B86-61DCA7D3E4B2}\RP247\A0056432.exe:{E3C76A6B-DD50-F646-5A32-71579B127FF7}
Status: Visible to the Windows API, but not on disk.
Path: C:\System Volume Information\_restore{B29903ED-0CEB-457B-8B86-61DCA7D3E4B2}\RP249\A0056512.exe:{E3C76A6B-DD50-F646-5A32-71579B127FF7}
Status: Visible to the Windows API, but not on disk.
Path: C:\System Volume Information\_restore{B29903ED-0CEB-457B-8B86-61DCA7D3E4B2}\RP254\A0060918.exe:{E3C76A6B-DD50-F646-5A32-71579B127FF7}
Status: Visible to the Windows API, but not on disk.
Path: C:\System Volume Information\_restore{B29903ED-0CEB-457B-8B86-61DCA7D3E4B2}\RP254\A0060922.exe:{E3C76A6B-DD50-F646-5A32-71579B127FF7}
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\system32\drivers\str.sys
Status: Invisible to the Windows API!
SSDT
-------------------
ServiceTable Hooked [0x84b13640]!
#: 019 Function Name: NtAssignProcessToJobObject
Status: Hooked by "<unknown>" at address 0x84df6580
#: 041 Function Name: NtCreateKey
Status: Hooked by "spnt.sys" at address 0xf73740e0
#: 057 Function Name: NtDebugActiveProcess
Status: Hooked by "<unknown>" at address 0x84df7100
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "<unknown>" at address 0x84df6b30
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spnt.sys" at address 0xf738cda4
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spnt.sys" at address 0xf738d132
#: 119 Function Name: NtOpenKey
Status: Hooked by "spnt.sys" at address 0xf73740c0
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0x84df5cc0
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0x84df5fc0
#: 137 Function Name: NtProtectVirtualMemory
Status: Hooked by "<unknown>" at address 0x84df69c0
#: 160 Function Name: NtQueryKey
Status: Hooked by "spnt.sys" at address 0xf738d20a
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spnt.sys" at address 0xf738d08a
#: 213 Function Name: NtSetContextThread
Status: Hooked by "<unknown>" at address 0x84df6860
#: 229 Function Name: NtSetInformationThread
Status: Hooked by "<unknown>" at address 0x84df66e0
#: 237 Function Name: NtSetSecurityObject
Status: Hooked by "<unknown>" at address 0x84df3700
#: 247 Function Name: NtSetValueKey
Status: Hooked by "spnt.sys" at address 0xf738d29c
#: 253 Function Name: NtSuspendProcess
Status: Hooked by "<unknown>" at address 0x84df6420
#: 254 Function Name: NtSuspendThread
Status: Hooked by "<unknown>" at address 0x84df62c0
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0x84df5e50
#: 258 Function Name: NtTerminateThread
Status: Hooked by "<unknown>" at address 0x84df6150
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "<unknown>" at address 0x84df6f50
Stealth Objects
-------------------
Object: Hidden Thread [ETHREAD: 0x85f85020, TID: 1800]
Process: svchost.exe (PID: 972) Address: 0x00a51f3c Size: -
Object: Hidden Thread [ETHREAD: 0x85e60bd8, TID: 1176]
Process: svchost.exe (PID: 972) Address: 0x00dd1f3c Size: -
Object: Hidden Thread [ETHREAD: 0x84afcaa0, TID: 1464]
Process: svchost.exe (PID: 972) Address: 0x00e91f3c Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x85fd4500 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE]
Process: System Address: 0x86012468 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE]
Process: System Address: 0x86012468 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86012468 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86012468 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER]
Process: System Address: 0x86012468 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86012468 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP]
Process: System Address: 0x86012468 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: ag4a2gqqЅఉ瑎捦܉@考, IRP_MJ_CREATE]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: ag4a2gqqЅఉ瑎捦܉@考, IRP_MJ_CLOSE]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: ag4a2gqqЅఉ瑎捦܉@考, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: ag4a2gqqЅఉ瑎捦܉@考, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: ag4a2gqqЅఉ瑎捦܉@考, IRP_MJ_POWER]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: ag4a2gqqЅఉ瑎捦܉@考, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: ag4a2gqqЅఉ瑎捦܉@考, IRP_MJ_PNP]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: nvgts, IRP_MJ_CREATE]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: nvgts, IRP_MJ_CLOSE]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: nvgts, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: nvgts, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: nvgts, IRP_MJ_POWER]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: nvgts, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: nvgts, IRP_MJ_PNP]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x84ec11f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x84ec11f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84ec11f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84ec11f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x84ec11f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x84ec11f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x86052500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x86052500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86052500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86052500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x86052500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86052500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x86052500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x84d631f8 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_CREATE]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_CLOSE]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_READ]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_SHUTDOWN]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_CLEANUP]
Process: System Address: 0x85f22500 Size: 121
Object: Hidden Code [Driver: CdfsЅఆ浗灩IPNATMofReso, IRP_MJ_PNP]
Process: System Address: 0x85f22500 Size: 121
Hidden Services
-------------------
Service Name: clrgi
Image Path: C:\DOCUME~1\MAJAJO~1\LOCALS~1\Temp\mteqdszrb.sys
Service Name: tgcmsmvjblcdi
Image Path: C:\DOCUME~1\MAJAJO~1\LOCALS~1\Temp\iwqemjfs.sys
Service Name: yxkzc
Image Path: C:\DOCUME~1\MAJAJO~1\LOCALS~1\Temp\uwcxa.sys
==EOF==
|