offline
- AlenOprosti
- Novi MyCity građanin
- Pridružio: 10 Feb 2009
- Poruke: 6
|
Hvala na ekspeditivnosti!
Log, as follows
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/02/11 19:25
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: 00000047
Image Path: \Driver\00000047
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA9FD1000 Size: 98304 File Visible: No
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7B03000 Size: 8192 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA95B6000 Size: 45056 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\WINDOWS\Temp\etilqs_7T0mtIf08A0NeO4
Status: Allocation size mismatch (API: 32768, Raw: 0)
Path: C:\Documents and Settings\User\Local Settings\Apps\2.0\2WVOOZ5O.G2M\JWKV56PV.QKD\manifests\clickonce_bootstrap.exe.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\User\Local Settings\Apps\2.0\2WVOOZ5O.G2M\JWKV56PV.QKD\manifests\clickonce_bootstrap.exe.manifest
Status: Locked to the Windows API!
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "sptd.sys" at address 0xf739bb3a
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf739bc7e
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf739bff6
#: 119 Function Name: NtOpenKey
Status: Hooked by "sptd.sys" at address 0xf739ba18
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf739c0c0
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "sptd.sys" at address 0xf739bf58
#: 247 Function Name: NtSetValueKey
Status: Hooked by "sptd.sys" at address 0xf739c148
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x86dcceb0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x868046b0 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_CREATE]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_CLOSE]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_READ]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_WRITE]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_POWER]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_PNP]
Process: System Address: 0x86d86398 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_CREATE]
Process: System Address: 0x86d865d0 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_CLOSE]
Process: System Address: 0x86d865d0 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86d865d0 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86d865d0 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_POWER]
Process: System Address: 0x86d865d0 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86d865d0 Size: -
Object: Hidden Code [Driver: imagedrv, IRP_MJ_PNP]
Process: System Address: 0x86d865d0 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x86d86c78 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_CREATE]
Process: System Address: 0x86d86808 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_CLOSE]
Process: System Address: 0x86d86808 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86d86808 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86d86808 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_POWER]
Process: System Address: 0x86d86808 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86d86808 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_PNP]
Process: System Address: 0x86d86808 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x86d86eb0 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x86b90748 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x86b90748 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86b90748 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86b90748 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x86b90748 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x86b90748 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLOSE]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_WRITE]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_EA]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_EA]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLEANUP]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_SECURITY]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_POWER]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_QUOTA]
Process: System Address: 0x86b9d560 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x86ba08b8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_CREATE]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_CLOSE]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_READ]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_WRITE]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_CLEANUP]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: Npfsȅ䵃䥖犠⬀Ȃఊ祓黈LL, IRP_MJ_SET_SECURITY]
Process: System Address: 0x869560e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_CREATE]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_CLOSE]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_READ]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_WRITE]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_CLEANUP]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: MsfsЅ瑎䅆뻠⌰Ђఆ义䍔啨켨, IRP_MJ_SET_SECURITY]
Process: System Address: 0x869060e8 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_CREATE]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_CLOSE]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_READ]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_SHUTDOWN]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_CLEANUP]
Process: System Address: 0x869e7218 Size: -
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_PNP]
Process: System Address: 0x869e7218 Size: -
|