Code:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/10/17 21:30
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: 00000064
Image Path: \Driver\00000064
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: ajxp3471.SYS
Image Path: C:\WINDOWS\System32\Drivers\ajxp3471.SYS
Address: 0xF74BA000 Size: 303104 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xEEBD5000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8BF7000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEECBE000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\Dokumente und Einstellungen\Mumi\Lokale Einstellungen\Anwendungsdaten\Microsoft\Messenger\ayse011@hotmail.de\SharingMetadata\kadir-conny@freenet.de\DFSR\Staging\CS{8B807E49-E3E0-BF2C-8214-077E16A0DD50}\02\1064-{~2.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0xf8d4322e
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xf8d43224
#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0xf8d43233
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0xf8d4323d
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf85c384e
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf85c3bee
#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xf8d43242
#: 119 Function Name: NtOpenKey
Status: Hooked by "sptd.sys" at address 0xf85be090
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xf8d43210
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xf8d43215
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf85c3cc6
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "sptd.sys" at address 0xf85c3b46
#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xf8d4324c
#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xf8d43247
#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0xf8d43238
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Programme\SUPERAntiSpyware\SASKUTIL.sys" at address 0xeee080b0
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x833d41d8 Size: 405
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x8304b400 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8314c1d8 Size: 463
Object: Hidden Code [Driver: ajxp3471ȅ浍浓닰Ȃం䵃䥖豈Ʀ낑, IRP_MJ_CREATE]
Process: System Address: 0x83141318 Size: 463
Object: Hidden Code [Driver: ajxp3471ȅ浍浓닰Ȃం䵃䥖豈Ʀ낑, IRP_MJ_CLOSE]
Process: System Address: 0x83141318 Size: 463
Object: Hidden Code [Driver: ajxp3471ȅ浍浓닰Ȃం䵃䥖豈Ʀ낑, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x83141318 Size: 463
Object: Hidden Code [Driver: ajxp3471ȅ浍浓닰Ȃం䵃䥖豈Ʀ낑, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x83141318 Size: 463
Object: Hidden Code [Driver: ajxp3471ȅ浍浓닰Ȃం䵃䥖豈Ʀ낑, IRP_MJ_POWER]
Process: System Address: 0x83141318 Size: 463
Object: Hidden Code [Driver: ajxp3471ȅ浍浓닰Ȃం䵃䥖豈Ʀ낑, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x83141318 Size: 463
Object: Hidden Code [Driver: ajxp3471ȅ浍浓닰Ȃం䵃䥖豈Ʀ낑, IRP_MJ_PNP]
Process: System Address: 0x83141318 Size: 463
Object: Hidden Code [Driver: usbstor, IRP_MJ_CREATE]
Process: System Address: 0x82b31558 Size: 463
Object: Hidden Code [Driver: usbstor, IRP_MJ_CLOSE]
Process: System Address: 0x82b31558 Size: 463
Object: Hidden Code [Driver: usbstor, IRP_MJ_READ]
Process: System Address: 0x82b31558 Size: 463
Object: Hidden Code [Driver: usbstor, IRP_MJ_WRITE]
Process: System Address: 0x82b31558 Size: 463
Object: Hidden Code [Driver: usbstor, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82b31558 Size: 463
Object: Hidden Code [Driver: usbstor, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82b31558 Size: 463
Object: Hidden Code [Driver: usbstor, IRP_MJ_POWER]
Process: System Address: 0x82b31558 Size: 463
Object: Hidden Code [Driver: usbstor, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82b31558 Size: 463
Object: Hidden Code [Driver: usbstor, IRP_MJ_PNP]
Process: System Address: 0x82b31558 Size: 463
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x831fe980 Size: 463
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x831fe980 Size: 463
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x831fe980 Size: 463
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x831fe980 Size: 463
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x831fe980 Size: 463
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x831fe980 Size: 463
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x831fe980 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8334f1d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x82dd11d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x82dd11d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82dd11d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82dd11d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x82dd11d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x82dd11d8 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x831a8610 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x831a8610 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x831a8610 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x831a8610 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x831a8610 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x831a8610 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x831a8610 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x82c021d8 Size: 463
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_CREATE]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_CLOSE]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_READ]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_CLEANUP]
Process: System Address: 0x8305a300 Size: 405
Object: Hidden Code [Driver: Cdfsȅఈ浗灩, IRP_MJ_PNP]
Process: System Address: 0x8305a300 Size: 405
==EOF== |