|   | Sashlyrics | 18.04.2010 11:58 |  
  Code: 
 ROOTREPEAL (c) AD, 2007-2009==================================================
 Scan Start Time:                2010/04/18 12:41
 Program Version:                Version 1.3.5.0
 Windows Version:                Windows XP Media Center Edition SP3
 ==================================================
 
 Drivers
 -------------------
 Name: klmdb.sys
 Image Path: klmdb.sys
 Address: 0xF7707000        Size: 31104        File Visible: No        Signed: -
 Status: -
 
 Name: PCI_PNP0260
 Image Path: \Driver\PCI_PNP0260
 Address: 0x00000000        Size: 0        File Visible: No        Signed: -
 Status: -
 
 Name: rootrepeal.sys
 Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
 Address: 0xA5D8A000        Size: 49152        File Visible: No        Signed: -
 Status: -
 
 Name: spgf.sys
 Image Path: spgf.sys
 Address: 0xF7293000        Size: 995328        File Visible: No        Signed: -
 Status: -
 
 Name: sptd
 Image Path: \Driver\sptd
 Address: 0x00000000        Size: 0        File Visible: No        Signed: -
 Status: -
 
 Name: tsk8F.tmp
 Image Path: tsk8F.tmp
 Address: 0xF71DE000        Size: 96512        File Visible: No        Signed: -
 Status: -
 
 Hidden/Locked Files
 -------------------
 Path: C:\WINDOWS\system32\cfqrufu.dll.bak
 Status: Locked to the Windows API!
 
 Path: c:\dokumente und einstellungen\sascha\anwendungsdaten\mozilla\firefox\profiles\kkokuipl.default\sessionstore.js
 Status: Size mismatch (API: 100357, Raw: 100699)
 
 Path: c:\dokumente und einstellungen\sascha\lokale einstellungen\anwendungsdaten\mozilla\firefox\profiles\kkokuipl.default\cache\_cache_001_
 Status: Size mismatch (API: 2065923, Raw: 2065332)
 
 SSDT
 -------------------
 #: 041        Function Name: NtCreateKey
 Status: Hooked by "Lbd.sys" at address 0xf74f787e
 
 #: 071        Function Name: NtEnumerateKey
 Status: Hooked by "spgf.sys" at address 0xf72acda4
 
 #: 073        Function Name: NtEnumerateValueKey
 Status: Hooked by "spgf.sys" at address 0xf72ad132
 
 #: 119        Function Name: NtOpenKey
 Status: Hooked by "spgf.sys" at address 0xf72940c0
 
 #: 122        Function Name: NtOpenProcess
 Status: Hooked by "C:\Programme\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xa6ec4c90
 
 #: 128        Function Name: NtOpenThread
 Status: Hooked by "C:\Programme\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xa6ec4d7e
 
 #: 160        Function Name: NtQueryKey
 Status: Hooked by "spgf.sys" at address 0xf72ad20a
 
 #: 177        Function Name: NtQueryValueKey
 Status: Hooked by "spgf.sys" at address 0xf72ad08a
 
 #: 247        Function Name: NtSetValueKey
 Status: Hooked by "Lbd.sys" at address 0xf74f7bfe
 
 #: 257        Function Name: NtTerminateProcess
 Status: Hooked by "C:\Programme\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xa6ec4bf4
 
 #: 258        Function Name: NtTerminateThread
 Status: Hooked by "C:\Programme\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xa6ec4ec4
 
 Stealth Objects
 -------------------
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
 Process: System        Address: 0x8a6031f8        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_CREATE]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_CLOSE]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_READ]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_WRITE]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_QUERY_INFORMATION]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_SET_INFORMATION]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_QUERY_VOLUME_INFORMATION]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_DIRECTORY_CONTROL]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_FILE_SYSTEM_CONTROL]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_LOCK_CONTROL]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_CLEANUP]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: UdfsЅ౨瑎晦܂Èੈ, IRP_MJ_PNP]
 Process: System        Address: 0x8a34e500        Size: 121
 
 Object: Hidden Code [Driver: sys, IRP_MJ_CREATE]
 Process: System        Address: 0x89f381f8        Size: 121
 
 Object: Hidden Code [Driver: sys, IRP_MJ_CLOSE]
 Process: System        Address: 0x89f381f8        Size: 121
 
 Object: Hidden Code [Driver: sys, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x89f381f8        Size: 121
 
 Object: Hidden Code [Driver: sys, IRP_MJ_INTERNAL_DEVICE_CONTROL]
 Process: System        Address: 0x89f381f8        Size: 121
 
 Object: Hidden Code [Driver: sys, IRP_MJ_POWER]
 Process: System        Address: 0x89f381f8        Size: 121
 
 Object: Hidden Code [Driver: sys, IRP_MJ_SYSTEM_CONTROL]
 Process: System        Address: 0x89f381f8        Size: 121
 
 Object: Hidden Code [Driver: sys, IRP_MJ_PNP]
 Process: System        Address: 0x89f381f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
 Process: System        Address: 0x89f5e1f8        Size: 121
 
 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CREATE]
 Process: System        Address: 0x89f311f8        Size: 121
 
 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CLOSE]
 Process: System        Address: 0x89f311f8        Size: 121
 
 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_READ]
 Process: System        Address: 0x89f311f8        Size: 121
 
 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_WRITE]
 Process: System        Address: 0x89f311f8        Size: 121
 
 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x89f311f8        Size: 121
 
 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_INTERNAL_DEVICE_CONTROL]
 Process: System        Address: 0x89f311f8        Size: 121
 
 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_POWER]
 Process: System        Address: 0x89f311f8        Size: 121
 
 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_SYSTEM_CONTROL]
 Process: System        Address: 0x89f311f8        Size: 121
 
 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_PNP]
 Process: System        Address: 0x89f311f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
 Process: System        Address: 0x8a6041f8        Size: 121
 
 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
 Process: System        Address: 0x8a3891f8        Size: 121
 
 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
 Process: System        Address: 0x8a3891f8        Size: 121
 
 Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x8a3891f8        Size: 121
 
 Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
 Process: System        Address: 0x8a3891f8        Size: 121
 
 Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
 Process: System        Address: 0x8a3891f8        Size: 121
 
 Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
 Process: System        Address: 0x8a3891f8        Size: 121
 
 Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
 Process: System        Address: 0x8a3891f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
 Process: System        Address: 0x8a6751f8        Size: 121
 
 Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
 Process: System        Address: 0x89ec3500        Size: 121
 
 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
 Process: System        Address: 0x89ec3500        Size: 121
 
 Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x89ec3500        Size: 121
 
 Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
 Process: System        Address: 0x89ec3500        Size: 121
 
 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
 Process: System        Address: 0x89ec3500        Size: 121
 
 Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
 Process: System        Address: 0x89ec3500        Size: 121
 
 Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
 Process: System        Address: 0x89f431f8        Size: 121
 
 Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
 Process: System        Address: 0x89f431f8        Size: 121
 
 Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x89f431f8        Size: 121
 
 Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
 Process: System        Address: 0x89f431f8        Size: 121
 
 Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
 Process: System        Address: 0x89f431f8        Size: 121
 
 Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
 Process: System        Address: 0x89f431f8        Size: 121
 
 Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
 Process: System        Address: 0x89f431f8        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
 Process: System        Address: 0x89f2f500        Size: 121
 
 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
 Process: System        Address: 0x89f2f500        Size: 121
 
 ==EOF==
 |