domi0815 | 07.12.2009 19:45 | Hab die drei Sachen gescant.
Hier ist die log: Code:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/12/07 19:44
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name:
Image Path:
Address: 0xB9DCB000 Size: 98304 File Visible: No Signed: -
Status: -
Name:
Image Path:
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xACD2E000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA622000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PCI_PNP4990
Image Path: \Driver\PCI_PNP4990
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA95B7000 Size: 49152 File Visible: No Signed: -
Status: -
Name: spiy.sys
Image Path: spiy.sys
Address: 0xB9EA7000 Size: 1048576 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8a6961f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_CREATE]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_CLOSE]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_READ]
Process: System Address: 0x8a2bd638 Size: 11
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_WRITE]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_CLEANUP]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Udfsȅః扏济Sessionsȃఛ楄, IRP_MJ_PNP]
Process: System Address: 0x8974f1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_EA]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLEANUP]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8a49c8e8 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_READ]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_WRITE]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_EA]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CLEANUP]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x8a2e4820 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_CREATE]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_CLOSE]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_READ]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_WRITE]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_QUERY_EA]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_SET_EA]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_CLEANUP]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_POWER]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: ak09zszsȅఉ瑎捦܉@考, IRP_MJ_PNP]
Process: System Address: 0x89c5cf00 Size: 99
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x8a6981f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x8a4581f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x8a4581f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a4581f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a4581f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x8a4581f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a4581f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x8a4581f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8a70a1f8 Size: 121
Object: Hidden Code [Driver: vax347s, IRP_MJ_CREATE]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_CLOSE]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_READ]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_WRITE]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_EA]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_CLEANUP]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_POWER]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: vax347s, IRP_MJ_PNP]
Process: System Address: 0x8a1e2a80 Size: 99
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x899d01f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x899d01f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x899d01f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x899d01f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x899d01f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x899d01f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x8a3e71f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x8a3e71f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a3e71f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a3e71f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x8a3e71f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a3e71f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x8a3e71f8 Size: 121
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x8a4acfb0 Size: 11
Object: Hidden Code [Driver: Srv, IRP_MJ_READ]
Process: System Address: 0x8a5ea468 Size: 11
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x8a5b5ac0 Size: 11
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x899651f8 Size: 121
Object: Hidden Code [Driver: NpfsЅఉ敓, IRP_MJ_READ]
Process: System Address: 0x8a662660 Size: 11
Object: Hidden Code [Driver: Msfsȅ扏煓ШȂఊ祓ジ, IRP_MJ_READ]
Process: System Address: 0x8a49a178 Size: 11
Object: Hidden Code [Driver: Fs_Rec, IRP_MJ_READ]
Process: System Address: 0x8a48eba0 Size: 11
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_CREATE]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_CLOSE]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_READ]
Process: System Address: 0x8a464178 Size: 11
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_SHUTDOWN]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_CLEANUP]
Process: System Address: 0x897501f8 Size: 121
Object: Hidden Code [Driver: Cdfsࠅ灎剆ࠁ敋ꁹ, IRP_MJ_PNP]
Process: System Address: 0x897501f8 Size: 121
==EOF== |