offline
- Pridružio: 18 Apr 2009
- Poruke: 34
|
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/12/06 18:00
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name:
Image Path:
Address: 0xB9EE3000 Size: 98304 File Visible: No Signed: -
Status: -
Name:
Image Path:
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: axloqpoc.sys
Image Path: C:\DOCUME~1\Ivan\LOCALS~1\Temp\axloqpoc.sys
Address: 0xB1265000 Size: 91904 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB2AB2000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA618000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB18D6000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: c:\windows\temp\964409fc-53f0-41a0-9c32-ff5bf160f346.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\555a4b28-7414-4718-a731-a40b85382ae6.tmp
Status: Allocation size mismatch (API: 8192, Raw: 0)
Path: c:\windows\temp\0b3a3eee-55aa-402c-8b77-4802fd81c9e8.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\0da1aaf6-cb4f-4efb-887a-05adcc5c5232.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\dba5c8cc-acb3-482f-8564-d3559104e585.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\bfcdc5a4-26f0-41e1-8a34-7d3c9d4db73a.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\11a4896f-ac1e-49c1-8f20-b0a682a35186.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\a82de2ed-7e25-40dc-806f-fc74e57ca93a.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\f4f90ce0-e836-4a87-9589-0480f2dc89b2.tmp
Status: Allocation size mismatch (API: 65536, Raw: 0)
Path: c:\windows\temp\f541709b-26cf-4988-93b1-8a90f9bf1be9.tmp
Status: Allocation size mismatch (API: 65536, Raw: 0)
Path: c:\windows\temp\ccf6dc29-b083-4405-a25d-66cf72a4b2cb.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\e5f6c449-1dea-4787-8026-74f562be75da.tmp
Status: Allocation size mismatch (API: 32768, Raw: 0)
Path: c:\windows\temp\2c6cdc6d-ca75-496f-97d4-33452fff11c6.tmp
Status: Allocation size mismatch (API: 8192, Raw: 0)
Path: c:\windows\temp\d27ac83f-2444-4a99-95b7-01438f23f020.tmp
Status: Allocation size mismatch (API: 65536, Raw: 0)
Path: c:\windows\temp\67acb019-afee-4c04-a896-2a8755ad0f98.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\67c6432e-badf-440e-b2ef-ee3ed23c834d.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\39619c85-ed80-416c-a6cc-8baa29469176.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\3b1017a1-92c0-455f-a660-b2aa6ae33925.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\3b599746-73f1-44c7-8827-159a92c2d9ce.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\7710f859-599b-4084-9387-f8abeec06945.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\7c002ab9-5753-4c46-961d-199e11674730.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\1710b8b5-d271-4314-9ca2-a19abe56f39d.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\8df7d7d0-4c11-429f-aa59-4a29a16c269a.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\85163706-f92d-49af-8d01-ea11e8afe93e.tmp
Status: Allocation size mismatch (API: 49152, Raw: 0)
Path: c:\windows\temp\0721818b-5ccc-4243-84a5-093517efdddd.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\c52e18df-2bd1-4c61-a620-c6c32c44b52a.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\eac2751b-99c0-47a0-8ca5-f2b22b835c9f.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\42ba7b65-1103-4e88-a880-3c6e96181154.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\45fa73ac-c424-46db-8c07-9eb68aaaa029.tmp
Status: Allocation size mismatch (API: 131072, Raw: 0)
Path: c:\documents and settings\ivan\application data\mozilla\firefox\profiles\00x37hrj.default\sessionstore.js
Status: Size mismatch (API: 4117, Raw: 4355)
SSDT
-------------------
#: 025 Function Name: NtClose
Status: Hooked by "a347bus.sys" at address 0xb9f8d028
#: 041 Function Name: NtCreateKey
Status: Hooked by "a347bus.sys" at address 0xb9f8cfe0
#: 045 Function Name: NtCreatePagingFile
Status: Hooked by "a347bus.sys" at address 0xb9f80b00
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "a347bus.sys" at address 0xb9f815dc
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "a347bus.sys" at address 0xb9f8d120
#: 116 Function Name: NtOpenFile
Status: Hooked by "a347bus.sys" at address 0xb9f80b40
#: 119 Function Name: NtOpenKey
Status: Hooked by "a347bus.sys" at address 0xb9f8cfa4
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xba4b1470
#: 160 Function Name: NtQueryKey
Status: Hooked by "a347bus.sys" at address 0xb9f815fc
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "a347bus.sys" at address 0xb9f8d076
#: 241 Function Name: NtSetSystemPowerState
Status: Hooked by "a347bus.sys" at address 0xb9f8c550
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xba4b1520
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xba4b15c0
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xba4b1660
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x89d04270 Size: 11
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_READ]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_WRITE]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_EA]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_EA]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CLEANUP]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x89b4f008 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_CREATE]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_CLOSE]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_READ]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_WRITE]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_QUERY_EA]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_SET_EA]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_CLEANUP]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_POWER]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: a347scsi, IRP_MJ_PNP]
Process: System Address: 0x89b0bd98 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_EA]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_EA]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLEANUP]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x89c38678 Size: 99
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x89e4cd08 Size: 11
Object: Hidden Code [Driver: Srv, IRP_MJ_READ]
Process: System Address: 0x88f59a20 Size: 11
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x89cc9af0 Size: 11
Object: Hidden Code [Driver: Npfsࠅఐ卆浩, IRP_MJ_READ]
Process: System Address: 0x89cffcd8 Size: 11
Object: Hidden Code [Driver: Msfsఇ癁⩧, IRP_MJ_READ]
Process: System Address: 0x89d03cd0 Size: 11
Object: Hidden Code [Driver: Fs_Rec, IRP_MJ_READ]
Process: System Address: 0x89c9c370 Size: 11
Object: Hidden Code [Driver: CdfsЅః杇獬þ, IRP_MJ_READ]
Process: System Address: 0x89483fb0 Size: 11
==EOF==
|