offline
- Pridružio: 28 Jun 2008
- Poruke: 61
|
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/01/15 00:11
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: 00000067
Image Path: \Driver\00000067
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: dump_iaStor.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
Address: 0x9A0AD000 Size: 819200 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xBA1C8000 Size: 45056 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Hum\Application Data\Sports Interactive\Installer Launcher
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Hum\Local Settings\temp\etilqs_YxEoCbhhBjueLnlm4Ofd
Status: Allocation size mismatch (API: 65536, Raw: 0)
Path: C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6yd6ihjy.default\sessionstore.js
Status: Could not get file information (Error 0xc0000008-)
Path: C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6yd6ihjy.default\extensions\{991A772A-BA13-4c1d-A9EF-F897F31DEC7D}\chrome\cache\alexa_240c9cb1bc89c0bca251a683f82202e6.xml
Status: Size mismatch (API: 2250, Raw: 2239)
Path: C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6yd6ihjy.default\extensions\{991A772A-BA13-4c1d-A9EF-F897F31DEC7D}\chrome\cache\alexa_ab7cdaba0acc9de71da05aa126256437.xml
Status: Could not get file information (Error 0xc0000008-)
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "sptd.sys" at address 0xb9edcb3a
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xb9edcc7e
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xb9edcff6
#: 119 Function Name: NtOpenKey
Status: Hooked by "sptd.sys" at address 0xb9edca18
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys" at address 0x99cfab4c
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys" at address 0x99cfac3a
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xb9edd0c0
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "sptd.sys" at address 0xb9edcf58
#: 247 Function Name: NtSetValueKey
Status: Hooked by "sptd.sys" at address 0xb9edd148
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys" at address 0x99cfaab0
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8aaf8788 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_CREATE]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_CLOSE]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_READ]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_WRITE]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_POWER]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Disk, IRP_MJ_PNP]
Process: System Address: 0x8aaf8a40 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x89f860e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x8aaab590 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_CREATE]
Process: System Address: 0x8aaf8eb0 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_CLOSE]
Process: System Address: 0x8aaf8eb0 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aaf8eb0 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8aaf8eb0 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_POWER]
Process: System Address: 0x8aaf8eb0 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8aaf8eb0 Size: -
Object: Hidden Code [Driver: iaStor, IRP_MJ_PNP]
Process: System Address: 0x8aaf8eb0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8aaab7c8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x89c092f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x89c092f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c092f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c092f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x89c092f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x89c092f8 Size: -
Object: Hidden Code [Driver: iastor78, IRP_MJ_CREATE]
Process: System Address: 0x8aaf8c78 Size: -
Object: Hidden Code [Driver: iastor78, IRP_MJ_CLOSE]
Process: System Address: 0x8aaf8c78 Size: -
Object: Hidden Code [Driver: iastor78, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aaf8c78 Size: -
Object: Hidden Code [Driver: iastor78, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8aaf8c78 Size: -
Object: Hidden Code [Driver: iastor78, IRP_MJ_POWER]
Process: System Address: 0x8aaf8c78 Size: -
Object: Hidden Code [Driver: iastor78, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8aaf8c78 Size: -
Object: Hidden Code [Driver: iastor78, IRP_MJ_PNP]
Process: System Address: 0x8aaf8c78 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLOSE]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_WRITE]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_EA]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_EA]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLEANUP]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_POWER]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89c05798 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x89c2cd18 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_CREATE]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_CLOSE]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_READ]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_WRITE]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_CLEANUP]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: Npfs敓, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89918598 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_CREATE]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_CLOSE]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_READ]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_WRITE]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_CLEANUP]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: VgaS, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89c05288 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_CREATE]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_CLOSE]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_READ]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_CLEANUP]
Process: System Address: 0x89e260e8 Size: -
Object: Hidden Code [Driver: CdfsЅఉ瑎捦܉@考, IRP_MJ_PNP]
Process: System Address: 0x89e260e8 Size: -
Dopuna: 15 Jan 2009 0:33
mycity.rs/must-login.png
Dopuna: 15 Jan 2009 13:39
Prikačio sam fajl na dnu ove poruke, izvinjavam se što sam ranije kopirao i zalijepio.
Dopuna: 15 Jan 2009 17:03
Ima li netko da mi pomogne???
|