offline
- cvetko_a
- Građanin
- Pridružio: 20 Feb 2005
- Poruke: 297
- Gde živiš: Vranje
|
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/05/03 08:58
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name:
Image Path:
Address: 0xF782F000 Size: 98304 File Visible: No
Status: -
Name:
Image Path:
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: 00000066
Image Path: \Driver\00000066
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: giveio.sys
Image Path: giveio.sys
Address: 0xF7A50000 Size: 1664 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA3EF7000 Size: 45056 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\WINDOWS\system32\config\system.LOG
Status: Size mismatch (API: 1024, Raw: 20480)
Path: C:\Documents and Settings\korisnik\Application Data\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρϴϱЄϱЃϵϳЅ
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Application Data\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρЂϻϵЉЃϵϳЅ
Status: Locked to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\av52.tmp
Status: Allocation size mismatch (API: 28565504, Raw: 0)
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\av59.tmp
Status: Allocation size mismatch (API: 28553216, Raw: 0)
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\dragan.milena@hotmail.de\DFSR\Staging\CS{3E45E3E9-8768-91D2-E5CE-F418464DB002}\01\29-{3E45E3E9-8768-91D2-E5CE-F418464DB002}-v1-{F89BC910-6049-4284-A21A-AE2539CC7237}-v29-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\dragan.milena@hotmail.de\DFSR\Staging\CS{3E45E3E9-8768-91D2-E5CE-F418464DB002}\12\12-{A9CB0F18-76F4-466A-8DC8-C53BA66C9AB4}-v12-{A9CB0F18-76F4-466A-8DC8-C53BA66C9AB4}-v12-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\jovan_a96@hotmail.com\DFSR\Staging\CS{BF9452D5-0E5C-D10D-996E-1CD13ACACA41}\01\17-{BF9452D5-0E5C-D10D-996E-1CD13ACACA41}-v1-{F89BC910-6049-4284-A21A-AE2539CC7237}-v17-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\manicslobodan@hotmail.com\DFSR\Staging\CS{2C421593-CC3E-74CB-9A9B-7C2855936169}\01\10-{2C421593-CC3E-74CB-9A9B-7C2855936169}-v1-{F89BC910-6049-4284-A21A-AE2539CC7237}-v10-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\manicslobodan@hotmail.com\DFSR\Staging\CS{2C421593-CC3E-74CB-9A9B-7C2855936169}\11\11-{F89BC910-6049-4284-A21A-AE2539CC7237}-v11-{F89BC910-6049-4284-A21A-AE2539CC7237}-v11-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\manicslobodan@hotmail.com\DFSR\Staging\CS{2C421593-CC3E-74CB-9A9B-7C2855936169}\12\12-{F89BC910-6049-4284-A21A-AE2539CC7237}-v12-{F89BC910-6049-4284-A21A-AE2539CC7237}-v12-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\manicslobodan@hotmail.com\DFSR\Staging\CS{2C421593-CC3E-74CB-9A9B-7C2855936169}\15\15-{F89BC910-6049-4284-A21A-AE2539CC7237}-v15-{F89BC910-6049-4284-A21A-AE2539CC7237}-v15-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\01\28-{25C26106-9A8B-0844-9E79-EA59AAB8C72B}-v1-{F89BC910-6049-4284-A21A-AE2539CC7237}-v28-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\11\11-{8E5FA966-7F0E-4C65-A444-F9FD480C59EF}-v11-{8E5FA966-7F0E-4C65-A444-F9FD480C59EF}-v11-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\11\11-{95BC613E-38A0-4363-8305-4095B9843B35}-v11-{95BC613E-38A0-4363-8305-4095B9843B35}-v11-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\12\12-{95BC613E-38A0-4363-8305-4095B9843B35}-v12-{95BC613E-38A0-4363-8305-4095B9843B35}-v12-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\13\13-{95BC613E-38A0-4363-8305-4095B9843B35}-v13-{95BC613E-38A0-4363-8305-4095B9843B35}-v13-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\14\14-{95BC613E-38A0-4363-8305-4095B9843B35}-v14-{95BC613E-38A0-4363-8305-4095B9843B35}-v14-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\15\15-{95BC613E-38A0-4363-8305-4095B9843B35}-v15-{95BC613E-38A0-4363-8305-4095B9843B35}-v15-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\16\16-{95BC613E-38A0-4363-8305-4095B9843B35}-v16-{95BC613E-38A0-4363-8305-4095B9843B35}-v16-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\17\17-{95BC613E-38A0-4363-8305-4095B9843B35}-v17-{95BC613E-38A0-4363-8305-4095B9843B35}-v17-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\18\18-{95BC613E-38A0-4363-8305-4095B9843B35}-v18-{95BC613E-38A0-4363-8305-4095B9843B35}-v18-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\19\19-{95BC613E-38A0-4363-8305-4095B9843B35}-v19-{95BC613E-38A0-4363-8305-4095B9843B35}-v19-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\20\20-{95BC613E-38A0-4363-8305-4095B9843B35}-v20-{95BC613E-38A0-4363-8305-4095B9843B35}-v20-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\21\21-{95BC613E-38A0-4363-8305-4095B9843B35}-v21-{95BC613E-38A0-4363-8305-4095B9843B35}-v21-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\23\23-{95BC613E-38A0-4363-8305-4095B9843B35}-v23-{95BC613E-38A0-4363-8305-4095B9843B35}-v23-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\24\24-{95BC613E-38A0-4363-8305-4095B9843B35}-v24-{95BC613E-38A0-4363-8305-4095B9843B35}-v24-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\26\26-{95BC613E-38A0-4363-8305-4095B9843B35}-v26-{95BC613E-38A0-4363-8305-4095B9843B35}-v26-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\27\27-{95BC613E-38A0-4363-8305-4095B9843B35}-v27-{95BC613E-38A0-4363-8305-4095B9843B35}-v27-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\28\28-{8E5FA966-7F0E-4C65-A444-F9FD480C59EF}-v28-{8E5FA966-7F0E-4C65-A444-F9FD480C59EF}-v28-Partial.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\28\28-{95BC613E-38A0-4363-8305-4095B9843B35}-v28-{95BC613E-38A0-4363-8305-4095B9843B35}-v28-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\29\29-{95BC613E-38A0-4363-8305-4095B9843B35}-v29-{95BC613E-38A0-4363-8305-4095B9843B35}-v29-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\30\30-{95BC613E-38A0-4363-8305-4095B9843B35}-v30-{95BC613E-38A0-4363-8305-4095B9843B35}-v30-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\30\30-{F89BC910-6049-4284-A21A-AE2539CC7237}-v30-{F89BC910-6049-4284-A21A-AE2539CC7237}-v30-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\31\31-{95BC613E-38A0-4363-8305-4095B9843B35}-v31-{95BC613E-38A0-4363-8305-4095B9843B35}-v31-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\31\31-{F89BC910-6049-4284-A21A-AE2539CC7237}-v31-{F89BC910-6049-4284-A21A-AE2539CC7237}-v31-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\32\32-{95BC613E-38A0-4363-8305-4095B9843B35}-v32-{95BC613E-38A0-4363-8305-4095B9843B35}-v32-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\34\34-{95BC613E-38A0-4363-8305-4095B9843B35}-v34-{95BC613E-38A0-4363-8305-4095B9843B35}-v34-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\35\35-{95BC613E-38A0-4363-8305-4095B9843B35}-v35-{95BC613E-38A0-4363-8305-4095B9843B35}-v35-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\37\37-{95BC613E-38A0-4363-8305-4095B9843B35}-v37-{95BC613E-38A0-4363-8305-4095B9843B35}-v37-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\38\38-{95BC613E-38A0-4363-8305-4095B9843B35}-v38-{95BC613E-38A0-4363-8305-4095B9843B35}-v38-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\39\39-{95BC613E-38A0-4363-8305-4095B9843B35}-v39-{95BC613E-38A0-4363-8305-4095B9843B35}-v39-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\40\40-{95BC613E-38A0-4363-8305-4095B9843B35}-v40-{95BC613E-38A0-4363-8305-4095B9843B35}-v40-Partial.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\hranca@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{25C26106-9A8B-0844-9E79-EA59AAB8C72B}\62\62-{F89BC910-6049-4284-A21A-AE2539CC7237}-v62-{F89BC910-6049-4284-A21A-AE2539CC7237}-v62-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\korisnik\Local Settings\Application Data\Microsoft\Messenger\stefansoki@hotmail.com\SharingMetadata\slobodan-manic@hotmail.com\DFSR\Staging\CS{575546BD-D4DE-8B77-0823-1F64DFC06609}\01\10-{575546BD-D4DE-8B77-0823-1F64DFC06609}-v1-{94E22F66-56F5-4DC6-B854-E3CD35B32941}-v10-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\retranslation\rollback\bases\av\emu\i386\klavemu.kdc:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Invisible to the Windows API!
SSDT
-------------------
#: 011 Function Name: NtAdjustPrivilegesToken
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660ca72
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660d01e
#: 031 Function Name: NtConnectPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660ea82
#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660e438
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660c1e8
#: 045 Function Name: NtCreatePagingFile
Status: Hooked by "d347bus.sys" at address 0xf74c2a20
#: 052 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa66103e4
#: 053 Function Name: NtCreateThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660ce1a
#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660c62a
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660c82a
#: 066 Function Name: NtDeviceIoControlFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660e744
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa66108f0
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660c940
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660c9a8
#: 084 Function Name: NtFsControlFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660e5fa
#: 097 Function Name: NtLoadDriver
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660fea8
#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660e294
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660c34a
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660cc40
#: 125 Function Name: NtOpenSection
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa661040e
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660cb96
#: 160 Function Name: NtQueryKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660ca10
#: 161 Function Name: NtQueryMultipleValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660c714
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660c4f2
#: 180 Function Name: NtQueueApcThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6610110
#: 193 Function Name: NtReplaceKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660be6a
#: 200 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660f30c
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa660bStealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8ae52bf0 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8af261d8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x8a73ec80 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x8a46f4f0 Size: -
Object: Hidden Code [Driver: iteatapi, IRP_MJ_CREATE]
Process: System Address: 0x8aeb31d8 Size: -
Object: Hidden Code [Driver: iteatapi, IRP_MJ_CLOSE]
Process: System Address: 0x8aeb31d8 Size: -
Object: Hidden Code [Driver: iteatapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aeb31d8 Size: -
Object: Hidden Code [Driver: iteatapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8aeb31d8 Size: -
Object: Hidden Code [Driver: iteatapi, IRP_MJ_POWER]
Process: System Address: 0x8aeb31d8 Size: -
Object: Hidden Code [Driver: iteatapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8aeb31d8 Size: -
Object: Hidden Code [Driver: iteatapi, IRP_MJ_PNP]
Process: System Address: 0x8aeb31d8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_READ]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_WRITE]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_EA]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CLEANUP]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x8a80f008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_EA]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLEANUP]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8a805008 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x8af291d8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x8aaff4e0 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x8aaff4e0 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aaff4e0 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8aaff4e0 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x8aaff4e0 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8aaff4e0 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x8aaff4e0 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8aeb51d8 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_CREATE]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_CLOSE]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_READ]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_WRITE]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_SET_EA]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_CLEANUP]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_POWER]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: d347prt, IRP_MJ_PNP]
Process: System Address: 0x8a377de0 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_CREATE]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_CLOSE]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_READ]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_WRITE]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_SET_EA]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_CLEANUP]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_POWER]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: Vax347s, IRP_MJ_PNP]
Process: System Address: 0x8a42dc48 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_CREATE]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_CLOSE]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_READ]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_WRITE]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_SET_EA]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_CLEANUP]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_POWER]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: FVDSCSI, IRP_MJ_PNP]
Process: System Address: 0x8a627b18 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x8a7df980 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x8a7df980 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a7df980 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a7df980 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x8a7df980 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x8a7df980 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x8a766e18 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x8a7ca6e8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x8a7b64a0 Size: -
Object: Hidden Code [Driver: Npfs灐䕅ం扏楄菘逰詛ఆ剒敬, IRP_MJ_READ]
Process: System Address: 0x8a979290 Size: -
Object: Hidden Code [Driver: Msfsࠅఊ䵃慖, IRP_MJ_READ]
Process: System Address: 0x8af37298 Size: -
Object: Hidden Code [Driver: Fs_Rec, IRP_MJ_READ]
Process: System Address: 0x8aafafb0 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_CREATE]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_CLOSE]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_READ]
Process: System Address: 0x8a5d7230 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_CLEANUP]
Process: System Address: 0x8a6b24b8 Size: -
Object: Hidden Code [Driver: CdfsЅ䱋湲Ё敓Ĩ, IRP_MJ_PNP]
Process: System Address: 0x8a6b24b8 Size: -
|