offline
- Acid_Burn
- Moderator foruma
- Glavni moderator foruma Zabava
- Hellraiser
- Demon to some. Angel to others
- Pridružio: 07 Jan 2005
- Poruke: 25503
- Gde živiš: Beneath the Black Sky
|
Kada otvori npr My ciomputer nestaju ikonice pojave se nestanu pojave se nestanu i sl.
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/01/30 23:41
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: ajflc6oz.SYS
Image Path: C:\WINDOWS\System32\Drivers\ajflc6oz.SYS
Address: 0xB7640000 Size: 417792 File Visible: No
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xADECB000 Size: 98304 File Visible: No
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA5F6000 Size: 8192 File Visible: No
Status: -
Name: PCI_NTPNP7858
Image Path: \Driver\PCI_NTPNP7858
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAA9CD000 Size: 45056 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\Documents and Settings\Tanja\Local Settings\Temp\etilqs_HowehbDAuq6YYtRKilCh
Status: Allocation size mismatch (API: 32768, Raw: 0)
SSDT
-------------------
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xae08c576
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xae08c432
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xae08c910
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xae08c00a
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xb9ec5e2c
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xb9ec61ba
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xae08c50c
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xae08bf4a
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xae08bfae
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xb9ec6292
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xae08c62c
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xae08c5ec
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xae08c76c
Stealth Objects
-------------------
Object: Hidden Module [Name: System.Runtime.Remoting.dll]
Process: MOM.exe (PID: 2556) Address: 0x01170000 Size: 307200
Object: Hidden Module [Name: MOM.Implementation.DLL]
Process: MOM.exe (PID: 2556) Address: 0x00d10000 Size: 118784
Object: Hidden Module [Name: LOG.Foundation.DLL]
Process: MOM.exe (PID: 2556) Address: 0x00d40000 Size: 45056
Object: Hidden Module [Name: LOG.Foundation.Implementation.DLL]
Process: MOM.exe (PID: 2556) Address: 0x00dc0000 Size: 69632
Object: Hidden Module [Name: LOG.Foundation.Private.DLL]
Process: MOM.exe (PID: 2556) Address: 0x00db0000 Size: 45056
Object: Hidden Module [Name: MOM.Foundation.DLL]
Process: MOM.exe (PID: 2556) Address: 0x00f30000 Size: 28672
Object: Hidden Module [Name: LOG.Foundation.Implementation.Private.DLL]
Process: MOM.exe (PID: 2556) Address: 0x01160000 Size: 28672
Object: Hidden Module [Name: CCC.Implementation.DLL]
Process: MOM.exe (PID: 2556) Address: 0x01860000 Size: 36864
Object: Hidden Module [Name: NEWAEM.Foundation.DLL]
Process: MOM.exe (PID: 2556) Address: 0x01880000 Size: 36864
Object: Hidden Module [Name: CLI.Aspect.MMVideo.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05310000 Size: 61440
Object: Hidden Module [Name: CLI.Aspect.DeviceLCD.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x051f0000 Size: 45056
Object: Hidden Module [Name: CLI.Caste.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x04ae0000 Size: 282624
Object: Hidden Module [Name: AEM.Plugin.WinMessages.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01cd0000 Size: 28672
Object: Hidden Module [Name: AxInterop.WBOCXLib.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01ac0000 Size: 36864
Object: Hidden Module [Name: CCC.Implementation.DLL]
Process: ccc.exe (PID: 3584) Address: 0x00d80000 Size: 36864
Object: Hidden Module [Name: CLI.Foundation.DLL]
Process: ccc.exe (PID: 3584) Address: 0x00dc0000 Size: 61440
Object: Hidden Module [Name: LOG.Foundation.DLL]
Process: ccc.exe (PID: 3584) Address: 0x00da0000 Size: 45056
Object: Hidden Module [Name: MOM.Foundation.DLL]
Process: ccc.exe (PID: 3584) Address: 0x00db0000 Size: 28672
Object: Hidden Module [Name: LOG.Foundation.Implementation.DLL]
Process: ccc.exe (PID: 3584) Address: 0x00de0000 Size: 69632
Object: Hidden Module [Name: LOG.Foundation.Implementation.Private.DLL]
Process: ccc.exe (PID: 3584) Address: 0x00dd0000 Size: 28672
Object: Hidden Module [Name: System.Runtime.Remoting.dll]
Process: ccc.exe (PID: 3584) Address: 0x00e10000 Size: 307200
Object: Hidden Module [Name: LOG.Foundation.Private.DLL]
Process: ccc.exe (PID: 3584) Address: 0x00e70000 Size: 45056
Object: Hidden Module [Name: CLI.Component.SkinFactory.DLL]
Process: ccc.exe (PID: 3584) Address: 0x019e0000 Size: 61440
Object: Hidden Module [Name: MOM.Implementation.DLL]
Process: ccc.exe (PID: 3584) Address: 0x019c0000 Size: 118784
Object: Hidden Module [Name: CLI.Foundation.XManifest.DLL]
Process: ccc.exe (PID: 3584) Address: 0x019f0000 Size: 36864
Object: Hidden Module [Name: CLI.Component.Runtime.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01a80000 Size: 28672
Object: Hidden Module [Name: CLI.Component.Runtime.Shared.Private.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01a60000 Size: 53248
Object: Hidden Module [Name: CLI.Component.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01a50000 Size: 61440
Object: Hidden Module [Name: CLI.Foundation.Private.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01a70000 Size: 53248
Object: Hidden Module [Name: ATICCCom.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01aa0000 Size: 45056
Object: Hidden Module [Name: LOCALIZATION.Foundation.Private.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01a90000 Size: 28672
Object: Hidden Module [Name: NEWAEM.Foundation.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01b10000 Size: 36864
Object: Hidden Module [Name: AEM.Server.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01af0000 Size: 53248
Object: Hidden Module [Name: AEM.Plugin.Source.Kit.Server.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01ad0000 Size: 53248
Object: Hidden Module [Name: AEM.Plugin.Hotkeys.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01c50000 Size: 28672
Object: Hidden Module [Name: AEM.Plugin.DPPE.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01c20000 Size: 28672
Object: Hidden Module [Name: AEM.Server.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01c10000 Size: 28672
Object: Hidden Module [Name: DEM.Graphics.I0601.DLL]
Process: ccc.exe (PID: 3584) Address: 0x01f80000 Size: 53248
Object: Hidden Module [Name: DEM.Graphics.DLL]
Process: ccc.exe (PID: 3584) Address: 0x02030000 Size: 28672
Object: Hidden Module [Name: DEM.Foundation.DLL]
Process: ccc.exe (PID: 3584) Address: 0x02020000 Size: 28672
Object: Hidden Module [Name: ATIDEMGX.dll]
Process: ccc.exe (PID: 3584) Address: 0x02040000 Size: 430080
Object: Hidden Module [Name: Interop.WBOCXLib.DLL]
Process: ccc.exe (PID: 3584) Address: 0x02150000 Size: 36864
Object: Hidden Module [Name: LOCALIZATION.Foundation.Implementation.DLL]
Process: ccc.exe (PID: 3584) Address: 0x02280000 Size: 36864
Object: Hidden Module [Name: ATIDEMOS.DLL]
Process: ccc.exe (PID: 3584) Address: 0x04ba0000 Size: 77824
Object: Hidden Module [Name: ACE.Graphics.DisplaysManager.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x04b40000 Size: 36864
Object: Hidden Module [Name: CLI.Caste.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x04b30000 Size: 61440
Object: Hidden Module [Name: DEM.OS.I0602.DLL]
Process: ccc.exe (PID: 3584) Address: 0x04b50000 Size: 28672
Object: Hidden Module [Name: DEM.Graphics.I0709.dll]
Process: ccc.exe (PID: 3584) Address: 0x04b90000 Size: 28672
Object: Hidden Module [Name: DEM.OS.DLL]
Process: ccc.exe (PID: 3584) Address: 0x04b70000 Size: 28672
Object: Hidden Module [Name: AEM.Actions.CCAA.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x04cf0000 Size: 28672
Object: Hidden Module [Name: AEM.Plugin.GD.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x04cd0000 Size: 28672
Object: Hidden Module [Name: DEM.Graphics.I0804.dll]
Process: ccc.exe (PID: 3584) Address: 0x04d10000 Size: 28672
Object: Hidden Module [Name: CLI.Aspect.HotkeysHandling.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05030000 Size: 28672
Object: Hidden Module [Name: CLI.Aspect.HotkeysHandling.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x04f80000 Size: 28672
Object: Hidden Module [Name: CLI.Caste.Graphics.Runtime.Shared.Private.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05010000 Size: 28672
Object: Hidden Module [Name: CLI.Aspect.DeviceCV.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05020000 Size: 53248
Object: Hidden Module [Name: DEM.Graphics.I0805.dll]
Process: ccc.exe (PID: 3584) Address: 0x050a0000 Size: 28672
Object: Hidden Module [Name: CLI.Aspect.DeviceProperty.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05070000 Size: 45056
Object: Hidden Module [Name: CLI.Aspect.DeviceCV.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05040000 Size: 77824
Object: Hidden Module [Name: CLI.Aspect.CustomFormats.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05080000 Size: 36864
Object: Hidden Module [Name: CLI.Aspect.DeviceProperty.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x050d0000 Size: 45056
Object: Hidden Module [Name: DEM.Graphics.I0706.DLL]
Process: ccc.exe (PID: 3584) Address: 0x050c0000 Size: 28672
Object: Hidden Module [Name: CLI.Aspect.DeviceTV.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05110000 Size: 86016
Object: Hidden Module [Name: CLI.Aspect.DeviceTV.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05130000 Size: 77824
Object: Hidden Module [Name: CLI.Aspect.DisplaysColour2.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05170000 Size: 36864
Object: Hidden Module [Name: CLI.Aspect.DisplaysColour2.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05160000 Size: 53248
Object: Hidden Module [Name: CLI.Aspect.DeviceCRT.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x051c0000 Size: 53248
Object: Hidden Module [Name: CLI.Aspect.DisplaysOptions.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x051a0000 Size: 45056
Object: Hidden Module [Name: CLI.Aspect.DisplaysOptions.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x051b0000 Size: 36864
Object: Hidden Module [Name: CLI.Aspect.DeviceCRT.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x051e0000 Size: 61440
Object: Hidden Module [Name: CLI.Aspect.DeviceDFP.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05250000 Size: 61440
Object: Hidden Module [Name: CLI.Aspect.DeviceLCD.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05200000 Size: 36864
Object: Hidden Module [Name: CLI.Aspect.DeviceDFP.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05230000 Size: 69632
Object: Hidden Module [Name: CLI.Aspect.VPURecover.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05270000 Size: 36864
Object: Hidden Module [Name: DEM.Graphics.I0712.dll]
Process: ccc.exe (PID: 3584) Address: 0x05260000 Size: 28672
Object: Hidden Module [Name: CLI.Aspect.Radeon3D.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x052a0000 Size: 69632
Object: Hidden Module [Name: CLI.Aspect.VPURecover.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05290000 Size: 28672
Object: Hidden Module [Name: CLI.Aspect.Radeon3D.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x052c0000 Size: 61440
Object: Hidden Module [Name: CLI.Aspect.MMVideo.Graphics.Runtime.DLL]
Process: ccc.exe (PID: 3584) Address: 0x052f0000 Size: 86016
Object: Hidden Module [Name: APM.Server.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05330000 Size: 69632
Object: Hidden Module [Name: APM.Foundation.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05460000 Size: 28672
Object: Hidden Module [Name: CLI.Caste.Graphics.Wizard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05480000 Size: 53248
Object: Hidden Module [Name: Branding.dll]
Process: ccc.exe (PID: 3584) Address: 0x05490000 Size: 28672
Object: Hidden Module [Name: CLI.Caste.Graphics.Wizard.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x054a0000 Size: 28672
Object: Hidden Module [Name: CLI.Aspect.TransCode.Graphics.Wizard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05500000 Size: 495616
Object: Hidden Module [Name: CLI.Aspect.Radeon3D.Graphics.Wizard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x054c0000 Size: 102400
Object: Hidden Module [Name: CLI.Aspect.TransCode.Graphics.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05590000 Size: 53248
Object: Hidden Module [Name: CLI.Aspect.InfoCentre.Graphics.Wizard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05640000 Size: 217088
Object: Hidden Module [Name: CLI.Component.Runtime.Extension.EEU.DLL]
Process: ccc.exe (PID: 3584) Address: 0x056d0000 Size: 28672
Object: Hidden Module [Name: CLI.Component.Wizard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05800000 Size: 405504
Object: Hidden Module [Name: CLI.Component.Client.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x057f0000 Size: 28672
Object: Hidden Module [Name: CLI.Component.Wizard.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05870000 Size: 28672
Object: Hidden Module [Name: CLI.Component.Wizard.Shared.Private.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05890000 Size: 36864
Object: Hidden Module [Name: atixclib.DLL]
Process: ccc.exe (PID: 3584) Address: 0x058a0000 Size: 28672
Object: Hidden Module [Name: CLI.Component.Dashboard.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x058b0000 Size: 28672
Object: Hidden Module [Name: CLI.Component.Dashboard.Shared.Private.DLL]
Process: ccc.exe (PID: 3584) Address: 0x058d0000 Size: 28672
Object: Hidden Module [Name: CLI.Aspect.Welcome.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05930000 Size: 143360
Object: Hidden Module [Name: AEM.Plugin.EEU.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x058f0000 Size: 28672
Object: Hidden Module [Name: CLI.Caste.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05900000 Size: 86016
Object: Hidden Module [Name: CLI.Caste.Graphics.Dashboard.Shared.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05920000 Size: 28672
Object: Hidden Module [Name: CLI.Component.Systemtray.DLL]
Process: ccc.exe (PID: 3584) Address: 0x06390000 Size: 430080
Object: Hidden Module [Name: CLI.Aspect.DisplaysOptions.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x059a0000 Size: 126976
Object: Hidden Module [Name: CLI.Aspect.InfoCentre.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05960000 Size: 233472
Object: Hidden Module [Name: CLI.Aspect.DisplaysManager.Graphics.Wizard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05ca0000 Size: 1699840
Object: Hidden Module [Name: CLI.Aspect.MMVideo.Graphics.Wizard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05c00000 Size: 413696
Object: Hidden Module [Name: CLI.Aspect.DisplaysManager.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05b00000 Size: 446464
Object: Hidden Module [Name: CLI.Aspect.DeviceCRT.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05b70000 Size: 389120
Object: Hidden Module [Name: CLI.Aspect.VPURecover.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x05bd0000 Size: 110592
Object: Hidden Module [Name: CLI.Aspect.DeviceTV.Graphics.Wizard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x061e0000 Size: 372736
Object: Hidden Module [Name: CLI.Aspect.Radeon3D.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x062f0000 Size: 356352
Object: Hidden Module [Name: CLI.Component.Client.Shared.Private.DLL]
Process: ccc.exe (PID: 3584) Address: 0x06400000 Size: 53248
Object: Hidden Module [Name: CLI.Aspect.DeviceCV.Graphics.Wizard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x06420000 Size: 700416
Object: Hidden Module [Name: CLI.Component.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x065d0000 Size: 1003520
Object: Hidden Module [Name: CLI.Aspect.DeviceCV.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x067d0000 Size: 675840
Object: Hidden Module [Name: CLI.Aspect.DeviceTV.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x06950000 Size: 806912
Object: Hidden Module [Name: CLI.Aspect.DisplaysColour2.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x06a20000 Size: 593920
Object: Hidden Module [Name: CLI.Aspect.MMVideo.Graphics.Dashboard.DLL]
Process: ccc.exe (PID: 3584) Address: 0x06b90000 Size: 815104
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x89d6f1e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x89c021e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_CREATE]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_CLOSE]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_READ]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_WRITE]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_CLEANUP]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Udfsȅ扏济ȁః瑎て, IRP_MJ_PNP]
Process: System Address: 0x88cda1e8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x89a6f7a0 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x89d021e8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE]
Process: System Address: 0x89afe1e8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE]
Process: System Address: 0x89afe1e8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89afe1e8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89afe1e8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER]
Process: System Address: 0x89afe1e8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89afe1e8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP]
Process: System Address: 0x89afe1e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x89d711e8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x89a8a488 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x89a8a488 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89a8a488 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89a8a488 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x89a8a488 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x89a8a488 Size: -
Object: Hidden Code [Driver: ajflc6ozȅ扏煓崨Ȃః瑎て, IRP_MJ_CREATE]
Process: System Address: 0x89adb498 Size: -
Object: Hidden Code [Driver: ajflc6ozȅ扏煓崨Ȃః瑎て, IRP_MJ_CLOSE]
Process: System Address: 0x89adb498 Size: -
Object: Hidden Code [Driver: ajflc6ozȅ扏煓崨Ȃః瑎て, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89adb498 Size: -
Object: Hidden Code [Driver: ajflc6ozȅ扏煓崨Ȃః瑎て, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89adb498 Size: -
Object: Hidden Code [Driver: ajflc6ozȅ扏煓崨Ȃః瑎て, IRP_MJ_POWER]
Process: System Address: 0x89adb498 Size: -
Object: Hidden Code [Driver: ajflc6ozȅ扏煓崨Ȃః瑎て, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89adb498 Size: -
Object: Hidden Code [Driver: ajflc6ozȅ扏煓崨Ȃః瑎て, IRP_MJ_PNP]
Process: System Address: 0x89adb498 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x89ae41e8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x89ae41e8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89ae41e8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89ae41e8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x89ae41e8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89ae41e8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x89ae41e8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x89854488 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_CREATE]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_CLOSE]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_READ]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_CLEANUP]
Process: System Address: 0x89b92430 Size: -
Object: Hidden Code [Driver: REG, IRP_MJ_PNP]
Process: System Address: 0x89b92430 Size: -
|