offline
- dusan-bg
- Novi MyCity građanin
- Pridružio: 14 Jan 2009
- Poruke: 8
- Gde živiš: Beograd
|
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/07/15 19:04
Program Version: Version 1.3.2.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\windows\System32\Drivers\dump_atapi.sys
Address: 0xBAD68000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\windows\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8D9D000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PCI_PNP2118
Image Path: \Driver\PCI_PNP2118
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\windows\system32\drivers\rootrepeal.sys
Address: 0xB78A0000 Size: 49152 File Visible: No Signed: -
Status: -
Name: spkn.sys
Image Path: spkn.sys
Address: 0xF8716000 Size: 1048576 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: c:\documents and settings\dusan pejic\application data\limewire\mozilla-profile\places.sqlite-stmtjrnl
Status: Allocation size mismatch (API: 8192, Raw: 0)
Path: c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\log\log_421.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\log\log_423.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)
SSDT
-------------------
#: 025 Function Name: NtClose
Status: Hooked by "C:\windows\System32\Drivers\aswSP.SYS" at address 0xbad886b8
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\windows\System32\Drivers\aswSP.SYS" at address 0xbad88574
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\windows\System32\Drivers\aswSP.SYS" at address 0xbad88a52
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\windows\System32\Drivers\aswSP.SYS" at address 0xbad8814c
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spkn.sys" at address 0xf8735ca2
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spkn.sys" at address 0xf8736030
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\windows\System32\Drivers\aswSP.SYS" at address 0xbad8864e
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\windows\System32\Drivers\aswSP.SYS" at address 0xbad8808c
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\windows\System32\Drivers\aswSP.SYS" at address 0xbad880f0
#: 160 Function Name: NtQueryKey
Status: Hooked by "spkn.sys" at address 0xf8736108
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\windows\System32\Drivers\aswSP.SYS" at address 0xbad8876e
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\windows\System32\Drivers\aswSP.SYS" at address 0xbad8872e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\windows\System32\Drivers\aswSP.SYS" at address 0xbad888ae
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x833dc1f8 Address: 121
Object: Hidden Code [Driver: al27fp3iȅః扏济al27fp3iȃఄ灐†, IRP_MJ_CREATE]
Process: System Address: 0x82f99500 Address: 121
Object: Hidden Code [Driver: al27fp3iȅః扏济al27fp3iȃఄ灐†, IRP_MJ_CLOSE]
Process: System Address: 0x82f99500 Address: 121
Object: Hidden Code [Driver: al27fp3iȅః扏济al27fp3iȃఄ灐†, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82f99500 Address: 121
Object: Hidden Code [Driver: al27fp3iȅః扏济al27fp3iȃఄ灐†, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82f99500 Address: 121
Object: Hidden Code [Driver: al27fp3iȅః扏济al27fp3iȃఄ灐†, IRP_MJ_POWER]
Process: System Address: 0x82f99500 Address: 121
Object: Hidden Code [Driver: al27fp3iȅః扏济al27fp3iȃఄ灐†, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82f99500 Address: 121
Object: Hidden Code [Driver: al27fp3iȅః扏济al27fp3iȃఄ灐†, IRP_MJ_PNP]
Process: System Address: 0x82f99500 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x82ffd1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x833de1f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x82fe51f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x82fe51f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82fe51f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82fe51f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x82fe51f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82fe51f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x82fe51f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x833731f8 Address: 121
Object: Hidden Code [Driver: viamraid, IRP_MJ_CREATE]
Process: System Address: 0x833dd1f8 Address: 121
Object: Hidden Code [Driver: viamraid, IRP_MJ_CLOSE]
Process: System Address: 0x833dd1f8 Address: 121
Object: Hidden Code [Driver: viamraid, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x833dd1f8 Address: 121
Object: Hidden Code [Driver: viamraid, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x833dd1f8 Address: 121
Object: Hidden Code [Driver: viamraid, IRP_MJ_POWER]
Process: System Address: 0x833dd1f8 Address: 121
Object: Hidden Code [Driver: viamraid, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x833dd1f8 Address: 121
Object: Hidden Code [Driver: viamraid, IRP_MJ_PNP]
Process: System Address: 0x833dd1f8 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x82cb8500 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x82cb8500 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82cb8500 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82cb8500 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x82cb8500 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x82cb8500 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x82fb81f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x82fb81f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82fb81f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82fb81f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x82fb81f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82fb81f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x82fb81f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x82cc0500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_CREATE]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_CLOSE]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_READ]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_SHUTDOWN]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_CLEANUP]
Process: System Address: 0x82eb01f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёం扏楄, IRP_MJ_PNP]
Process: System Address: 0x82eb01f8 Address: 121
==EOF==
|