offline
- dusan93
- Novi MyCity građanin
- Pridružio: 18 Jan 2009
- Poruke: 17
- Gde živiš: Novi Beograd
|
Moram da restartujem komp da bih ti pokazao....
Zato sto samo napise....da je pronadjena zarazena datoteka pod procesom winlogon.exe,a ne mogu da je odstranim i pise ime datoteke(nesto trojan.sc/ds/php <---- nije tacan naziv al' znam da na kraju ima php....
Dopuna: 22 Feb 2009 20:46
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/02/22 20:37
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: catchme.sys
Image Path: C:\ComboFix\catchme.sys
Address: 0xF77CF000 Size: 30592 File Visible: No
Status: -
Name: Combo-Fix.sys
Image Path: Combo-Fix.sys
Address: 0xF7677000 Size: 60416 File Visible: No
Status: -
Name: PCI_PNP8342
Image Path: \Driver\PCI_PNP8342
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: PROCEXP90.SYS
Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Address: 0xA4A0D000 Size: 6464 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA492E000 Size: 45056 File Visible: No
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: spwx.sys
Image Path: spwx.sys
Address: 0xF74D6000 Size: 1048576 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\WINDOWS\Temp\358f35d4-30a5-4be8-a9de-82bb94aedf81.tmp
Status: Allocation size mismatch (API: 262144, Raw: 0)
Path: C:\Documents and Settings\Dule\Local Settings\temp\etilqs_ainLkIDNoi30WprdnPzk
Status: Allocation size mismatch (API: 65536, Raw: 0)
Path: C:\Documents and Settings\Dule\Local Settings\Application Data\Mozilla\Firefox\Profiles\sx6w9550.default\Cache\FA50B60Ad01
Status: Size mismatch (API: 16988, Raw: 17017)
Path: C:\Documents and Settings\Dule\Local Settings\Application Data\Mozilla\Firefox\Profiles\sx6w9550.default\Cache\_CACHE_001_
Status: Size mismatch (API: 740422, Raw: 739207)
Path: C:\Documents and Settings\Dule\Local Settings\Application Data\Microsoft\Messenger\dushan1389@gmail.com\SharingMetadata\milanadamovic@live.com\DFSR\Staging\CS{DC4F8574-7216-292C-A7EB-B62B6B2FB7F6}\01\13-{DC4F8574-7216-292C-A7EB-B62B6B2FB7F6}-v1-{6FDCBFE1-C3CD-4BC4-9347-F9CCD7979093}-v13-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Dule\Local Settings\Application Data\Microsoft\Messenger\dushan1389@gmail.com\SharingMetadata\milanadamovic@live.com\DFSR\Staging\CS{DC4F8574-7216-292C-A7EB-B62B6B2FB7F6}\15\15-{6E816F0B-5CD2-4462-9364-AF75F6EC82F2}-v15-{6E816F0B-5CD2-4462-9364-AF75F6EC82F2}-v15-Partial.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Dule\Local Settings\Application Data\Microsoft\Messenger\dushan1389@gmail.com\SharingMetadata\miloslalic@hotmail.com\DFSR\Staging\CS{3DD21A01-858B-4A1D-A064-B3B6DF5FE428}\01\12-{3DD21A01-858B-4A1D-A064-B3B6DF5FE428}-v1-{6FDCBFE1-C3CD-4BC4-9347-F9CCD7979093}-v12-Downloaded.frx
Status: Locked to the Windows API!
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_CREATE]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_CLOSE]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_POWER]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_PNP]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_CREATE]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_CLOSE]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_READ]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_SHUTDOWN]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_CLEANUP]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_PNP]
Process: System Address: 0x895c63a0 Size: -
Dopuna: 22 Feb 2009 21:05
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/02/22 20:37
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: catchme.sys
Image Path: C:\ComboFix\catchme.sys
Address: 0xF77CF000 Size: 30592 File Visible: No
Status: -
Name: Combo-Fix.sys
Image Path: Combo-Fix.sys
Address: 0xF7677000 Size: 60416 File Visible: No
Status: -
Name: PCI_PNP8342
Image Path: \Driver\PCI_PNP8342
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: PROCEXP90.SYS
Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Address: 0xA4A0D000 Size: 6464 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA492E000 Size: 45056 File Visible: No
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: spwx.sys
Image Path: spwx.sys
Address: 0xF74D6000 Size: 1048576 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\WINDOWS\Temp\358f35d4-30a5-4be8-a9de-82bb94aedf81.tmp
Status: Allocation size mismatch (API: 262144, Raw: 0)
Path: C:\Documents and Settings\Dule\Local Settings\temp\etilqs_ainLkIDNoi30WprdnPzk
Status: Allocation size mismatch (API: 65536, Raw: 0)
Path: C:\Documents and Settings\Dule\Local Settings\Application Data\Mozilla\Firefox\Profiles\sx6w9550.default\Cache\FA50B60Ad01
Status: Size mismatch (API: 16988, Raw: 17017)
Path: C:\Documents and Settings\Dule\Local Settings\Application Data\Mozilla\Firefox\Profiles\sx6w9550.default\Cache\_CACHE_001_
Status: Size mismatch (API: 740422, Raw: 739207)
Path: C:\Documents and Settings\Dule\Local Settings\Application Data\Microsoft\Messenger\dushan1389@gmail.com\SharingMetadata\milanadamovic@live.com\DFSR\Staging\CS{DC4F8574-7216-292C-A7EB-B62B6B2FB7F6}\01\13-{DC4F8574-7216-292C-A7EB-B62B6B2FB7F6}-v1-{6FDCBFE1-C3CD-4BC4-9347-F9CCD7979093}-v13-Downloaded.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Dule\Local Settings\Application Data\Microsoft\Messenger\dushan1389@gmail.com\SharingMetadata\milanadamovic@live.com\DFSR\Staging\CS{DC4F8574-7216-292C-A7EB-B62B6B2FB7F6}\15\15-{6E816F0B-5CD2-4462-9364-AF75F6EC82F2}-v15-{6E816F0B-5CD2-4462-9364-AF75F6EC82F2}-v15-Partial.frx
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Dule\Local Settings\Application Data\Microsoft\Messenger\dushan1389@gmail.com\SharingMetadata\miloslalic@hotmail.com\DFSR\Staging\CS{3DD21A01-858B-4A1D-A064-B3B6DF5FE428}\01\12-{3DD21A01-858B-4A1D-A064-B3B6DF5FE428}-v1-{6FDCBFE1-C3CD-4BC4-9347-F9CCD7979093}-v12-Downloaded.frx
Status: Locked to the Windows API!
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x89c0e1f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x89a1a500 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x89b9c1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP]
Process: System Address: 0x8995a1f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_CREATE]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_CLOSE]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_POWER]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: Sys, IRP_MJ_PNP]
Process: System Address: 0x899251f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x88ec51f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x899fe1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x88eb41f8 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_CREATE]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_CLOSE]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_READ]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_SHUTDOWN]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_CLEANUP]
Process: System Address: 0x895c63a0 Size: -
Object: Hidden Code [Driver: HDAUDIO#, IRP_MJ_PNP]
Process: System Address: 0x895c63a0 Size: -
|