offline
- zokce
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Građanin
- Pridružio: 23 Mar 2006
- Poruke: 84
|
Napisano: 06 Jul 2009 21:29
Evo reporta:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Time: 2009/07/06 21:29
Program Version: Version 1.3.0.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: 00000044
Image Path: \Driver\00000044
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: a0a2kb4k.SYS
Image Path: C:\WINDOWS\System32\Drivers\a0a2kb4k.SYS
Address: 0xBA058000 Size: 303104 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB62AA000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79B3000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB2D94000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: c:\documents and settings\Зоки\local settings\temp\etilqs_fctirste4gbkijof9rgd
Status: Allocation size mismatch (API: 32768, Raw: 0)
Path: c:\documents and settings\Зоки\local settings\temp\etilqs_hxikcsx8pbznbmp7o4zl
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\Зоки\local settings\temp\etilqs_qfghqgljccb9q1ucvpbj
Status: Allocation size mismatch (API: 32768, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_urx7btlyhf2populyvnh
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_gbumojf6cvmxdnhses9v
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_gmcdfjkfp24zhdcec8qa
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_god79fexspwc1jd75wvt
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_ib9sdazo3qabklm1qqba
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_jnxmkpjbonufhhyaphhx
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_npeepdvr0dgrjlebzp8i
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_plgb9ejsrpkrwiytpm4h
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_sflb6ylmeycqtzgh9ax4
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_2ffmh1bsnyhs6gdlrzry
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_3gtgbiiukykirjoir5ug
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_acvxqp9fw6sxt40jr9nd
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_cn5j3ldwjadrp0vwlzem
Status: Allocation size mismatch (API: 32768, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_cshatvfgd1trjgxxujed
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_cutvulbrpkxakvdjqt4r
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_vd5od4fdsvvmran8atsq
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_vnrmpkr8zvvyfm0rbgno
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_wuwydggmhmqe49lltoqx
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_wwf4gvdrfkflfdmcbtig
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\Зоки\application data\skype\zokcevi\etilqs_xsj4ikqqgdhg9twewfy5
Status: Allocation size mismatch (API: 16384, Raw: 0)
SSDT
-------------------
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb62de6b8
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb62de574
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb62dea52
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb62de14c
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf750584c
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf7505bec
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb62de64e
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb62de08c
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb62de0f0
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf7505cc4
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb62de76e
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb62de72e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb62de8ae
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x897901d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x891ae5d8 Size: 463
Object: Hidden Code [Driver: a0a2kb4kȅఅ瑁䅭뢠쀅Binary, IRP_MJ_CREATE]
Process: System Address: 0x891b1980 Size: 463
Object: Hidden Code [Driver: a0a2kb4kȅఅ瑁䅭뢠쀅Binary, IRP_MJ_CLOSE]
Process: System Address: 0x891b1980 Size: 463
Object: Hidden Code [Driver: a0a2kb4kȅఅ瑁䅭뢠쀅Binary, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x891b1980 Size: 463
Object: Hidden Code [Driver: a0a2kb4kȅఅ瑁䅭뢠쀅Binary, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x891b1980 Size: 463
Object: Hidden Code [Driver: a0a2kb4kȅఅ瑁䅭뢠쀅Binary, IRP_MJ_POWER]
Process: System Address: 0x891b1980 Size: 463
Object: Hidden Code [Driver: a0a2kb4kȅఅ瑁䅭뢠쀅Binary, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x891b1980 Size: 463
Object: Hidden Code [Driver: a0a2kb4kȅఅ瑁䅭뢠쀅Binary, IRP_MJ_PNP]
Process: System Address: 0x891b1980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x8926c980 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x897921d8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE]
Process: System Address: 0x892f81d8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE]
Process: System Address: 0x892f81d8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x892f81d8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x892f81d8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER]
Process: System Address: 0x892f81d8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x892f81d8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP]
Process: System Address: 0x892f81d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x897231d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x889551d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x889551d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x889551d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x889551d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x889551d8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x889551d8 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x892e5910 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x892e5910 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x892e5910 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x892e5910 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x892e5910 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x892e5910 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x892e5910 Size: 463
Object: Hidden Code [Driver: Si3112r, IRP_MJ_CREATE]
Process: System Address: 0x897911d8 Size: 463
Object: Hidden Code [Driver: Si3112r, IRP_MJ_CLOSE]
Process: System Address: 0x897911d8 Size: 463
Object: Hidden Code [Driver: Si3112r, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x897911d8 Size: 463
Object: Hidden Code [Driver: Si3112r, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x897911d8 Size: 463
Object: Hidden Code [Driver: Si3112r, IRP_MJ_POWER]
Process: System Address: 0x897911d8 Size: 463
Object: Hidden Code [Driver: Si3112r, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x897911d8 Size: 463
Object: Hidden Code [Driver: Si3112r, IRP_MJ_PNP]
Process: System Address: 0x897911d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x889541d8 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_CREATE]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_CLOSE]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_READ]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_SHUTDOWN]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_CLEANUP]
Process: System Address: 0x891aa980 Size: 463
Object: Hidden Code [Driver: CdfsЅ捐楓, IRP_MJ_PNP]
Process: System Address: 0x891aa980 Size: 463
==EOF==
Dopuna: 06 Jul 2009 21:47
Mora da m nesto.
I disk mi se cesto aktivira.
|