offline
- Pridružio: 18 Jan 2009
- Poruke: 205
|
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/04/23 00:36
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name:
Image Path:
Address: 0xF7473000 Size: 98304 File Visible: No
Status: -
Name:
Image Path:
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: catchme.sys
Image Path: C:\DOCUME~1\1\LOCALS~1\Temp\catchme.sys
Address: 0xF77E7000 Size: 31744 File Visible: No
Status: -
Name: Combo-Fix.sys
Image Path: Combo-Fix.sys
Address: 0xF7657000 Size: 60416 File Visible: No
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAF465000 Size: 98304 File Visible: No
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBAC3D000 Size: 8192 File Visible: No
Status: -
Name: PROCEXP90.SYS
Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Address: 0xF79D9000 Size: 6464 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAE670000 Size: 45056 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\sccfg.sys
Status: Invisible to the Windows API!
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
SSDT
-------------------
#: 025 Function Name: NtClose
Status: Hooked by "vax347b.sys" at address 0xf75bcbb8
#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\system32\windrvNT.sys" at address 0xf777336a
#: 041 Function Name: NtCreateKey
Status: Hooked by "vax347b.sys" at address 0xf75bcb70
#: 045 Function Name: NtCreatePagingFile
Status: Hooked by "vax347b.sys" at address 0xf75b0c70
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "vax347b.sys" at address 0xf75b14fe
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "vax347b.sys" at address 0xf75bccb0
#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\WINDOWS\system32\windrvNT.sys" at address 0xf7773cd8
#: 119 Function Name: NtOpenKey
Status: Hooked by "vax347b.sys" at address 0xf75bcb34
#: 145 Function Name: NtQueryDirectoryFile
Status: Hooked by "C:\WINDOWS\system32\windrvNT.sys" at address 0xf7773842
#: 154 Function Name: NtQueryInformationProcess
Status: Hooked by "C:\WINDOWS\system32\windrvNT.sys" at address 0xf77701e0
#: 160 Function Name: NtQueryKey
Status: Hooked by "vax347b.sys" at address 0xf75b151e
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "vax347b.sys" at address 0xf75bcc06
#: 224 Function Name: NtSetInformationFile
Status: Hooked by "C:\WINDOWS\system32\windrvNT.sys" at address 0xf7774142
#: 241 Function Name: NtSetSystemPowerState
Status: Hooked by "vax347b.sys" at address 0xf75bc450
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x89788370 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_READ]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_WRITE]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_EA]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_EA]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CLEANUP]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x89309140 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_EA]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_EA]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLEANUP]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_SECURITY]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_QUOTA]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x892f67e0 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_CREATE]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_CLOSE]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_READ]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_WRITE]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_EA]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_EA]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SHUTDOWN]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_CLEANUP]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_SECURITY]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_POWER]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_SET_QUOTA]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: vax347s, IRP_MJ_PNP]
Process: System Address: 0x892b8928 Size: -
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x8923c458 Size: -
Object: Hidden Code [Driver: Srv, IRP_MJ_READ]
Process: System Address: 0x89367030 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x89265430 Size: -
Object: Hidden Code [Driver: NpfsЅఅ坓慤͈ᇐឹꀀ⋉阱, IRP_MJ_READ]
Process: System Address: 0x89259cf0 Size: -
Object: Hidden Code [Driver: Msfsȅ䵃慄쪈Ȃం扏楄䒸嶠褢, IRP_MJ_READ]
Process: System Address: 0x8923d468 Size: -
Object: Hidden Code [Driver: Fs_Rec, IRP_MJ_READ]
Process: System Address: 0x892752d8 Size: -
Object: Hidden Code [Driver: Cdfsȅ卆浩ȁం䵃䥖Ũ叁Ȃ敋ꁹ, IRP_MJ_READ]
Process: System Address: 0x8933a758 Size: -
|