Scan completed with these results:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Time: 2009/07/08 10:30
Program Version: Version 1.3.0.0
Windows Version: Windows Vista SP1
==================================================
Drivers
-------------------
Name: dump_ahcix86s.sys
Image Path: C:\Windows\System32\Drivers\dump_ahcix86s.sys
Address: 0xA054A000 Size: 262144 File Visible: No Signed: -
Status: -
Name: dump_diskdump.sys
Image Path: C:\Windows\System32\Drivers\dump_diskdump.sys
Address: 0xA0540000 Size: 40960 File Visible: No Signed: -
Status: -
Name: MSIVXrmqcijvwxhhvcxwovhisiayxwieqsppy.sys
Image Path: C:\Windows\system32\drivers\MSIVXrmqcijvwxhhvcxwovhisiayxwieqsppy.sys
Address: 0x9F64B000 Size: 180224 File Visible: - Signed: -
Status: Hidden from Windows API!
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0xB0DCF000 Size: 49152 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: spvx.sys
Image Path: C:\Windows\System32\Drivers\spvx.sys
Address: 0x80600000 Size: 1052672 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\Avenger\MSIVXcount
Status: Invisible to the Windows API!
Path: C:\Windows\System32\MSIVXcount
Status: Invisible to the Windows API!
Path: C:\Windows\System32\MSIVXqxeiuktudskouqxygaadmyfpuchqnpln.dll
Status: Invisible to the Windows API!
Path: C:\Windows\System32\MSIVXtwqekcuplateiepneomwtxrejgxxysko.dll
Status: Invisible to the Windows API!
Path: C:\Windows\System32\drivers\MSIVXrmqcijvwxhhvcxwovhisiayxwieqsppy.sys
Status: Invisible to the Windows API!
Path: C:\Windows\System32\drivers\MSIVXviveqpttwqypstjufbmurpwplvxsyekq.sys
Status: Invisible to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_uninstallsqlstatetem_b03f5f7f11d50a3a_6.0.6000.16720_none_04c87b54ba4ac535\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_uninstallsqlstatetem_b03f5f7f11d50a3a_6.0.6000.20883_none_ee0091f8d3ed0a28\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_uninstallsqlstatetem_b03f5f7f11d50a3a_6.0.6001.18111_none_04a3600aba9cd1d6\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_uninstallsqlstatetem_b03f5f7f11d50a3a_6.0.6001.22230_none_edd7d0a6d4424ae9\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4f196f15369ae496\APPCON~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4f196f15369ae496\APPSET~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4f196f15369ae496\CREATE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4f196f15369ae496\DEBUGA~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4f196f15369ae496\DEFINE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4f196f15369ae496\EDITAP~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4f196f15369ae496\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4f196f15369ae496\SMTPSE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.20883_none_385185b9503d2989\APPCON~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.20883_none_385185b9503d2989\APPSET~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.20883_none_385185b9503d2989\CREATE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.20883_none_385185b9503d2989\DEBUGA~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.20883_none_385185b9503d2989\DEFINE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.20883_none_385185b9503d2989\EDITAP~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.20883_none_385185b9503d2989\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6000.20883_none_385185b9503d2989\SMTPSE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4ef453cb36ecf137\APPCON~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4ef453cb36ecf137\APPSET~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4ef453cb36ecf137\CREATE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4ef453cb36ecf137\DEBUGA~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4ef453cb36ecf137\DEFINE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4ef453cb36ecf137\EDITAP~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4ef453cb36ecf137\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4ef453cb36ecf137\SMTPSE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.22230_none_3828c46750926a4a\APPCON~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.22230_none_3828c46750926a4a\APPSET~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.22230_none_3828c46750926a4a\CREATE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.22230_none_3828c46750926a4a\DEBUGA~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.22230_none_3828c46750926a4a\DEFINE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.22230_none_3828c46750926a4a\EDITAP~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.22230_none_3828c46750926a4a\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appcfg_res_b03f5f7f11d50a3a_6.0.6001.22230_none_3828c46750926a4a\SMTPSE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.16720_none_4ef4fbb8699d6b09\CREATE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.16720_none_4ef4fbb8699d6b09\DEFINE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.16720_none_4ef4fbb8699d6b09\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.20883_none_382d125c833faffc\CREATE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.20883_none_382d125c833faffc\DEFINE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.20883_none_382d125c833faffc\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6001.18111_none_4ecfe06e69ef77aa\CREATE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6001.18111_none_4ecfe06e69ef77aa\DEFINE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6001.18111_none_4ecfe06e69ef77aa\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6000.16720_none_950a4e2fda3ee0ba\CREATE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6000.16720_none_950a4e2fda3ee0ba\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6000.20883_none_7e4264d3f3e125ad\CREATE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6000.20883_none_7e4264d3f3e125ad\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6001.18111_none_94e532e5da90ed5b\CREATE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6001.18111_none_94e532e5da90ed5b\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6001.22230_none_7e19a381f436666e\CREATE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6001.22230_none_7e19a381f436666e\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4cb2b120b7498755\CREATE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4cb2b120b7498755\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6000.20883_none_35eac7c4d0ebcc48\CREATE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6000.20883_none_35eac7c4d0ebcc48\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4c8d95d6b79b93f6\CREATE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4c8d95d6b79b93f6\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6001.22230_none_35c20672d1410d09\CREATE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6001.22230_none_35c20672d1410d09\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.16720_none_7325c867d7281910\CHOOSE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.16720_none_7325c867d7281910\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.16720_none_7325c867d7281910\MANAGE~2.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.20883_none_5c5ddf0bf0ca5e03\CHOOSE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.20883_none_5c5ddf0bf0ca5e03\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.20883_none_5c5ddf0bf0ca5e03\MANAGE~2.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.18111_none_7300ad1dd77a25b1\CHOOSE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.18111_none_7300ad1dd77a25b1\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.18111_none_7300ad1dd77a25b1\MANAGE~2.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6001.22230_none_3804510a8394f0bd\CREATE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6001.22230_none_3804510a8394f0bd\DEFINE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6001.22230_none_3804510a8394f0bd\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.18111_none_7c6b3231b9c3046e\WEBADM~2.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.18111_none_7c6b3231b9c3046e\WEBADM~3.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.18111_none_7c6b3231b9c3046e\WEBADM~4.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.18111_none_7c6b3231b9c3046e\WEBB00~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.22230_none_5c351db9f11f9ec4\CHOOSE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.22230_none_5c351db9f11f9ec4\MANAGE~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.22230_none_5c351db9f11f9ec4\MANAGE~2.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_b03f5f7f11d50a3a_6.0.6001.18111_none_75c874a9a137a5f0\MANAGE~2.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_users_res_b03f5f7f11d50a3a_6.0.6001.22230_none_9a1350e27965368d\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webevent_sqlprov_b03f5f7f11d50a3a_6.0.6001.18111_none_a335242e0936a3fd\INSTAL~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webevent_sqlprov_b03f5f7f11d50a3a_6.0.6001.18111_none_a335242e0936a3fd\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_secur_res_b03f5f7f11d50a3a_6.0.6000.16720_none_c39efe8a3f927437\SETUPA~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_secur_res_b03f5f7f11d50a3a_6.0.6000.20883_none_acd7152e5934b92a\SETUPA~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_secur_res_b03f5f7f11d50a3a_6.0.6001.18111_none_c379e3403fe480d8\SETUPA~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_secur_res_b03f5f7f11d50a3a_6.0.6001.22230_none_acae53dc5989f9eb\SETUPA~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_users_res_b03f5f7f11d50a3a_6.0.6000.16720_none_b103fb905f6db0d9\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_users_res_b03f5f7f11d50a3a_6.0.6000.20883_none_9a3c1234790ff5cc\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_users_res_b03f5f7f11d50a3a_6.0.6001.18111_none_b0dee0465fbfbd7a\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webmintrust_config_b03f5f7f11d50a3a_6.0.6000.16720_none_e2c358ab062e054b\WEB_MI~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webmintrust_config_b03f5f7f11d50a3a_6.0.6000.20883_none_cbfb6f4f1fd04a3e\WEB_MI~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webmintrust_config_b03f5f7f11d50a3a_6.0.6001.18111_none_e29e3d61068011ec\WEB_MI~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webmintrust_config_b03f5f7f11d50a3a_6.0.6001.22230_none_cbd2adfd20258aff\WEB_MI~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-mscorjit_dll_b03f5f7f11d50a3a_6.0.6001.18111_none_bf5d932d312ea83f\$$DeleteMe.mscorjit.dll.01c9f918fe4fc34e.0000
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.16386_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_ini_31bf3856ad364e35_6.0.6001.18096_none_33db43850c7307a2\_SMSVC~1.INI
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_ini_31bf3856ad364e35_6.0.6001.22208_none_34c832162545dbc8\_SMSVC~1.INI
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webevent_sqlprov_b03f5f7f11d50a3a_6.0.6001.22230_none_8c6994ca22dc1d10\INSTAL~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webevent_sqlprov_b03f5f7f11d50a3a_6.0.6001.22230_none_8c6994ca22dc1d10\UNINST~1.SQL
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webmedtrust_config_b03f5f7f11d50a3a_6.0.6000.16720_none_2c88b9b71ca44e71\WEB_ME~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webmedtrust_config_b03f5f7f11d50a3a_6.0.6000.20883_none_15c0d05b36469364\WEB_ME~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webmedtrust_config_b03f5f7f11d50a3a_6.0.6001.18111_none_2c639e6d1cf65b12\WEB_ME~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webmedtrust_config_b03f5f7f11d50a3a_6.0.6001.22230_none_15980f09369bd425\WEB_ME~1.CON
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_b03f5f7f11d50a3a_6.0.6001.22230_none_5efce545badd1f03\MANAGE~2.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6000.16720_none_87d39b55197883e6\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6000.16720_none_87d39b55197883e6\MANAGE~2.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6000.20883_none_710bb1f9331ac8d9\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6000.20883_none_710bb1f9331ac8d9\MANAGE~2.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6001.18111_none_87ae800b19ca9087\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6001.18111_none_87ae800b19ca9087\MANAGE~2.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6001.22230_none_70e2f0a73370099a\MANAGE~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6001.22230_none_70e2f0a73370099a\MANAGE~2.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_security_b03f5f7f11d50a3a_6.0.6000.16720_none_62b207ce0c996d96\SETUPA~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_security_b03f5f7f11d50a3a_6.0.6000.20883_none_4bea1e72263bb289\SETUPA~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_security_b03f5f7f11d50a3a_6.0.6001.18111_none_628cec840ceb7a37\SETUPA~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_security_b03f5f7f11d50a3a_6.0.6001.22230_none_4bc15d202690f34a\SETUPA~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.22230_none_659fa2cdd3687d81\WEBADM~2.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.22230_none_659fa2cdd3687d81\WEBADM~3.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.22230_none_659fa2cdd3687d81\WEBADM~4.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.22230_none_659fa2cdd3687d81\WEBB00~1.ASP
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\ASPX_F~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\DESELE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\GRADIE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\GRADIE~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\HEADER~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\REQUIR~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\SECURI~1.JPG
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\SELECT~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\SELECT~3.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\UNSELE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\UNSELE~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\ASPX_F~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\DESELE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\GRADIE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\GRADIE~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\HEADER~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\REQUIR~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\SECURI~1.JPG
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\SELECT~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\SELECT~3.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\UNSELE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\UNSELE~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\ASPX_F~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\DESELE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\GRADIE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\GRADIE~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\HEADER~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\REQUIR~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\SECURI~1.JPG
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\SELECT~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\SELECT~3.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\UNSELE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.18111_none_aec031a01914d723\UNSELE~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\ASPX_F~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\DESELE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\GRADIE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\GRADIE~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\HEADER~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\REQUIR~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\SECURI~1.JPG
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\SELECT~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\SELECT~3.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\UNSELE~1.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6001.22230_none_97f4a23c32ba5036\UNSELE~2.GIF
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_locres_res_b03f5f7f11d50a3a_6.0.6000.16720_none_e101494a280d4e0b\NAVIGA~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_locres_res_b03f5f7f11d50a3a_6.0.6000.16720_none_e101494a280d4e0b\WEBADM~1.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_locres_res_b03f5f7f11d50a3a_6.0.6000.16720_none_e101494a280d4e0b\WEBADM~2.RES
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_locres_res_b03f5f7f11d50a3a_6.0.6000.16720_none_e101494a280d4e0b\WEBADProcesses
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1444 Status: Locked to the Windows API!
SSDT
-------------------
#: 013 Function Name: NtAlertResumeThread
Status: Hooked by "<unknown>" at address 0x889d6110
#: 014 Function Name: NtAlertThread
Status: Hooked by "<unknown>" at address 0x889d01e8
#: 018 Function Name: NtAllocateVirtualMemory
Status: Hooked by "<unknown>" at address 0x88a6fb18
#: 021 Function Name: NtAlpcConnectPort
Status: Hooked by "<unknown>" at address 0x88869da0
#: 042 Function Name: NtAssignProcessToJobObject
Status: Hooked by "<unknown>" at address 0x889c98e8
#: 067 Function Name: NtCreateMutant
Status: Hooked by "<unknown>" at address 0x8941d680
#: 072 Function Name: NtCreateProcess
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x8ac52282
#: 073 Function Name: NtCreateProcessEx
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x8ac52474
#: 077 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "<unknown>" at address 0x89421f60
#: 078 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0x889d2390
#: 116 Function Name: NtDebugActiveProcess
Status: Hooked by "<unknown>" at address 0x889c8b18
#: 129 Function Name: NtDuplicateObject
Status: Hooked by "<unknown>" at address 0x88a60df0
#: 147 Function Name: NtFreeVirtualMemory
Status: Hooked by "<unknown>" at address 0x88a66b30
#: 156 Function Name: NtImpersonateAnonymousToken
Status: Hooked by "<unknown>" at address 0x88a71120
#: 158 Function Name: NtImpersonateThread
Status: Hooked by "<unknown>" at address 0x88a70108
#: 165 Function Name: NtLoadDriver
Status: Hooked by "<unknown>" at address 0x88869d28
#: 177 Function Name: NtMapViewOfSection
Status: Hooked by "<unknown>" at address 0x88a69360
#: 184 Function Name: NtOpenEvent
Status: Hooked by "<unknown>" at address 0x88a8b108
#: 194 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xb0dadc90
#: 195 Function Name: NtOpenProcessToken
Status: Hooked by "<unknown>" at address 0x88997a00
#: 197 Function Name: NtOpenSection
Status: Hooked by "<unknown>" at address 0x89433658
#: 201 Function Name: NtOpenThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xb0dadd7e
#: 210 Function Name: NtProtectVirtualMemory
Status: Hooked by "<unknown>" at address 0x89421808
#: 282 Function Name: NtResumeThread
Status: Hooked by "<unknown>" at address 0x889b9ad0
#: 289 Function Name: NtSetContextThread
Status: Hooked by "<unknown>" at address 0x889d04c8
#: 305 Function Name: NtSetInformationProcess
Status: Hooked by "<unknown>" at address 0x88a69128
#: 317 Function Name: NtSetSystemInformation
Status: Hooked by "<unknown>" at address 0x894366b8
#: 330 Function Name: NtSuspendProcess
Status: Hooked by "<unknown>" at address 0x889bb128
#: 331 Function Name: NtSuspendThread
Status: Hooked by "<unknown>" at address 0x889a04b0
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xa003fdf0
#: 335 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xb0dadec4
#: 348 Function Name: NtUnmapViewOfSection
Status: Hooked by "<unknown>" at address 0x889ce248
#: 358 Function Name: NtWriteVirtualMemory
Status: Hooked by "<unknown>" at address 0x88a65480
#: 382 Function Name: NtCreateThreadEx
Status: Hooked by "<unknown>" at address 0x894201d8
#: 383 Function Name: NtCreateUserProcess
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x8ac5267c
Stealth Objects
-------------------
Object: Hidden Module [Name: MSIVXqxeiuktudskouqxygaadmyfpuchqnpln.dll]
Process: svchost.exe (PID: 804) Address: 0x10000000 Size: 53248
Object: Hidden Module [Name: WinMgmtR.dll]
Process: svchost.exe (PID: 1172) Address: 0x00db0000 Size: 8192
Object: Hidden Module [Name: winlogon.exe]
Process: svchost.exe (PID: 1172) Address: 0x010c0000 Size: 323584
Object: Hidden Module [Name: winlogon.exe]
Process: svchost.exe (PID: 1172) Address: 0x01b00000 Size: 323584
Object: Hidden Module [Name: WinMgmtR.dll]
Process: svchost.exe (PID: 1172) Address: 0x70560000 Size: 8192
Object: Hidden Module [Name: tquery.dll]
Process: svchost.exe (PID: 1172) Address: 0x70e50000 Size: 1589248
Object: Hidden Module [Name: profsvc.dll]
Process: svchost.exe (PID: 1172) Address: 0x72fb0000 Size: 163840
Object: Hidden Module [Name: wevtapi.dll]
Process: svchost.exe (PID: 1172) Address: 0x750a0000 Size: 258048
Object: Hidden Module [Name: msgrvsta.thm]
Process: msnmsgr.exe (PID: 4456) Address: 0x73ca0000 Size: 20480
Object: Hidden Module [Name: MSIVXtwqekcuplateiepneomwtxrejgxxysko.dll]
Process: firefox.exe (PID: 4516) Address: 0x10000000 Size: 237568
Object: Hidden Code [ETHREAD: 0x85581570]
Process: System Address: 0x8ba104a0 Size: 2912
Object: Hidden Code [ETHREAD: 0x855cb2d8]
Process: System Address: 0x855cb4cc Size: 2776
Object: Hidden Code [ETHREAD: 0x855cc020]
Process: System Address: 0xa6a973f0 Size: 3088
Object: Hidden Code [ETHREAD: 0x855ccd78]
Process: System Address: 0x815d2bf0 Size: 2
Object: Hidden Code [ETHREAD: 0x855ccad0]
Process: System Address: 0xbc380410 Size: 3061
Object: Hidden Code [ETHREAD: 0x855cc2d8]
Process: System Address: 0x8140d290 Size: 3445
Object: Hidden Code [ETHREAD: 0x8901f408]
Process: System Address: 0xf365f530 Size: 2768
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x863931f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_CREATE]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_READ]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_WRITE]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_POWER]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: cdrom, IRP_MJ_PNP]
Process: System Address: 0x87c831f8 Size: 121
Object: Hidden Code [Driver: LSI_SAS, IRP_MJ_CREATE]
Process: System Address: 0x863831f8 Size: 121
Object: Hidden Code [Driver: LSI_SAS, IRP_MJ_CLOSE]
Process: System Address: 0x863831f8 Size: 121
Object: Hidden Code [Driver: LSI_SAS, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863831f8 Size: 121
Object: Hidden Code [Driver: LSI_SAS, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863831f8 Size: 121
Object: Hidden Code [Driver: LSI_SAS, IRP_MJ_POWER]
Process: System Address: 0x863831f8 Size: 121
Object: Hidden Code [Driver: LSI_SAS, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863831f8 Size: 121
Object: Hidden Code [Driver: LSI_SAS, IRP_MJ_PNP]
Process: System Address: 0x863831f8 Size: 121
Object: Hidden Code [Driver: arc, IRP_MJ_CREATE]
Process: System Address: 0x8637b1f8 Size: 121
Object: Hidden Code [Driver: arc, IRP_MJ_CLOSE]
Process: System Address: 0x8637b1f8 Size: 121
Object: Hidden Code [Driver: arc, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8637b1f8 Size: 121
Object: Hidden Code [Driver: arc, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8637b1f8 Size: 121
Object: Hidden Code [Driver: arc, IRP_MJ_POWER]
Process: System Address: 0x8637b1f8 Size: 121
Object: Hidden Code [Driver: arc, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8637b1f8 Size: 121
Object: Hidden Code [Driver: arc, IRP_MJ_PNP]
Process: System Address: 0x8637b1f8 Size: 121
Object: Hidden Code [Driver: iteatapi, IRP_MJ_CREATE]
Process: System Address: 0x863801f8 Size: 121
Object: Hidden Code [Driver: iteatapi, IRP_MJ_CLOSE]
Process: System Address: 0x863801f8 Size: 121
Object: Hidden Code [Driver: iteatapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863801f8 Size: 121
Object: Hidden Code [Driver: iteatapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863801f8 Size: 121
Object: Hidden Code [Driver: iteatapi, IRP_MJ_POWER]
Process: System Address: 0x863801f8 Size: 121
Object: Hidden Code [Driver: iteatapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863801f8 Size: 121
Object: Hidden Code [Driver: iteatapi, IRP_MJ_PNP]
Process: System Address: 0x863801f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_CREATE]
Process: System Address: 0x863711f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_CLOSE]
Process: System Address: 0x863711f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863711f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863711f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_POWER]
Process: System Address: 0x863711f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863711f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_PNP]
Process: System Address: 0x863711f8 Size: 121
Object: Hidden Code [Driver: ql2300, IRP_MJ_CREATE]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: ql2300, IRP_MJ_CLOSE]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: ql2300, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: ql2300, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: ql2300, IRP_MJ_POWER]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: ql2300, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: ql2300, IRP_MJ_PNP]
Process: System Address: 0x863881f8 Size: 121
Object: Hidden Code [Driver: megasas, IRP_MJ_CREATE]
Process: System Address: 0x863841f8 Size: 121
Object: Hidden Code [Driver: megasas, IRP_MJ_CLOSE]
Process: System Address: 0x863841f8 Size: 121
Object: Hidden Code [Driver: megasas, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863841f8 Size: 121
Object: Hidden Code [Driver: megasas, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863841f8 Size: 121
Object: Hidden Code [Driver: megasas, IRP_MJ_POWER]
Process: System Address: 0x863841f8 Size: 121
Object: Hidden Code [Driver: megasas, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863841f8 Size: 121
Object: Hidden Code [Driver: megasas, IRP_MJ_PNP]
Process: System Address: 0x863841f8 Size: 121
Object: Hidden Code [Driver: HpCISSs, IRP_MJ_CREATE]
Process: System Address: 0x863761f8 Size: 121
Object: Hidden Code [Driver: HpCISSs, IRP_MJ_CLOSE]
Process: System Address: 0x863761f8 Size: 121
Object: Hidden Code [Driver: HpCISSs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863761f8 Size: 121
Object: Hidden Code [Driver: HpCISSs, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863761f8 Size: 121
Object: Hidden Code [Driver: HpCISSs, IRP_MJ_POWER]
Process: System Address: 0x863761f8 Size: 121
Object: Hidden Code [Driver: HpCISSs, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863761f8 Size: 121
Object: Hidden Code [Driver: HpCISSs, IRP_MJ_PNP]
Process: System Address: 0x863761f8 Size: 121
Object: Hidden Code [Driver: arcsas, IRP_MJ_CREATE]
Process: System Address: 0x8637c1f8 Size: 121
Object: Hidden Code [Driver: arcsas, IRP_MJ_CLOSE]
Process: System Address: 0x8637c1f8 Size: 121
Object: Hidden Code [Driver: arcsas, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8637c1f8 Size: 121
Object: Hidden Code [Driver: arcsas, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8637c1f8 Size: 121
Object: Hidden Code [Driver: arcsas, IRP_MJ_POWER]
Process: System Address: 0x8637c1f8 Size: 121
Object: Hidden Code [Driver: arcsas, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8637c1f8 Size: 121
Object: Hidden Code [Driver: arcsas, IRP_MJ_PNP]
Process: System Address: 0x8637c1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid2, IRP_MJ_CREATE]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid2, IRP_MJ_CLOSE]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid2, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid2, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid2, IRP_MJ_POWER]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid2, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid2, IRP_MJ_PNP]
Process: System Address: 0x8638a1f8 Size: 121
Object: Hidden Code [Driver: Mraid35x, IRP_MJ_CREATE]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Mraid35x, IRP_MJ_CLOSE]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Mraid35x, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Mraid35x, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Mraid35x, IRP_MJ_POWER]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Mraid35x, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: Mraid35x, IRP_MJ_PNP]
Process: System Address: 0x863861f8 Size: 121
Object: Hidden Code [Driver: adpu320, IRP_MJ_CREATE]
Process: System Address: 0x8637a1f8 Size: 121
Object: Hidden Code [Driver: adpu320, IRP_MJ_CLOSE]
Process: System Address: 0x8637a1f8 Size: 121
Object: Hidden Code [Driver: adpu320, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8637a1f8 Size: 121
Object: Hidden Code [Driver: adpu320, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8637a1f8 Size: 121
Object: Hidden Code [Driver: adpu320, IRP_MJ_POWER]
Process: System Address: 0x8637a1f8 Size: 121
Object: Hidden Code [Driver: adpu320, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8637a1f8 Size: 121
Object: Hidden Code [Driver: adpu320, IRP_MJ_PNP]
Process: System Address: 0x8637a1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x863721f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x863721f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863721f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863721f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x863721f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863721f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x863721f8 Size: 121
Object: Hidden Code [Driver: SiSRaid4, IRP_MJ_CREATE]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid4, IRP_MJ_CLOSE]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid4, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid4, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid4, IRP_MJ_POWER]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid4, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: SiSRaid4, IRP_MJ_PNP]
Process: System Address: 0x8638b1f8 Size: 121
Object: Hidden Code [Driver: adpahci, IRP_MJ_CREATE]
Process: System Address: 0x863781f8 Size: 121
Object: Hidden Code [Driver: adpahci, IRP_MJ_CLOSE]
Process: System Address: 0x863781f8 Size: 121
Object: Hidden Code [Driver: adpahci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863781f8 Size: 121
Object: Hidden Code [Driver: adpahci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863781f8 Size: 121
Object: Hidden Code [Driver: adpahci, IRP_MJ_POWER]
Process: System Address: 0x863781f8 Size: 121
Object: Hidden Code [Driver: adpahci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863781f8 Size: 121
Object: Hidden Code [Driver: adpahci, IRP_MJ_PNP]
Process: System Address: 0x863781f8 Size: 121
Object: Hidden Code [Driver: iirsp, IRP_MJ_CREATE]
Process: System Address: 0x8637f1f8 Size: 121
Object: Hidden Code [Driver: iirsp, IRP_MJ_CLOSE]
Process: System Address: 0x8637f1f8 Size: 121
Object: Hidden Code [Driver: iirsp, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8637f1f8 Size: 121
Object: Hidden Code [Driver: iirsp, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8637f1f8 Size: 121
Object: Hidden Code [Driver: iirsp, IRP_MJ_POWER]
Process: System Address: 0x8637f1f8 Size: 121
Object: Hidden Code [Driver: iirsp, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8637f1f8 Size: 121
Object: Hidden Code [Driver: iirsp, IRP_MJ_PNP]
Process: System Address: 0x8637f1f8 Size: 121
Object: Hidden Code [Driver: ql40xx, IRP_MJ_CREATE]
Process: System Address: 0x863891f8 Size: 121
Object: Hidden Code [Driver: ql40xx, IRP_MJ_CLOSE]
Process: System Address: 0x863891f8 Size: 121
Object: Hidden Code [Driver: ql40xx, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863891f8 Size: 121
Object: Hidden Code [Driver: ql40xx, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863891f8 Size: 121
Object: Hidden Code [Driver: ql40xx, IRP_MJ_POWER]
Process: System Address: 0x863891f8 Size: 121
Object: Hidden Code [Driver: ql40xx, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863891f8 Size: 121
Object: Hidden Code [Driver: ql40xx, IRP_MJ_PNP]
Process: System Address: 0x863891f8 Size: 121
Object: Hidden Code [Driver: uliahci, IRP_MJ_CREATE]
Process: System Address: 0x8638f1f8 Size: 121
Object: Hidden Code [Driver: uliahci, IRP_MJ_CLOSE]
Process: System Address: 0x8638f1f8 Size: 121
Object: Hidden Code [Driver: uliahci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8638f1f8 Size: 121
Object: Hidden Code [Driver: uliahci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8638f1f8 Size: 121
Object: Hidden Code [Driver: uliahci, IRP_MJ_POWER]
Process: System Address: 0x8638f1f8 Size: 121
Object: Hidden Code [Driver: uliahci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8638f1f8 Size: 121
Object: Hidden Code [Driver: uliahci, IRP_MJ_PNP]
Process: System Address: 0x8638f1f8 Size: 121
Object: Hidden Code [Driver: usbohci捩Ђ䑎䵃, IRP_MJ_CREATE]
Process: System Address: 0x87c161f8 Size: 121
Object: Hidden Code [Driver: usbohci捩Ђ䑎䵃, IRP_MJ_CLOSE]
Process: System Address: 0x87c161f8 Size: 121
Object: Hidden Code [Driver: usbohci捩Ђ䑎䵃, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x87c161f8 Size: 121
Object: Hidden Code [Driver: usbohci捩Ђ䑎䵃, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x87c161f8 Size: 121
Object: Hidden Code [Driver: usbohci捩Ђ䑎䵃, IRP_MJ_POWER]
Process: System Address: 0x87c161f8 Size: 121
Object: Hidden Code [Driver: usbohci捩Ђ䑎䵃, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x87c161f8 Size: 121
Object: Hidden Code [Driver: usbohci捩Ђ䑎䵃, IRP_MJ_PNP]
Process: System Address: 0x87c161f8 Size: 121
Object: Hidden Code [Driver: Symc8xx, IRP_MJ_CREATE]
Process: System Address: 0x8638c1f8 Size: 121
Object: Hidden Code [Driver: Symc8xx, IRP_MJ_CLOSE]
Process: System Address: 0x8638c1f8 Size: 121
Object: Hidden Code [Driver: Symc8xx, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8638c1f8 Size: 121
Object: Hidden Code [Driver: Symc8xx, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8638c1f8 Size: 121
Object: Hidden Code [Driver: Symc8xx, IRP_MJ_POWER]
Process: System Address: 0x8638c1f8 Size: 121
Object: Hidden Code [Driver: Symc8xx, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8638c1f8 Size: 121
Object: Hidden Code [Driver: Symc8xx, IRP_MJ_PNP]
Process: System Address: 0x8638c1f8 Size: 121
Object: Hidden Code [Driver: nfrd960, IRP_MJ_CREATE]
Process: System Address: 0x863871f8 Size: 121
Object: Hidden Code [Driver: nfrd960, IRP_MJ_CLOSE]
Process: System Address: 0x863871f8 Size: 121
Object: Hidden Code [Driver: nfrd960, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863871f8 Size: 121
Object: Hidden Code [Driver: nfrd960, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863871f8 Size: 121
Object: Hidden Code [Driver: nfrd960, IRP_MJ_POWER]
Process: System Address: 0x863871f8 Size: 121
Object: Hidden Code [Driver: nfrd960, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863871f8 Size: 121
Object: Hidden Code [Driver: nfrd960, IRP_MJ_PNP]
Process: System Address: 0x863871f8 Size: 121
Object: Hidden Code [Driver: LSI_FC, IRP_MJ_CREATE]
Process: System Address: 0x863821f8 Size: 121
Object: Hidden Code [Driver: LSI_FC, IRP_MJ_CLOSE]
Process: System Address: 0x863821f8 Size: 121
Object: Hidden Code [Driver: LSI_FC, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863821f8 Size: 121
Object: Hidden Code [Driver: LSI_FC, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863821f8 Size: 121
Object: Hidden Code [Driver: LSI_FC, IRP_MJ_POWER]
Process: System Address: 0x863821f8 Size: 121
Object: Hidden Code [Driver: LSI_FC, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863821f8 Size: 121
Object: Hidden Code [Driver: LSI_FC, IRP_MJ_PNP]
Process: System Address: 0x863821f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_CREATE]
Process: System Address: 0x863791f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_CLOSE]
Process: System Address: 0x863791f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863791f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863791f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_POWER]
Process: System Address: 0x863791f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863791f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_PNP]
Process: System Address: 0x863791f8 Size: 121
Object: Hidden Code [Driver: Sym_u3, IRP_MJ_CREATE]
Process: System Address: 0x8638e1f8 Size: 121
Object: Hidden Code [Driver: Sym_u3, IRP_MJ_CLOSE]
Process: System Address: 0x8638e1f8 Size: 121
Object: Hidden Code [Driver: Sym_u3, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8638e1f8 Size: 121
Object: Hidden Code [Driver: Sym_u3, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8638e1f8 Size: 121
Object: Hidden Code [Driver: Sym_u3, IRP_MJ_POWER]
Process: System Address: 0x8638e1f8 Size: 121
Object: Hidden Code [Driver: Sym_u3, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8638e1f8 Size: 121
Object: Hidden Code [Driver: Sym_u3, IRP_MJ_PNP]
Process: System Address: 0x8638e1f8 Size: 121
Object: Hidden Code [Driver: Smb前Ї䅓䵃ꊼ齱훴袆훴袆, IRP_MJ_CREATE]
Process: System Address: 0x889471f8 Size: 121
Object: Hidden Code [Driver: Smb前Ї䅓䵃ꊼ齱훴袆훴袆, IRP_MJ_CLOSE]
Process: System Address: 0x889471f8 Size: 121
Object: Hidden Code [Driver: Smb前Ї䅓䵃ꊼ齱훴袆훴袆, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x889471f8 Size: 121
Object: Hidden Code [Driver: Smb前Ї䅓䵃ꊼ齱훴袆훴袆, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x889471f8 Size: 121
Object: Hidden Code [Driver: Smb前Ї䅓䵃ꊼ齱훴袆훴袆, IRP_MJ_CLEANUP]
Process: System Address: 0x889471f8 Size: 121
Object: Hidden Code [Driver: Smb前Ї䅓䵃ꊼ齱훴袆훴袆, IRP_MJ_PNP]
Process: System Address: 0x889471f8 Size: 121
Object: Hidden Code [Driver: netbt衶, IRP_MJ_CREATE]
Process: System Address: 0x889cf500 Size: 121
Object: Hidden Code [Driver: netbt衶, IRP_MJ_CLOSE]
Process: System Address: 0x889cf500 Size: 121
Object: Hidden Code [Driver: netbt衶, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x889cf500 Size: 121
Object: Hidden Code [Driver: netbt衶, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x889cf500 Size: 121
Object: Hidden Code [Driver: netbt衶, IRP_MJ_CLEANUP]
Process: System Address: 0x889cf500 Size: 121
Object: Hidden Code [Driver: netbt衶, IRP_MJ_PNP]
Process: System Address: 0x889cf500 Size: 121
Object: Hidden Code [Driver: UlSata, IRP_MJ_CREATE]
Process: System Address: 0x863901f8 Size: 121
Object: Hidden Code [Driver: UlSata, IRP_MJ_CLOSE]
Process: System Address: 0x863901f8 Size: 121
Object: Hidden Code [Driver: UlSata, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863901f8 Size: 121
Object: Hidden Code [Driver: UlSata, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863901f8 Size: 121
Object: Hidden Code [Driver: UlSata, IRP_MJ_POWER]
Process: System Address: 0x863901f8 Size: 121
Object: Hidden Code [Driver: UlSata, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863901f8 Size: 121
Object: Hidden Code [Driver: UlSata, IRP_MJ_PNP]
Process: System Address: 0x863901f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄㞀讦赫, IRP_MJ_CREATE]
Process: System Address: 0x87d56500 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄㞀讦赫, IRP_MJ_CLOSE]
Process: System Address: 0x87d56500 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄㞀讦赫, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x87d56500 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄㞀讦赫, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x87d56500 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄㞀讦赫, IRP_MJ_POWER]
Process: System Address: 0x87d56500 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄㞀讦赫, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x87d56500 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄㞀讦赫, IRP_MJ_PNP]
Process: System Address: 0x87d56500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x87c141f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x87c141f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x87c141f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x87c141f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x87c141f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x87c141f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x87c141f8 Size: 121
Object: Hidden Code [Driver: ack51btzЈ瑎牦ᶰ蟁宨螿, IRP_MJ_CREATE]
Process: System Address: 0x87d012e0 Size: 121
Object: Hidden Code [Driver: ack51btzЈ瑎牦ᶰ蟁宨螿, IRP_MJ_CLOSE]
Process: System Address: 0x87d012e0 Size: 121
Object: Hidden Code [Driver: ack51btzЈ瑎牦ᶰ蟁宨螿, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x87d012e0 Size: 121
Object: Hidden Code [Driver: ack51btzЈ瑎牦ᶰ蟁宨螿, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x87d012e0 Size: 121
Object: Hidden Code [Driver: ack51btzЈ瑎牦ᶰ蟁宨螿, IRP_MJ_POWER]
Process: System Address: 0x87d012e0 Size: 121
Object: Hidden Code [Driver: ack51btzЈ瑎牦ᶰ蟁宨螿, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x87d012e0 Size: 121
Object: Hidden Code [Driver: ack51btzЈ瑎牦ᶰ蟁宨螿, IRP_MJ_PNP]
Process: System Address: 0x87d012e0 Size: 121
Object: Hidden Code [Driver: iteraid, IRP_MJ_CREATE]
Process: System Address: 0x863811f8 Size: 121
Object: Hidden Code [Driver: iteraid, IRP_MJ_CLOSE]
Process: System Address: 0x863811f8 Size: 121
Object: Hidden Code [Driver: iteraid, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863811f8 Size: 121
Object: Hidden Code [Driver: iteraid, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863811f8 Size: 121
Object: Hidden Code [Driver: iteraid, IRP_MJ_POWER]
Process: System Address: 0x863811f8 Size: 121
Object: Hidden Code [Driver: iteraid, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863811f8 Size: 121
Object: Hidden Code [Driver: iteraid, IRP_MJ_PNP]
Process: System Address: 0x863811f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_CREATE]
Process: System Address: 0x8636f1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_READ]
Process: System Address: 0x8636f1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_WRITE]
Process: System Address: 0x8636f1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8636f1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8636f1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8636f1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8636f1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_CLEANUP]
Process: System Address: 0x8636f1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_POWER]
Process: System Address: 0x8636f1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8636f1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_PNP]
Process: System Address: 0x8636f1f8 Size: 12Hidden Services
-------------------
Service Name: MSIVXserv.sys
Image Path: C:\Windows\system32\drivers\MSIVXrmqcijvwxhhvcxwovhisiayxwieqsppy.sys
==EOF==