garmanma, thanks for your post. I've been using mbam for a while and have never had any problems. Its gotten rid of some things that superantispyware doesn't notice or notices but doesn't seem to get rid of. My last scan with malwarebytes (done today) did not show any problems.
Here is my report from RootRepeal
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/18 21:58
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: 00000159
Image Path: \Driver\00000159
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF5195000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8C3D000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF294C000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\WINDOWS\$hf_mig$\{29F8DDC1-9487-49b8-B27E-3E0C3C1298FF}
Status: Locked to the Windows API!
Path: c:\windows\temp\04467d16-03c3-4abe-840d-529504c25b47.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\0603c38a-8c35-41d6-bcae-d980892320f8.tmp
Status: Allocation size mismatch (API: 49152, Raw: 0)
Path: c:\windows\temp\30b4c277-ac3f-4021-a050-e4b1a0fbe2f6.tmp
Status: Allocation size mismatch (API: 8192, Raw: 0)
Path: c:\windows\temp\c0ace011-06bf-4696-9cd0-51a417ac8fad.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\e495e388-dc47-482d-b0bd-48465b1f3b5a.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\ea2f14f8-8469-4046-8cb5-bfc5368713a6.tmp
Status: Allocation size mismatch (API: 8192, Raw: 0)
Path: c:\windows\temp\6ff69d24-8efd-493b-a082-5b40b2abc49e.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\598b8e2b-1508-4d95-a81f-58c0fbe77c1c.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\f2765ff5-31b2-4347-859c-94e730be46c7.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\f74e27b0-c4aa-467e-a00a-91191695220a.tmp
Status: Allocation size mismatch (API: 32768, Raw: 0)
Path: c:\windows\temp\41eb89cb-e469-4c2b-bb45-ac54f2c6f072.tmp
Status: Allocation size mismatch (API: 32768, Raw: 0)
Path: c:\windows\temp\4670f0ab-341a-4591-865e-1cbdbbcd665d.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\4b2c1bc9-b9ae-4365-bb68-c72ce6ad6834.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\9b8ceed2-f748-4ad4-b311-757eb7407901.tmp
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\9c9aef2e-28c5-400c-9dfd-59c088e5a122.tmp
Status: Allocation size mismatch (API: 0, Raw: 131072)
Path: c:\windows\temp\9d5d54f6-ef16-4b93-87c4-72292b61fba8.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\9f13faad-cd71-480d-b36e-6c5755c9146f.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\cb5538f9-ac1f-418f-88f1-e3fb1ee0c683.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: C:\WINDOWS\temp\72f42fed-5372-4f7c-9a7d-d4c015f721e1.tmp
Status: Visible to the Windows API, but not on disk.
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "sptd.sys" at address 0xf85a2ac8
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf85a2c22
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf85a2f9a
#: 119 Function Name: NtOpenKey
Status: Hooked by "sptd.sys" at address 0xf85a298e
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf8a6a470
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf85a3064
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "sptd.sys" at address 0xf85a2efc
#: 247 Function Name: NtSetValueKey
Status: Hooked by "sptd.sys" at address 0xf85a30ec
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf8a6a520
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf8a6a5c0
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf8a6a660
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8339f0e8 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CREATE]
Process: System Address: 0x82f74ca0 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CLOSE]
Process: System Address: 0x82f74ca0 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82f74ca0 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82f74ca0 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_POWER]
Process: System Address: 0x82f74ca0 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82f74ca0 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_PNP]
Process: System Address: 0x82f74ca0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x831b5eb0 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_CREATE]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_CLOSE]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_READ]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_WRITE]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_POWER]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_PNP]
Process: System Address: 0x833a02d8 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x833a0848 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x82ff50e8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x82ff50e8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82ff50e8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82ff50e8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x82ff50e8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x82ff50e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLOSE]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_WRITE]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_EA]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_EA]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SHUTDOWN]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLEANUP]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_SECURITY]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_POWER]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_QUOTA]
Process: System Address: 0x82cac1e8 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x8311da98 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_CREATE]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_CLOSE]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_READ]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_WRITE]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_CLEANUP]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: Npfsȅఆ䵃慖, IRP_MJ_SET_SECURITY]
Process: System Address: 0x82d580e8 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_CREATE]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_CLOSE]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_READ]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_WRITE]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_SET_INFORMATION]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_CLEANUP]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: , IRP_MJ_SET_SECURITY]
Process: System Address: 0x83142768 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_CREATE]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_CLOSE]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_READ]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_SHUTDOWN]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_CLEANUP]
Process: System Address: 0x830ae0e8 Size: 15
Object: Hidden Code [Driver: Cdfsȅఄ浗灩MofResource, IRP_MJ_PNP]
Process: System Address: 0x830ae0e8 Size: 15
==EOF==
Thanks.