removed, restarted, issue still prevalent.
Malwarebytes' Anti-Malware 1.41
Database version: 2787
Windows 6.0.6002 Service Pack 2
9/12/2009 10:26:22 PM
mbam-log-2009-09-12 (22-26-14).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 226468
Time elapsed: 1 hour(s), 17 minute(s), 33 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\V CAST Music with Rhapsody\mpaplugins\rjdspln.dll (Malware.Packer) -> No action taken.
______
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/12 21:03
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x90F2A000 Size: 815104 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9E7F4000 Size: 49152 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: spwu.sys
Image Path: C:\Windows\System32\Drivers\spwu.sys
Address: 0x8068D000 Size: 1052672 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\System Volume Information\{2acf8841-5a95-11de-b509-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{2acf889d-5a95-11de-b509-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{439ccd48-55f4-11de-8136-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{45011e7c-87e3-11de-bef4-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{65f283b7-5f99-11de-96a4-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{6c753b01-9d00-11de-9e09-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{6fc8a227-8f5c-11de-bb0f-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{6fc8a22c-8f5c-11de-bb0f-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{816fba48-9022-11de-82f0-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{a43a94b6-6b88-11de-80a7-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{a43a94dc-6b88-11de-80a7-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{a43a94ef-6b88-11de-80a7-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{ba8504a1-965f-11de-9390-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{bf750277-9024-11de-966f-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\Windows\System32\GATHER~1.VBS
Status: Locked to the Windows API!
Path: C:\Windows\System32\GATHER~1.XSL
Status: Locked to the Windows API!
Path: C:\Windows\Temp\TMP0000005729B24DA6E4D28E65
Status: Visible to the Windows API, but not on disk.
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b5d18a9128.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d218504d2.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c35eb.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_818f59bf601aa775.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_7658964504b9f3b6.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_81c25f21d3d46d84.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8dd7dea5d5a7a18a.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_91949b06671d08ae.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c2866332652.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_58843c41d2730d3f.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003bc63e949f6.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a620671dde41.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c0566bec5b24.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_7dd1e0ebd6590e0b.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_10b3ea459bfee365.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_61305e07e4f1bc01.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11df268b7c6d9.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053e8c6967ba9d.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_45e008191e507087.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_5c94f2bbe7d4aaf6.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_0e9c2a8d74fd3ce6.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_abac38a907ee8801.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_fdproxy_31bf3856ad364e35_6.0.6000.16386_none_792f8ff471a64e3b\$$DeleteMe.fdProxy.dll.01c9ea3c4ff82dde.001e
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_fdssdp_31bf3856ad364e35_6.0.6001.18000_none_3addf297743e6161\$$DeleteMe.fdSSDP.dll.01c9ea3c511cf6fe.004b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_fdwsd_31bf3856ad364e35_6.0.6001.18000_none_7da88373c225d895\$$DeleteMe.fdWSD.dll.01c9ea3c52ef847e.0091
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_fundisc_31bf3856ad364e35_6.0.6001.18000_none_7be46ed83ae29055\$$DeleteMe.fundisc.dll.01c9ea3c509c6cbe.0036
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6001.18000_none_420aa4b9c28d5162\$$DeleteMe.SmartcardCredentialProvider.dll.01c9ea3c52206cde.006d
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6001.18000_none_d51103be4cb9d6c3\$$DeleteMe.apphelp.dll.01c9ea3c52f6a89e.0094
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6001.18000_none_5f327439667d597c\$$DeleteMe.adsldpc.dll.01c9ea3c509a0b5e.0034
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6002.18005_none_0e0fb1c9ef6c69c7\$$DeleteMe.AcGenral.dll.01ca310d130bae88.0000
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-advapi32_31bf3856ad364e35_6.0.6001.18000_none_e34851aa8681b8b0\$$DeleteMe.advapi32.dll.01c9ea3c4fcaf3be.0019
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6001.18000_none_ab203fc659b26ce7\$$DeleteMe.atl.dll.01ca1c331cda97b0.0008
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.audiodg.exe.01c9ea3c4fcfb67e.001a
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.AudioSes.dll.01c9ea3c520fc33e.0069
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.audiosrv.dll.01c9ea3c52c24a5e.008c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6001.18000_none_b5dfbc3a51b01b87\$$DeleteMe.winmm.dll.01c9ea3c527fa3de.007f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6001.18000_none_0bf37d16f567e1f7\$$DeleteMe.authui.dll.01c9ea3c51ec0e9e.0062
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-dsound_31bf3856ad364e35_6.0.6001.18000_none_589bbe5841e2df00\$$DeleteMe.dsound.dll.01c9ea3c51965d1e.005c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\$$DeleteMe.bcrypt.dll.01c9ea3c4fe0601e.001c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6001.18000_none_2390c4ecf9720b8c\$$DeleteMe.qmgr.dll.01c9ea3c516de5be.0057
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-bits-igdsearcher_31bf3856ad364e35_6.0.6001.18000_none_b16c3d098f004f58\$$DeleteMe.bitsigd.dll.01c9ea3c513be8de.0050
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-bth-user_31bf3856ad364e35_6.0.6001.18000_none_65193febd52e137a\$$DeleteMe.wshbth.dll.01c9ea3c4fa9a07e.0014
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18057_none_0cbe918751dfdd3f\$$DeleteMe.es.dll.01c9ea3c52bd879e.008b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6001.18000_none_d71173946e986845\$$DeleteMe.diagperf.dll.01c9ea3c539624be.00a5
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.0.6001.18000_none_d77db57c3ca78826\$$DeleteMe.certcli.dll.01c9ea3c50a8539e.003b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6001.18000_none_a9ce4a485a8ade99\$$DeleteMe.cmiv2.dll.01c9ea3c56d4e49e.00ba
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6001.18000_none_ac1da75bf2516084\$$DeleteMe.ole32.dll.01c9ea3c50ed5b7e.0046
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.18000_none_69cadbfc3ddffe3c\$$DeleteMe.rpcss.dll.01c9ea3c52b8c4de.0089
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-comdlg32_31bf3856ad364e35_6.0.6001.18000_none_b5b111a1a5a793a5\$$DeleteMe.comdlg32.dll.01c9ea3c50aab4fe.003c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6001.18000_none_7701ab362cebf905\$$DeleteMe.umpnpmgr.dll.01c9ea3c534c5a1e.009d
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6001.18000_none_db374cc18eed7408\$$DeleteMe.credui.dll.01c9ea3c4f5b131e.0009
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6001.18000_none_5b6fc1dbddd3c6da\$$DeleteMe.crypt32.dll.01c9ea3c5241c01e.0074
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\$$DeleteMe.cryptsvc.dll.01c9ea3c50e1749e.0042
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-cryptui-dll_31bf3856ad364e35_6.0.6001.18000_none_85ee5b5e98235317\$$DeleteMe.cryptui.dll.01c9ea3c519d813e.005d
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6001.18000_none_8da39414bd31fb37\$$DeleteMe.uxsms.dll.01c9ea3c530c14fe.0097
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02e8fcf7a\$$DeleteMe.dhcpcsvc.dll.01c9ea3c531a5d3e.0099
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02e8fcf7a\$$DeleteMe.dhcpcsvc6.dll.01c9ea3c4f695b5e.000c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samlib.dll.01c9ea3c5158795e.0052
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samsrv.dll.01c9ea3c4fbf0cde.0016
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.0.6000.16386_none_571790f3532b2696\$$DeleteMe.winrnr.dll.01c9ea3c53adf27e.00a8
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsapi.dll.01c9ea3c4fae633e.0015
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsrslvr.dll.01c9ea3c5078b81e.002f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2cc36a286b\$$DeleteMe.eappcfg.dll.01c9ea3c4f6bbcbe.000d
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2cc36a286b\$$DeleteMe.eapphost.dll.01c9ea3c538f009e.00a4
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18098_none_9e329f52f6fc276d\$$DeleteMe.emdmgmt.dll.01c9ea3c5248e43e.0076
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6001.18000_none_f1e446e12c0bbf09\$$DeleteMe.esent.dll.01c9ea3c51f5941e.0065
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_6.0.6001.18000_none_2076b21605e43be9\$$DeleteMe.wer.dll.01c9ea3c50f47f9e.0047
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6001.18000_none_dcc45c1a12d92f84\$$DeleteMe.wevtsvc.dll.01c9ea3c4fc8925e.0017
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-feclient_31bf3856ad364e35_6.0.6001.18000_none_beda112b5794d4e0\$$DeleteMe.feclient.dll.01c9ea3c53537e3e.009f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-feedback-service_31bf3856ad364e35_6.0.6001.18145_none_79a5b70991018b47\$$DeleteMe.wersvc.dll.01c9ea3c52252f9e.006e
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpapi.dll.01c9ea3c5164603e.0056
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpsvc.dll.01c9ea3c526c98de.007d
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-hid-user_31bf3856ad364e35_6.0.6000.16386_none_d47586718a839763\$$DeleteMe.hidserv.dll.01c9ea3c5284669e.0080
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18148_none_01c5b803a1ec4989\$$DeleteMe.wininet.dll.01c9ea3c51d440de.0060
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-icm-base_31bf3856ad364e35_6.0.6001.18000_none_22c7ea5489633945\$$DeleteMe.mscms.dll.01c9ea3c5164603e.0055
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18148_none_47806edf8c9d67e6\$$DeleteMe.iertutil.dll.01c9ea3c5132635e.004f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_5c561e167a6afd02\$$DeleteMe.imm32.dll.01c9ea3c5023069e.0026
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18000_none_93bde541564b88ae\$$DeleteMe.kernel32.dll.01c9ea3c5023069e.0025
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-ldap-client_31bf3856ad364e35_6.0.6001.18000_none_f33c4797566bb3db\$$DeleteMe.Wldap32.dll.01c9ea3c515f9d7e.0054
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\$$DeleteMe.lsasrv.dll.01c9ea3c4c12cdbe.0004
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\$$DeleteMe.lsass.exe.01ca1c331c9cb3f0.0000
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\$$DeleteMe.secur32.dll.01c9ea3c4c1eb49e.0006
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\$$DeleteMe.lsasrv.dll.01ca1c331c9f1550.0001
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\$$DeleteMe.lsass.exe.01ca1c331c9cb3f0.0000
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\$$DeleteMe.secur32.dll.01ca1c331c9f1550.0002
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18000_none_9c5f2f3c0cc1aa83\$$DeleteMe.mf.dll.01c966324aa24420.0000
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mfplat_31bf3856ad364e35_6.0.6001.18000_none_f6aa98ad53755122\$$DeleteMe.mfplat.dll.01c9ea3c4f91d2be.0011
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mmdeviceapi_31bf3856ad364e35_6.0.6001.18000_none_55044397b961da8a\$$DeleteMe.MMDevAPI.dll.01c9ea3c5374d17e.00a2
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mprapi_31bf3856ad364e35_6.0.6001.18000_none_140c84ec53049b39\$$DeleteMe.mprapi.dll.01c9ea3c4f5fd5de.000b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.0.6001.18000_none_c7427a4e786d74bc\$$DeleteMe.adtschema.dll.01c9ea3c5235d93e.0071
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mpr_31bf3856ad364e35_6.0.6001.18000_none_add5c97257f151a1\$$DeleteMe.mpr.dll.01c9ea3c50c4e41e.003f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18136_none_8853d47896e90b40\$$DeleteMe.msxml3.dll.01c9ea3c52bb263e.008a
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6001.18000_none_d15536209ee61dad\$$DeleteMe.msvcrt.dll.01c9ea3c512da09e.004e
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-n..-domain-clients-svc_31bf3856ad364e35_6.0.6001.18000_none_440e77d1ec053e6c\$$DeleteMe.FwRemoteSvr.dll.01c9ea3c51919a5e.005b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-n..-domain-clients-svc_31bf3856ad364e35_6.0.6001.18094_none_43b129adec4a9f41\$$DeleteMe.FwRemoteSvr.dll.01c9ea3c51919a5e.005b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-n..-domain-clients-svc_31bf3856ad364e35_6.0.6001.18094_none_43b129adec4a9f41\$$DeleteMe.IPSECSVC.DLL.01c9ea3c5111101e.004a
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_none_9d81873e2afd9b5e\$$DeleteMe.NaturalLanguage6.dll.01c9ea3c535f651e.00a1
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_none_9d81873e2afd9b5e\$$DeleteMe.NlsLexicons0009.dll.01c9ea3c50a5f23e.0039
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_5dde5591f19c0ea3\$$DeleteMe.ncrypt.dll.01c9ea3c51d1df7e.005f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6001.18157_none_8d050f6301b2186f\$$DeleteMe.netapi32.dll.01c9ea3c52a0f71e.0084
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-netshell_31bf3856ad364e35_6.0.6001.18000_none_d5836ad30e0ac92d\$$DeleteMe.netshell.dll.01c9ea3c52b6637e.0088
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.18000_none_cd246fe92a8ad809\$$DeleteMe.BFE.DLL.01c9ea3c4c02241e.0002
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.18000_none_cd246fe92a8ad809\$$DeleteMe.FWPUCLNT.DLL.01c9ea3c4bfd615e.0001
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.18000_none_cd246fe92a8ad809\$$DeleteMe.IKEEXT.DLL.01c9ea3c4c1c533e.0005
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-ntdll_31bf3856ad364e35_6.0.6001.18000_none_58d6de41fc2dac16\$$DeleteMe.ntdll.dll.01c9ea3c4c0ba99e.0003
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-o..inefiles-win32-apis_31bf3856ad364e35_6.0.6001.18000_none_ab6af9d0f92539f0\$$DeleteMe.cscapi.dll.01c9ea3c530e765e.0098
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-ole-automation_31bf3856ad364e35_6.0.6001.18000_none_bd002a8dfb7a3328\$$DeleteMe.oleaut32.dll.01c9ea3c5073f55e.002e
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-onex_31bf3856ad364e35_6.0.6001.18000_none_a5cb1bed1d5ba052\$$DeleteMe.onex.dll.01c9ea3c4f81291e.000f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6001.18000_none_301b5dfb92ae18db\$$DeleteMe.localspl.dll.01c9ea00e8bc7fe8.0001
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6001.18247_none_2ff7241d92c8344e\$$DeleteMe.localspl.dll.01c9ea3c52fdccbe.0095
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..pooler-core-spoolss_31bf3856ad364e35_6.0.6001.18000_none_5b3992df8e604356\$$DeleteMe.spoolss.dll.01c9ea3c51f5941e.0064
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..rnetprinting-client_31bf3856ad364e35_6.0.6001.18000_none_8ad265adc8633a42\$$DeleteMe.inetpp.dll.01c9ea3c5059c63e.002b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..rtmonitor-tcpmondll_31bf3856ad364e35_6.0.6001.18000_none_d2ac9d5aa723258e\$$DeleteMe.tcpmon.dll.01c9ea3c538a3dde.00a3
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..ting-wsdportmonitor_31bf3856ad364e35_6.0.6001.18000_none_16d3442ddf994157\$$DeleteMe.WSDMon.dll.01c9ea3c4ffcf09e.0020
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..ting-spooler-client_31bf3856ad364e35_6.0.6001.18000_none_932df61f18add086\$$DeleteMe.winspool.drv.01c9ea3c52af3f5e.0087
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-pantherengine_31bf3856ad364e35_6.0.6001.18000_none_ae116f90a5d6b7d4\$$DeleteMe.wdscore.dll.01c9ea3c5180f0be.0059
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.18000_none_d64ba321c188c516\$$DeleteMe.spoolsv.exe.01c9ea3c52c70d1e.008e
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-profsvc_31bf3856ad364e35_6.0.6001.18000_none_fbb1576d32ad0ba9\$$DeleteMe.profsvc.dll.01c9ea3c5250085e.0078
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-propsys_31bf3856ad364e35_7.0.6001.16503_none_f3d11aeeb9526bbb\$$DeleteMe.propsys.dll.01c9ea3c502567fe.0027
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-raschap_31bf3856ad364e35_6.0.6001.18000_none_12bf0305774c76e6\$$DeleteMe.raschap.dll.01c9ea3c50680e7e.002c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rasdlg_31bf3856ad364e35_6.0.6001.18000_none_6d133c0e4fa0edb1\$$DeleteMe.rasdlg.dll.01c9ea3c4f5d747e.000a
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rasrtutils_31bf3856ad364e35_6.0.6001.18000_none_0d159410ea7a8f9d\$$DeleteMe.rtutils.dll.01c9ea3c50849efe.0030
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rasmanservice_31bf3856ad364e35_6.0.6001.18000_none_9ebd9641a0a88359\$$DeleteMe.rasmans.dll.01c9ea3c521948be.006c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rasplap_31bf3856ad364e35_6.0.6001.18000_none_1236753177b2477f\$$DeleteMe.rasplap.dll.01c9ea3c52dc797e.0090
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rasppp_31bf3856ad364e35_6.0.6001.18000_none_6c94b11e4fff8902\$$DeleteMe.rasppp.dll.01c9ea3c50cc083e.0040
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rastapi_31bf3856ad364e35_6.0.6001.18000_none_0ee42a5979dd0144\$$DeleteMe.rastapi.dll.01c9ea3c522790fe.006f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rastls_31bf3856ad364e35_6.0.6001.18000_none_6c652bee5023e04d\$$DeleteMe.rastls.dll.01c9ea3c5185b37e.005a
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-riched32_31bf3856ad364e35_6.0.6001.18000_none_9d00b3d6829ba4d0\$$DeleteMe.riched20.dll.01c9ea3c50a5f23e.003a
Status: Locked to thProcesses
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1280 Status: Locked to the Windows API!
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_CREATE]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_CLOSE]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_READ]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_WRITE]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_QUERY_EA]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_SET_EA]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_CLEANUP]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_PNP]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_CREATE]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_CLOSE]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_POWER]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_PNP]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_CREATE]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_CLOSE]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_READ]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_WRITE]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_POWER]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_PNP]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_CREATE]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_CLOSE]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_POWER]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_PNP]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_CREATE]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_CLOSE]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_CLEANUP]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_PNP]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_CREATE]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_CLOSE]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_CLEANUP]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_PNP]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_CREATE]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_CLOSE]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_POWER]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_PNP]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_CREATE]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_READ]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_WRITE]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_SHUTDOWN]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_CLEANUP]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_POWER]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_PNP]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_CREATE]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_CLOSE]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_READ]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_WRITE]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_QUERY_EA]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SET_EA]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_CLEANUP]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_POWER]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_PNP]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_CREATE]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_CLOSE]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_READ]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_WRITE]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_CLEANUP]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_PNP]
Process: System Address: 0x8995d1f8 Size: 121
==EOF==
Malwarebytes' Anti-Malware 1.41
Database version: 2787
Windows 6.0.6002 Service Pack 2
9/12/2009 10:26:22 PM
mbam-log-2009-09-12 (22-26-14).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 226468
Time elapsed: 1 hour(s), 17 minute(s), 33 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\V CAST Music with Rhapsody\mpaplugins\rjdspln.dll (Malware.Packer) -> No action taken.
______
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/12 21:03
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x90F2A000 Size: 815104 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9E7F4000 Size: 49152 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: spwu.sys
Image Path: C:\Windows\System32\Drivers\spwu.sys
Address: 0x8068D000 Size: 1052672 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\System Volume Information\{2acf8841-5a95-11de-b509-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{2acf889d-5a95-11de-b509-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{439ccd48-55f4-11de-8136-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{45011e7c-87e3-11de-bef4-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{65f283b7-5f99-11de-96a4-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{6c753b01-9d00-11de-9e09-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{6fc8a227-8f5c-11de-bb0f-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{6fc8a22c-8f5c-11de-bb0f-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{816fba48-9022-11de-82f0-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{a43a94b6-6b88-11de-80a7-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{a43a94dc-6b88-11de-80a7-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{a43a94ef-6b88-11de-80a7-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{ba8504a1-965f-11de-9390-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\System Volume Information\{bf750277-9024-11de-966f-001fe1f10a5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!
Path: C:\Windows\System32\GATHER~1.VBS
Status: Locked to the Windows API!
Path: C:\Windows\System32\GATHER~1.XSL
Status: Locked to the Windows API!
Path: C:\Windows\Temp\TMP0000005729B24DA6E4D28E65
Status: Visible to the Windows API, but not on disk.
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b5d18a9128.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d218504d2.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c35eb.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_818f59bf601aa775.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_7658964504b9f3b6.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_81c25f21d3d46d84.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8dd7dea5d5a7a18a.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_91949b06671d08ae.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c2866332652.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_58843c41d2730d3f.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003bc63e949f6.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a620671dde41.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c0566bec5b24.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_7dd1e0ebd6590e0b.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_10b3ea459bfee365.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_61305e07e4f1bc01.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11df268b7c6d9.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053e8c6967ba9d.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_45e008191e507087.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_5c94f2bbe7d4aaf6.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_0e9c2a8d74fd3ce6.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_abac38a907ee8801.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1.cat
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_fdproxy_31bf3856ad364e35_6.0.6000.16386_none_792f8ff471a64e3b\$$DeleteMe.fdProxy.dll.01c9ea3c4ff82dde.001e
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_fdssdp_31bf3856ad364e35_6.0.6001.18000_none_3addf297743e6161\$$DeleteMe.fdSSDP.dll.01c9ea3c511cf6fe.004b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_fdwsd_31bf3856ad364e35_6.0.6001.18000_none_7da88373c225d895\$$DeleteMe.fdWSD.dll.01c9ea3c52ef847e.0091
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_fundisc_31bf3856ad364e35_6.0.6001.18000_none_7be46ed83ae29055\$$DeleteMe.fundisc.dll.01c9ea3c509c6cbe.0036
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6001.18000_none_420aa4b9c28d5162\$$DeleteMe.SmartcardCredentialProvider.dll.01c9ea3c52206cde.006d
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6001.18000_none_d51103be4cb9d6c3\$$DeleteMe.apphelp.dll.01c9ea3c52f6a89e.0094
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6001.18000_none_5f327439667d597c\$$DeleteMe.adsldpc.dll.01c9ea3c509a0b5e.0034
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c3_31bf3856ad364e35_6.0.6002.18005_none_0e0fb1c9ef6c69c7\$$DeleteMe.AcGenral.dll.01ca310d130bae88.0000
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-advapi32_31bf3856ad364e35_6.0.6001.18000_none_e34851aa8681b8b0\$$DeleteMe.advapi32.dll.01c9ea3c4fcaf3be.0019
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6001.18000_none_ab203fc659b26ce7\$$DeleteMe.atl.dll.01ca1c331cda97b0.0008
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.audiodg.exe.01c9ea3c4fcfb67e.001a
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.AudioSes.dll.01c9ea3c520fc33e.0069
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.audiosrv.dll.01c9ea3c52c24a5e.008c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6001.18000_none_b5dfbc3a51b01b87\$$DeleteMe.winmm.dll.01c9ea3c527fa3de.007f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6001.18000_none_0bf37d16f567e1f7\$$DeleteMe.authui.dll.01c9ea3c51ec0e9e.0062
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-audio-dsound_31bf3856ad364e35_6.0.6001.18000_none_589bbe5841e2df00\$$DeleteMe.dsound.dll.01c9ea3c51965d1e.005c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\$$DeleteMe.bcrypt.dll.01c9ea3c4fe0601e.001c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6001.18000_none_2390c4ecf9720b8c\$$DeleteMe.qmgr.dll.01c9ea3c516de5be.0057
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-bits-igdsearcher_31bf3856ad364e35_6.0.6001.18000_none_b16c3d098f004f58\$$DeleteMe.bitsigd.dll.01c9ea3c513be8de.0050
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-bth-user_31bf3856ad364e35_6.0.6001.18000_none_65193febd52e137a\$$DeleteMe.wshbth.dll.01c9ea3c4fa9a07e.0014
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18057_none_0cbe918751dfdd3f\$$DeleteMe.es.dll.01c9ea3c52bd879e.008b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6001.18000_none_d71173946e986845\$$DeleteMe.diagperf.dll.01c9ea3c539624be.00a5
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.0.6001.18000_none_d77db57c3ca78826\$$DeleteMe.certcli.dll.01c9ea3c50a8539e.003b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6001.18000_none_a9ce4a485a8ade99\$$DeleteMe.cmiv2.dll.01c9ea3c56d4e49e.00ba
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.0.6001.18000_none_ac1da75bf2516084\$$DeleteMe.ole32.dll.01c9ea3c50ed5b7e.0046
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6001.18000_none_69cadbfc3ddffe3c\$$DeleteMe.rpcss.dll.01c9ea3c52b8c4de.0089
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-comdlg32_31bf3856ad364e35_6.0.6001.18000_none_b5b111a1a5a793a5\$$DeleteMe.comdlg32.dll.01c9ea3c50aab4fe.003c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6001.18000_none_7701ab362cebf905\$$DeleteMe.umpnpmgr.dll.01c9ea3c534c5a1e.009d
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6001.18000_none_db374cc18eed7408\$$DeleteMe.credui.dll.01c9ea3c4f5b131e.0009
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6001.18000_none_5b6fc1dbddd3c6da\$$DeleteMe.crypt32.dll.01c9ea3c5241c01e.0074
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\$$DeleteMe.cryptsvc.dll.01c9ea3c50e1749e.0042
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-cryptui-dll_31bf3856ad364e35_6.0.6001.18000_none_85ee5b5e98235317\$$DeleteMe.cryptui.dll.01c9ea3c519d813e.005d
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6001.18000_none_8da39414bd31fb37\$$DeleteMe.uxsms.dll.01c9ea3c530c14fe.0097
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02e8fcf7a\$$DeleteMe.dhcpcsvc.dll.01c9ea3c531a5d3e.0099
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02e8fcf7a\$$DeleteMe.dhcpcsvc6.dll.01c9ea3c4f695b5e.000c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samlib.dll.01c9ea3c5158795e.0052
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samsrv.dll.01c9ea3c4fbf0cde.0016
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.0.6000.16386_none_571790f3532b2696\$$DeleteMe.winrnr.dll.01c9ea3c53adf27e.00a8
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsapi.dll.01c9ea3c4fae633e.0015
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsrslvr.dll.01c9ea3c5078b81e.002f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2cc36a286b\$$DeleteMe.eappcfg.dll.01c9ea3c4f6bbcbe.000d
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2cc36a286b\$$DeleteMe.eapphost.dll.01c9ea3c538f009e.00a4
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18098_none_9e329f52f6fc276d\$$DeleteMe.emdmgmt.dll.01c9ea3c5248e43e.0076
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6001.18000_none_f1e446e12c0bbf09\$$DeleteMe.esent.dll.01c9ea3c51f5941e.0065
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_6.0.6001.18000_none_2076b21605e43be9\$$DeleteMe.wer.dll.01c9ea3c50f47f9e.0047
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6001.18000_none_dcc45c1a12d92f84\$$DeleteMe.wevtsvc.dll.01c9ea3c4fc8925e.0017
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-feclient_31bf3856ad364e35_6.0.6001.18000_none_beda112b5794d4e0\$$DeleteMe.feclient.dll.01c9ea3c53537e3e.009f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-feedback-service_31bf3856ad364e35_6.0.6001.18145_none_79a5b70991018b47\$$DeleteMe.wersvc.dll.01c9ea3c52252f9e.006e
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpapi.dll.01c9ea3c5164603e.0056
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpsvc.dll.01c9ea3c526c98de.007d
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-hid-user_31bf3856ad364e35_6.0.6000.16386_none_d47586718a839763\$$DeleteMe.hidserv.dll.01c9ea3c5284669e.0080
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18148_none_01c5b803a1ec4989\$$DeleteMe.wininet.dll.01c9ea3c51d440de.0060
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-icm-base_31bf3856ad364e35_6.0.6001.18000_none_22c7ea5489633945\$$DeleteMe.mscms.dll.01c9ea3c5164603e.0055
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18148_none_47806edf8c9d67e6\$$DeleteMe.iertutil.dll.01c9ea3c5132635e.004f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_5c561e167a6afd02\$$DeleteMe.imm32.dll.01c9ea3c5023069e.0026
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18000_none_93bde541564b88ae\$$DeleteMe.kernel32.dll.01c9ea3c5023069e.0025
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-ldap-client_31bf3856ad364e35_6.0.6001.18000_none_f33c4797566bb3db\$$DeleteMe.Wldap32.dll.01c9ea3c515f9d7e.0054
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\$$DeleteMe.lsasrv.dll.01c9ea3c4c12cdbe.0004
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\$$DeleteMe.lsass.exe.01ca1c331c9cb3f0.0000
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\$$DeleteMe.secur32.dll.01c9ea3c4c1eb49e.0006
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\$$DeleteMe.lsasrv.dll.01ca1c331c9f1550.0001
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\$$DeleteMe.lsass.exe.01ca1c331c9cb3f0.0000
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\$$DeleteMe.secur32.dll.01ca1c331c9f1550.0002
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18000_none_9c5f2f3c0cc1aa83\$$DeleteMe.mf.dll.01c966324aa24420.0000
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mfplat_31bf3856ad364e35_6.0.6001.18000_none_f6aa98ad53755122\$$DeleteMe.mfplat.dll.01c9ea3c4f91d2be.0011
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mmdeviceapi_31bf3856ad364e35_6.0.6001.18000_none_55044397b961da8a\$$DeleteMe.MMDevAPI.dll.01c9ea3c5374d17e.00a2
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mprapi_31bf3856ad364e35_6.0.6001.18000_none_140c84ec53049b39\$$DeleteMe.mprapi.dll.01c9ea3c4f5fd5de.000b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-msauditevtlog_31bf3856ad364e35_6.0.6001.18000_none_c7427a4e786d74bc\$$DeleteMe.adtschema.dll.01c9ea3c5235d93e.0071
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-mpr_31bf3856ad364e35_6.0.6001.18000_none_add5c97257f151a1\$$DeleteMe.mpr.dll.01c9ea3c50c4e41e.003f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18136_none_8853d47896e90b40\$$DeleteMe.msxml3.dll.01c9ea3c52bb263e.008a
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6001.18000_none_d15536209ee61dad\$$DeleteMe.msvcrt.dll.01c9ea3c512da09e.004e
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-n..-domain-clients-svc_31bf3856ad364e35_6.0.6001.18000_none_440e77d1ec053e6c\$$DeleteMe.FwRemoteSvr.dll.01c9ea3c51919a5e.005b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-n..-domain-clients-svc_31bf3856ad364e35_6.0.6001.18094_none_43b129adec4a9f41\$$DeleteMe.FwRemoteSvr.dll.01c9ea3c51919a5e.005b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-n..-domain-clients-svc_31bf3856ad364e35_6.0.6001.18094_none_43b129adec4a9f41\$$DeleteMe.IPSECSVC.DLL.01c9ea3c5111101e.004a
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_none_9d81873e2afd9b5e\$$DeleteMe.NaturalLanguage6.dll.01c9ea3c535f651e.00a1
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_none_9d81873e2afd9b5e\$$DeleteMe.NlsLexicons0009.dll.01c9ea3c50a5f23e.0039
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-ncrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_5dde5591f19c0ea3\$$DeleteMe.ncrypt.dll.01c9ea3c51d1df7e.005f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6001.18157_none_8d050f6301b2186f\$$DeleteMe.netapi32.dll.01c9ea3c52a0f71e.0084
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-netshell_31bf3856ad364e35_6.0.6001.18000_none_d5836ad30e0ac92d\$$DeleteMe.netshell.dll.01c9ea3c52b6637e.0088
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.18000_none_cd246fe92a8ad809\$$DeleteMe.BFE.DLL.01c9ea3c4c02241e.0002
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.18000_none_cd246fe92a8ad809\$$DeleteMe.FWPUCLNT.DLL.01c9ea3c4bfd615e.0001
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.18000_none_cd246fe92a8ad809\$$DeleteMe.IKEEXT.DLL.01c9ea3c4c1c533e.0005
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-ntdll_31bf3856ad364e35_6.0.6001.18000_none_58d6de41fc2dac16\$$DeleteMe.ntdll.dll.01c9ea3c4c0ba99e.0003
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-o..inefiles-win32-apis_31bf3856ad364e35_6.0.6001.18000_none_ab6af9d0f92539f0\$$DeleteMe.cscapi.dll.01c9ea3c530e765e.0098
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-ole-automation_31bf3856ad364e35_6.0.6001.18000_none_bd002a8dfb7a3328\$$DeleteMe.oleaut32.dll.01c9ea3c5073f55e.002e
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-onex_31bf3856ad364e35_6.0.6001.18000_none_a5cb1bed1d5ba052\$$DeleteMe.onex.dll.01c9ea3c4f81291e.000f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6001.18000_none_301b5dfb92ae18db\$$DeleteMe.localspl.dll.01c9ea00e8bc7fe8.0001
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6001.18247_none_2ff7241d92c8344e\$$DeleteMe.localspl.dll.01c9ea3c52fdccbe.0095
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..pooler-core-spoolss_31bf3856ad364e35_6.0.6001.18000_none_5b3992df8e604356\$$DeleteMe.spoolss.dll.01c9ea3c51f5941e.0064
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..rnetprinting-client_31bf3856ad364e35_6.0.6001.18000_none_8ad265adc8633a42\$$DeleteMe.inetpp.dll.01c9ea3c5059c63e.002b
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..rtmonitor-tcpmondll_31bf3856ad364e35_6.0.6001.18000_none_d2ac9d5aa723258e\$$DeleteMe.tcpmon.dll.01c9ea3c538a3dde.00a3
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..ting-wsdportmonitor_31bf3856ad364e35_6.0.6001.18000_none_16d3442ddf994157\$$DeleteMe.WSDMon.dll.01c9ea3c4ffcf09e.0020
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-p..ting-spooler-client_31bf3856ad364e35_6.0.6001.18000_none_932df61f18add086\$$DeleteMe.winspool.drv.01c9ea3c52af3f5e.0087
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-pantherengine_31bf3856ad364e35_6.0.6001.18000_none_ae116f90a5d6b7d4\$$DeleteMe.wdscore.dll.01c9ea3c5180f0be.0059
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.18000_none_d64ba321c188c516\$$DeleteMe.spoolsv.exe.01c9ea3c52c70d1e.008e
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-profsvc_31bf3856ad364e35_6.0.6001.18000_none_fbb1576d32ad0ba9\$$DeleteMe.profsvc.dll.01c9ea3c5250085e.0078
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-propsys_31bf3856ad364e35_7.0.6001.16503_none_f3d11aeeb9526bbb\$$DeleteMe.propsys.dll.01c9ea3c502567fe.0027
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-raschap_31bf3856ad364e35_6.0.6001.18000_none_12bf0305774c76e6\$$DeleteMe.raschap.dll.01c9ea3c50680e7e.002c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rasdlg_31bf3856ad364e35_6.0.6001.18000_none_6d133c0e4fa0edb1\$$DeleteMe.rasdlg.dll.01c9ea3c4f5d747e.000a
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rasrtutils_31bf3856ad364e35_6.0.6001.18000_none_0d159410ea7a8f9d\$$DeleteMe.rtutils.dll.01c9ea3c50849efe.0030
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rasmanservice_31bf3856ad364e35_6.0.6001.18000_none_9ebd9641a0a88359\$$DeleteMe.rasmans.dll.01c9ea3c521948be.006c
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rasplap_31bf3856ad364e35_6.0.6001.18000_none_1236753177b2477f\$$DeleteMe.rasplap.dll.01c9ea3c52dc797e.0090
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rasppp_31bf3856ad364e35_6.0.6001.18000_none_6c94b11e4fff8902\$$DeleteMe.rasppp.dll.01c9ea3c50cc083e.0040
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rastapi_31bf3856ad364e35_6.0.6001.18000_none_0ee42a5979dd0144\$$DeleteMe.rastapi.dll.01c9ea3c522790fe.006f
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-rastls_31bf3856ad364e35_6.0.6001.18000_none_6c652bee5023e04d\$$DeleteMe.rastls.dll.01c9ea3c5185b37e.005a
Status: Locked to the Windows API!
Path: C:\Windows\winsxs\x86_microsoft-windows-riched32_31bf3856ad364e35_6.0.6001.18000_none_9d00b3d6829ba4d0\$$DeleteMe.riched20.dll.01c9ea3c50a5f23e.003a
Status: Locked to thProcesses
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1280 Status: Locked to the Windows API!
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x856a61f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_CREATE]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_CLOSE]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_READ]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_WRITE]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_QUERY_EA]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_SET_EA]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_CLEANUP]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: fastfat䀀慖â¤Đ†ç™…, IRP_MJ_PNP]
Process: System Address: 0x89a471f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_CREATE]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_CLOSE]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_POWER]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_PNP]
Process: System Address: 0x856a31f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x856a51f8 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_CREATE]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_CLOSE]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_READ]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_WRITE]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_POWER]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: cdromॸ, IRP_MJ_PNP]
Process: System Address: 0x86f82500 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_CREATE]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_CLOSE]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_POWER]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: usbuhciŕ °Đ…ć˝‰â€ , IRP_MJ_PNP]
Process: System Address: 0x86efd1f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_CREATE]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_CLOSE]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_CLEANUP]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: Smb迟Е楆, IRP_MJ_PNP]
Process: System Address: 0x875c91f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_CREATE]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_CLOSE]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_CLEANUP]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: netbtč’, IRP_MJ_PNP]
Process: System Address: 0x876031f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_CREATE]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_CLOSE]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_POWER]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄çŽč°¦ěč·ľ, IRP_MJ_PNP]
Process: System Address: 0x86ff61f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_CREATE]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_READ]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_WRITE]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_SHUTDOWN]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_CLEANUP]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_POWER]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_PNP]
Process: System Address: 0x84d151f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x86f881f8 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_CREATE]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_CLOSE]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_READ]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_WRITE]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_QUERY_EA]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SET_EA]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_CLEANUP]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_POWER]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: mrxsmb緰蛌Ї敓î…, IRP_MJ_PNP]
Process: System Address: 0x8910c500 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_CREATE]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_CLOSE]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_READ]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_WRITE]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_CLEANUP]
Process: System Address: 0x8995d1f8 Size: 121
Object: Hidden Code [Driver: cdfsП牄㣀谦㝀躌, IRP_MJ_PNP]
Process: System Address: 0x8995d1f8 Size: 121
==EOF==
Edited by easjogren, 12 September 2009 - 09:40 PM.