Posted 15 October 2009 - 05:33 AM
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/15 05:30
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x90D12000 Size: 753664 File Visible: No Signed: -
Status: -
Name: kwlcapoc.sys
Image Path: C:\Users\Frito\AppData\Local\Temp\kwlcapoc.sys
Address: 0x9F7CF000 Size: 87040 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9F7F1000 Size: 49152 File Visible: No Signed: -
Status: -
Name: spfv.sys
Image Path: C:\Windows\System32\Drivers\spfv.sys
Address: 0x8068D000 Size: 1052672 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Processes
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x858f01f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_CREATE]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_READ]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_WRITE]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: fastfat, IRP_MJ_PNP]
Process: System Address: 0x8837d1f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_CREATE]
Process: System Address: 0x858ed1f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_CLOSE]
Process: System Address: 0x858ed1f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x858ed1f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x858ed1f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_POWER]
Process: System Address: 0x858ed1f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x858ed1f8 Size: 121
Object: Hidden Code [Driver: iaStorV, IRP_MJ_PNP]
Process: System Address: 0x858ed1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x858ef1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x858ef1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x858ef1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x858ef1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x858ef1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x858ef1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x858ef1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_CREATE]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_CLOSE]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_READ]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_WRITE]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_POWER]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: cdrom虃, IRP_MJ_PNP]
Process: System Address: 0x8709e1f8 Size: 121
Object: Hidden Code [Driver: USBSTOR蠙П牄识싨踟, IRP_MJ_CREATE]
Process: System Address: 0x88195500 Size: 121
Object: Hidden Code [Driver: USBSTOR蠙П牄识싨踟, IRP_MJ_CLOSE]
Process: System Address: 0x88195500 Size: 121
Object: Hidden Code [Driver: USBSTOR蠙П牄识싨踟, IRP_MJ_READ]
Process: System Address: 0x88195500 Size: 121
Object: Hidden Code [Driver: USBSTOR蠙П牄识싨踟, IRP_MJ_WRITE]
Process: System Address: 0x88195500 Size: 121
Object: Hidden Code [Driver: USBSTOR蠙П牄识싨踟, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x88195500 Size: 121
Object: Hidden Code [Driver: USBSTOR蠙П牄识싨踟, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x88195500 Size: 121
Object: Hidden Code [Driver: USBSTOR蠙П牄识싨踟, IRP_MJ_POWER]
Process: System Address: 0x88195500 Size: 121
Object: Hidden Code [Driver: USBSTOR蠙П牄识싨踟, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x88195500 Size: 121
Object: Hidden Code [Driver: USBSTOR蠙П牄识싨踟, IRP_MJ_PNP]
Process: System Address: 0x88195500 Size: 121
Object: Hidden Code [Driver: usbuhci草ҫ䑎晩, IRP_MJ_CREATE]
Process: System Address: 0x875091f8 Size: 121
Object: Hidden Code [Driver: usbuhci草ҫ䑎晩, IRP_MJ_CLOSE]
Process: System Address: 0x875091f8 Size: 121
Object: Hidden Code [Driver: usbuhci草ҫ䑎晩, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x875091f8 Size: 121
Object: Hidden Code [Driver: usbuhci草ҫ䑎晩, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x875091f8 Size: 121
Object: Hidden Code [Driver: usbuhci草ҫ䑎晩, IRP_MJ_POWER]
Process: System Address: 0x875091f8 Size: 121
Object: Hidden Code [Driver: usbuhci草ҫ䑎晩, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x875091f8 Size: 121
Object: Hidden Code [Driver: usbuhci草ҫ䑎晩, IRP_MJ_PNP]
Process: System Address: 0x875091f8 Size: 121
Object: Hidden Code [Driver: ay9pe6nwП牄识쫨踗, IRP_MJ_CREATE]
Process: System Address: 0x8756e1f8 Size: 121
Object: Hidden Code [Driver: ay9pe6nwП牄识쫨踗, IRP_MJ_CLOSE]
Process: System Address: 0x8756e1f8 Size: 121
Object: Hidden Code [Driver: ay9pe6nwП牄识쫨踗, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8756e1f8 Size: 121
Object: Hidden Code [Driver: ay9pe6nwП牄识쫨踗, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8756e1f8 Size: 121
Object: Hidden Code [Driver: ay9pe6nwП牄识쫨踗, IRP_MJ_POWER]
Process: System Address: 0x8756e1f8 Size: 121
Object: Hidden Code [Driver: ay9pe6nwП牄识쫨踗, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8756e1f8 Size: 121
Object: Hidden Code [Driver: ay9pe6nwП牄识쫨踗, IRP_MJ_PNP]
Process: System Address: 0x8756e1f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_CREATE]
Process: System Address: 0x881b91f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_CLOSE]
Process: System Address: 0x881b91f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x881b91f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x881b91f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_CLEANUP]
Process: System Address: 0x881b91f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_PNP]
Process: System Address: 0x881b91f8 Size: 121
Object: Hidden Code [Driver: netbt蠟, IRP_MJ_CREATE]
Process: System Address: 0x88187500 Size: 121
Object: Hidden Code [Driver: netbt蠟, IRP_MJ_CLOSE]
Process: System Address: 0x88187500 Size: 121
Object: Hidden Code [Driver: netbt蠟, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x88187500 Size: 121
Object: Hidden Code [Driver: netbt蠟, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x88187500 Size: 121
Object: Hidden Code [Driver: netbt蠟, IRP_MJ_CLEANUP]
Process: System Address: 0x88187500 Size: 121
Object: Hidden Code [Driver: netbt蠟, IRP_MJ_PNP]
Process: System Address: 0x88187500 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄识쭨踘, IRP_MJ_CREATE]
Process: System Address: 0x874ad1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄识쭨踘, IRP_MJ_CLOSE]
Process: System Address: 0x874ad1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄识쭨踘, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x874ad1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄识쭨踘, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x874ad1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄识쭨踘, IRP_MJ_POWER]
Process: System Address: 0x874ad1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄识쭨踘, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x874ad1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrtП牄识쭨踘, IRP_MJ_PNP]
Process: System Address: 0x874ad1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_CREATE]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_READ]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_WRITE]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_SHUTDOWN]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_CLEANUP]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_POWER]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_PNP]
Process: System Address: 0x84f5d1f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x875701f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x875701f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x875701f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x875701f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x875701f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x875701f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x875701f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_CREATE]
Process: System Address: 0x858f11f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_CLOSE]
Process: System Address: 0x858f11f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x858f11f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x858f11f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_POWER]
Process: System Address: 0x858f11f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x858f11f8 Size: 121
Object: Hidden Code [Driver: sbp2port, IRP_MJ_PNP]
Process: System Address: 0x858f11f8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CLOSE]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_READ]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_WRITE]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_EA]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CLEANUP]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_POWER]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_PNP]
Process: System Address: 0x8744e500 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_CREATE]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_CLOSE]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_READ]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_WRITE]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_SHUTDOWN]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_CLEANUP]
Process: System Address: 0x851c51f8 Size: 121
Object: Hidden Code [Driver: cdfs瑎牦셠蔞仨蛍⫰蔏Ѕ捓䙌, IRP_MJ_PNP]
Process: System Address: 0x851c51f8 Size: 121
==EOF==