Re: Nejdú zobraziť skryté súbory a priečinky windows xp sp3
Napsal: 08 led 2010 12:26
Log z Root Repeal
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/01/08 12:03
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA6BA8000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA63A000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA5CB3000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\ADSM_PData_0150
Status: Invisible to the Windows API!
Path: \\?\C:\ADSM_PData_0150\*
Status: Could not enumerate files with the Windows API (0x00000006)!
Path: C:\ADSM_PData_0150\DB
Status: Invisible to the Windows API!
Path: C:\ADSM_PData_0150\DragWait.exe
Status: Invisible to the Windows API!
Path: C:\ADSM_PData_0150\_avt
Status: Invisible to the Windows API!
Path: \\?\C:\ADSM_PData_0150\DB\*
Status: Could not enumerate files with the Windows API (0x00000006)!
Path: C:\ADSM_PData_0150\DB\SI.db
Status: Invisible to the Windows API!
Path: C:\ADSM_PData_0150\DB\UL.db
Status: Invisible to the Windows API!
Path: C:\ADSM_PData_0150\DB\VL.db
Status: Invisible to the Windows API!
Path: C:\ADSM_PData_0150\DB\_avt
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\cch6B0.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\cch6B1.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\cch6CD.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\Temp\cch6CE.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\Temp\cch6D0.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\Temp\cch6D1.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\Temp\cch6D3.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\Temp\cch6D4.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\temp\etilqs_eywnRbuzguhv1beGFcWi
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\temp\etilqs_VdjhLM34eJG5WSWGb7n6
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\temp\chrome_shutdown_ms.txt
Status: Visible to the Windows API, but not on disk.
Path: \\?\C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86\*
Status: Could not enumerate files with the Windows API (0x00000006)!
Path: C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86\AsDsm.sys
Status: Invisible to the Windows API!
Path: C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86\_avt
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Andy\My Documents\Fotky\Fotky škola\veci.rar:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
Status: Visible to the Windows API, but not on disk.
Path: c:\documents and settings\all users\application data\kaspersky lab\avp9\report\01\0000018d_events.dat
Status: Size mismatch (API: 78692, Raw: 76872)
Path: c:\documents and settings\all users\application data\kaspersky lab\avp9\report\01\0000018d_objbt.dat
Status: Size mismatch (API: 3160, Raw: 3096)
Path: c:\documents and settings\all users\application data\kaspersky lab\avp9\report\01\0000018d_objdt.dat
Status: Size mismatch (API: 43060, Raw: 42412)
Path: c:\documents and settings\all users\application data\kaspersky lab\avp9\report\01\0000018d_objid.dat
Status: Size mismatch (API: 4130, Raw: 4072)
Path: C:\Documents and Settings\Andy\Local Settings\Apps\2.0\M4OA22RM.WV2\3V9DE1ZV.J00\manifests\clickonce_bootstrap.exe.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\Apps\2.0\M4OA22RM.WV2\3V9DE1ZV.J00\manifests\clickonce_bootstrap.exe.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\Apps\2.0\M4OA22RM.WV2\3V9DE1ZV.J00\manifests\CZD Kalkulacka.exe.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\Apps\2.0\M4OA22RM.WV2\3V9DE1ZV.J00\manifests\CZD Kalkulacka.exe.manifest
Status: Locked to the Windows API!
SSDT
-------------------
#: 011 Function Name: NtAdjustPrivilegesToken
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7736e
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77a86
#: 031 Function Name: NtConnectPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7860c
#: 035 Function Name: NtCreateEvent
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78b40
#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77d78
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76460
#: 043 Function Name: NtCreateMutant
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78a18
#: 044 Function Name: NtCreateNamedPipeFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f75d0a
#: 046 Function Name: NtCreatePort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f788d4
#: 050 Function Name: NtCreateSection
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77102
#: 051 Function Name: NtCreateSemaphore
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78c72
#: 052 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a40e
#: 053 Function Name: NtCreateThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77886
#: 056 Function Name: NtCreateWaitablePort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78976
#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76a20
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76cf8
#: 066 Function Name: NtDeviceIoControlFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7821c
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a980
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76e3a
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76ee4
#: 084 Function Name: NtFsControlFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78016
#: 097 Function Name: NtLoadDriver
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f79ea6
#: 098 Function Name: NtLoadKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7643c
#: 099 Function Name: NtLoadKey2
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7644e
#: 111 Function Name: NtNotifyChangeKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77030
#: 114 Function Name: NtOpenEvent
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78be2
#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77b08
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76604
#: 120 Function Name: NtOpenMutant
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78ab0
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7756e
#: 125 Function Name: NtOpenSection
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a438
#: 126 Function Name: NtOpenSemaphore
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78d14
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77492
#: 160 Function Name: NtQueryKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76f8e
#: 161 Function Name: NtQueryMultipleValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76bb6
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f768bc
#: 180 Function Name: NtQueueApcThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a128
#: 192 Function Name: NtRenameKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76b34
#: 193 Function Name: NtReplaceKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f760c2
#: 194 Function Name: NtReplyPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7909e
#: 195 Function Name: NtReplyWaitReceivePort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78f64
#: 200 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f79c30
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76224
#: 206 Function Name: NtResumeThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a860
#: 207 Function Name: NtSaveKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f75ec4
#: 210 Function Name: NtSecureConnectPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78312
#: 213 Function Name: NtSetContextThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77984
#: 230 Function Name: NtSetInformationToken
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f795f2
#: 237 Function Name: NtSetSecurityObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f79fa0
#: 240 Function Name: NtSetSystemInformation
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a4c2
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76744
#: 253 Function Name: NtSuspendProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a5a6
#: 254 Function Name: NtSuspendThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a6d2
#: 255 Function Name: NtSystemDebugControl
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f79dd2
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f776ea
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7763c
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f777c8
Shadow SSDT
-------------------
#: 013 Function Name: NtGdiBitBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f8732a
#: 227 Function Name: NtGdiMaskBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f873ee
#: 237 Function Name: NtGdiPlgBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f87454
#: 292 Function Name: NtGdiStretchBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f8738a
#: 307 Function Name: NtUserAttachThreadInput
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86ec4
#: 323 Function Name: NtUserCallOneParam
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f87242
#: 378 Function Name: NtUserFindWindowEx
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f870b2
#: 383 Function Name: NtUserGetAsyncKeyState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86e2c
#: 414 Function Name: NtUserGetKeyboardState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f8717a
#: 416 Function Name: NtUserGetKeyState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86e78
#: 460 Function Name: NtUserMessageCall
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f87004
#: 475 Function Name: NtUserPostMessage
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86f5a
#: 476 Function Name: NtUserPostThreadMessage
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86fae
#: 491 Function Name: NtUserRegisterRawInputDevices
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f8710a
#: 502 Function Name: NtUserSendInput
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f87064
#: 549 Function Name: NtUserSetWindowsHookEx
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86d7c
#: 552 Function Name: NtUserSetWinEventHook
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86dd2
==EOF==
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/01/08 12:03
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA6BA8000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA63A000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA5CB3000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\ADSM_PData_0150
Status: Invisible to the Windows API!
Path: \\?\C:\ADSM_PData_0150\*
Status: Could not enumerate files with the Windows API (0x00000006)!
Path: C:\ADSM_PData_0150\DB
Status: Invisible to the Windows API!
Path: C:\ADSM_PData_0150\DragWait.exe
Status: Invisible to the Windows API!
Path: C:\ADSM_PData_0150\_avt
Status: Invisible to the Windows API!
Path: \\?\C:\ADSM_PData_0150\DB\*
Status: Could not enumerate files with the Windows API (0x00000006)!
Path: C:\ADSM_PData_0150\DB\SI.db
Status: Invisible to the Windows API!
Path: C:\ADSM_PData_0150\DB\UL.db
Status: Invisible to the Windows API!
Path: C:\ADSM_PData_0150\DB\VL.db
Status: Invisible to the Windows API!
Path: C:\ADSM_PData_0150\DB\_avt
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\cch6B0.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\cch6B1.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\cch6CD.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\Temp\cch6CE.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\Temp\cch6D0.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\Temp\cch6D1.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\Temp\cch6D3.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\Temp\cch6D4.tmp
Status: Visible to the Windows API, but not on disk.
Path: C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\temp\etilqs_eywnRbuzguhv1beGFcWi
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\temp\etilqs_VdjhLM34eJG5WSWGb7n6
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\temp\chrome_shutdown_ms.txt
Status: Visible to the Windows API, but not on disk.
Path: \\?\C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86\*
Status: Could not enumerate files with the Windows API (0x00000006)!
Path: C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86\AsDsm.sys
Status: Invisible to the Windows API!
Path: C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86\_avt
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Andy\My Documents\Fotky\Fotky škola\veci.rar:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
Status: Visible to the Windows API, but not on disk.
Path: c:\documents and settings\all users\application data\kaspersky lab\avp9\report\01\0000018d_events.dat
Status: Size mismatch (API: 78692, Raw: 76872)
Path: c:\documents and settings\all users\application data\kaspersky lab\avp9\report\01\0000018d_objbt.dat
Status: Size mismatch (API: 3160, Raw: 3096)
Path: c:\documents and settings\all users\application data\kaspersky lab\avp9\report\01\0000018d_objdt.dat
Status: Size mismatch (API: 43060, Raw: 42412)
Path: c:\documents and settings\all users\application data\kaspersky lab\avp9\report\01\0000018d_objid.dat
Status: Size mismatch (API: 4130, Raw: 4072)
Path: C:\Documents and Settings\Andy\Local Settings\Apps\2.0\M4OA22RM.WV2\3V9DE1ZV.J00\manifests\clickonce_bootstrap.exe.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\Apps\2.0\M4OA22RM.WV2\3V9DE1ZV.J00\manifests\clickonce_bootstrap.exe.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\Apps\2.0\M4OA22RM.WV2\3V9DE1ZV.J00\manifests\CZD Kalkulacka.exe.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Andy\Local Settings\Apps\2.0\M4OA22RM.WV2\3V9DE1ZV.J00\manifests\CZD Kalkulacka.exe.manifest
Status: Locked to the Windows API!
SSDT
-------------------
#: 011 Function Name: NtAdjustPrivilegesToken
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7736e
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77a86
#: 031 Function Name: NtConnectPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7860c
#: 035 Function Name: NtCreateEvent
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78b40
#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77d78
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76460
#: 043 Function Name: NtCreateMutant
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78a18
#: 044 Function Name: NtCreateNamedPipeFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f75d0a
#: 046 Function Name: NtCreatePort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f788d4
#: 050 Function Name: NtCreateSection
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77102
#: 051 Function Name: NtCreateSemaphore
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78c72
#: 052 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a40e
#: 053 Function Name: NtCreateThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77886
#: 056 Function Name: NtCreateWaitablePort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78976
#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76a20
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76cf8
#: 066 Function Name: NtDeviceIoControlFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7821c
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a980
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76e3a
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76ee4
#: 084 Function Name: NtFsControlFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78016
#: 097 Function Name: NtLoadDriver
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f79ea6
#: 098 Function Name: NtLoadKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7643c
#: 099 Function Name: NtLoadKey2
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7644e
#: 111 Function Name: NtNotifyChangeKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77030
#: 114 Function Name: NtOpenEvent
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78be2
#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77b08
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76604
#: 120 Function Name: NtOpenMutant
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78ab0
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7756e
#: 125 Function Name: NtOpenSection
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a438
#: 126 Function Name: NtOpenSemaphore
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78d14
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77492
#: 160 Function Name: NtQueryKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76f8e
#: 161 Function Name: NtQueryMultipleValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76bb6
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f768bc
#: 180 Function Name: NtQueueApcThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a128
#: 192 Function Name: NtRenameKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76b34
#: 193 Function Name: NtReplaceKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f760c2
#: 194 Function Name: NtReplyPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7909e
#: 195 Function Name: NtReplyWaitReceivePort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78f64
#: 200 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f79c30
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76224
#: 206 Function Name: NtResumeThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a860
#: 207 Function Name: NtSaveKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f75ec4
#: 210 Function Name: NtSecureConnectPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f78312
#: 213 Function Name: NtSetContextThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f77984
#: 230 Function Name: NtSetInformationToken
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f795f2
#: 237 Function Name: NtSetSecurityObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f79fa0
#: 240 Function Name: NtSetSystemInformation
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a4c2
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f76744
#: 253 Function Name: NtSuspendProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a5a6
#: 254 Function Name: NtSuspendThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7a6d2
#: 255 Function Name: NtSystemDebugControl
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f79dd2
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f776ea
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f7763c
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f777c8
Shadow SSDT
-------------------
#: 013 Function Name: NtGdiBitBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f8732a
#: 227 Function Name: NtGdiMaskBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f873ee
#: 237 Function Name: NtGdiPlgBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f87454
#: 292 Function Name: NtGdiStretchBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f8738a
#: 307 Function Name: NtUserAttachThreadInput
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86ec4
#: 323 Function Name: NtUserCallOneParam
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f87242
#: 378 Function Name: NtUserFindWindowEx
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f870b2
#: 383 Function Name: NtUserGetAsyncKeyState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86e2c
#: 414 Function Name: NtUserGetKeyboardState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f8717a
#: 416 Function Name: NtUserGetKeyState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86e78
#: 460 Function Name: NtUserMessageCall
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f87004
#: 475 Function Name: NtUserPostMessage
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86f5a
#: 476 Function Name: NtUserPostThreadMessage
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86fae
#: 491 Function Name: NtUserRegisterRawInputDevices
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f8710a
#: 502 Function Name: NtUserSendInput
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f87064
#: 549 Function Name: NtUserSetWindowsHookEx
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86d7c
#: 552 Function Name: NtUserSetWinEventHook
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa6f86dd2
==EOF==