Prosim o kontrolu logu
Napsal: 20 srp 2010 08:05
Mam tam asi WIN32/mebroot ale vsechny zarucene navody zatim nevysly ,,
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-19 14:58:33
Windows 5.1.2600 Service Pack 3
Running: tr5ohnqq.exe; Driver: C:\DOCUME~1\ADMINI~1.002\LOCALS~1\Temp\aftyifow.sys
---- System - GMER 1.0.15 ----
SSDT spcp.sys ZwEnumerateKey [0xF74F6CA2]
SSDT spcp.sys ZwEnumerateValueKey [0xF74F7030]
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A1341F8
Device \FileSystem\Fastfat \Fat 89DCB500
---- EOF - GMER 1.0.15 ----
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-20 08:52:05
Windows 5.1.2600 Service Pack 3
Running: tr5ohnqq.exe; Driver: C:\DOCUME~1\ADMINI~1.002\LOCALS~1\Temp\aftyifow.sys
---- System - GMER 1.0.15 ----
SSDT spcp.sys ZwCreateKey [0xF74D90E0]
SSDT spcp.sys ZwEnumerateKey [0xF74F6CA2]
SSDT spcp.sys ZwEnumerateValueKey [0xF74F7030]
SSDT spcp.sys ZwOpenKey [0xF74D90C0]
SSDT spcp.sys ZwQueryKey [0xF74F7108]
SSDT spcp.sys ZwQueryValueKey [0xF74F6F88]
SSDT spcp.sys ZwSetValueKey [0xF74F719A]
INT 0x63 ? 89FADF00
INT 0x73 ? 8A136BF8
INT 0x73 ? 8A136BF8
INT 0x73 ? 8A136BF8
INT 0x73 ? 8A136BF8
INT 0x73 ? 89FADF00
INT 0x73 ? 8A136BF8
INT 0x83 ? 8A1A7BF8
INT 0x94 ? 89FADF00
INT 0xB4 ? 89FADF00
---- Kernel code sections - GMER 1.0.15 ----
PAGE ntoskrnl.exe!ZwSetTimerResolution + 15768 80600C00 73 Bytes [04, 8B, 07, 3B, C3, 0F, 84, ...]
PAGE ntoskrnl.exe!ZwSetTimerResolution + 157B2 80600C4A 35 Bytes CALL 804E192E \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!ZwSetTimerResolution + 157D6 80600C6E 11 Bytes [15, 0C, 81, 4D, 80, E9, FD, ...]
PAGE ntoskrnl.exe!ZwSetTimerResolution + 157E3 80600C7B 23 Bytes [3B, F3, 0F, 84, 96, 4A, F7, ...]
PAGE ntoskrnl.exe!ZwSetTimerResolution + 157FB 80600C93 29 Bytes CALL 805511E4 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ...
PAGE ntoskrnl.exe!CcMdlRead + 53 8061BED0 36 Bytes [8D, 45, D0, 50, 8D, 45, CC, ...]
PAGE ntoskrnl.exe!CcMdlRead + 78 8061BEF5 45 Bytes CALL 804F1DA2 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!CcMdlRead + A6 8061BF23 32 Bytes [C7, 05, 28, 30, 55, 80, 78, ...]
PAGE ntoskrnl.exe!CcMdlRead + C7 8061BF44 49 Bytes [00, 00, 8D, 45, E0, 50, 8D, ...]
PAGE ntoskrnl.exe!CcMdlRead + F9 8061BF76 43 Bytes [9C, 13, 4D, A8, 89, 4D, A0, ...]
PAGE ...
PAGE ntoskrnl.exe!CcMdlReadComplete + 28 8061C158 17 Bytes [75, 08, FF, D1, 84, C0, 75, ...]
PAGE ntoskrnl.exe!CcMdlReadComplete + 3A 8061C16A 156 Bytes [CC, CC, CC, CC, CC, CC, 90, ...]
PAGE ntoskrnl.exe!CmUnRegisterCallback + 3C 8061C207 5 Bytes [53, E8, D6, 09, 03]
PAGE ntoskrnl.exe!CmUnRegisterCallback + 42 8061C20D 11 Bytes [84, C0, 74, 46, 83, C8, FF, ...]
PAGE ntoskrnl.exe!CmUnRegisterCallback + 4E 8061C219 29 Bytes [F0, 0F, C1, 01, 8B, 45, FC, ...]
PAGE ntoskrnl.exe!CmUnRegisterCallback + 6C 8061C237 2 Bytes [76, 10] {JBE 0x12}
PAGE ntoskrnl.exe!CmUnRegisterCallback + 6F 8061C23A 3 Bytes CALL 805511E7 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ...
PAGE ntoskrnl.exe!CmRegisterCallback + 2 8061C289 21 Bytes [55, 8B, EC, 51, 53, 56, 57, ...]
PAGE ntoskrnl.exe!CmRegisterCallback + 18 8061C29F 6 Bytes [8B, F0, 33, FF, 3B, F7] {MOV ESI, EAX; XOR EDI, EDI; CMP ESI, EDI}
PAGE ntoskrnl.exe!CmRegisterCallback + 1F 8061C2A6 13 Bytes [84, CB, 00, 00, 00, 53, 6A, ...]
PAGE ntoskrnl.exe!CmRegisterCallback + 2D 8061C2B4 66 Bytes [3B, C7, 89, 46, 10, 74, 19, ...]
PAGE ntoskrnl.exe!CmRegisterCallback + 70 8061C2F7 67 Bytes [40, 04, 89, 00, 8B, 46, 10, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlMdlReadDev + 5 8061C4C2 1 Byte [52]
PAGE ntoskrnl.exe!FsRtlMdlReadDev + 5 8061C4C2 27 Bytes CALL 804E2EA1 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!FsRtlMdlReadDev + 21 8061C4DE 183 Bytes JMP 8061C5CA \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!FsRtlMdlReadDev + D9 8061C596 25 Bytes [1C, C7, 00, 11, 00, 00, C0, ...]
PAGE ntoskrnl.exe!FsRtlMdlReadDev + F3 8061C5B0 20 Bytes [80, D4, 00, 00, 00, 75, 13, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlPrepareMdlWriteDev + 30 8061C76B 22 Bytes [6A, 01, 8B, 5D, 10, 53, 8B, ...]
PAGE ntoskrnl.exe!FsRtlPrepareMdlWriteDev + 47 8061C782 51 Bytes [F6, 46, 2C, 10, 0F, 85, 99, ...]
PAGE ntoskrnl.exe!FsRtlPrepareMdlWriteDev + 7B 8061C7B6 215 Bytes [CB, 33, C0, 03, 0F, 13, 47, ...]
PAGE ntoskrnl.exe!FsRtlPrepareMdlWriteDev + 153 8061C88E 96 Bytes CALL 804DA3A1 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!FsRtlPrepareMdlWriteDev + 1B4 8061C8EF 37 Bytes CALL 804E842C \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ...
PAGE ntoskrnl.exe!FsRtlPrepareMdlWrite + 48 8061CB83 44 Bytes [40, 08, 8B, 40, 28, 85, C0, ...]
PAGE ntoskrnl.exe!FsRtlPrepareMdlWrite + 75 8061CBB0 37 Bytes [FF, 5F, 5E, 5D, C2, 18, 00, ...]
PAGE ntoskrnl.exe!FsRtlMdlWriteCompleteDev + 13 8061CBD6 74 Bytes [75, 10, FF, 75, 0C, 50, E8, ...]
PAGE ntoskrnl.exe!FsRtlIncrementCcFastReadNotPossible + C 8061CC21 40 Bytes [C3, CC, CC, CC, CC, CC, CC, ...]
PAGE ntoskrnl.exe!FsRtlCopyRead + 1A 8061CC4B 100 Bytes [8B, 4D, 10, 8D, 84, 08, FF, ...]
PAGE ntoskrnl.exe!FsRtlCopyRead + 7F 8061CCB0 38 Bytes [00, FF, 88, D4, 00, 00, 00, ...]
PAGE ntoskrnl.exe!FsRtlCopyRead + A6 8061CCD7 14 Bytes [83, 7E, 18, 00, 0F, 84, 00, ...]
PAGE ntoskrnl.exe!FsRtlCopyRead + B5 8061CCE6 32 Bytes [0F, 84, F5, 01, 00, 00, 3C, ...]
PAGE ntoskrnl.exe!FsRtlCopyRead + D6 8061CD07 31 Bytes [75, 18, FF, 75, 14, FF, 75, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlCopyWrite + 18 8061CF4F 5 Bytes [8B, 5D, 0C, 83, 3B]
PAGE ntoskrnl.exe!FsRtlCopyWrite + 1E 8061CF55 19 Bytes [75, 0A, 83, 7B, 04, FF, C6, ...] {JNZ 0xc; CMP DWORD [EBX+0x4], -0x1; MOV BYTE [EBP-0x1a], 0x1; JZ 0x10; MOV BYTE [EBP-0x1a], 0x0; MOV EDI, [EBP+0x8]}
PAGE ntoskrnl.exe!FsRtlCopyWrite + 32 8061CF69 26 Bytes [77, 0C, 89, 75, CC, 6A, 00, ...]
PAGE ntoskrnl.exe!FsRtlCopyWrite + 4D 8061CF84 48 Bytes [F6, 47, 2C, 10, 0F, 85, B1, ...]
PAGE ntoskrnl.exe!FsRtlCopyWrite + 7E 8061CFB5 2 Bytes [88, D4] {MOV AH, DL}
PAGE ...
PAGE ntoskrnl.exe!FsRtlMdlWriteComplete + 8 8061D663 69 Bytes CALL 804E842D \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!FsRtlMdlWriteComplete + 4E 8061D6A9 27 Bytes [78, 4C, 00, 74, 04, 32, C0, ...]
PAGE ntoskrnl.exe!FsRtlMdlWriteComplete + 6A 8061D6C5 42 Bytes [90, 90, 90, CC, CC, CC, CC, ...]
PAGE ntoskrnl.exe!FsRtlInitializeMcb + 11 8061D6F0 20 Bytes [90, 90, 90, 90, 8B, FF, 55, ...]
PAGE ntoskrnl.exe!FsRtlUninitializeMcb + 14 8061D708 114 Bytes [90, A1, 0C, A0, 69, 80, 83, ...]
PAGE ntoskrnl.exe!FsRtlSyncVolumes + 30 8061D77B 4 Bytes [75, 08, E8, 27]
PAGE ntoskrnl.exe!FsRtlSyncVolumes + 35 8061D780 1 Byte [EC]
PAGE ntoskrnl.exe!FsRtlSyncVolumes + 35 8061D780 86 Bytes [EC, FF, 5D, C2, 08, 00, CC, ...]
PAGE ntoskrnl.exe!FsRtlSyncVolumes + 8C 8061D7D7 100 Bytes [8B, C6, EB, 7E, 8B, 4E, 1C, ...]
PAGE ntoskrnl.exe!FsRtlSyncVolumes + F1 8061D83C 36 Bytes [C0, 8B, 4D, 10, 8B, 45, E4, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlDeregisterUncProvider + 2F 8061D9D2 5 Bytes [3B, 35, 18, A0, 69]
PAGE ntoskrnl.exe!FsRtlDeregisterUncProvider + 35 8061D9D8 67 Bytes [75, 34, A1, 20, A0, 69, 80, ...]
PAGE ntoskrnl.exe!FsRtlDeregisterUncProvider + 79 8061DA1C 29 Bytes [57, 6A, 01, 57, 53, E8, A8, ...]
PAGE ntoskrnl.exe!FsRtlDissectDbcs + 2 8061DA3A 19 Bytes [55, 8B, EC, 8B, 45, 10, 8B, ...]
PAGE ntoskrnl.exe!FsRtlDissectDbcs + 16 8061DA4E 157 Bytes [18, 66, 89, 58, 02, 89, 58, ...]
PAGE ntoskrnl.exe!FsRtlDoesDbcsContainWildCards + B 8061DAEC 104 Bytes [B7, 30, 33, D2, 85, F6, 57, ...]
PAGE ntoskrnl.exe!FsRtlIsDbcsInExpression + 2 8061DB55 149 Bytes [55, 8B, EC, 81, EC, 84, 00, ...]
PAGE ntoskrnl.exe!FsRtlIsDbcsInExpression + 98 8061DBEB 153 Bytes [00, 89, 4D, 8C, 74, 3E, 33, ...]
PAGE ntoskrnl.exe!FsRtlIsDbcsInExpression + 132 8061DC85 4 Bytes [74, 2B, 8B, 3D]
PAGE ntoskrnl.exe!FsRtlIsDbcsInExpression + 137 8061DC8A 34 Bytes [C4, 56, 80, 0F, B6, F2, 66, ...]
PAGE ntoskrnl.exe!FsRtlIsDbcsInExpression + 15A 8061DCAD 45 Bytes [4D, A0, 58, EB, 0B, 66, 0F, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlIsHpfsDbcsLegal + 16 8061DFCA 29 Bytes [00, 38, 5D, 10, 8B, 4D, 0C, ...]
PAGE ntoskrnl.exe!FsRtlIsHpfsDbcsLegal + 34 8061DFE8 5 Bytes [14, 8A, 01, 3C, 2E] {ADC AL, 0x8a; ADD [ESI+EBP], EDI}
PAGE ntoskrnl.exe!FsRtlIsHpfsDbcsLegal + 3A 8061DFEE 26 Bytes [05, 38, 41, 01, 74, 66, 3C, ...]
PAGE ntoskrnl.exe!FsRtlIsHpfsDbcsLegal + 55 8061E009 30 Bytes [FA, 01, 76, 4D, 41, 66, 4A, ...]
PAGE ntoskrnl.exe!FsRtlIsHpfsDbcsLegal + 74 8061E028 98 Bytes [45, 0C, 80, 38, 5C, 74, 39, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlNotifyFullChangeDirectory + 1D 8061E190 97 Bytes [75, 10, FF, 75, 0C, FF, 75, ...]
PAGE ntoskrnl.exe!FsRtlNotifyFullReportChange + 7 8061E1F2 12 Bytes [FF, 75, 28, FF, 75, 24, FF, ...] {PUSH DWORD [EBP+0x28]; PUSH DWORD [EBP+0x24]; PUSH DWORD [EBP+0x20]; PUSH DWORD [EBP+0x1c]}
PAGE ntoskrnl.exe!FsRtlNotifyFullReportChange + 14 8061E1FF 1 Byte [75]
PAGE ntoskrnl.exe!FsRtlNotifyFullReportChange + 14 8061E1FF 37 Bytes [75, 18, FF, 75, 14, FF, 75, ...]
PAGE ntoskrnl.exe!FsRtlNotifyFullReportChange + 3C 8061E227 29 Bytes [8B, FF, 55, 8B, EC, 51, 51, ...]
PAGE ntoskrnl.exe!FsRtlNotifyFullReportChange + 5A 8061E245 240 Bytes [B8, FF, 00, 00, 00, 74, 05, ...]
PAGE ...
PAGE ntoskrnl.exe!IoSetPartitionInformation + 4 8061E51B 22 Bytes [EC, 83, EC, 40, 53, BB, 00, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformation + 1B 8061E532 41 Bytes [89, 55, F8, 73, 03, 89, 5D, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformation + 45 8061E55C 85 Bytes [89, 5D, E0, EB, 03, 89, 75, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformation + 9B 8061E5B2 29 Bytes [C8, 57, 8D, 45, C0, 50, E8, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformation + B9 8061E5D0 13 Bytes CALL 80518DB5 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ...
PAGE ntoskrnl.exe!IoWritePartitionTable + 1C 8061E7A7 42 Bytes [00, 89, 5D, F4, 88, 5D, FE, ...]
PAGE ntoskrnl.exe!IoWritePartitionTable + 47 8061E7D2 3 Bytes CALL 8050D44C \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!IoWritePartitionTable + 4B 8061E7D6 103 Bytes [39, 5D, E0, 74, 12, 53, FF, ...]
PAGE ntoskrnl.exe!IoWritePartitionTable + B3 8061E83E 19 Bytes [23, 75, 03, 88, 45, FF, C6, ...]
PAGE ntoskrnl.exe!IoWritePartitionTable + C7 8061E852 150 Bytes [10, 00, 00, 39, 45, EC, 72, ...]
PAGE ...
PAGE ntoskrnl.exe!IoWritePartitionTableEx + 28 8061F9EE 27 Bytes [06, 2B, C3, 0F, 84, B5, 00, ...]
PAGE ntoskrnl.exe!IoWritePartitionTableEx + 44 8061FA0A 20 Bytes [75, FC, 89, 5D, 08, E8, DB, ...]
PAGE ntoskrnl.exe!IoWritePartitionTableEx + 59 8061FA1F 6 Bytes [75, FC, E8, C9, F9, FF]
PAGE ntoskrnl.exe!IoWritePartitionTableEx + 60 8061FA26 95 Bytes [8B, F8, 3B, FB, 0F, 8C, 87, ...]
PAGE ntoskrnl.exe!IoWritePartitionTableEx + C0 8061FA86 45 Bytes [70, 04, 6A, 01, FF, 73, 34, ...]
PAGE ...
PAGE ntoskrnl.exe!IoVerifyPartitionTable + 27 8061FB07 36 Bytes [F0, 85, F6, 7C, 25, 8B, 45, ...]
PAGE ntoskrnl.exe!IoVerifyPartitionTable + 4C 8061FB2C 89 Bytes [F6, 85, FF, 74, 06, 57, E8, ...]
PAGE ntoskrnl.exe!IoVerifyPartitionTable + A6 8061FB86 31 Bytes [4D, 10, 8D, 04, F6, 57, C1, ...]
PAGE ntoskrnl.exe!IoVerifyPartitionTable + C6 8061FBA6 5 Bytes [51, 20, 89, 50, 20]
PAGE ntoskrnl.exe!IoVerifyPartitionTable + CC 8061FBAC 57 Bytes [51, 24, 6A, 12, 8D, 71, 28, ...]
PAGE ...
PAGE ntoskrnl.exe!IoSetPartitionInformationEx + 2F 8061FD59 21 Bytes [7C, 44, 8B, 4D, FC, 8B, 45, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformationEx + 45 8061FD6F 112 Bytes [74, 19, 49, 74, 07, BE, BB, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformationEx + B6 8061FDE0 35 Bytes [8B, 7D, 18, 8B, 45, 14, C1, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformationEx + DA 8061FE04 41 Bytes [75, 08, FF, 15, 98, 80, 4D, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformationEx + 104 8061FE2E 18 Bytes [FF, 89, 73, 08, 89, 73, 04, ...] {DEC DWORD [ECX+0x73890873]; ADD AL, 0x33; SHR BL, 0x32; MOV EAX, [ECX+0x8]; LEA ECX, [EBP+0x10]; PUSH ECX}
PAGE ...
PAGE ntoskrnl.exe!IoCheckQuotaBufferValidity + D3 80620097 48 Bytes CALL 804DA2A1 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!IoCheckQuotaBufferValidity + 104 806200C8 11 Bytes CALL 80574887 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!IoCheckQuotaBufferValidity + 110 806200D4 10 Bytes [6E, 01, 00, 00, 57, 68, 70, ...]
PAGE ntoskrnl.exe!IoCheckQuotaBufferValidity + 11B 806200DF 21 Bytes CALL 804DA2A2 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!IoCheckQuotaBufferValidity + 131 806200F5 8 Bytes [D0, 50, C7, 45, A4, 18, 00, ...]
PAGE ...
PAGE ntoskrnl.exe!IoEnqueueIrp 806202B8 77 Bytes [8B, FF, 55, 8B, EC, 56, 57, ...]
PAGE ntoskrnl.exe!IoFastQueryNetworkAttributes + B 80620306 21 Bytes [A1, 60, A3, 55, 80, 8B, 55, ...]
PAGE ntoskrnl.exe!IoFastQueryNetworkAttributes + 21 8062031C 24 Bytes [64, FF, FF, FF, 33, C0, 6A, ...]
PAGE ntoskrnl.exe!IoFastQueryNetworkAttributes + 3A 80620335 57 Bytes [33, DB, 43, 89, 85, 24, FF, ...]
PAGE ntoskrnl.exe!IoFastQueryNetworkAttributes + 74 8062036F 17 Bytes [FF, FF, 88, 9D, 4D, FF, FF, ...]
PAGE ntoskrnl.exe!IoFastQueryNetworkAttributes + 86 80620381 53 Bytes [FF, FF, 64, A1, 24, 01, 00, ...]
PAGE ...
PAGE ntoskrnl.exe!IoIsValidNameGraftingBuffer + D 8062040D 283 Bytes [53, 8B, 5D, 0C, 81, 3B, 03, ...]
PAGE ntoskrnl.exe!IoIsValidNameGraftingBuffer + 12A 8062052A 58 Bytes [BE, 9A, 07, 62, 80, 8D, 7D, ...]
PAGE ntoskrnl.exe!IoIsValidNameGraftingBuffer + 166 80620566 21 Bytes [00, 89, 7D, B0, C7, 45, B8, ...]
PAGE ntoskrnl.exe!IoIsValidNameGraftingBuffer + 17C 8062057C 116 Bytes [85, C0, 0F, 8C, 09, 01, 00, ...]
PAGE ntoskrnl.exe!IoIsValidNameGraftingBuffer + 1F1 806205F1 100 Bytes [44, 0F, 85, 8C, 00, 00, 00, ...]
PAGE ...
PAGE ntoskrnl.exe!IoRegisterLastChanceShutdownNotification + 26 80620959 104 Bytes CALL 804DA06A \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!IoSetInformation + 33 806209C2 21 Bytes [89, 7B, 60, C6, 45, 0B, 01, ...]
PAGE ntoskrnl.exe!IoSetInformation + 49 806209D8 40 Bytes [FF, FF, 50, 57, 53, E8, 83, ...]
? spcp.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload B85D48AC 5 Bytes JMP 89FAD4E0
.text aqniud2s.SYS B846C384 1 Byte [20]
.text aqniud2s.SYS B846C384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text aqniud2s.SYS B846C3AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text aqniud2s.SYS B846C3C4 3 Bytes [00, 00, 00]
.text aqniud2s.SYS B846C3C9 1 Byte [00]
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8A1A72D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74FF6D0] spcp.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7503708] spcp.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74DA046] spcp.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74DA142] spcp.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74DA0C4] spcp.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74DA7CE] spcp.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74DA6A4] spcp.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 89FAD5E0
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74E5D7A] spcp.sys
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlInitUnicodeString] 000000A5
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!swprintf] 000000E5
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeSetEvent] 000000F1
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 00000071
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 000000D8
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 00000031
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmFreeMappingAddress] 00000015
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 00000004
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 000000C7
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmUnmapIoSpace] 00000023
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 000000C3
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IofCompleteRequest] 00000018
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 00000096
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IofCallDriver] 00000005
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 0000009A
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 00000007
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoConnectInterrupt] 00000012
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoDetachDevice] 00000080
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeWaitForSingleObject] 000000E2
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInitializeEvent] 000000EB
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeCancelTimer] 00000027
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 000000B2
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlInitAnsiString] 00000075
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 00000009
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoQueueWorkItem] 00000083
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmMapIoSpace] 0000002C
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 0000001A
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoReportDetectedDevice] 0000001B
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoReportResourceForDetection] 0000006E
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 0000005A
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!NlsMbCodePageTag] 000000A0
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!PoRequestPowerIrp] 00000052
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 0000003B
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 000000D6
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!sprintf] 000000B3
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 00000029
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ObfDereferenceObject] 000000E3
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 0000002F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 00000084
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ZwClose] 00000053
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 000000D1
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 00000000
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 000000ED
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 00000020
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoCreateDevice] 000000FC
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 000000B1
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 0000005B
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 0000006A
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ZwOpenKey] 000000CB
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 000000BE
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoStartTimer] 00000039
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInitializeTimer] 0000004A
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoInitializeTimer] 0000004C
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInitializeDpc] 00000058
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInitializeSpinLock] 000000CF
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoInitializeIrp] 000000D0
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ZwCreateKey] 000000EF
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 000000AA
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 000000FB
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ZwSetValueKey] 00000043
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInsertQueueDpc] 0000004D
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 00000033
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoStartPacket] 00000085
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 00000045
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000F9
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoFreeMdl] 00000002
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmUnlockPages] 0000007F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 00000050
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 0000003C
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 0000009F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000A8
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeSynchronizeExecution] 00000051
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoStartNextPacket] 000000A3
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeBugCheckEx] 00000040
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 0000008F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeSetTimer] 00000092
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!_allmul] 0000009D
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmProbeAndLockPages] 00000038
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!_except_handler3] 000000F5
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!PoSetPowerState] 000000BC
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 000000B6
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 000000DA
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlDeleteRegistryValue] 00000021
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!_aulldiv] 00000010
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!strstr] 000000FF
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!_strupr] 000000F3
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeQuerySystemTime] 000000D2
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000CD
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeTickCount] 0000000C
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 00000013
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoDeleteDevice] 000000EC
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 0000005F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAllocateWorkItem] 00000097
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAllocateIrp] 00000044
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAllocateMdl] 00000017
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 000000C4
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000A7
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 0000007E
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 0000003D
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ExFreePoolWithTag] 00000064
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoFreeIrp] 0000005D
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoFreeWorkItem] 00000019
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!InitSafeBootMode] 00000073
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlCompareMemory] 00000060
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!PoCallDriver] 00000081
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!memmove] 0000004F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmHighestUserAddress] 000000DC
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KfAcquireSpinLock] 000000AD
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KeGetCurrentIrql] 000000A2
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KfRaiseIrql] 000000AF
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KfLowerIrql] 0000009C
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!HalGetInterruptVector] 000000A4
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!HalTranslateBusAddress] 00000072
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KfReleaseSpinLock] 000000B7
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!READ_PORT_USHORT] 00000093
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[WMILIB.SYS!WmiSystemControl] 000000F7
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-19 14:58:33
Windows 5.1.2600 Service Pack 3
Running: tr5ohnqq.exe; Driver: C:\DOCUME~1\ADMINI~1.002\LOCALS~1\Temp\aftyifow.sys
---- System - GMER 1.0.15 ----
SSDT spcp.sys ZwEnumerateKey [0xF74F6CA2]
SSDT spcp.sys ZwEnumerateValueKey [0xF74F7030]
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A1341F8
Device \FileSystem\Fastfat \Fat 89DCB500
---- EOF - GMER 1.0.15 ----
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-20 08:52:05
Windows 5.1.2600 Service Pack 3
Running: tr5ohnqq.exe; Driver: C:\DOCUME~1\ADMINI~1.002\LOCALS~1\Temp\aftyifow.sys
---- System - GMER 1.0.15 ----
SSDT spcp.sys ZwCreateKey [0xF74D90E0]
SSDT spcp.sys ZwEnumerateKey [0xF74F6CA2]
SSDT spcp.sys ZwEnumerateValueKey [0xF74F7030]
SSDT spcp.sys ZwOpenKey [0xF74D90C0]
SSDT spcp.sys ZwQueryKey [0xF74F7108]
SSDT spcp.sys ZwQueryValueKey [0xF74F6F88]
SSDT spcp.sys ZwSetValueKey [0xF74F719A]
INT 0x63 ? 89FADF00
INT 0x73 ? 8A136BF8
INT 0x73 ? 8A136BF8
INT 0x73 ? 8A136BF8
INT 0x73 ? 8A136BF8
INT 0x73 ? 89FADF00
INT 0x73 ? 8A136BF8
INT 0x83 ? 8A1A7BF8
INT 0x94 ? 89FADF00
INT 0xB4 ? 89FADF00
---- Kernel code sections - GMER 1.0.15 ----
PAGE ntoskrnl.exe!ZwSetTimerResolution + 15768 80600C00 73 Bytes [04, 8B, 07, 3B, C3, 0F, 84, ...]
PAGE ntoskrnl.exe!ZwSetTimerResolution + 157B2 80600C4A 35 Bytes CALL 804E192E \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!ZwSetTimerResolution + 157D6 80600C6E 11 Bytes [15, 0C, 81, 4D, 80, E9, FD, ...]
PAGE ntoskrnl.exe!ZwSetTimerResolution + 157E3 80600C7B 23 Bytes [3B, F3, 0F, 84, 96, 4A, F7, ...]
PAGE ntoskrnl.exe!ZwSetTimerResolution + 157FB 80600C93 29 Bytes CALL 805511E4 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ...
PAGE ntoskrnl.exe!CcMdlRead + 53 8061BED0 36 Bytes [8D, 45, D0, 50, 8D, 45, CC, ...]
PAGE ntoskrnl.exe!CcMdlRead + 78 8061BEF5 45 Bytes CALL 804F1DA2 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!CcMdlRead + A6 8061BF23 32 Bytes [C7, 05, 28, 30, 55, 80, 78, ...]
PAGE ntoskrnl.exe!CcMdlRead + C7 8061BF44 49 Bytes [00, 00, 8D, 45, E0, 50, 8D, ...]
PAGE ntoskrnl.exe!CcMdlRead + F9 8061BF76 43 Bytes [9C, 13, 4D, A8, 89, 4D, A0, ...]
PAGE ...
PAGE ntoskrnl.exe!CcMdlReadComplete + 28 8061C158 17 Bytes [75, 08, FF, D1, 84, C0, 75, ...]
PAGE ntoskrnl.exe!CcMdlReadComplete + 3A 8061C16A 156 Bytes [CC, CC, CC, CC, CC, CC, 90, ...]
PAGE ntoskrnl.exe!CmUnRegisterCallback + 3C 8061C207 5 Bytes [53, E8, D6, 09, 03]
PAGE ntoskrnl.exe!CmUnRegisterCallback + 42 8061C20D 11 Bytes [84, C0, 74, 46, 83, C8, FF, ...]
PAGE ntoskrnl.exe!CmUnRegisterCallback + 4E 8061C219 29 Bytes [F0, 0F, C1, 01, 8B, 45, FC, ...]
PAGE ntoskrnl.exe!CmUnRegisterCallback + 6C 8061C237 2 Bytes [76, 10] {JBE 0x12}
PAGE ntoskrnl.exe!CmUnRegisterCallback + 6F 8061C23A 3 Bytes CALL 805511E7 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ...
PAGE ntoskrnl.exe!CmRegisterCallback + 2 8061C289 21 Bytes [55, 8B, EC, 51, 53, 56, 57, ...]
PAGE ntoskrnl.exe!CmRegisterCallback + 18 8061C29F 6 Bytes [8B, F0, 33, FF, 3B, F7] {MOV ESI, EAX; XOR EDI, EDI; CMP ESI, EDI}
PAGE ntoskrnl.exe!CmRegisterCallback + 1F 8061C2A6 13 Bytes [84, CB, 00, 00, 00, 53, 6A, ...]
PAGE ntoskrnl.exe!CmRegisterCallback + 2D 8061C2B4 66 Bytes [3B, C7, 89, 46, 10, 74, 19, ...]
PAGE ntoskrnl.exe!CmRegisterCallback + 70 8061C2F7 67 Bytes [40, 04, 89, 00, 8B, 46, 10, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlMdlReadDev + 5 8061C4C2 1 Byte [52]
PAGE ntoskrnl.exe!FsRtlMdlReadDev + 5 8061C4C2 27 Bytes CALL 804E2EA1 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!FsRtlMdlReadDev + 21 8061C4DE 183 Bytes JMP 8061C5CA \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!FsRtlMdlReadDev + D9 8061C596 25 Bytes [1C, C7, 00, 11, 00, 00, C0, ...]
PAGE ntoskrnl.exe!FsRtlMdlReadDev + F3 8061C5B0 20 Bytes [80, D4, 00, 00, 00, 75, 13, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlPrepareMdlWriteDev + 30 8061C76B 22 Bytes [6A, 01, 8B, 5D, 10, 53, 8B, ...]
PAGE ntoskrnl.exe!FsRtlPrepareMdlWriteDev + 47 8061C782 51 Bytes [F6, 46, 2C, 10, 0F, 85, 99, ...]
PAGE ntoskrnl.exe!FsRtlPrepareMdlWriteDev + 7B 8061C7B6 215 Bytes [CB, 33, C0, 03, 0F, 13, 47, ...]
PAGE ntoskrnl.exe!FsRtlPrepareMdlWriteDev + 153 8061C88E 96 Bytes CALL 804DA3A1 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!FsRtlPrepareMdlWriteDev + 1B4 8061C8EF 37 Bytes CALL 804E842C \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ...
PAGE ntoskrnl.exe!FsRtlPrepareMdlWrite + 48 8061CB83 44 Bytes [40, 08, 8B, 40, 28, 85, C0, ...]
PAGE ntoskrnl.exe!FsRtlPrepareMdlWrite + 75 8061CBB0 37 Bytes [FF, 5F, 5E, 5D, C2, 18, 00, ...]
PAGE ntoskrnl.exe!FsRtlMdlWriteCompleteDev + 13 8061CBD6 74 Bytes [75, 10, FF, 75, 0C, 50, E8, ...]
PAGE ntoskrnl.exe!FsRtlIncrementCcFastReadNotPossible + C 8061CC21 40 Bytes [C3, CC, CC, CC, CC, CC, CC, ...]
PAGE ntoskrnl.exe!FsRtlCopyRead + 1A 8061CC4B 100 Bytes [8B, 4D, 10, 8D, 84, 08, FF, ...]
PAGE ntoskrnl.exe!FsRtlCopyRead + 7F 8061CCB0 38 Bytes [00, FF, 88, D4, 00, 00, 00, ...]
PAGE ntoskrnl.exe!FsRtlCopyRead + A6 8061CCD7 14 Bytes [83, 7E, 18, 00, 0F, 84, 00, ...]
PAGE ntoskrnl.exe!FsRtlCopyRead + B5 8061CCE6 32 Bytes [0F, 84, F5, 01, 00, 00, 3C, ...]
PAGE ntoskrnl.exe!FsRtlCopyRead + D6 8061CD07 31 Bytes [75, 18, FF, 75, 14, FF, 75, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlCopyWrite + 18 8061CF4F 5 Bytes [8B, 5D, 0C, 83, 3B]
PAGE ntoskrnl.exe!FsRtlCopyWrite + 1E 8061CF55 19 Bytes [75, 0A, 83, 7B, 04, FF, C6, ...] {JNZ 0xc; CMP DWORD [EBX+0x4], -0x1; MOV BYTE [EBP-0x1a], 0x1; JZ 0x10; MOV BYTE [EBP-0x1a], 0x0; MOV EDI, [EBP+0x8]}
PAGE ntoskrnl.exe!FsRtlCopyWrite + 32 8061CF69 26 Bytes [77, 0C, 89, 75, CC, 6A, 00, ...]
PAGE ntoskrnl.exe!FsRtlCopyWrite + 4D 8061CF84 48 Bytes [F6, 47, 2C, 10, 0F, 85, B1, ...]
PAGE ntoskrnl.exe!FsRtlCopyWrite + 7E 8061CFB5 2 Bytes [88, D4] {MOV AH, DL}
PAGE ...
PAGE ntoskrnl.exe!FsRtlMdlWriteComplete + 8 8061D663 69 Bytes CALL 804E842D \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!FsRtlMdlWriteComplete + 4E 8061D6A9 27 Bytes [78, 4C, 00, 74, 04, 32, C0, ...]
PAGE ntoskrnl.exe!FsRtlMdlWriteComplete + 6A 8061D6C5 42 Bytes [90, 90, 90, CC, CC, CC, CC, ...]
PAGE ntoskrnl.exe!FsRtlInitializeMcb + 11 8061D6F0 20 Bytes [90, 90, 90, 90, 8B, FF, 55, ...]
PAGE ntoskrnl.exe!FsRtlUninitializeMcb + 14 8061D708 114 Bytes [90, A1, 0C, A0, 69, 80, 83, ...]
PAGE ntoskrnl.exe!FsRtlSyncVolumes + 30 8061D77B 4 Bytes [75, 08, E8, 27]
PAGE ntoskrnl.exe!FsRtlSyncVolumes + 35 8061D780 1 Byte [EC]
PAGE ntoskrnl.exe!FsRtlSyncVolumes + 35 8061D780 86 Bytes [EC, FF, 5D, C2, 08, 00, CC, ...]
PAGE ntoskrnl.exe!FsRtlSyncVolumes + 8C 8061D7D7 100 Bytes [8B, C6, EB, 7E, 8B, 4E, 1C, ...]
PAGE ntoskrnl.exe!FsRtlSyncVolumes + F1 8061D83C 36 Bytes [C0, 8B, 4D, 10, 8B, 45, E4, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlDeregisterUncProvider + 2F 8061D9D2 5 Bytes [3B, 35, 18, A0, 69]
PAGE ntoskrnl.exe!FsRtlDeregisterUncProvider + 35 8061D9D8 67 Bytes [75, 34, A1, 20, A0, 69, 80, ...]
PAGE ntoskrnl.exe!FsRtlDeregisterUncProvider + 79 8061DA1C 29 Bytes [57, 6A, 01, 57, 53, E8, A8, ...]
PAGE ntoskrnl.exe!FsRtlDissectDbcs + 2 8061DA3A 19 Bytes [55, 8B, EC, 8B, 45, 10, 8B, ...]
PAGE ntoskrnl.exe!FsRtlDissectDbcs + 16 8061DA4E 157 Bytes [18, 66, 89, 58, 02, 89, 58, ...]
PAGE ntoskrnl.exe!FsRtlDoesDbcsContainWildCards + B 8061DAEC 104 Bytes [B7, 30, 33, D2, 85, F6, 57, ...]
PAGE ntoskrnl.exe!FsRtlIsDbcsInExpression + 2 8061DB55 149 Bytes [55, 8B, EC, 81, EC, 84, 00, ...]
PAGE ntoskrnl.exe!FsRtlIsDbcsInExpression + 98 8061DBEB 153 Bytes [00, 89, 4D, 8C, 74, 3E, 33, ...]
PAGE ntoskrnl.exe!FsRtlIsDbcsInExpression + 132 8061DC85 4 Bytes [74, 2B, 8B, 3D]
PAGE ntoskrnl.exe!FsRtlIsDbcsInExpression + 137 8061DC8A 34 Bytes [C4, 56, 80, 0F, B6, F2, 66, ...]
PAGE ntoskrnl.exe!FsRtlIsDbcsInExpression + 15A 8061DCAD 45 Bytes [4D, A0, 58, EB, 0B, 66, 0F, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlIsHpfsDbcsLegal + 16 8061DFCA 29 Bytes [00, 38, 5D, 10, 8B, 4D, 0C, ...]
PAGE ntoskrnl.exe!FsRtlIsHpfsDbcsLegal + 34 8061DFE8 5 Bytes [14, 8A, 01, 3C, 2E] {ADC AL, 0x8a; ADD [ESI+EBP], EDI}
PAGE ntoskrnl.exe!FsRtlIsHpfsDbcsLegal + 3A 8061DFEE 26 Bytes [05, 38, 41, 01, 74, 66, 3C, ...]
PAGE ntoskrnl.exe!FsRtlIsHpfsDbcsLegal + 55 8061E009 30 Bytes [FA, 01, 76, 4D, 41, 66, 4A, ...]
PAGE ntoskrnl.exe!FsRtlIsHpfsDbcsLegal + 74 8061E028 98 Bytes [45, 0C, 80, 38, 5C, 74, 39, ...]
PAGE ...
PAGE ntoskrnl.exe!FsRtlNotifyFullChangeDirectory + 1D 8061E190 97 Bytes [75, 10, FF, 75, 0C, FF, 75, ...]
PAGE ntoskrnl.exe!FsRtlNotifyFullReportChange + 7 8061E1F2 12 Bytes [FF, 75, 28, FF, 75, 24, FF, ...] {PUSH DWORD [EBP+0x28]; PUSH DWORD [EBP+0x24]; PUSH DWORD [EBP+0x20]; PUSH DWORD [EBP+0x1c]}
PAGE ntoskrnl.exe!FsRtlNotifyFullReportChange + 14 8061E1FF 1 Byte [75]
PAGE ntoskrnl.exe!FsRtlNotifyFullReportChange + 14 8061E1FF 37 Bytes [75, 18, FF, 75, 14, FF, 75, ...]
PAGE ntoskrnl.exe!FsRtlNotifyFullReportChange + 3C 8061E227 29 Bytes [8B, FF, 55, 8B, EC, 51, 51, ...]
PAGE ntoskrnl.exe!FsRtlNotifyFullReportChange + 5A 8061E245 240 Bytes [B8, FF, 00, 00, 00, 74, 05, ...]
PAGE ...
PAGE ntoskrnl.exe!IoSetPartitionInformation + 4 8061E51B 22 Bytes [EC, 83, EC, 40, 53, BB, 00, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformation + 1B 8061E532 41 Bytes [89, 55, F8, 73, 03, 89, 5D, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformation + 45 8061E55C 85 Bytes [89, 5D, E0, EB, 03, 89, 75, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformation + 9B 8061E5B2 29 Bytes [C8, 57, 8D, 45, C0, 50, E8, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformation + B9 8061E5D0 13 Bytes CALL 80518DB5 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ...
PAGE ntoskrnl.exe!IoWritePartitionTable + 1C 8061E7A7 42 Bytes [00, 89, 5D, F4, 88, 5D, FE, ...]
PAGE ntoskrnl.exe!IoWritePartitionTable + 47 8061E7D2 3 Bytes CALL 8050D44C \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!IoWritePartitionTable + 4B 8061E7D6 103 Bytes [39, 5D, E0, 74, 12, 53, FF, ...]
PAGE ntoskrnl.exe!IoWritePartitionTable + B3 8061E83E 19 Bytes [23, 75, 03, 88, 45, FF, C6, ...]
PAGE ntoskrnl.exe!IoWritePartitionTable + C7 8061E852 150 Bytes [10, 00, 00, 39, 45, EC, 72, ...]
PAGE ...
PAGE ntoskrnl.exe!IoWritePartitionTableEx + 28 8061F9EE 27 Bytes [06, 2B, C3, 0F, 84, B5, 00, ...]
PAGE ntoskrnl.exe!IoWritePartitionTableEx + 44 8061FA0A 20 Bytes [75, FC, 89, 5D, 08, E8, DB, ...]
PAGE ntoskrnl.exe!IoWritePartitionTableEx + 59 8061FA1F 6 Bytes [75, FC, E8, C9, F9, FF]
PAGE ntoskrnl.exe!IoWritePartitionTableEx + 60 8061FA26 95 Bytes [8B, F8, 3B, FB, 0F, 8C, 87, ...]
PAGE ntoskrnl.exe!IoWritePartitionTableEx + C0 8061FA86 45 Bytes [70, 04, 6A, 01, FF, 73, 34, ...]
PAGE ...
PAGE ntoskrnl.exe!IoVerifyPartitionTable + 27 8061FB07 36 Bytes [F0, 85, F6, 7C, 25, 8B, 45, ...]
PAGE ntoskrnl.exe!IoVerifyPartitionTable + 4C 8061FB2C 89 Bytes [F6, 85, FF, 74, 06, 57, E8, ...]
PAGE ntoskrnl.exe!IoVerifyPartitionTable + A6 8061FB86 31 Bytes [4D, 10, 8D, 04, F6, 57, C1, ...]
PAGE ntoskrnl.exe!IoVerifyPartitionTable + C6 8061FBA6 5 Bytes [51, 20, 89, 50, 20]
PAGE ntoskrnl.exe!IoVerifyPartitionTable + CC 8061FBAC 57 Bytes [51, 24, 6A, 12, 8D, 71, 28, ...]
PAGE ...
PAGE ntoskrnl.exe!IoSetPartitionInformationEx + 2F 8061FD59 21 Bytes [7C, 44, 8B, 4D, FC, 8B, 45, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformationEx + 45 8061FD6F 112 Bytes [74, 19, 49, 74, 07, BE, BB, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformationEx + B6 8061FDE0 35 Bytes [8B, 7D, 18, 8B, 45, 14, C1, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformationEx + DA 8061FE04 41 Bytes [75, 08, FF, 15, 98, 80, 4D, ...]
PAGE ntoskrnl.exe!IoSetPartitionInformationEx + 104 8061FE2E 18 Bytes [FF, 89, 73, 08, 89, 73, 04, ...] {DEC DWORD [ECX+0x73890873]; ADD AL, 0x33; SHR BL, 0x32; MOV EAX, [ECX+0x8]; LEA ECX, [EBP+0x10]; PUSH ECX}
PAGE ...
PAGE ntoskrnl.exe!IoCheckQuotaBufferValidity + D3 80620097 48 Bytes CALL 804DA2A1 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!IoCheckQuotaBufferValidity + 104 806200C8 11 Bytes CALL 80574887 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!IoCheckQuotaBufferValidity + 110 806200D4 10 Bytes [6E, 01, 00, 00, 57, 68, 70, ...]
PAGE ntoskrnl.exe!IoCheckQuotaBufferValidity + 11B 806200DF 21 Bytes CALL 804DA2A2 \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!IoCheckQuotaBufferValidity + 131 806200F5 8 Bytes [D0, 50, C7, 45, A4, 18, 00, ...]
PAGE ...
PAGE ntoskrnl.exe!IoEnqueueIrp 806202B8 77 Bytes [8B, FF, 55, 8B, EC, 56, 57, ...]
PAGE ntoskrnl.exe!IoFastQueryNetworkAttributes + B 80620306 21 Bytes [A1, 60, A3, 55, 80, 8B, 55, ...]
PAGE ntoskrnl.exe!IoFastQueryNetworkAttributes + 21 8062031C 24 Bytes [64, FF, FF, FF, 33, C0, 6A, ...]
PAGE ntoskrnl.exe!IoFastQueryNetworkAttributes + 3A 80620335 57 Bytes [33, DB, 43, 89, 85, 24, FF, ...]
PAGE ntoskrnl.exe!IoFastQueryNetworkAttributes + 74 8062036F 17 Bytes [FF, FF, 88, 9D, 4D, FF, FF, ...]
PAGE ntoskrnl.exe!IoFastQueryNetworkAttributes + 86 80620381 53 Bytes [FF, FF, 64, A1, 24, 01, 00, ...]
PAGE ...
PAGE ntoskrnl.exe!IoIsValidNameGraftingBuffer + D 8062040D 283 Bytes [53, 8B, 5D, 0C, 81, 3B, 03, ...]
PAGE ntoskrnl.exe!IoIsValidNameGraftingBuffer + 12A 8062052A 58 Bytes [BE, 9A, 07, 62, 80, 8D, 7D, ...]
PAGE ntoskrnl.exe!IoIsValidNameGraftingBuffer + 166 80620566 21 Bytes [00, 89, 7D, B0, C7, 45, B8, ...]
PAGE ntoskrnl.exe!IoIsValidNameGraftingBuffer + 17C 8062057C 116 Bytes [85, C0, 0F, 8C, 09, 01, 00, ...]
PAGE ntoskrnl.exe!IoIsValidNameGraftingBuffer + 1F1 806205F1 100 Bytes [44, 0F, 85, 8C, 00, 00, 00, ...]
PAGE ...
PAGE ntoskrnl.exe!IoRegisterLastChanceShutdownNotification + 26 80620959 104 Bytes CALL 804DA06A \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
PAGE ntoskrnl.exe!IoSetInformation + 33 806209C2 21 Bytes [89, 7B, 60, C6, 45, 0B, 01, ...]
PAGE ntoskrnl.exe!IoSetInformation + 49 806209D8 40 Bytes [FF, FF, 50, 57, 53, E8, 83, ...]
? spcp.sys Systém nemůže nalézt uvedený soubor. !
.text USBPORT.SYS!DllUnload B85D48AC 5 Bytes JMP 89FAD4E0
.text aqniud2s.SYS B846C384 1 Byte [20]
.text aqniud2s.SYS B846C384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text aqniud2s.SYS B846C3AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text aqniud2s.SYS B846C3C4 3 Bytes [00, 00, 00]
.text aqniud2s.SYS B846C3C9 1 Byte [00]
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8A1A72D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74FF6D0] spcp.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7503708] spcp.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74DA046] spcp.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74DA142] spcp.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74DA0C4] spcp.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74DA7CE] spcp.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74DA6A4] spcp.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 89FAD5E0
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74E5D7A] spcp.sys
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlInitUnicodeString] 000000A5
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!swprintf] 000000E5
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeSetEvent] 000000F1
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 00000071
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 000000D8
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 00000031
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmFreeMappingAddress] 00000015
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 00000004
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 000000C7
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmUnmapIoSpace] 00000023
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 000000C3
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IofCompleteRequest] 00000018
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 00000096
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IofCallDriver] 00000005
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 0000009A
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 00000007
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoConnectInterrupt] 00000012
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoDetachDevice] 00000080
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeWaitForSingleObject] 000000E2
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInitializeEvent] 000000EB
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeCancelTimer] 00000027
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 000000B2
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlInitAnsiString] 00000075
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 00000009
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoQueueWorkItem] 00000083
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmMapIoSpace] 0000002C
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 0000001A
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoReportDetectedDevice] 0000001B
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoReportResourceForDetection] 0000006E
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 0000005A
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!NlsMbCodePageTag] 000000A0
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!PoRequestPowerIrp] 00000052
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 0000003B
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 000000D6
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!sprintf] 000000B3
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 00000029
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ObfDereferenceObject] 000000E3
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 0000002F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 00000084
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ZwClose] 00000053
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 000000D1
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 00000000
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 000000ED
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 00000020
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoCreateDevice] 000000FC
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 000000B1
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 0000005B
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 0000006A
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ZwOpenKey] 000000CB
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 000000BE
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoStartTimer] 00000039
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInitializeTimer] 0000004A
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoInitializeTimer] 0000004C
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInitializeDpc] 00000058
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInitializeSpinLock] 000000CF
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoInitializeIrp] 000000D0
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ZwCreateKey] 000000EF
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 000000AA
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 000000FB
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ZwSetValueKey] 00000043
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeInsertQueueDpc] 0000004D
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 00000033
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoStartPacket] 00000085
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 00000045
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000F9
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoFreeMdl] 00000002
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmUnlockPages] 0000007F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 00000050
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 0000003C
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 0000009F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000A8
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeSynchronizeExecution] 00000051
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoStartNextPacket] 000000A3
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeBugCheckEx] 00000040
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 0000008F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeSetTimer] 00000092
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!_allmul] 0000009D
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmProbeAndLockPages] 00000038
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!_except_handler3] 000000F5
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!PoSetPowerState] 000000BC
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 000000B6
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 000000DA
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlDeleteRegistryValue] 00000021
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!_aulldiv] 00000010
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!strstr] 000000FF
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!_strupr] 000000F3
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeQuerySystemTime] 000000D2
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000CD
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!KeTickCount] 0000000C
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 00000013
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoDeleteDevice] 000000EC
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 0000005F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAllocateWorkItem] 00000097
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAllocateIrp] 00000044
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoAllocateMdl] 00000017
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 000000C4
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000A7
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 0000007E
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 0000003D
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!ExFreePoolWithTag] 00000064
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoFreeIrp] 0000005D
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!IoFreeWorkItem] 00000019
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!InitSafeBootMode] 00000073
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!RtlCompareMemory] 00000060
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!PoCallDriver] 00000081
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!memmove] 0000004F
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[ntoskrnl.exe!MmHighestUserAddress] 000000DC
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KfAcquireSpinLock] 000000AD
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KeGetCurrentIrql] 000000A2
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KfRaiseIrql] 000000AF
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KfLowerIrql] 0000009C
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!HalGetInterruptVector] 000000A4
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!HalTranslateBusAddress] 00000072
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!KfReleaseSpinLock] 000000B7
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!READ_PORT_USHORT] 00000093
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[WMILIB.SYS!WmiSystemControl] 000000F7
IAT \SystemRoot\System32\Drivers\aqniud2s.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC