AVPtool konečně dokončil sken, ale nic nového nepřinesl, log vypadá takto:
Autoscan: completed 2 hours ago (events: 2, objects: 232885, time: 15:46:30)
5.1.2010 0:31:42 Task started
5.1.2010 16:18:17 Task completed
Jsou to important events. Nepodařilo se mu proskenovat jenom dva soubory:
C:/hyberfil.sys (má 766 MB)
C:/pagefyle.sys (má 1,3 GB)
CPU vytěžují z cca 99% ty nečinné procesy systému (přes Ctrt+Alt+Delete a Procesy, o jiném způsobu zjišťování zatížení nevím)
U toho Rootkitu jsem hledal jako u ostatních textový soubor s výstupem někde po okolí, ale přitom jsem to posledně neuložil

posílám aktuální (kromě files)
Všiml jsem si, že se mi na disku D objevily složky Recycler a skryté found.000 (vní složka dir0000.chk a v ní mp3ky vytažené z nějaké hluboko pohbřené složky) a neotevřitelná System volume information. Nemá to s tím něco společného?
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Time: 2010/01/05 18:47
Program Version: Version 1.3.0.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAA1E8000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xEB8DA000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PCI_NTPNP2512
Image Path: \Driver\PCI_NTPNP2512
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA7035000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 017 Function Name: NtAllocateVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf3682b30
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa7ed6b8
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa7ed574
#: 053 Function Name: NtCreateThread
Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf36826f0
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa7eda52
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa7ed14c
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf733da92
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf733de20
#: 108 Function Name: NtMapViewOfSection
Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf3682470
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa7ed64e
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa7ed08c
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa7ed0f0
#: 137 Function Name: NtProtectVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf3682c50
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf733def8
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa7ed76e
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa7ed72e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa7ed8ae
#: 249 Function Name: NtShutdownSystem
Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf3682990
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf36828d0
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xf3682d60
Stealth Objects
-------------------
Object: Hidden Module [Name: System.ServiceProcess.dll]
Process: WDSmartWareBackgroundService.exe (PID: 1424) Address: 0x00a00000 Size: 126976
Object: Hidden Module [Name: MemeoRemoteCore.dll]
Process: WDSmartWareBackgroundService.exe (PID: 1424) Address: 0x00a60000 Size: 36864
Object: Hidden Module [Name: System.Runtime.Remoting.dll]
Process: WDSmartWareBackgroundService.exe (PID: 1424) Address: 0x00db0000 Size: 307200
Object: Hidden Module [Name: Tanagra.DataClad.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x04630000 Size: 1077248
Object: Hidden Module [Name: Memeo.API.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x044f0000 Size: 69632
Object: Hidden Module [Name: Tanagra.Utility.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x04210000 Size: 913408
Object: Hidden Module [Name: Tanagra.DataClad.DataAccess.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x04440000 Size: 299008
Object: Hidden Module [Name: System.Management.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x04990000 Size: 380928
Object: Hidden Module [Name: XMLSettings.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x04880000 Size: 36864
Object: Hidden Module [Name: System.Data.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x049f0000 Size: 2908160
Object: Hidden Module [Name: System.Runtime.Remoting.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x04fd0000 Size: 307200
Object: Hidden Module [Name: System.ServiceProcess.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x05020000 Size: 126976
Object: Hidden Module [Name: Tanagra.Interop.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x05070000 Size: 61440
Object: Hidden Module [Name: SQLite.NET.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x05940000 Size: 77824
Object: Hidden Module [Name: Tanagra.BMU.dll]
Process: WDSmartWare.exe (PID: 2568) Address: 0x05640000 Size: 1413120
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x839d31e8 Size: 463
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x8338a980 Size: 162
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x839d41e8 Size: 463
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x839d41e8 Size: 463
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x839d41e8 Size: 463
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x839d41e8 Size: 463
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x839d41e8 Size: 463
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x839d41e8 Size: 463
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x839d41e8 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x83710980 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x839671e8 Size: 463
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CREATE]
Process: System Address: 0x83492980 Size: 463
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CLOSE]
Process: System Address: 0x83492980 Size: 463
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_READ]
Process: System Address: 0x83492980 Size: 463
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_WRITE]
Process: System Address: 0x83492980 Size: 463
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x83492980 Size: 463
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x83492980 Size: 463
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_POWER]
Process: System Address: 0x83492980 Size: 463
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x83492980 Size: 463
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_PNP]
Process: System Address: 0x83492980 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE]
Process: System Address: 0x8371d5c8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE]
Process: System Address: 0x8371d5c8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8371d5c8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8371d5c8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER]
Process: System Address: 0x8371d5c8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8371d5c8 Size: 463
Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP]
Process: System Address: 0x8371d5c8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x839d51e8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x836041e8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x836041e8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x836041e8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x836041e8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x836041e8 Size: 463
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x836041e8 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x837111e8 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x837111e8 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x837111e8 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x837111e8 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x837111e8 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x837111e8 Size: 463
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x837111e8 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x8357d980 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_CREATE]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_CLOSE]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_READ]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_SHUTDOWN]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_CLEANUP]
Process: System Address: 0x833a0678 Size: 463
Object: Hidden Code [Driver: CdfsЅక浗灩, IRP_MJ_PNP]
Process: System Address: 0x833a0678 Size: 463
Hidden Services
-------------------
Service Name: control
Image Path: C:\WINDOWS\system32\drivers\control.sys
Service Name: ControlSet001
Image Path: C:\WINDOWS\system32\drivers\ControlSet001.sys
Service Name: ControlSet003
Image Path: C:\WINDOWS\system32\drivers\ControlSet003.sys
Service Name: LastKnownGoodRecovery
Image Path: C:\WINDOWS\system32\drivers\LastKnownGoodRecovery.sys
Service Name: MountedDevices
Image Path: C:\WINDOWS\system32\drivers\MountedDevices.sys
Service Name: Select
Image Path: C:\WINDOWS\system32\drivers\Select.sys
==EOF==