Code:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/07/18 22:47
Program Version: Version 1.3.2.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
Address: 0x9ABC4000 Size: 815104 File Visible: No Signed: -
Status: -
Name: PCI_PNP0260
Image Path: \Driver\PCI_PNP0260
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x9A1F4000 Size: 49152 File Visible: No Signed: -
Status: -
Name: spja.sys
Image Path: spja.sys
Address: 0xB9EA7000 Size: 1048576 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: c:\dokumente und einstellungen\u9200\lokale einstellungen\temp\etilqs_bmf7xjy5nanwve6hys8z
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\dokumente und einstellungen\u9200\lokale einstellungen\temp\etilqs_v3ahx9aeozy42zwantpp
Status: Allocation size mismatch (API: 32768, Raw: 0)
Path: c:\dokumente und einstellungen\u9200\lokale einstellungen\temp\etilqs_vpf1mrgbalmsga437ejq
Status: Allocation size mismatch (API: 4096, Raw: 0)
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0x9fbea49e
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0x9fbea494
#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0x9fbea4a3
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0x9fbea4ad
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spja.sys" at address 0xb9ec6ca2
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spja.sys" at address 0xb9ec7030
#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0x9fbea4b2
#: 119 Function Name: NtOpenKey
Status: Hooked by "TfSysMon.sys" at address 0xba0fccee
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0x9fbea480
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0x9fbea485
#: 160 Function Name: NtQueryKey
Status: Hooked by "spja.sys" at address 0xb9ec7108
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spja.sys" at address 0xb9ec6f88
#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0x9fbea4bc
#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0x9fbea4b7
#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0x9fbea4a8
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0x9fbea48f
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8a6c01f8 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x892dd500 Address: 121
Object: Hidden Code [Driver: a0tzqjecЅ浍浓Ёం䵃䥖ƈﰡЂఉ瑎捦, IRP_MJ_CREATE]
Process: System Address: 0x89a151f8 Address: 121
Object: Hidden Code [Driver: a0tzqjecЅ浍浓Ёం䵃䥖ƈﰡЂఉ瑎捦, IRP_MJ_CLOSE]
Process: System Address: 0x89a151f8 Address: 121
Object: Hidden Code [Driver: a0tzqjecЅ浍浓Ёం䵃䥖ƈﰡЂఉ瑎捦, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89a151f8 Address: 121
Object: Hidden Code [Driver: a0tzqjecЅ浍浓Ёం䵃䥖ƈﰡЂఉ瑎捦, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89a151f8 Address: 121
Object: Hidden Code [Driver: a0tzqjecЅ浍浓Ёం䵃䥖ƈﰡЂఉ瑎捦, IRP_MJ_POWER]
Process: System Address: 0x89a151f8 Address: 121
Object: Hidden Code [Driver: a0tzqjecЅ浍浓Ёం䵃䥖ƈﰡЂఉ瑎捦, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89a151f8 Address: 121
Object: Hidden Code [Driver: a0tzqjecЅ浍浓Ёం䵃䥖ƈﰡЂఉ瑎捦, IRP_MJ_PNP]
Process: System Address: 0x89a151f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x89a6d1f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x8a6c21f8 Address: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CREATE]
Process: System Address: 0x894601f8 Address: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CLOSE]
Process: System Address: 0x894601f8 Address: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_READ]
Process: System Address: 0x894601f8 Address: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_WRITE]
Process: System Address: 0x894601f8 Address: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x894601f8 Address: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x894601f8 Address: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_POWER]
Process: System Address: 0x894601f8 Address: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x894601f8 Address: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_PNP]
Process: System Address: 0x894601f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x89b0d1f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x89b0d1f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b0d1f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89b0d1f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x89b0d1f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89b0d1f8 Address: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x89b0d1f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8a6531f8 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x894821f8 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x894821f8 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x894821f8 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x894821f8 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x894821f8 Address: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x894821f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x89af61f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x89af61f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89af61f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89af61f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x89af61f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89af61f8 Address: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x89af61f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x894621f8 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_CREATE]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_CLOSE]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_READ]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_SHUTDOWN]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_CLEANUP]
Process: System Address: 0x892df500 Address: 121
Object: Hidden Code [Driver: CdfsЅ敓摓Ёఅ瑎獆錨褐済, IRP_MJ_PNP]
Process: System Address: 0x892df500 Address: 121
==EOF==