Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- PID 0 Parent PID 0 [System Process]
- PID 4 Parent PID 0 System
- PID 264 Parent PID 4 kind {Session manager} C:\Windows\System32\smss.exe
- PID 360 Parent PID 352 kind {Client Server Runtime Process} C:\Windows\System32\csrss.exe
- PID 412 Parent PID 352 kind {Windows Start-Up Application} C:\Windows\System32\wininit.exe
- PID 424 Parent PID 404 kind {Client Server Runtime Process} C:\Windows\System32\csrss.exe
- PID 472 Parent PID 404 kind {WinLogon} C:\Windows\System32\winlogon.exe
- PID 500 Parent PID 412 kind {Services.exe} C:\Windows\System32\services.exe
- PID 508 Parent PID 412 kind {lsass} C:\Windows\System32\lsass.exe
- PID 516 Parent PID 412 kind {Local Session Manager Service} C:\Windows\System32\lsm.exe
- PID 636 Parent PID 500 kind {DCom Server} C:\Windows\System32\svchost.exe
- PID 700 Parent PID 500 kind {RPC Service} C:\Windows\System32\svchost.exe
- PID 748 Parent PID 500 kind {DHCP Client} C:\Windows\System32\svchost.exe
- PID 872 Parent PID 500 kind {Wired AutoConfig Service} C:\Windows\System32\svchost.exe
- PID 912 Parent PID 500 kind {Extensible Authentication Protocol Service} C:\Windows\System32\svchost.exe
- PID 968 Parent PID 748 audiodg.exe
- PID 1044 Parent PID 500 kind {WebClient} C:\Windows\System32\svchost.exe
- PID 1124 Parent PID 500 kind {DNS Client} C:\Windows\System32\svchost.exe
- PID 1300 Parent PID 500 kind {Print Spooler} C:\Windows\System32\spoolsv.exe
- PID 1348 Parent PID 500 kind {Host Process for Windows Tasks} C:\Windows\System32\taskhost.exe
- PID 1356 Parent PID 500 kind {Windows firewall} C:\Windows\System32\svchost.exe
- PID 1576 Parent PID 500 kind {VMWare service} C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
- PID 1668 Parent PID 500 service {VMUpgradeHelper} C:\Program Files\VMware\VMware Tools\VMUpgradeHelper.exe
- PID 1804 Parent PID 500 kind {Microsoft Software Protection Platform Service} C:\Windows\System32\sppsvc.exe
- PID 364 Parent PID 636 kind {wmiprvse} C:\Windows\System32\wbem\WmiPrvSE.exe
- PID 1188 Parent PID 872 kind {Desktop Window Manager} C:\Windows\System32\dwm.exe
- PID 1152 Parent PID 1112 kind {Explorer} C:\Windows\explorer.exe
- PID 2016 Parent PID 1152 C:\Program Files\VMware\VMware Tools\VMwareTray.exe
- PID 1228 Parent PID 1152 C:\Program Files\VMware\VMware Tools\VMwareUser.exe
- PID 324 Parent PID 500 kind {Windows Search Indexer} C:\Windows\System32\SearchIndexer.exe
- PID 1384 Parent PID 324 kind {Search Protocol Host} C:\Windows\System32\SearchProtocolHost.exe
- PID 1560 Parent PID 324 kind {Search Filter Host} C:\Windows\System32\SearchFilterHost.exe
- PID 2436 Parent PID 1152 kind {Cmd.exe} C:\Windows\System32\cmd.exe
- PID 2444 Parent PID 424 kind {Console Window Host} C:\Windows\System32\conhost.exe
- PID 2544 Parent PID 2436 C:\Users\Admin\Desktop\wincheck.exe
- MyWindowsChecker: len 13, kernel name ntkrnlpa.exe
- Major 6 Minor 1 BuildNumber 7600 PlatformId 2 ServicePackMajor 0 ServicePackMinor 0 SuiteMask 256 ProductType 1 CSDVersion
- ProductType: 1
- HighestUserAddress: 7FFEFFFF
- UserProbeAddress: 7FFF0000
- SystemRangeStart: 80000000
- NtMajorVersion: 6
- NtMinorVersion: 1
- BuildNumber: 7600
- GlobalFlag: 0
- Processors: 1
- MmVerifierFlags 0
- MmSystemSize 2 Large
- DebuggerEnabled 0
- DebuggerNotPresent 1
- SafeBootMode 0
- NXSupportPolicy 2
- MmAvailablePages: 0002BD6A
- MmTotalCommittedPages: 00014C98
- MmTotalCommitLimit: 0007FF7E
- MmPeakCommitment: 000171AB
- CR0 80010031 PE ET NE WP PG
- CR4 000006F9 VME DE PSE PAE MCE PGE OSFXSR OSXMMEXCPT
- cpuid 0: 10677
- cpuid 1: 10800
- cpuid 2: 80082201 SSE3 SSSE3 CMPXCHG16B SSE4.1
- cpuid 3: FEBFBFF FPU VME DE PSE TSC MSR PAE MCE CX8 APIC SEP MTRR PGE MCA CMOV PAT PSE-36 CLFSH DS ACPI MMX FXSR SSE SSE2 SS
- WindowsType: Multiprocessor Free
- KDDB:
- ETHREAD.StartAddress 218
- PsLoadedModuleList: 82983810
- PsActiveProcessHead: 8297BE98
- PspCidTable: 8297BEB4
- MmLoadedUserImageList: 82983DF8
- KiProcessorBlock: 829A38C0 (1688C0)
- KernelVerifier: 0
- KeBugCheckCallbackList: 8299EB20 (163B20)
- MmNonPagedPoolStart: 8B501000
- MmNonPagedPoolEnd: 00000000
- MmPagedPoolStart: 00000000
- MmPagedPoolEnd: 00000000
- MmPageSize: 4096
- KeNumberNodes: 1
- KeLargestCacheLine: 40
- MmProductType: 0
- Decode system scheme - rotr sub
- Decode scheme - rotr sub
- Driver RPHook loaded from C:\Users\Admin\AppData\Local\Temp\drv2
- 8283B000:410000 flags 8004000 LoadCount 107 \SystemRoot\system32\ntkrnlpa.exe
- 82804000:37000 flags 8004000 LoadCount 86 \SystemRoot\system32\halmacpi.dll
- 80BA9000:8000 flags 8004000 LoadCount 3 \SystemRoot\system32\kdcom.dll
- 82E17000:78000 flags 9104000 LoadCount 1 \SystemRoot\system32\mcupdate_GenuineIntel.dll
- 82E8F000:11000 flags D104000 LoadCount 3 \SystemRoot\system32\PSHED.dll
- 82EA0000:8000 flags D104000 LoadCount 1 \SystemRoot\system32\BOOTVID.dll
- 82EA8000:42000 flags 9104000 LoadCount 3 \SystemRoot\system32\CLFS.SYS
- 82EEA000:AB000 flags D104000 LoadCount 2 \SystemRoot\system32\CI.dll
- 83434000:71000 flags 9104000 LoadCount 1 \SystemRoot\system32\drivers\Wdf01000.sys
- 834A5000:E000 flags D104000 LoadCount 10 \SystemRoot\system32\drivers\WDFLDR.SYS
- 834B3000:48000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\ACPI.sys
- 834FB000:9000 flags D104000 LoadCount 22 \SystemRoot\system32\DRIVERS\WMILIB.SYS
- 83504000:8000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\msisadrv.sys
- 8350C000:2A000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\pci.sys
- 83536000:B000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\vdrvroot.sys
- 83541000:11000 flags 9104000 LoadCount 1 \SystemRoot\System32\drivers\partmgr.sys
- 83552000:8000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\compbatt.sys
- 8355A000:B000 flags D104000 LoadCount 2 \SystemRoot\system32\DRIVERS\BATTC.SYS
- 83565000:10000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\volmgr.sys
- 83575000:4B000 flags 9104000 LoadCount 1 \SystemRoot\System32\drivers\volmgrx.sys
- 835C0000:7000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\intelide.sys
- 835C7000:E000 flags D104000 LoadCount 1 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
- 835D5000:16000 flags 9104000 LoadCount 1 \SystemRoot\System32\drivers\mountmgr.sys
- 835EB000:9000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\atapi.sys
- 83400000:23000 flags D104000 LoadCount 1 \SystemRoot\system32\DRIVERS\ataport.SYS
- 82F95000:18000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\lsi_sas.sys
- 82FAD000:47000 flags D104000 LoadCount 1 \SystemRoot\system32\DRIVERS\storport.sys
- 83423000:9000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\amdxata.sys
- 83613000:34000 flags 9104000 LoadCount 4 \SystemRoot\system32\drivers\fltmgr.sys
- 83647000:11000 flags 9104000 LoadCount 1 \SystemRoot\system32\drivers\fileinfo.sys
- 83658000:12F000 flags 9104000 LoadCount 1 \SystemRoot\System32\Drivers\Ntfs.sys
- 83787000:2B000 flags D104000 LoadCount 9 \SystemRoot\System32\Drivers\msrpc.sys
- 837B2000:13000 flags 9104000 LoadCount 16 \SystemRoot\System32\Drivers\ksecdd.sys
- 8DE2A000:5D000 flags 9104000 LoadCount 3 \SystemRoot\System32\Drivers\cng.sys
- 8DE87000:E000 flags 9104020 LoadCount 1 \SystemRoot\System32\drivers\pcw.sys
- 8DE95000:9000 flags 9104000 LoadCount 1 \SystemRoot\System32\Drivers\Fs_Rec.sys
- 8DE9E000:B7000 flags 9104000 LoadCount 24 \SystemRoot\system32\drivers\ndis.sys
- 8DF55000:3E000 flags D104000 LoadCount 23 \SystemRoot\system32\drivers\NETIO.SYS
- 8DF93000:25000 flags 9104000 LoadCount 1 \SystemRoot\System32\Drivers\ksecpkg.sys
- 8E03F000:149000 flags 9104020 LoadCount 1 \SystemRoot\System32\drivers\tcpip.sys
- 8E188000:31000 flags D104000 LoadCount 8 \SystemRoot\System32\drivers\fwpkclnt.sys
- 8E1B9000:9000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\vmstorfl.sys
- 8E000000:3F000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\volsnap.sys
- 8E1C2000:8000 flags 9104000 LoadCount 1 \SystemRoot\System32\Drivers\spldr.sys
- 8E1CA000:2D000 flags 9104000 LoadCount 1 \SystemRoot\System32\drivers\rdyboost.sys
- 8DFB8000:10000 flags 9104000 LoadCount 4 \SystemRoot\System32\Drivers\mup.sys
- 8E1F7000:8000 flags 9104000 LoadCount 1 \SystemRoot\System32\drivers\hwpolicy.sys
- 8DFC8000:32000 flags 9104000 LoadCount 1 \SystemRoot\System32\DRIVERS\fvevol.sys
- 8DE00000:11000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\disk.sys
- 837C5000:25000 flags D104000 LoadCount 2 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
- 8DE11000:10000 flags 9104000 LoadCount 1 \SystemRoot\system32\DRIVERS\agp440.sys
- 92435000:1F000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\cdrom.sys
- 92454000:7000 flags 49104000 LoadCount 1 \SystemRoot\System32\Drivers\Null.SYS
- 9245B000:7000 flags 49104000 LoadCount 1 \SystemRoot\System32\Drivers\Beep.SYS
- 92462000:8000 flags 49104000 LoadCount 1 \??\C:\Program Files\VMware\VMware Tools\vmrawdsk.sys
- 9246A000:C000 flags 49104000 LoadCount 1 \SystemRoot\System32\drivers\vga.sys
- 92476000:21000 flags 4D104000 LoadCount 5 \SystemRoot\System32\drivers\VIDEOPRT.SYS
- 92497000:D000 flags 4D104000 LoadCount 5 \SystemRoot\System32\drivers\watchdog.sys
- 924A4000:8000 flags 49104000 LoadCount 1 \SystemRoot\System32\DRIVERS\RDPCDD.sys
- 924AC000:8000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\rdpencdd.sys
- 924B4000:8000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\rdprefmp.sys
- 924BC000:B000 flags 49104000 LoadCount 1 \SystemRoot\System32\Drivers\Msfs.SYS
- 924C7000:E000 flags 49104000 LoadCount 1 \SystemRoot\System32\Drivers\Npfs.SYS
- 924D5000:17000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\tdx.sys
- 924EC000:B000 flags 4D104000 LoadCount 7 \SystemRoot\system32\DRIVERS\TDI.SYS
- 924F7000:5A000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\afd.sys
- 92551000:32000 flags 49104000 LoadCount 1 \SystemRoot\System32\DRIVERS\netbt.sys
- 92583000:9000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\ws2ifsl.sys
- 9258C000:7000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\wfplwf.sys
- 92593000:1F000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\pacer.sys
- 925B2000:E000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\netbios.sys
- 925C0000:1E000 flags 49104000 LoadCount 1 \SystemRoot\System32\DRIVERS\vmhgfs.sys
- 925DE000:1A000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\serial.sys
- 92400000:9000 flags 49104000 LoadCount 1 \??\C:\Windows\system32\Drivers\vmdebug.sys
- 82E00000:13000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\wanarp.sys
- 92E2B000:10000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\termdd.sys
- 92E3B000:41000 flags 49104000 LoadCount 5 \SystemRoot\system32\DRIVERS\rdbss.sys
- 92E7C000:A000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\nsiproxy.sys
- 92E86000:A000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\mssmbios.sys
- 92E90000:C000 flags 49104000 LoadCount 1 \SystemRoot\System32\drivers\discache.sys
- 92E9C000:64000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\csc.sys
- 92F00000:18000 flags 49104000 LoadCount 1 \SystemRoot\System32\Drivers\dfsc.sys
- 92F18000:E000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\blbdrive.sys
- 92F26000:21000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\tunnel.sys
- 92F47000:18000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\i8042prt.sys
- 92F5F000:D000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\kbdclass.sys
- 92F6C000:2000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\vmmouse.sys
- 92F6E000:D000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\mouclass.sys
- 92F7B000:18000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\parport.sys
- 92F93000:A000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\serenum.sys
- 92F9D000:B000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\fdc.sys
- 92FA8000:E000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\vmci.sys
- 92FB6000:17000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\vm3dmp.sys
- 9320A000:B7000 flags 49104000 LoadCount 2 \SystemRoot\System32\drivers\dxgkrnl.sys
- 932C1000:39000 flags 49104000 LoadCount 1 \SystemRoot\System32\drivers\dxgmms1.sys
- 932FA000:B000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\usbuhci.sys
- 93305000:4B000 flags 4D104000 LoadCount 2 \SystemRoot\system32\DRIVERS\USBPORT.SYS
- 93350000:1D000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\E1G60I32.sys
- 9336D000:5000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\vmaudio.sys
- 93372000:2F000 flags 4D104000 LoadCount 1 \SystemRoot\system32\drivers\portcls.sys
- 933A1000:19000 flags 4D104000 LoadCount 1 \SystemRoot\system32\drivers\drmk.sys
- 933BA000:34000 flags 4D104000 LoadCount 3 \SystemRoot\system32\drivers\ks.sys
- 933EE000:F000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\usbehci.sys
- 93200000:4000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\CmBatt.sys
- 92FCD000:12000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\intelppm.sys
- 92FDF000:D000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\CompositeBus.sys
- 92FEC000:12000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\AgileVpn.sys
- 92E00000:18000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\rasl2tp.sys
- 92E18000:B000 flags 49104000 LoadCount 2 \SystemRoot\system32\DRIVERS\ndistapi.sys
- 9343C000:22000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\ndiswan.sys
- 9345E000:18000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\raspppoe.sys
- 93476000:17000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\raspptp.sys
- 9348D000:17000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\rassstp.sys
- 934A4000:A000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\rdpbus.sys
- 934AE000:2000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\swenum.sys
- 934B0000:E000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\umbus.sys
- 934BE000:A000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\flpydisk.sys
- 934C8000:44000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\usbhub.sys
- 9350C000:11000 flags 49104000 LoadCount 1 \SystemRoot\System32\Drivers\NDProxy.SYS
- 9351D000:D000 flags 49104000 LoadCount 1 \SystemRoot\System32\Drivers\crashdmp.sys
- 9352A000:A000 flags 49104000 LoadCount 2 \SystemRoot\System32\Drivers\dump_diskdump.sys
- 93534000:18000 flags 49104000 LoadCount 1 \SystemRoot\System32\Drivers\dump_LSI_SAS.sys
- 9354C000:11000 flags 49104020 LoadCount 1 \SystemRoot\System32\Drivers\dump_dumpfve.sys
- 97290000:24A000 flags 69104000 LoadCount 4 \SystemRoot\System32\win32k.sys
- 9355D000:A000 flags 4D104000 LoadCount 1 \SystemRoot\System32\drivers\Dxapi.sys
- 93567000:B000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\monitor.sys
- 974F0000:9000 flags 69104000 LoadCount 1 \SystemRoot\System32\TSDDD.dll
- 97520000:1E000 flags 69104000 LoadCount 1 \SystemRoot\System32\cdd.dll
- 93572000:17000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\usbccgp.sys
- 93589000:2000 flags 4D104000 LoadCount 2 \SystemRoot\system32\DRIVERS\USBD.SYS
- 9358B000:B000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\hidusb.sys
- 93596000:13000 flags 4D104000 LoadCount 1 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
- 935A9000:7000 flags 4D104000 LoadCount 2 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
- 935B0000:B000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\mouhid.sys
- 935BB000:1B000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\luafv.sys
- 935D6000:10000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\lltdio.sys
- 935E6000:13000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\rspndr.sys
- 9300E000:85000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\HTTP.sys
- 93093000:19000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\bowser.sys
- 930AC000:12000 flags 49104000 LoadCount 1 \SystemRoot\System32\drivers\mpsdrv.sys
- 930BE000:23000 flags 49104000 LoadCount 3 \SystemRoot\system32\DRIVERS\mrxsmb.sys
- 930E1000:3B000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
- 9311C000:1B000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
- 93137000:7000 flags 49104000 LoadCount 1 \SystemRoot\system32\DRIVERS\parvdm.sys
- 9313E000:2000 flags 49104000 LoadCount 1 \??\C:\Program Files\VMware\VMware Tools\Drivers\memctl\vmmemctl.sys
- 93140000:97000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\peauth.sys
- 931D7000:A000 flags 49104000 LoadCount 1 \SystemRoot\System32\Drivers\secdrv.SYS
- 93400000:21000 flags 49104000 LoadCount 3 \SystemRoot\System32\DRIVERS\srvnet.sys
- 931E1000:D000 flags 49104000 LoadCount 1 \SystemRoot\System32\drivers\tcpipreg.sys
- 95A0E000:4F000 flags 49104000 LoadCount 1 \SystemRoot\System32\DRIVERS\srv2.sys
- 95A5D000:51000 flags 49104000 LoadCount 1 \SystemRoot\System32\DRIVERS\srv.sys
- 95AAE000:6A000 flags 49104000 LoadCount 1 \SystemRoot\system32\drivers\spsys.sys
- 95B18000:10000 flags 49104000 LoadCount 1 \??\C:\Users\Admin\AppData\Local\Temp\drv2
- 775A0000:13C000 flags 0 LoadCount 1 \Windows\System32\ntdll.dll
- 47950000:13000 flags 0 LoadCount 1 \Windows\System32\smss.exe
- 777E0000:50000 flags 0 LoadCount 1 \Windows\System32\apisetschema.dll
- 00AD0000:A6000 flags 0 LoadCount 1 \Windows\System32\autochk.exe
- 77720000:A1000 flags 0 LoadCount 1 \Windows\System32\rpcrt4.dll
- 77400000:19D000 flags 0 LoadCount 1 \Windows\System32\setupapi.dll
- 77360000:9D000 flags 0 LoadCount 1 \Windows\System32\usp10.dll
- 77200000:15C000 flags 0 LoadCount 1 \Windows\System32\ole32.dll
- 77120000:D4000 flags 0 LoadCount 1 \Windows\System32\kernel32.dll
- 77710000:6000 flags 0 LoadCount 1 \Windows\System32\nsi.dll
- 76F20000:1F9000 flags 0 LoadCount 1 \Windows\System32\iertutil.dll
- 77700000:A000 flags 0 LoadCount 1 \Windows\System32\lpk.dll
- 76E70000:AC000 flags 0 LoadCount 1 \Windows\System32\msvcrt.dll
- 76E20000:4E000 flags 0 LoadCount 1 \Windows\System32\gdi32.dll
- 76DD0000:45000 flags 0 LoadCount 1 \Windows\System32\Wldap32.dll
- 76D70000:52000 flags 0 LoadCount 1 \Windows\System32\difxapi.dll
- 76120000:C49000 flags 0 LoadCount 1 \Windows\System32\shell32.dll
- 75FE0000:135000 flags 0 LoadCount 1 \Windows\System32\urlmon.dll
- 75F40000:A0000 flags 0 LoadCount 1 \Windows\System32\advapi32.dll
- 75EB0000:8F000 flags 0 LoadCount 1 \Windows\System32\oleaut32.dll
- 776F0000:3000 flags 0 LoadCount 1 \Windows\System32\normaliz.dll
- 75E30000:7B000 flags 0 LoadCount 1 \Windows\System32\comdlg32.dll
- 75E10000:19000 flags 0 LoadCount 1 \Windows\System32\sechost.dll
- 75D10000:F4000 flags 0 LoadCount 1 \Windows\System32\wininet.dll
- 75CF0000:1F000 flags 0 LoadCount 1 \Windows\System32\imm32.dll
- 75CB0000:35000 flags 0 LoadCount 1 \Windows\System32\ws2_32.dll
- 75BE0000:CC000 flags 0 LoadCount 1 \Windows\System32\msctf.dll
- 75B80000:57000 flags 0 LoadCount 1 \Windows\System32\shlwapi.dll
- 75AF0000:83000 flags 0 LoadCount 1 \Windows\System32\clbcatq.dll
- 75AC0000:2A000 flags 0 LoadCount 1 \Windows\System32\imagehlp.dll
- 776E0000:5000 flags 0 LoadCount 1 \Windows\System32\psapi.dll
- 759F0000:C9000 flags 0 LoadCount 1 \Windows\System32\user32.dll
- 758D0000:11C000 flags 0 LoadCount 1 \Windows\System32\crypt32.dll
- 758B0000:12000 flags 0 LoadCount 1 \Windows\System32\devobj.dll
- 75880000:27000 flags 0 LoadCount 1 \Windows\System32\cfgmgr32.dll
- 757F0000:84000 flags 0 LoadCount 1 \Windows\System32\comctl32.dll
- 757C0000:2D000 flags 0 LoadCount 1 \Windows\System32\wintrust.dll
- 75770000:4A000 flags 0 LoadCount 1 \Windows\System32\KernelBase.dll
- 75760000:C000 flags 0 LoadCount 1 \Windows\System32\msasn1.dll
- Patched ZwYieldExecution + CA5
- Patched KiDispatchInterrupt + 5A2
- KernelSection .text rva 1000, size 11B901, 0x4C60 relocs has 0x15 patched bytes !
- KPRCB worker routines:
- Boot environment:
- A1025C15 11E0173E ACF9D5AD 3533A862 1
- ObTypeIndexTable: 8297D8C0
- [00] 00000000
- [01] BAD0B0B0
- [02] 8B5B38E8
- [03] 8B5B3820
- [04] 8B5B3758
- [05] 8B5B3528
- [06] 8B5B8F78
- [07] 8B5B8EB0
- [08] 8B5B8DE8
- [09] 8B5B8D20
- [0A] 8B5B8C58
- [0B] 8B5B88B0
- [0C] 8B629418
- [0D] 8B629350
- [0E] 8B62B418
- [0F] 8B62B350
- [10] 8B628470
- [11] 8B6283A8
- [12] 8B62C9B8
- [13] 8B62C8F0
- [14] 8B62C828
- [15] 8B62C760
- [16] 8B62C698
- [17] 8B62C5D0
- [18] 8B62C508
- [19] 8B62C440
- [1A] 8B62C378
- [1B] 8B62D040
- [1C] 8B62DF78
- [1D] 8B62DAB0
- [1E] 8B62D9E8
- [1F] 8B62D920
- [20] 8B62D858
- [21] 8B62D688
- [22] 8B62D2E8
- [23] 8B631B10
- [24] 8B62F4B8
- [25] 8B619A30
- [26] 8B646830
- [27] 8B646480
- [28] 8B6463B8
- [29] 8C062F08
- [2A] 8CA4A718
- [2B] 8C798DD0
- ObTypes:
- ObType TpWorkerFactory (8B62C698):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 82ABBEB2 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 828FC96B \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Directory (8B5B3820):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 82AB824A \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Mutant (8B62B418):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 828F5EC6 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Thread (8B5B8DE8):
- DumpProcedure: 00000000
- OpenProcedure: 82A9C891 \SystemRoot\system32\ntkrnlpa.exe
- CloseProcedure: 00000000
- DeleteProcedure: 82A83D8C \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType FilterCommunicationPort (8CA4A718):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 8363051A \SystemRoot\system32\drivers\fltmgr.sys
- DeleteProcedure: 8362FFC8 \SystemRoot\system32\drivers\fltmgr.sys
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType TmTx (8B62D9E8):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 82A0DBDF \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82A33FE2 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Controller (8B62C508):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType EtwRegistration (8B646480):
- DumpProcedure: 00000000
- OpenProcedure: 82ABBB73 \SystemRoot\system32\ntkrnlpa.exe
- CloseProcedure: 82A9CE84 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82A9CD6F \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Profile (8B62C9B8):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 82B447DA \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Event (8B629418):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Type (8B5B38E8):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Section (8B62D688):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 82A6C340 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType EventPair (8B629350):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType SymbolicLink (8B5B3758):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 82A423C8 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 82A5C551 \SystemRoot\system32\ntkrnlpa.exe
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Desktop (8B62C760):
- DumpProcedure: 00000000
- OpenProcedure: 82ABF15A \SystemRoot\system32\ntkrnlpa.exe
- CloseProcedure: 82AB8B38 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 829E16AF \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 82AB8AB9 \SystemRoot\system32\ntkrnlpa.exe
- ObType UserApcReserve (8B5B8D20):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType EtwConsumer (8B6463B8):
- DumpProcedure: 00000000
- OpenProcedure: 82ABBB73 \SystemRoot\system32\ntkrnlpa.exe
- CloseProcedure: 82AD3E76 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82AD3DB1 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Timer (8B6283A8):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 82861F94 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType File (8B62DF78):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 82A96BAF \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82A7CCBB \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 82AC4FE0 \SystemRoot\system32\ntkrnlpa.exe
- SecurityProcedure: 82A9B41D \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 82AA8E11 \SystemRoot\system32\ntkrnlpa.exe
- OkayToCloseProcedure: 00000000
- ObType WindowStation (8B62C828):
- DumpProcedure: 00000000
- OpenProcedure: 82ABF15A \SystemRoot\system32\ntkrnlpa.exe
- CloseProcedure: 82AB8B38 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 829E16AF \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 82ABF1DE \SystemRoot\system32\ntkrnlpa.exe
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 82AB8AB9 \SystemRoot\system32\ntkrnlpa.exe
- ObType PcwObject (8C798DD0):
- DumpProcedure: 00000000
- OpenProcedure: 8DE8DC70 \SystemRoot\System32\drivers\pcw.sys
- CloseProcedure: 8DE8DC8A \SystemRoot\System32\drivers\pcw.sys
- DeleteProcedure: 8DE8DCAC \SystemRoot\System32\drivers\pcw.sys
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType TmEn (8B62D858):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 82A0DAE2 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82A0DB19 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Driver (8B62C378):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 82AF64DF \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType WmiGuid (8B646830):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 8285DCBB \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82A28EE8 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType KeyedEvent (8B62C8F0):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Device (8B62C440):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 829F4C64 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 82A7A756 \SystemRoot\system32\ntkrnlpa.exe
- SecurityProcedure: 82A9B41D \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Token (8B5B3528):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 82AB6D66 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType ALPC Port (8B62F4B8):
- DumpProcedure: 00000000
- OpenProcedure: 82ABBF87 \SystemRoot\system32\ntkrnlpa.exe
- CloseProcedure: 82AABE45 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82AA6514 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType DebugObject (8B5B88B0):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 82AE9FA9 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82AC1873 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType IoCompletion (8B62D040):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 82A9EF1A \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82A9F703 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Process (8B5B8EB0):
- DumpProcedure: 00000000
- OpenProcedure: 82ABA267 \SystemRoot\system32\ntkrnlpa.exe
- CloseProcedure: 82AABECC \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82AAB10A \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType TmRm (8B62D920):
- DumpProcedure: 00000000
- OpenProcedure: 829D798B \SystemRoot\system32\ntkrnlpa.exe
- CloseProcedure: 82AC7D7A \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82AC7F8A \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Adapter (8B62C5D0):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType PowerRequest (8B619A30):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 82A1D35D \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Key (8B631B10):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 82AA7C47 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82A9800D \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 82A71552 \SystemRoot\system32\ntkrnlpa.exe
- SecurityProcedure: 82A47142 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 82A02170 \SystemRoot\system32\ntkrnlpa.exe
- OkayToCloseProcedure: 00000000
- ObType Job (8B5B8F78):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 82A2D801 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82A30E96 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Session (8B62D2E8):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 82AC71BE \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType TmTm (8B62DAB0):
- DumpProcedure: 00000000
- OpenProcedure: 82A03C9F \SystemRoot\system32\ntkrnlpa.exe
- CloseProcedure: 82A03919 \SystemRoot\system32\ntkrnlpa.exe
- DeleteProcedure: 82AC9831 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType IoCompletionReserve (8B5B8C58):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Callback (8B62B350):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 82AC1873 \SystemRoot\system32\ntkrnlpa.exe
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType FilterConnectionPort (8C062F08):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 8363054A \SystemRoot\system32\drivers\fltmgr.sys
- DeleteProcedure: 8362FFE2 \SystemRoot\system32\drivers\fltmgr.sys
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- ObType Semaphore (8B628470):
- DumpProcedure: 00000000
- OpenProcedure: 00000000
- CloseProcedure: 00000000
- DeleteProcedure: 00000000
- ParseProcedure: 00000000
- SecurityProcedure: 82AAED13 \SystemRoot\system32\ntkrnlpa.exe
- QueryNameProcedure: 00000000
- OkayToCloseProcedure: 00000000
- Callbacks:
- CB: AfdTdxCallback, total 0:
- CB: IoSessionNotifications, total 0:
- CB: ProcessorAdd, total 6:
- 834D5890 (\SystemRoot\system32\DRIVERS\ACPI.sys)
- 8DECB760 (\SystemRoot\system32\drivers\ndis.sys)
- 8E0D2999 (\SystemRoot\System32\drivers\tcpip.sys)
- 82B1145D (\SystemRoot\system32\ntkrnlpa.exe)
- 92F292C2 (\SystemRoot\system32\DRIVERS\tunnel.sys)
- 9301E2C1 (\SystemRoot\system32\drivers\HTTP.sys)
- CB: Phase1InitComplete, total 0:
- CB: SetSystemState, total 0:
- CB: NdisBindUnbind, total 0:
- CB: PowerState, total D:
- 829D15DA (\SystemRoot\system32\ntkrnlpa.exe)
- 829D15AD (\SystemRoot\system32\ntkrnlpa.exe)
- 8280FE70 (\SystemRoot\system32\halmacpi.dll)
- 834C62DE (\SystemRoot\system32\DRIVERS\ACPI.sys)
- 835158F6 (\SystemRoot\system32\DRIVERS\pci.sys)
- 8348469D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 8348469D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 92F7C39B (\SystemRoot\system32\DRIVERS\parport.sys)
- 93200BAA (\SystemRoot\system32\DRIVERS\CmBatt.sys)
- 8348469D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 8348469D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 8348469D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 8348469D (\SystemRoot\system32\drivers\Wdf01000.sys)
- CB: LicensingData, total 0:
- CB: EnlightenmentState, total 1:
- 8292C09D (\SystemRoot\system32\ntkrnlpa.exe)
- CB: LLTDCallbackMapper0006000006000000, total 0:
- CB: LLTDCallbackRspndr0006000006000000, total 1:
- 935E7DE6 (\SystemRoot\system32\DRIVERS\rspndr.sys)
- CB: TcpConnectionCallbackTemp, total 0:
- CB: SetSystemTime, total 0:
- CB: TcpTimerStarvationCallbackTemp, total 0:
- bugcheck callbacks - 4:
- 8DED4B96 (\SystemRoot\system32\drivers\ndis.sys)
- 8DED4B96 (\SystemRoot\system32\drivers\ndis.sys)
- 8DED4B96 (\SystemRoot\system32\drivers\ndis.sys)
- 82813908 (\SystemRoot\system32\halmacpi.dll)
- bugcheck reason callbacks - 31:
- 8348972D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 935B350E (\SystemRoot\system32\DRIVERS\mouhid.sys)
- 9359EA2C (\SystemRoot\system32\DRIVERS\HIDCLASS.SYS)
- 9358E85C (\SystemRoot\system32\DRIVERS\hidusb.sys)
- 8348972D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 9351E1BE (\SystemRoot\System32\Drivers\crashdmp.sys)
- 934EE82A (\SystemRoot\system32\DRIVERS\usbhub.sys)
- 934EE7D5 (\SystemRoot\system32\DRIVERS\usbhub.sys)
- 8348972D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 8348972D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 8348972D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 93326D79 (\SystemRoot\system32\DRIVERS\USBPORT.SYS)
- 93326E30 (\SystemRoot\system32\DRIVERS\USBPORT.SYS)
- 93326DD6 (\SystemRoot\system32\DRIVERS\USBPORT.SYS)
- 93219470 (\SystemRoot\System32\drivers\dxgkrnl.sys)
- 92F715F5 (\SystemRoot\system32\DRIVERS\mouclass.sys)
- 92F62861 (\SystemRoot\system32\DRIVERS\kbdclass.sys)
- 92F4F8D5 (\SystemRoot\system32\DRIVERS\i8042prt.sys)
- 92E87EEC (\SystemRoot\system32\DRIVERS\mssmbios.sys)
- 92E87EA4 (\SystemRoot\system32\DRIVERS\mssmbios.sys)
- 92E87E54 (\SystemRoot\system32\DRIVERS\mssmbios.sys)
- 92E87E0C (\SystemRoot\system32\DRIVERS\mssmbios.sys)
- 9247A392 (\SystemRoot\System32\drivers\VIDEOPRT.SYS)
- 8348972D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 9243F88B (\SystemRoot\system32\DRIVERS\cdrom.sys)
- 837D64FF (\SystemRoot\system32\DRIVERS\CLASSPNP.SYS)
- 8348972D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 8348972D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 8348972D (\SystemRoot\system32\drivers\Wdf01000.sys)
- 8348922A (\SystemRoot\system32\drivers\Wdf01000.sys)
- 834022A6 (\SystemRoot\system32\DRIVERS\ataport.SYS)
- NMI callbacks - 1:
- Process notifiers:
- [0] 828F736C \SystemRoot\system32\ntkrnlpa.exe
- [1] 837BE9D8 \SystemRoot\System32\Drivers\ksecdd.sys
- [2] 8DE2ED96 \SystemRoot\System32\Drivers\cng.sys
- [3] 8E0CC733 \SystemRoot\System32\drivers\tcpip.sys
- [4] 82EF8DF0 \SystemRoot\system32\CI.dll
- [5] 924016AE \??\C:\Windows\system32\Drivers\vmdebug.sys
- Image notifiers:
- [0] 82ABB833 \SystemRoot\system32\ntkrnlpa.exe
- FS Change notifiers: 3 (actual 3)
- DriverObj 8B6A31B8 addr 8362CBDA \SystemRoot\system32\drivers\fltmgr.sys
- DriverObj 8BEC91B8 addr 8C477D40 UNKNOWN
- DriverObj 8B6A31B8 addr 8362CBDA \SystemRoot\system32\drivers\fltmgr.sys
- LogonSessionTerminatedRoutines: 2
- [0] 930CD03E \SystemRoot\system32\DRIVERS\mrxsmb.sys
- [1] 935C99D9 \SystemRoot\system32\drivers\luafv.sys
- Callouts (18):
- PspW32ProcessCallout: 9735E8DA \SystemRoot\System32\win32k.sys
- PspW32ThreadCallout: 9735EA6C \SystemRoot\System32\win32k.sys
- ExGlobalAtomTableCallout: 97305C24 \SystemRoot\System32\win32k.sys
- PopEventCallout: 9737D040 \SystemRoot\System32\win32k.sys
- PopStateCallout: 9737B90F \SystemRoot\System32\win32k.sys
- PopWin32InfoCallout: 972D9FAC \SystemRoot\System32\win32k.sys
- PspW32JobCallout: 972FC08F \SystemRoot\System32\win32k.sys
- KeGdiFlushUserBatch: 9733F9E4 \SystemRoot\System32\win32k.sys
- ExDesktopOpenProcedureCallout: 9735C108 \SystemRoot\System32\win32k.sys
- ExDesktopOkToCloseProcedureCallout: 973610F4 \SystemRoot\System32\win32k.sys
- ExDesktopCloseProcedureCallout: 97361083 \SystemRoot\System32\win32k.sys
- ExDesktopDeleteProcedureCallout: 972AD47B \SystemRoot\System32\win32k.sys
- ExWindowStationOkToCloseProcedureCallout: 9735EB9C \SystemRoot\System32\win32k.sys
- ExWindowStationCloseProcedureCallout: 9735EB25 \SystemRoot\System32\win32k.sys
- ExWindowStationDeleteProcedureCallout: 9737555F \SystemRoot\System32\win32k.sys
- ExWindowStationParseProcedureCallout: 97364DE8 \SystemRoot\System32\win32k.sys
- ExWindowStationOpenProcedureCallout: 97364EA4 \SystemRoot\System32\win32k.sys
- ExLicensingWin32Callout: 973F5837 \SystemRoot\System32\win32k.sys
- FltMgrCallbacks: 8361FB3C \SystemRoot\system32\drivers\fltmgr.sys
- FsRtlpMupCalls: 8DFBC068 \SystemRoot\System32\Drivers\mup.sys
- DbgkLkmdCallback:
- DbgkLkmd[0] callback 9740A9F6 \SystemRoot\System32\win32k.sys
- ExpDisQueryAttributeInformation 92E91A72 \SystemRoot\System32\drivers\discache.sys
- ExpDisSetAttributeInformation 92E91EE2 \SystemRoot\System32\drivers\discache.sys
- PriorityCallbacks:
- [0] 828660DE \SystemRoot\system32\ntkrnlpa.exe
- Pnp Notifiers: total 19, readed 19
- Pnp[0] CategoryHardwareProfileChange DEVINTERFACE_HID addr 829C84D0 \SystemRoot\system32\ntkrnlpa.exe
- Pnp[1] CategoryHardwareProfileChange DEVICE_THERMAL_ZONE addr 829C84D0 \SystemRoot\system32\ntkrnlpa.exe
- Pnp[2] CategoryHardwareProfileChange DEVINTERFACE_HID addr 9729B547 \SystemRoot\System32\win32k.sys
- Pnp[3] CategoryHardwareProfileChange DEVINTERFACE_MT_TRANSPORT addr 92FE793A \SystemRoot\system32\DRIVERS\CompositeBus.sys
- Pnp[4] CategoryHardwareProfileChange DEVICE_SYS_BUTTON addr 829C84D0 \SystemRoot\system32\ntkrnlpa.exe
- Pnp[5] CategoryHardwareProfileChange DEVICE_MEMORY addr 829C84D0 \SystemRoot\system32\ntkrnlpa.exe
- Pnp[6] CategoryHardwareProfileChange DEVINTERFACE_MT_COMPOSITE addr 92FE793A \SystemRoot\system32\DRIVERS\CompositeBus.sys
- Pnp[7] CategoryHardwareProfileChange DEVINTERFACE_DISK addr 8B618180 UNKNOWN
- Pnp[8] CategoryHardwareProfileChange DEVINTERFACE_HIDDEN_VOLUME addr 8356D3E0 \SystemRoot\system32\DRIVERS\volmgr.sys
- Pnp[9] CategoryHardwareProfileChange DEVINTERFACE_MONITOR_DRIVER addr 932501AA \SystemRoot\System32\drivers\dxgkrnl.sys
- Pnp[10] CategoryHardwareProfileChange DEVINTERFACE_MOUSE addr 9729B547 \SystemRoot\System32\win32k.sys
- Pnp[11] CategoryHardwareProfileChange DEVINTERFACE_CDROM addr 9729BCCC \SystemRoot\System32\win32k.sys
- Pnp[12] CategoryHardwareProfileChange DEVINTERFACE_VOLUME addr 8356D3E0 \SystemRoot\system32\DRIVERS\volmgr.sys
- Pnp[13] CategoryHardwareProfileChange DEVINTERFACE_VOLUME addr 835E6216 \SystemRoot\System32\drivers\mountmgr.sys
- Pnp[14] CategoryHardwareProfileChange DEVINTERFACE_VOLUME addr 8E02FD42 \SystemRoot\system32\DRIVERS\volsnap.sys
- Pnp[15] CategoryHardwareProfileChange DEVINTERFACE_KEYBOARD addr 9729B547 \SystemRoot\System32\win32k.sys
- Pnp[16] CategoryHardwareProfileChange DEVCLASS_BATTERY addr 829C84D0 \SystemRoot\system32\ntkrnlpa.exe
- Pnp[17] CategoryHardwareProfileChange VOLMGR_VOLUME_MANAGER addr 83549D86 \SystemRoot\System32\drivers\partmgr.sys
- Pnp[18] CategoryHardwareProfileChange DEVCLASS_BATTERY addr 83553664 \SystemRoot\system32\DRIVERS\compbatt.sys
- PlugPlayHandlerTable: 23 items
- PlugPlayHandlerTable[0] 82B00117 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[1] 82B00094 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[2] 82AFFF9D \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[3] 82ACD97B \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[4] 829EB833 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[6] 829EF945 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[7] 829F23EC \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[8] 82B001B9 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[9] 82A2334A \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[10] 829F164F \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[11] 82B002E3 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[12] 82A05A83 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[13] 82A1795D \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[14] 82A16EDA \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[15] 829DB513 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[16] 82B00532 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[17] 82A17F2A \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[18] 82B00658 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[19] 82AC9AA5 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[20] 82AFFF12 \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[21] 82B00A1A \SystemRoot\system32\ntkrnlpa.exe
- PlugPlayHandlerTable[22] 829DB18F \SystemRoot\system32\ntkrnlpa.exe
- InitIsWinPEMode: 0
- CiEnabled: 1
- CI Table:
- [0]: 82EF0D5E \SystemRoot\system32\CI.dll
- [1]: 82EEF926 \SystemRoot\system32\CI.dll
- [2]: 82EEF09A \SystemRoot\system32\CI.dll
- CrashdmpCallTable (82971D94): 8 items:
- [0] CrashdmpInitialize: 93524408 \SystemRoot\System32\Drivers\crashdmp.sys
- [1] CrashdmpLoadDumpStack: 93524006 \SystemRoot\System32\Drivers\crashdmp.sys
- [2] CrashdmpInitDumpStack: 9351E006 \SystemRoot\System32\Drivers\crashdmp.sys
- [3] CrashdmpFreeDumpStack: 935242FA \SystemRoot\System32\Drivers\crashdmp.sys
- [4] CrashdmpDisable: 9352436E \SystemRoot\System32\Drivers\crashdmp.sys
- [5] CrashdmpNotify: 9351E0BC \SystemRoot\System32\Drivers\crashdmp.sys
- [6] CrashdmpWrite: 9351E108 \SystemRoot\System32\Drivers\crashdmp.sys
- [7] CrashdmpUpdatePhysicalRange: 9351E180 \SystemRoot\System32\Drivers\crashdmp.sys
- CI.dll data:
- g_CiOptions: 4
- g_CiSystemProcess: 8B5B8958
- Driver C:\Windows\system32\drivers\Wdf01000.sys!.text has 185C patched bytes !
- Driver C:\Windows\system32\drivers\Wdf01000.sys!PAGEWdfV has 13E patched bytes !
- Driver C:\Windows\system32\drivers\Wdf01000.sys!PAGE has 144 patched bytes !
- Driver C:\Windows\system32\drivers\ACPI.sys!.text has AD patched bytes !
- Patched DeRegisterOpRegionHandler + BB7E
- Driver C:\Windows\system32\drivers\ACPI.sys!PAGE has 189D patched bytes !
- Driver C:\Windows\system32\drivers\pci.sys!.text has 1926 patched bytes !
- Driver C:\Windows\system32\drivers\pci.sys!PAGE has 1C patched bytes !
- Driver C:\Windows\system32\drivers\pci.sys!PAGEKD has 96 patched bytes !
- Driver atapi DrvObj 8B65F1B8:
- DriverUnload patched by \SystemRoot\system32\DRIVERS\ataport.SYS, addr 83415DE6
- AddDevice patched by \SystemRoot\system32\DRIVERS\ataport.SYS, addr 83418750
- Handler MJ_CREATE patched by \SystemRoot\system32\DRIVERS\ataport.SYS, addr 8341A8C4
- Handler MJ_CLOSE patched by \SystemRoot\system32\DRIVERS\ataport.SYS, addr 8341A8C4
- Handler MJ_DEVICE_CONTROL patched by \SystemRoot\system32\DRIVERS\ataport.SYS, addr 8340647C
- Handler MJ_INTERNAL_DEVICE_CONTROL patched by \SystemRoot\system32\DRIVERS\ataport.SYS, addr 8340644E
- Handler MJ_POWER patched by \SystemRoot\system32\DRIVERS\ataport.SYS, addr 834064AA
- Handler MJ_SYSTEM_CONTROL patched by \SystemRoot\system32\DRIVERS\ataport.SYS, addr 83415DB2
- Handler MJ_PNP patched by \SystemRoot\system32\DRIVERS\ataport.SYS, addr 83415D7E
- Patched FltGetRequestorProcessIdEx + 4CB
- Driver C:\Windows\system32\drivers\fltmgr.sys!.text has 8A patched bytes !
- Patched FltGetRequestorProcessIdEx + 7F90
- Patched FltAttachVolume
- Patched FltAttachVolumeAtAltitude
- Patched FltDetachVolume
- Patched FltGetTransactionContext
- Patched FltSetTransactionContext
- Patched FltNotifyFilterChangeDirectory + 1D0
- Driver C:\Windows\system32\drivers\fltmgr.sys!PAGE has 182A patched bytes !
- Patched FltNotifyFilterChangeDirectory + 4E4F
- Driver C:\Windows\system32\drivers\fltmgr.sys!PAGEVRF1 has 18B patched bytes !
- Driver C:\Windows\system32\drivers\Ntfs.sys!.text has 1995 patched bytes !
- Driver C:\Windows\system32\drivers\Ntfs.sys!PAGE has DE patched bytes !
- Patched NetDmaIsDmaCopyComplete + 119F
- Driver C:\Windows\system32\drivers\ndis.sys!.text has 40 patched bytes !
- Patched NetDmaIsDmaCopyComplete + 7DFD
- Patched NdisCloseAdapterEx
- Patched NdisIMNotifyPnPEvent + 3C08
- Driver C:\Windows\system32\drivers\ndis.sys!PAGE has 18AC patched bytes !
- Patched NdisMSynchronizeWithInterrupt + 1410
- Driver C:\Windows\system32\drivers\ndis.sys!PAGENDSM has 19 patched bytes !
- Patched NdisCompletePnPEvent + 650
- Driver C:\Windows\system32\drivers\ndis.sys!PAGENDSP has 81 patched bytes !
- Patched TrFilterDprIndicateReceiveComplete + 886
- Driver C:\Windows\system32\drivers\ndis.sys!PAGENDST has C9 patched bytes !
- Patched NdisMRegisterInterrupt + 864
- Driver C:\Windows\system32\drivers\ndis.sys!PAGENPNP has 103 patched bytes !
- Patched EthFilterDprIndicateReceive + D29
- Driver C:\Windows\system32\drivers\ndis.sys!PAGENDSE has 7B patched bytes !
- Patched NdisMCoSendComplete + 68
- Driver C:\Windows\system32\drivers\ndis.sys!PAGENDCO has 55 patched bytes !
- Driver C:\Windows\system32\drivers\volsnap.sys!.text has 1876 patched bytes !
- Driver C:\Windows\system32\drivers\volsnap.sys!PAGELK has B6 patched bytes !
- Driver Disk DrvObj 8C432E40:
- DriverUnload patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837E092B
- AddDevice patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837DE603
- Handler MJ_CREATE patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- Handler MJ_CLOSE patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- Handler MJ_READ patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- Handler MJ_WRITE patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- Handler MJ_FLUSH_BUFFERS patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- Handler MJ_DEVICE_CONTROL patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- Handler MJ_INTERNAL_DEVICE_CONTROL patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- Handler MJ_SHUTDOWN patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- Handler MJ_POWER patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- Handler MJ_SYSTEM_CONTROL patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- Handler MJ_PNP patched by \SystemRoot\system32\DRIVERS\CLASSPNP.SYS, addr 837C939F
- CLASS_DRIVER_EXTENSION: 8C432AB8
- Fdo.ClassError: 8DE01DCC \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassReadWriteVerification: 8DE015C2 \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassDeviceControl: 8DE01B5E \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassShutdownFlush: 8DE09212 \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassInitDevice: 8DE0B78E \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassStartDevice: 8DE0B0D2 \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassPowerDevice: 8DE031D8 \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassStopDevice: 8DE02FEE \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassRemoveDevice: 8DE0B6D8 \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassWmiInfo.ClassQueryWmiRegInfo: 8DE09A62 \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassWmiInfo.ClassQueryWmiDataBlock: 8DE09B02 \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassWmiInfo.ClassSetWmiDataBlock: 8DE09D82 \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassWmiInfo.ClassSetWmiDataItem: 8DE09EEA \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassWmiInfo.ClassExecuteWmiMethod: 8DE0A432 \SystemRoot\system32\DRIVERS\disk.sys
- Fdo.ClassWmiInfo.ClassWmiFunctionControl: 8DE0A2A8 \SystemRoot\system32\DRIVERS\disk.sys
- ClassAddDevice: 8DE0AEE6 \SystemRoot\system32\DRIVERS\disk.sys
- ClassUnload: 8DE06422 \SystemRoot\system32\DRIVERS\disk.sys
- Driver usbehci DrvObj 8C81F460:
- DriverUnload patched by \SystemRoot\system32\DRIVERS\USBPORT.SYS, addr 93326B31
- AddDevice patched by \SystemRoot\system32\DRIVERS\USBPORT.SYS, addr 9331C7C0
- Handler MJ_CREATE patched by \SystemRoot\system32\DRIVERS\USBPORT.SYS, addr 9330863B
- Handler MJ_CLOSE patched by \SystemRoot\system32\DRIVERS\USBPORT.SYS, addr 9330863B
- Handler MJ_DEVICE_CONTROL patched by \SystemRoot\system32\DRIVERS\USBPORT.SYS, addr 9330863B
- Handler MJ_INTERNAL_DEVICE_CONTROL patched by \SystemRoot\system32\DRIVERS\USBPORT.SYS, addr 9330863B
- Handler MJ_POWER patched by \SystemRoot\system32\DRIVERS\USBPORT.SYS, addr 9330863B
- Handler MJ_SYSTEM_CONTROL patched by \SystemRoot\system32\DRIVERS\USBPORT.SYS, addr 9330863B
- Handler MJ_PNP patched by \SystemRoot\system32\DRIVERS\USBPORT.SYS, addr 93314455
- Shadow SDT: 97495000, limit 339
- Driver MRxSmb DrvObj 8D4915C0:
- FastIOHandler FastIoCheckIfPossible patched by \SystemRoot\system32\DRIVERS\rdbss.sys, addr 92E63B44
- FastIOHandler FastIoRead patched by \SystemRoot\system32\DRIVERS\rdbss.sys, addr 92E63FE7
- FastIOHandler FastIoWrite patched by \SystemRoot\system32\DRIVERS\rdbss.sys, addr 92E6BCD5
- FastIOHandler FastIoDeviceControl patched by \SystemRoot\system32\DRIVERS\rdbss.sys, addr 92E45A98
- FastIOHandler AcquireForModWrite patched by \SystemRoot\system32\DRIVERS\rdbss.sys, addr 92E490C9
- FastIOHandler ReleaseForModWrite patched by \SystemRoot\system32\DRIVERS\rdbss.sys, addr 92E49193
- FastIOHandler AcquireForCcFlush patched by \SystemRoot\system32\DRIVERS\rdbss.sys, addr 92E41018
- FastIOHandler ReleaseForCcFlush patched by \SystemRoot\system32\DRIVERS\rdbss.sys, addr 92E41018
- FS_FILTER_CALLBACKS PreAcquireForSectionSynchronization patched by \SystemRoot\system32\DRIVERS\rdbss.sys, addr 92E640A0
- FS_FILTER_CALLBACKS PreReleaseForSectionSynchronization patched by \SystemRoot\system32\DRIVERS\rdbss.sys, addr 92E641AA
- Driver C:\Windows\system32\drivers\peauth.sys!.text has 36 patched bytes !
- Driver C:\Windows\system32\drivers\peauth.sys!PAGE has 65 patched bytes !
- Driver C:\Windows\system32\drivers\spsys.sys!CODE_NP has 119 patched bytes !
- Patched ?SPRevision@@3PADA + 4F90
- Driver C:\Windows\system32\drivers\spsys.sys!PAGE has 319FD patched bytes !
- KSecPkg tables:
- gKsecExBuiltinPackages[0].tab 837BC288 (8DFA5140) patched by \SystemRoot\System32\Drivers\ksecdd.sys
- gKsecpBCryptExtension: 8DE79180 \SystemRoot\System32\Drivers\cng.sys
- gKsecpSslExtension: 8DE7920C \SystemRoot\System32\Drivers\cng.sys
- Win32kCallout: 97293491 \SystemRoot\System32\win32k.sys
- SessionStartCallout: 9324B17A \SystemRoot\System32\drivers\dxgkrnl.sys
- RtlpStartThreadFunc: C:\Windows\system32\kernel32.dll (771C9DD5)
- RtlpExitThreadFunc: C:\Windows\system32\kernel32.dll (771C9DC1)
- RtlpUnhandledExceptionFilter: C:\Windows\system32\kernel32.dll (77182B35)
- LdrpManifestProberRoutine: C:\Windows\system32\kernel32.dll (7717172A)
- LdrpCreateActCtxLanguage: C:\Windows\system32\kernel32.dll (771B7074)
- LdrpReleaseActCtx: C:\Windows\system32\kernel32.dll (771691BD)
- UnhandledExceptionFilter: c:\Users\Admin\Desktop\wincheck.exe (01489EC4)
- ConsoleCtrlHandler: C:\Windows\system32\kernel32.dll (771CD2E5)
- Check took 2765 msecs
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement