Share Pastebin
Guest
Public paste!

IOF

By: a guest | Feb 9th, 2010 | Syntax: None | Size: 54.20 KB | Hits: 34 | Expires: Never
Copy text to clipboard
  1. ROOTREPEAL (c) AD, 2007-2009
  2. ==================================================
  3. Scan Start Time:                2010/02/09 15:49
  4. Program Version:                Version 1.3.5.0
  5. Windows Version:                Windows Vista SP1
  6. ==================================================
  7.  
  8. Drivers
  9. -------------------
  10. Name: dump_iaStor.sys
  11. Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
  12. Address: 0x8A90A000     Size: 815104    File Visible: No        Signed: -
  13. Status: -
  14.  
  15. Name: rootrepeal.sys
  16. Image Path: C:\Windows\system32\drivers\rootrepeal.sys
  17. Address: 0xB3777000     Size: 49152     File Visible: No        Signed: -
  18. Status: -
  19.  
  20. Name: spmt.sys
  21. Image Path: C:\Windows\System32\Drivers\spmt.sys
  22. Address: 0x80694000     Size: 1048576   File Visible: No        Signed: -
  23. Status: -
  24.  
  25. Name: sptd
  26. Image Path: \Driver\sptd
  27. Address: 0x00000000     Size: 0 File Visible: No        Signed: -
  28. Status: -
  29.  
  30. Hidden/Locked Files
  31. -------------------
  32. Path: C:\System Volume Information\{ace728af-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  33. Status: Locked to the Windows API!
  34.  
  35. Path: C:\System Volume Information\{ace728ca-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  36. Status: Locked to the Windows API!
  37.  
  38. Path: C:\System Volume Information\{ace72928-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  39. Status: Locked to the Windows API!
  40.  
  41. Path: C:\System Volume Information\{ace72960-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  42. Status: Locked to the Windows API!
  43.  
  44. Path: C:\System Volume Information\{ace729a1-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  45. Status: Locked to the Windows API!
  46.  
  47. Path: C:\System Volume Information\{ace729d5-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  48. Status: Locked to the Windows API!
  49.  
  50. Path: C:\System Volume Information\{ace72a14-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  51. Status: Locked to the Windows API!
  52.  
  53. Path: C:\System Volume Information\{ace72a3e-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  54. Status: Locked to the Windows API!
  55.  
  56. Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
  57. Status: Locked to the Windows API!
  58.  
  59. Path: C:\System Volume Information\{be2989c4-e5f3-11de-835b-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  60. Status: Locked to the Windows API!
  61.  
  62. Path: C:\System Volume Information\{f85c0137-f3d5-11de-97b3-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  63. Status: Locked to the Windows API!
  64.  
  65. Path: C:\System Volume Information\{f85c0168-f3d5-11de-97b3-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  66. Status: Locked to the Windows API!
  67.  
  68. Path: C:\System Volume Information\{f85c019d-f3d5-11de-97b3-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  69. Status: Locked to the Windows API!
  70.  
  71. Path: C:\System Volume Information\{f85c01f6-f3d5-11de-97b3-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  72. Status: Locked to the Windows API!
  73.  
  74. Path: C:\System Volume Information\{5a1401ac-f764-11de-9216-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  75. Status: Locked to the Windows API!
  76.  
  77. Path: C:\System Volume Information\{7201103f-e647-11de-8870-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  78. Status: Locked to the Windows API!
  79.  
  80. Path: C:\System Volume Information\{7201105b-e647-11de-8870-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  81. Status: Locked to the Windows API!
  82.  
  83. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$I7KHDVO.dat
  84. Status: Visible to the Windows API, but not on disk.
  85.  
  86. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$I9B31E5.dmp
  87. Status: Visible to the Windows API, but not on disk.
  88.  
  89. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$IWUDRLF.txt
  90. Status: Visible to the Windows API, but not on disk.
  91.  
  92. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$R7KHDVO.dat
  93. Status: Visible to the Windows API, but not on disk.
  94.  
  95. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$R9B31E5.dmp
  96. Status: Visible to the Windows API, but not on disk.
  97.  
  98. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$RWUDRLF.txt
  99. Status: Visible to the Windows API, but not on disk.
  100.  
  101. Path: C:\Windows\System32\GATHER~1.VBS
  102. Status: Locked to the Windows API!
  103.  
  104. Path: C:\ProgramData\Microsoft\Windows Defender\Quarantine
  105. Status: Locked to the Windows API!
  106.  
  107. Path: C:\Windows\Microsoft.NET\Framework\NETFXS~1.HKF
  108. Status: Locked to the Windows API!
  109.  
  110. Path: C:\Windows\System32\drivers\sfi.dat
  111. Status: Locked to the Windows API!
  112.  
  113. Path: c:\windows\temp\dwdd703.tmp\rootrepeal.exe.hu.kdmp
  114. Status: Allocation size mismatch (API: 26476544, Raw: 0)
  115.  
  116. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1833_none_d08b763a442c70c2.cat
  117. Status: Locked to the Windows API!
  118.  
  119. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8.cat
  120. Status: Locked to the Windows API!
  121.  
  122. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c.cat
  123. Status: Locked to the Windows API!
  124.  
  125. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.1833_none_4dddbf6711947267.cat
  126. Status: Locked to the Windows API!
  127.  
  128. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8dd7dea5d5a7a18a.cat
  129. Status: Locked to the Windows API!
  130.  
  131. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c0566bec5b24.cat
  132. Status: Locked to the Windows API!
  133.  
  134. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.1833_none_03c84dcc205e88fb.cat
  135. Status: Locked to the Windows API!
  136.  
  137. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat
  138. Status: Locked to the Windows API!
  139.  
  140. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_91949b06671d08ae.cat
  141. Status: Locked to the Windows API!
  142.  
  143. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003bc63e949f6.cat
  144. Status: Locked to the Windows API!
  145.  
  146. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1833_none_516c26fb0f4a960b.cat
  147. Status: Locked to the Windows API!
  148.  
  149. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131.cat
  150. Status: Locked to the Windows API!
  151.  
  152. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_10b3ea459bfee365.cat
  153. Status: Locked to the Windows API!
  154.  
  155. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.1833_none_cbf00aee470f5fb7.cat
  156. Status: Locked to the Windows API!
  157.  
  158. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.1833_none_d1c5318643596706.cat
  159. Status: Locked to the Windows API!
  160.  
  161. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.cat
  162. Status: Locked to the Windows API!
  163.  
  164. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.1833_none_49ed4131141912ee.cat
  165. Status: Locked to the Windows API!
  166.  
  167. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.1833_none_4db05f807dd45954.cat
  168. Status: Locked to the Windows API!
  169.  
  170. Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat
  171. Status: Locked to the Windows API!
  172.  
  173. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed.cat
  174. Status: Locked to the Windows API!
  175.  
  176. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d.cat
  177. Status: Locked to the Windows API!
  178.  
  179. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053e8c6967ba9d.cat
  180. Status: Locked to the Windows API!
  181.  
  182. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a620671dde41.cat
  183. Status: Locked to the Windows API!
  184.  
  185. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_516e2e610f48bda6.cat
  186. Status: Locked to the Windows API!
  187.  
  188. Path: C:\Windows\winsxs\x86_microsoft-windows-aero_31bf3856ad364e35_6.0.6001.18000_none_abe3118b19699649\aero.msstyles.vgorg
  189. Status: Locked to the Windows API!
  190.  
  191. Path: C:\Windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_cd305d2a1ced96e2\shsvcs.dll.vgorg
  192. Status: Locked to the Windows API!
  193.  
  194. Path: C:\Windows\winsxs\x86_microsoft-windows-themeui_31bf3856ad364e35_6.0.6001.18000_none_84fe96731b81293b\themeui.dll.vgorg
  195. Status: Locked to the Windows API!
  196.  
  197. Path: C:\Windows\winsxs\x86_microsoft-windows-uxtheme_31bf3856ad364e35_6.0.6001.18000_none_a5e49ad4068f9b12\uxtheme.dll.vgorg
  198. Status: Locked to the Windows API!
  199.  
  200. Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\GATHER~1.VBS
  201. Status: Locked to the Windows API!
  202.  
  203. Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\GATHER~1.VBS
  204. Status: Locked to the Windows API!
  205.  
  206. Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\GATHER~1.VBS
  207. Status: Locked to the Windows API!
  208.  
  209. Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\GATHER~1.VBS
  210. Status: Locked to the Windows API!
  211.  
  212. Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\GATHER~1.VBS
  213. Status: Locked to the Windows API!
  214.  
  215. Path: C:\Windows\winsxs\x86_netfx-installutil_exe_config_rtm_31bf3856ad364e35_6.0.6000.16720_none_c2e2272db9e7b99c\INSTAL~1.CON
  216. Status: Locked to the Windows API!
  217.  
  218. Path: C:\Windows\winsxs\x86_netfx-installutil_exe_config_rtm_31bf3856ad364e35_6.0.6000.20883_none_c32de54ed3334d11\INSTAL~1.CON
  219. Status: Locked to the Windows API!
  220.  
  221. Path: C:\Windows\winsxs\x86_netfx-installutil_exe_config_rtm_31bf3856ad364e35_6.0.6001.18111_none_c4d43609b70547f3\INSTAL~1.CON
  222. Status: Locked to the Windows API!
  223.  
  224. Path: C:\Windows\winsxs\x86_netfx-installutil_exe_config_rtm_31bf3856ad364e35_6.0.6001.22230_none_c54732b2d0340648\INSTAL~1.CON
  225. Status: Locked to the Windows API!
  226.  
  227. Path: C:\Windows\winsxs\x86_netfx-msbuild_data_files_b03f5f7f11d50a3a_6.0.6001.18111_none_7c8b5cbf426fb0d2\MICROS~1.TAS
  228. Status: Locked to the Windows API!
  229.  
  230. Path: C:\Windows\winsxs\x86_netfx-msbuild_data_files_b03f5f7f11d50a3a_6.0.6001.22230_none_65bfcd5b5c1529e5\MICROS~1.TAS
  231. Status: Locked to the Windows API!
  232.  
  233. Path: C:\Windows\winsxs\x86_netfx-msbuild_targetfiles_b03f5f7f11d50a3a_6.0.6000.16720_none_8d57832b7d03f5e1\MICROS~3.TAR
  234. Status: Locked to the Windows API!
  235.  
  236. Path: C:\Windows\winsxs\x86_netfx-msbuild_targetfiles_b03f5f7f11d50a3a_6.0.6000.20883_none_768f99cf96a63ad4\MICROS~3.TAR
  237. Status: Locked to the Windows API!
  238.  
  239. Path: C:\Windows\winsxs\x86_netfx-uninstallsqlstate_sql_b03f5f7f11d50a3a_6.0.6000.16720_none_a2f69a4627a6df36\UNINST~1.SQL
  240. Status: Locked to the Windows API!
  241.  
  242. Path: C:\Windows\winsxs\x86_netfx-uninstallsqlstate_sql_b03f5f7f11d50a3a_6.0.6000.20883_none_8c2eb0ea41492429\UNINST~1.SQL
  243. Status: Locked to the Windows API!
  244.  
  245. Path: C:\Windows\winsxs\x86_netfx-uninstallsqlstate_sql_b03f5f7f11d50a3a_6.0.6001.18111_none_a2d17efc27f8ebd7\UNINST~1.SQL
  246. Status: Locked to the Windows API!
  247.  
  248. Path: C:\Windows\winsxs\x86_netfx-uninstallsqlstate_sql_b03f5f7f11d50a3a_6.0.6001.22230_none_8c05ef98419e64ea\UNINST~1.SQL
  249. Status: Locked to the Windows API!
  250.  
  251. Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.16386_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config
  252. Status: Locked to the Windows API!
  253.  
  254. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6000.16708_none_2e6f68d711833115\_SMSVC~1.REG
  255. Status: Locked to the Windows API!
  256.  
  257. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6000.20864_none_2eb424f22ad51329\_SMSVC~1.REG
  258. Status: Locked to the Windows API!
  259.  
  260. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6001.18096_none_2ff255b70ef48daa\_SMSVC~1.REG
  261. Status: Locked to the Windows API!
  262.  
  263. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6001.22208_none_30df444827c761d0\_SMSVC~1.REG
  264. Status: Locked to the Windows API!
  265.  
  266. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6000.16708_none_c4f661e592b1c88e\_SERVI~1.REG
  267. Status: Locked to the Windows API!
  268.  
  269. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6000.20864_none_c53b1e00ac03aaa2\_SERVI~1.REG
  270. Status: Locked to the Windows API!
  271.  
  272. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6001.18096_none_c6794ec590232523\_SERVI~1.REG
  273. Status: Locked to the Windows API!
  274.  
  275. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6001.22208_none_c7663d56a8f5f949\_SERVI~1.REG
  276. Status: Locked to the Windows API!
  277.  
  278. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6000.16708_none_cab9e41b8efd69ed\_SERVI~1.VRG
  279. Status: Locked to the Windows API!
  280.  
  281. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6000.20864_none_cafea036a84f4c01\_SERVI~1.VRG
  282. Status: Locked to the Windows API!
  283.  
  284. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6001.18096_none_cc3cd0fb8c6ec682\_SERVI~1.VRG
  285. Status: Locked to the Windows API!
  286.  
  287. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6001.22208_none_cd29bf8ca5419aa8\_SERVI~1.VRG
  288. Status: Locked to the Windows API!
  289.  
  290. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6000.16708_none_f87832f6f02b1a0c\_SERVI~1.H
  291. Status: Locked to the Windows API!
  292.  
  293. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6000.20864_none_f8bcef12097cfc20\_SERVI~1.H
  294. Status: Locked to the Windows API!
  295.  
  296. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6001.18096_none_f9fb1fd6ed9c76a1\_SERVI~1.H
  297. Status: Locked to the Windows API!
  298.  
  299. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6000.16708_none_74dcd7a292078251\_SERVI~1.REG
  300. Status: Locked to the Windows API!
  301.  
  302. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6000.20864_none_752193bdab596465\_SERVI~1.REG
  303. Status: Locked to the Windows API!
  304.  
  305. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6001.18096_none_765fc4828f78dee6\_SERVI~1.REG
  306. Status: Locked to the Windows API!
  307.  
  308. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6001.22208_none_774cb313a84bb30c\_SERVI~1.REG
  309. Status: Locked to the Windows API!
  310.  
  311. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6000.16708_none_7aa059d88e5323b0\_SERVI~1.VRG
  312. Status: Locked to the Windows API!
  313.  
  314. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6000.20864_none_7ae515f3a7a505c4\_SERVI~1.VRG
  315. Status: Locked to the Windows API!
  316.  
  317. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6001.18096_none_7c2346b88bc48045\_SERVI~1.VRG
  318. Status: Locked to the Windows API!
  319.  
  320. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6001.22208_none_7d103549a497546b\_SERVI~1.VRG
  321. Status: Locked to the Windows API!
  322.  
  323. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_h_31bf3856ad364e35_6.0.6000.20864_none_24101549d032590a\_SERVI~1.H
  324. Status: Locked to the Windows API!
  325.  
  326. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6001.22208_none_fae80e68066f4ac7\_SERVI~1.H
  327. Status: Locked to the Windows API!
  328.  
  329. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_reg_31bf3856ad364e35_6.0.6001.22208_none_c8512a7445976b57\_SERVI~1.REG
  330. Status: Locked to the Windows API!
  331.  
  332. Path: C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18865_none_474fb235c4186a78\$$DeleteMe.ieframe.dll.01ca9c1d67aaec80.0002
  333. Status: Locked to the Windows API!
  334.  
  335. Path: C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18865_none_2a50efefa27d9172\$$DeleteMe.iertutil.dll.01ca9c1d67a08c40.0001
  336. Status: Locked to the Windows API!
  337.  
  338. Path: C:\Windows\winsxs\x86_netfx-msbuild_targetfiles_b03f5f7f11d50a3a_6.0.6001.18111_none_8d3267e17d560282\MICROS~3.TAR
  339. Status: Locked to the Windows API!
  340.  
  341. Path: C:\Windows\winsxs\x86_netfx-msbuild_targetfiles_b03f5f7f11d50a3a_6.0.6001.22230_none_7666d87d96fb7b95\MICROS~3.TAR
  342. Status: Locked to the Windows API!
  343.  
  344. Path: C:\Windows\winsxs\x86_netfx-msbuild_commontypes_schema_b03f5f7f11d50a3a_6.0.6000.16720_none_7081409dee51e2d7\MICROS~1.XSD
  345. Status: Locked to the Windows API!
  346.  
  347. Path: C:\Windows\winsxs\x86_netfx-msbuild_commontypes_schema_b03f5f7f11d50a3a_6.0.6000.20883_none_59b9574207f427ca\MICROS~1.XSD
  348. Status: Locked to the Windows API!
  349.  
  350. Path: C:\Windows\winsxs\x86_netfx-msbuild_commontypes_schema_b03f5f7f11d50a3a_6.0.6001.18111_none_705c2553eea3ef78\MICROS~1.XSD
  351. Status: Locked to the Windows API!
  352.  
  353. Path: C:\Windows\winsxs\x86_netfx-msbuild_commontypes_schema_b03f5f7f11d50a3a_6.0.6001.22230_none_599095f00849688b\MICROS~1.XSD
  354. Status: Locked to the Windows API!
  355.  
  356. Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6000.16720_none_b462fc0cbe880bcb\MICROS~1.XSD
  357. Status: Locked to the Windows API!
  358.  
  359. Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6000.20883_none_9d9b12b0d82a50be\MICROS~1.XSD
  360. Status: Locked to the Windows API!
  361.  
  362. Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6001.18111_none_b43de0c2beda186c\MICROS~1.XSD
  363. Status: Locked to the Windows API!
  364.  
  365. Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6001.22230_none_9d72515ed87f917f\MICROS~1.XSD
  366. Status: Locked to the Windows API!
  367.  
  368. Path: C:\Windows\winsxs\x86_netfx-msbuild_data_files_b03f5f7f11d50a3a_6.0.6000.16720_none_7cb07809421da431\MICROS~1.TAS
  369. Status: Locked to the Windows API!
  370.  
  371. Path: C:\Windows\winsxs\x86_netfx-msbuild_data_files_b03f5f7f11d50a3a_6.0.6000.20883_none_65e88ead5bbfe924\MICROS~1.TAS
  372. Status: Locked to the Windows API!
  373.  
  374. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6000.16720_none_ea4958dde0dcb61b\_DATAP~1.H
  375. Status: Locked to the Windows API!
  376.  
  377. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6000.16720_none_ea4958dde0dcb61b\_DATAP~2.H
  378. Status: Locked to the Windows API!
  379.  
  380. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6000.20883_none_d3816f81fa7efb0e\_DATAP~1.H
  381. Status: Locked to the Windows API!
  382.  
  383. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6000.20883_none_d3816f81fa7efb0e\_DATAP~2.H
  384. Status: Locked to the Windows API!
  385.  
  386. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6001.18111_none_ea243d93e12ec2bc\_DATAP~1.H
  387. Status: Locked to the Windows API!
  388.  
  389. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6001.18111_none_ea243d93e12ec2bc\_DATAP~2.H
  390. Status: Locked to the Windows API!
  391.  
  392. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6001.22230_none_d358ae2ffad43bcf\_DATAP~1.H
  393. Status: Locked to the Windows API!
  394.  
  395. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6001.22230_none_d358ae2ffad43bcf\_DATAP~2.H
  396. Status: Locked to the Windows API!
  397.  
  398. Path: C:\Windows\winsxs\x86_netfx-csc_exe_config_b03f5f7f11d50a3a_6.0.6000.16720_none_879a188098bde787\CSCEXE~1.CON
  399. Status: Locked to the Windows API!
  400.  
  401. Path: C:\Windows\winsxs\x86_netfx-csc_exe_config_b03f5f7f11d50a3a_6.0.6000.20883_none_70d22f24b2602c7a\CSCEXE~1.CON
  402. Status: Locked to the Windows API!
  403.  
  404. Path: C:\Windows\winsxs\x86_netfx-csc_exe_config_b03f5f7f11d50a3a_6.0.6001.18111_none_8774fd36990ff428\CSCEXE~1.CON
  405. Status: Locked to the Windows API!
  406.  
  407. Path: C:\Windows\winsxs\x86_netfx-csc_exe_config_b03f5f7f11d50a3a_6.0.6001.22230_none_70a96dd2b2b56d3b\CSCEXE~1.CON
  408. Status: Locked to the Windows API!
  409.  
  410. Path: C:\Windows\winsxs\x86_netfx-dv_aspnetmmc_chm_res_b03f5f7f11d50a3a_6.0.6000.16720_none_f49cbb9015dc43b3\DV_ASP~1.CHM
  411. Status: Locked to the Windows API!
  412.  
  413. Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6000.16720_none_7b4eba45cecd6936\IEEXEC~1.CON
  414. Status: Locked to the Windows API!
  415.  
  416. Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6000.20883_none_6486d0e9e86fae29\IEEXEC~1.CON
  417. Status: Locked to the Windows API!
  418.  
  419. Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6001.18111_none_7b299efbcf1f75d7\IEEXEC~1.CON
  420. Status: Locked to the Windows API!
  421.  
  422. Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6001.22230_none_645e0f97e8c4eeea\IEEXEC~1.CON
  423. Status: Locked to the Windows API!
  424.  
  425. Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6000.16720_none_0bca521ee450d037\NETFXS~1.HKF
  426. Status: Locked to the Windows API!
  427.  
  428. Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6000.20883_none_0c16103ffd9c63ac\NETFXS~1.HKF
  429. Status: Locked to the Windows API!
  430.  
  431. Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6001.18111_none_0dbc60fae16e5e8e\NETFXS~1.HKF
  432. Status: Locked to the Windows API!
  433.  
  434. Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6001.22230_none_0e2f5da3fa9d1ce3\NETFXS~1.HKF
  435. Status: Locked to the Windows API!
  436.  
  437. Path: C:\Windows\winsxs\x86_netfx-dv_aspnetmmc_chm_res_b03f5f7f11d50a3a_6.0.6000.20883_none_ddd4d2342f7e88a6\DV_ASP~1.CHM
  438. Status: Locked to the Windows API!
  439.  
  440. Path: C:\Windows\winsxs\x86_netfx-dv_aspnetmmc_chm_res_b03f5f7f11d50a3a_6.0.6001.18111_none_f477a046162e5054\DV_ASP~1.CHM
  441. Status: Locked to the Windows API!
  442.  
  443. Path: C:\Windows\winsxs\x86_netfx-dv_aspnetmmc_chm_res_b03f5f7f11d50a3a_6.0.6001.22230_none_ddac10e22fd3c967\DV_ASP~1.CHM
  444. Status: Locked to the Windows API!
  445.  
  446. Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6000.16720_none_9b01a5fdd9371aff\GACUTI~1.CON
  447. Status: Locked to the Windows API!
  448.  
  449. Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6000.20883_none_9b4d641ef282ae74\GACUTI~1.CON
  450. Status: Locked to the Windows API!
  451.  
  452. Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6001.18111_none_9cf3b4d9d654a956\GACUTI~1.CON
  453. Status: Locked to the Windows API!
  454.  
  455. Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6001.22230_none_9d66b182ef8367ab\GACUTI~1.CON
  456. Status: Locked to the Windows API!
  457.  
  458. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6001.18096_none_8023fb392e87c40a\_TRANS~1.INI
  459. Status: Locked to the Windows API!
  460.  
  461. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6001.18096_none_8023fb392e87c40a\_TRANS~2.INI
  462. Status: Locked to the Windows API!
  463.  
  464. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6001.22208_none_8110e9ca475a9830\_TRANS~1.INI
  465. Status: Locked to the Windows API!
  466.  
  467. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6001.22208_none_8110e9ca475a9830\_TRANS~2.INI
  468. Status: Locked to the Windows API!
  469.  
  470. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6000.16708_none_7ab8208b3397ed7d\_TRANS~1.REG
  471. Status: Locked to the Windows API!
  472.  
  473. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6000.20864_none_7afcdca64ce9cf91\_TRANS~1.REG
  474. Status: Locked to the Windows API!
  475.  
  476. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6001.18096_none_7c3b0d6b31094a12\_TRANS~1.REG
  477. Status: Locked to the Windows API!
  478.  
  479. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6001.22208_none_7d27fbfc49dc1e38\_TRANS~1.REG
  480. Status: Locked to the Windows API!
  481.  
  482. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6000.16708_none_807ba2c12fe38edc\_TRANS~1.VRG
  483. Status: Locked to the Windows API!
  484.  
  485. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6000.20864_none_80c05edc493570f0\_TRANS~1.VRG
  486. Status: Locked to the Windows API!
  487.  
  488. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6001.18096_none_81fe8fa12d54eb71\_TRANS~1.VRG
  489. Status: Locked to the Windows API!
  490.  
  491. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6001.22208_none_82eb7e324627bf97\_TRANS~1.VRG
  492. Status: Locked to the Windows API!
  493.  
  494. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_vrg_31bf3856ad364e35_6.0.6000.16708_none_c71adcbf2e98b7f5\_SERVI~1.VRG
  495. Status: Locked to the Windows API!
  496.  
  497. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_vrg_31bf3856ad364e35_6.0.6000.20864_none_c75f98da47ea9a09\_SERVI~1.VRG
  498. Status: Locked to the Windows API!
  499.  
  500. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_vrg_31bf3856ad364e35_6.0.6001.18096_none_c89dc99f2c0a148a\_SERVI~1.VRG
  501. Status: Locked to the Windows API!
  502.  
  503. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_vrg_31bf3856ad364e35_6.0.6001.22208_none_c98ab83044dce8b0\_SERVI~1.VRG
  504. Status: Locked to the Windows API!
  505.  
  506. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_h_31bf3856ad364e35_6.0.6000.16708_none_9958372092944487\_SERVI~1.H
  507. Status: Locked to the Windows API!
  508.  
  509. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_h_31bf3856ad364e35_6.0.6000.20864_none_999cf33babe6269b\_SERVI~1.H
  510. Status: Locked to the Windows API!
  511.  
  512. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_h_31bf3856ad364e35_6.0.6001.18096_none_9adb24009005a11c\_SERVI~1.H
  513. Status: Locked to the Windows API!
  514.  
  515. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_h_31bf3856ad364e35_6.0.6001.22208_none_9bc81291a8d87542\_SERVI~1.H
  516. Status: Locked to the Windows API!
  517.  
  518. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6000.16708_none_78c5c5708f85fc49\_SERVI~1.INI
  519. Status: Locked to the Windows API!
  520.  
  521. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6000.16708_none_78c5c5708f85fc49\_SERVI~2.INI
  522. Status: Locked to the Windows API!
  523.  
  524. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6000.20864_none_790a818ba8d7de5d\_SERVI~1.INI
  525. Status: Locked to the Windows API!
  526.  
  527. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6000.20864_none_790a818ba8d7de5d\_SERVI~2.INI
  528. Status: Locked to the Windows API!
  529.  
  530. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6001.18096_none_7a48b2508cf758de\_SERVI~1.INI
  531. Status: Locked to the Windows API!
  532.  
  533. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6001.18096_none_7a48b2508cf758de\_SERVI~2.INI
  534. Status: Locked to the Windows API!
  535.  
  536. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6001.22208_none_7b35a0e1a5ca2d04\_SERVI~1.INI
  537. Status: Locked to the Windows API!
  538.  
  539. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6001.22208_none_7b35a0e1a5ca2d04\_SERVI~2.INI
  540. Status: Locked to the Windows API!
  541.  
  542. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_h_31bf3856ad364e35_6.0.6000.16708_none_23cb592eb6e076f6\_SERVI~1.H
  543. Status: Locked to the Windows API!
  544.  
  545. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6000.16708_none_b25b01638e2dbfa3\_TRANS~1.H
  546. Status: Locked to the Windows API!
  547.  
  548. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6000.20864_none_b29fbd7ea77fa1b7\_TRANS~1.H
  549. Status: Locked to the Windows API!
  550.  
  551. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6001.18096_none_b3ddee438b9f1c38\_TRANS~1.H
  552. Status: Locked to the Windows API!
  553.  
  554. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6001.22208_none_b4cadcd4a471f05e\_TRANS~1.H
  555. Status: Locked to the Windows API!
  556.  
  557. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6000.16708_none_7ea10e5931166775\_TRANS~1.INI
  558. Status: Locked to the Windows API!
  559.  
  560. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6000.16708_none_7ea10e5931166775\_TRANS~2.INI
  561. Status: Locked to the Windows API!
  562.  
  563. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6000.20864_none_7ee5ca744a684989\_TRANS~1.INI
  564. Status: Locked to the Windows API!
  565.  
  566. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6000.20864_none_7ee5ca744a684989\_TRANS~2.INI
  567. Status: Locked to the Windows API!
  568.  
  569. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_reg_31bf3856ad364e35_6.0.6000.16708_none_c5e14f032f533a9c\_SERVI~1.REG
  570. Status: Locked to the Windows API!
  571.  
  572. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_reg_31bf3856ad364e35_6.0.6000.20864_none_c6260b1e48a51cb0\_SERVI~1.REG
  573. Status: Locked to the Windows API!
  574.  
  575. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_reg_31bf3856ad364e35_6.0.6001.18096_none_c7643be32cc49731\_SERVI~1.REG
  576. Status: Locked to the Windows API!
  577.  
  578. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_h_31bf3856ad364e35_6.0.6001.18096_none_254e460eb451d38b\_SERVI~1.H
  579. Status: Locked to the Windows API!
  580.  
  581. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_h_31bf3856ad364e35_6.0.6001.22208_none_263b349fcd24a7b1\_SERVI~1.H
  582. Status: Locked to the Windows API!
  583.  
  584. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_h_31bf3856ad364e35_6.0.6000.16708_none_4180b46a5c473b6d\_SMSVC~1.H
  585. Status: Locked to the Windows API!
  586.  
  587. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_h_31bf3856ad36Processes
  588. -------------------
  589. Path: System
  590. PID: 4  Status: Locked to the Windows API!
  591.  
  592. Path: C:\Windows\System32\audiodg.exe
  593. PID: 1388       Status: Locked to the Windows API!
  594.  
  595. SSDT
  596. -------------------
  597. #: 012  Function Name: NtAdjustPrivilegesToken
  598. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe00fa
  599.  
  600. #: 021  Function Name: NtAlpcConnectPort
  601. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe10a8
  602.  
  603. #: 022  Function Name: NtAlpcCreatePort
  604. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe02e0
  605.  
  606. #: 054  Function Name: NtConnectPort
  607. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf472
  608.  
  609. #: 060  Function Name: NtCreateFile
  610. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d5660d8
  611.  
  612. #: 064  Function Name: NtCreateKey
  613. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d584aa6
  614.  
  615. #: 071  Function Name: NtCreatePort
  616. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf150
  617.  
  618. #: 075  Function Name: NtCreateSection
  619. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdfb0c
  620.  
  621. #: 077  Function Name: NtCreateSymbolicLinkObject
  622. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe0d7e
  623.  
  624. #: 078  Function Name: NtCreateThread
  625. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abded16
  626.  
  627. #: 122  Function Name: NtDeleteFile
  628. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d566f9a
  629.  
  630. #: 123  Function Name: NtDeleteKey
  631. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d5864bc
  632.  
  633. #: 126  Function Name: NtDeleteValueKey
  634. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d585db2
  635.  
  636. #: 129  Function Name: NtDuplicateObject
  637. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdea78
  638.  
  639. #: 165  Function Name: NtLoadDriver
  640. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe0a00
  641.  
  642. #: 166  Function Name: NtLoadKey
  643. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d586e86
  644.  
  645. #: 167  Function Name: NtLoadKey2
  646. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d5870c4
  647.  
  648. #: 168  Function Name: NtLoadKeyEx
  649. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d587576
  650.  
  651. #: 174  Function Name: NtMakeTemporaryObject
  652. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf6f6
  653.  
  654. #: 186  Function Name: NtOpenFile
  655. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d566a8c
  656.  
  657. #: 194  Function Name: NtOpenProcess
  658. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abde7a8
  659.  
  660. #: 197  Function Name: NtOpenSection
  661. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf986
  662.  
  663. #: 201  Function Name: NtOpenThread
  664. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abde920
  665.  
  666. #: 267  Function Name: NtRenameKey
  667. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d58830c
  668.  
  669. #: 268  Function Name: NtReplaceKey
  670. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d587840
  671.  
  672. #: 276  Function Name: NtRequestWaitReplyPort
  673. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf26e
  674.  
  675. #: 280  Function Name: NtRestoreKey
  676. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d587f4c
  677.  
  678. #: 286  Function Name: NtSecureConnectPort
  679. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe079c
  680.  
  681. #: 301  Function Name: NtSetInformationFile
  682. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d5673a4
  683.  
  684. #: 314  Function Name: NtSetSecurityObject
  685. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d588894
  686.  
  687. #: 317  Function Name: NtSetSystemInformation
  688. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe0bae
  689.  
  690. #: 324  Function Name: NtSetValueKey
  691. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d5854d6
  692.  
  693. #: 326  Function Name: NtShutdownSystem
  694. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf690
  695.  
  696. #: 332  Function Name: NtSystemDebugControl
  697. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf87a
  698.  
  699. #: 334  Function Name: NtTerminateProcess
  700. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf01a
  701.  
  702. #: 335  Function Name: NtTerminateThread
  703. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdeee8
  704.  
  705. #: 382  Function Name: NtCreateThreadEx
  706. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe03ec
  707.  
  708. Stealth Objects
  709. -------------------
  710. Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
  711. Process: System Address: 0x859181f8     Size: 121
  712.  
  713. Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
  714. Process: System Address: 0x859181f8     Size: 121
  715.  
  716. Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
  717. Process: System Address: 0x859181f8     Size: 121
  718.  
  719. Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
  720. Process: System Address: 0x859181f8     Size: 121
  721.  
  722. Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
  723. Process: System Address: 0x859181f8     Size: 121
  724.  
  725. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
  726. Process: System Address: 0x859181f8     Size: 121
  727.  
  728. Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
  729. Process: System Address: 0x859181f8     Size: 121
  730.  
  731. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
  732. Process: System Address: 0x859181f8     Size: 121
  733.  
  734. Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
  735. Process: System Address: 0x859181f8     Size: 121
  736.  
  737. Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
  738. Process: System Address: 0x859181f8     Size: 121
  739.  
  740. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
  741. Process: System Address: 0x859181f8     Size: 121
  742.  
  743. Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
  744. Process: System Address: 0x859181f8     Size: 121
  745.  
  746. Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
  747. Process: System Address: 0x859181f8     Size: 121
  748.  
  749. Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
  750. Process: System Address: 0x859181f8     Size: 121
  751.  
  752. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
  753. Process: System Address: 0x859181f8     Size: 121
  754.  
  755. Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
  756. Process: System Address: 0x859181f8     Size: 121
  757.  
  758. Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
  759. Process: System Address: 0x859181f8     Size: 121
  760.  
  761. Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
  762. Process: System Address: 0x859181f8     Size: 121
  763.  
  764. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
  765. Process: System Address: 0x859181f8     Size: 121
  766.  
  767. Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
  768. Process: System Address: 0x859181f8     Size: 121
  769.  
  770. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
  771. Process: System Address: 0x859181f8     Size: 121
  772.  
  773. Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
  774. Process: System Address: 0x859181f8     Size: 121
  775.  
  776. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_CREATE]
  777. Process: System Address: 0xb058e1f8     Size: 121
  778.  
  779. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_CLOSE]
  780. Process: System Address: 0xb058e1f8     Size: 121
  781.  
  782. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_READ]
  783. Process: System Address: 0xb058e1f8     Size: 121
  784.  
  785. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_WRITE]
  786. Process: System Address: 0xb058e1f8     Size: 121
  787.  
  788. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_QUERY_INFORMATION]
  789. Process: System Address: 0xb058e1f8     Size: 121
  790.  
  791. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_SET_INFORMATION]
  792. Process: System Address: 0xb058e1f8     Size: 121
  793.  
  794. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_QUERY_EA]
  795. Process: System Address: 0xb058e1f8     Size: 121
  796.  
  797. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_SET_EA]
  798. Process: System Address: 0xb058e1f8     Size: 121
  799.  
  800. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_FLUSH_BUFFERS]
  801. Process: System Address: 0xb058e1f8     Size: 121
  802.  
  803. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_QUERY_VOLUME_INFORMATION]
  804. Process: System Address: 0xb058e1f8     Size: 121
  805.  
  806. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_SET_VOLUME_INFORMATION]
  807. Process: System Address: 0xb058e1f8     Size: 121
  808.  
  809. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_DIRECTORY_CONTROL]
  810. Process: System Address: 0xb058e1f8     Size: 121
  811.  
  812. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_FILE_SYSTEM_CONTROL]
  813. Process: System Address: 0xb058e1f8     Size: 121
  814.  
  815. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_DEVICE_CONTROL]
  816. Process: System Address: 0xb058e1f8     Size: 121
  817.  
  818. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_SHUTDOWN]
  819. Process: System Address: 0xb058e1f8     Size: 121
  820.  
  821. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_LOCK_CONTROL]
  822. Process: System Address: 0xb058e1f8     Size: 121
  823.  
  824. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_CLEANUP]
  825. Process: System Address: 0xb058e1f8     Size: 121
  826.  
  827. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_PNP]
  828. Process: System Address: 0xb058e1f8     Size: 121
  829.  
  830. Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
  831. Process: System Address: 0x869e8500     Size: 121
  832.  
  833. Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
  834. Process: System Address: 0x869e8500     Size: 121
  835.  
  836. Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
  837. Process: System Address: 0x869e8500     Size: 121
  838.  
  839. Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  840. Process: System Address: 0x869e8500     Size: 121
  841.  
  842. Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
  843. Process: System Address: 0x869e8500     Size: 121
  844.  
  845. Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
  846. Process: System Address: 0x869e8500     Size: 121
  847.  
  848. Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
  849. Process: System Address: 0x869e8500     Size: 121
  850.  
  851. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_CREATE]
  852. Process: System Address: 0x86a2a4d0     Size: 121
  853.  
  854. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_CLOSE]
  855. Process: System Address: 0x86a2a4d0     Size: 121
  856.  
  857. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_READ]
  858. Process: System Address: 0x86a2a4d0     Size: 121
  859.  
  860. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_WRITE]
  861. Process: System Address: 0x86a2a4d0     Size: 121
  862.  
  863. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_FLUSH_BUFFERS]
  864. Process: System Address: 0x86a2a4d0     Size: 121
  865.  
  866. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_DEVICE_CONTROL]
  867. Process: System Address: 0x86a2a4d0     Size: 121
  868.  
  869. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  870. Process: System Address: 0x86a2a4d0     Size: 121
  871.  
  872. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_SHUTDOWN]
  873. Process: System Address: 0x86a2a4d0     Size: 121
  874.  
  875. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_POWER]
  876. Process: System Address: 0x86a2a4d0     Size: 121
  877.  
  878. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_SYSTEM_CONTROL]
  879. Process: System Address: 0x86a2a4d0     Size: 121
  880.  
  881. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_PNP]
  882. Process: System Address: 0x86a2a4d0     Size: 121
  883.  
  884. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_CREATE]
  885. Process: System Address: 0x870c1500     Size: 121
  886.  
  887. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_CLOSE]
  888. Process: System Address: 0x870c1500     Size: 121
  889.  
  890. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_DEVICE_CONTROL]
  891. Process: System Address: 0x870c1500     Size: 121
  892.  
  893. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  894. Process: System Address: 0x870c1500     Size: 121
  895.  
  896. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_CLEANUP]
  897. Process: System Address: 0x870c1500     Size: 121
  898.  
  899. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_PNP]
  900. Process: System Address: 0x870c1500     Size: 121
  901.  
  902. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_CREATE]
  903. Process: System Address: 0x86f5c500     Size: 121
  904.  
  905. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_CLOSE]
  906. Process: System Address: 0x86f5c500     Size: 121
  907.  
  908. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_DEVICE_CONTROL]
  909. Process: System Address: 0x86f5c500     Size: 121
  910.  
  911. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  912. Process: System Address: 0x86f5c500     Size: 121
  913.  
  914. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_CLEANUP]
  915. Process: System Address: 0x86f5c500     Size: 121
  916.  
  917. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_PNP]
  918. Process: System Address: 0x86f5c500     Size: 121
  919.  
  920. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_CREATE]
  921. Process: System Address: 0x86a26458     Size: 121
  922.  
  923. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_CLOSE]
  924. Process: System Address: 0x86a26458     Size: 121
  925.  
  926. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_DEVICE_CONTROL]
  927. Process: System Address: 0x86a26458     Size: 121
  928.  
  929. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  930. Process: System Address: 0x86a26458     Size: 121
  931.  
  932. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_POWER]
  933. Process: System Address: 0x86a26458     Size: 121
  934.  
  935. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_SYSTEM_CONTROL]
  936. Process: System Address: 0x86a26458     Size: 121
  937.  
  938. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_PNP]
  939. Process: System Address: 0x86a26458     Size: 121
  940.  
  941. Object: Hidden Code [Driver: volmgr, IRP_MJ_CREATE]
  942. Process: System Address: 0x84b521f8     Size: 121
  943.  
  944. Object: Hidden Code [Driver: volmgr, IRP_MJ_READ]
  945. Process: System Address: 0x84b521f8     Size: 121
  946.  
  947. Object: Hidden Code [Driver: volmgr, IRP_MJ_WRITE]
  948. Process: System Address: 0x84b521f8     Size: 121
  949.  
  950. Object: Hidden Code [Driver: volmgr, IRP_MJ_FLUSH_BUFFERS]
  951. Process: System Address: 0x84b521f8     Size: 121
  952.  
  953. Object: Hidden Code [Driver: volmgr, IRP_MJ_DEVICE_CONTROL]
  954. Process: System Address: 0x84b521f8     Size: 121
  955.  
  956. Object: Hidden Code [Driver: volmgr, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  957. Process: System Address: 0x84b521f8     Size: 121
  958.  
  959. Object: Hidden Code [Driver: volmgr, IRP_MJ_SHUTDOWN]
  960. Process: System Address: 0x84b521f8     Size: 121
  961.  
  962. Object: Hidden Code [Driver: volmgr, IRP_MJ_CLEANUP]
  963. Process: System Address: 0x84b521f8     Size: 121
  964.  
  965. Object: Hidden Code [Driver: volmgr, IRP_MJ_POWER]
  966. Process: System Address: 0x84b521f8     Size: 121
  967.  
  968. Object: Hidden Code [Driver: volmgr, IRP_MJ_SYSTEM_CONTROL]
  969. Process: System Address: 0x84b521f8     Size: 121
  970.  
  971. Object: Hidden Code [Driver: volmgr, IRP_MJ_PNP]
  972. Process: System Address: 0x84b521f8     Size: 121
  973.  
  974. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_CREATE]
  975. Process: System Address: 0x869f9500     Size: 121
  976.  
  977. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_CLOSE]
  978. Process: System Address: 0x869f9500     Size: 121
  979.  
  980. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_DEVICE_CONTROL]
  981. Process: System Address: 0x869f9500     Size: 121
  982.  
  983. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  984. Process: System Address: 0x869f9500     Size: 121
  985.  
  986. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_POWER]
  987. Process: System Address: 0x869f9500     Size: 121
  988.  
  989. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_SYSTEM_CONTROL]
  990. Process: System Address: 0x869f9500     Size: 121
  991.  
  992. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_PNP]
  993. Process: System Address: 0x869f9500     Size: 121
  994.  
  995. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_CREATE]
  996. Process: System Address: 0x85960500     Size: 121
  997.  
  998. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_CREATE_NAMED_PIPE]
  999. Process: System Address: 0x85960500     Size: 121
  1000.  
  1001. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_CLOSE]
  1002. Process: System Address: 0x85960500     Size: 121
  1003.  
  1004. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_READ]
  1005. Process: System Address: 0x85960500     Size: 121
  1006.  
  1007. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_WRITE]
  1008. Process: System Address: 0x85960500     Size: 121
  1009.  
  1010. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_QUERY_INFORMATION]
  1011. Process: System Address: 0x85960500     Size: 121
  1012.  
  1013. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SET_INFORMATION]
  1014. Process: System Address: 0x85960500     Size: 121
  1015.  
  1016. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_QUERY_EA]
  1017. Process: System Address: 0x85960500     Size: 121
  1018.  
  1019. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SET_EA]
  1020. Process: System Address: 0x85960500     Size: 121
  1021.  
  1022. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_FLUSH_BUFFERS]
  1023. Process: System Address: 0x85960500     Size: 121
  1024.  
  1025. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_QUERY_VOLUME_INFORMATION]
  1026. Process: System Address: 0x85960500     Size: 121
  1027.  
  1028. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SET_VOLUME_INFORMATION]
  1029. Process: System Address: 0x85960500     Size: 121
  1030.  
  1031. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_DIRECTORY_CONTROL]
  1032. Process: System Address: 0x85960500     Size: 121
  1033.  
  1034. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_FILE_SYSTEM_CONTROL]
  1035. Process: System Address: 0x85960500     Size: 121
  1036.  
  1037. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_DEVICE_CONTROL]
  1038. Process: System Address: 0x85960500     Size: 121
  1039.  
  1040. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  1041. Process: System Address: 0x85960500     Size: 121
  1042.  
  1043. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SHUTDOWN]
  1044. Process: System Address: 0x85960500     Size: 121
  1045.  
  1046. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_LOCK_CONTROL]
  1047. Process: System Address: 0x85960500     Size: 121
  1048.  
  1049. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_CLEANUP]
  1050. Process: System Address: 0x85960500     Size: 121
  1051.  
  1052. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_CREATE_MAILSLOT]
  1053. Process: System Address: 0x85960500     Size: 121
  1054.  
  1055. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_QUERY_SECURITY]
  1056. Process: System Address: 0x85960500     Size: 121
  1057.  
  1058. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SET_SECURITY]
  1059. Process: System Address: 0x85960500     Size: 121
  1060.  
  1061. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_POWER]
  1062. Process: System Address: 0x85960500     Size: 121
  1063.  
  1064. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SYSTEM_CONTROL]
  1065. Process: System Address: 0x85960500     Size: 121
  1066.  
  1067. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_DEVICE_CHANGE]
  1068. Process: System Address: 0x85960500     Size: 121
  1069.  
  1070. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_QUERY_QUOTA]
  1071. Process: System Address: 0x85960500     Size: 121
  1072.  
  1073. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SET_QUOTA]
  1074. Process: System Address: 0x85960500     Size: 121
  1075.  
  1076. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_PNP]
  1077. Process: System Address: 0x85960500     Size: 121
  1078.  
  1079. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_CREATE]
  1080. Process: System Address: 0xb646c1f8     Size: 121
  1081.  
  1082. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_CLOSE]
  1083. Process: System Address: 0xb646c1f8     Size: 121
  1084.  
  1085. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_READ]
  1086. Process: System Address: 0xb646c1f8     Size: 121
  1087.  
  1088. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_WRITE]
  1089. Process: System Address: 0xb646c1f8     Size: 121
  1090.  
  1091. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_QUERY_INFORMATION]
  1092. Process: System Address: 0xb646c1f8     Size: 121
  1093.  
  1094. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_SET_INFORMATION]
  1095. Process: System Address: 0xb646c1f8     Size: 121
  1096.  
  1097. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_QUERY_VOLUME_INFORMATION]
  1098. Process: System Address: 0xb646c1f8     Size: 121
  1099.  
  1100. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_DIRECTORY_CONTROL]
  1101. Process: System Address: 0xb646c1f8     Size: 121
  1102.  
  1103. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_FILE_SYSTEM_CONTROL]
  1104. Process: System Address: 0xb646c1f8     Size: 121
  1105.  
  1106. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_DEVICE_CONTROL]
  1107. Process: System Address: 0xb646c1f8     Size: 121
  1108.  
  1109. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_SHUTDOWN]
  1110. Process: System Address: 0xb646c1f8     Size: 121
  1111.  
  1112. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_LOCK_CONTROL]
  1113. Process: System Address: 0xb646c1f8     Size: 121
  1114.  
  1115. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_CLEANUP]
  1116. Process: System Address: 0xb646c1f8     Size: 121
  1117.  
  1118. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_PNP]
  1119. Process: System Address: 0xb646c1f8     Size: 121
  1120.  
  1121. ==EOF==