Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- RkU Version: 3.8.388.590, Type LE (SR2)
- ==============================================
- OS Name: Windows XP
- Version 5.1.2600 (Service Pack 3)
- Number of processors #2
- ==============================================
- >SSDT State
- ==============================================
- ntkrnlpa.exe-->NtTerminateProcess, Type: Address change 0x805D29AC-->F3D3A620 [C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS]
- ==============================================
- >Shadow
- ==============================================
- ==============================================
- >Processes
- ==============================================
- 0x871C47C0 [4] System
- 0x86FE4C10 [200] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x860BE4A0 [236] C:\Program Files\iPod\bin\iPodService.exe (Apple Inc., iPodService Module (32-bit))
- 0x860AF798 [644] C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co., HP CUE Status Root)
- 0x864A0560 [748] C:\WINDOWS\explorer.exe (Microsoft Corporation, Windows Explorer)
- 0x864EE020 [764] C:\WINDOWS\system32\smss.exe (Microsoft Corporation, Windows NT Session Manager)
- 0x864A36E8 [820] C:\WINDOWS\system32\csrss.exe (Microsoft Corporation, Client Server Runtime Process)
- 0x864D9020 [844] C:\WINDOWS\system32\winlogon.exe (Microsoft Corporation, Windows NT Logon Application)
- 0x8648E458 [888] C:\WINDOWS\system32\services.exe (Microsoft Corporation, Services and Controller app)
- 0x8652E568 [900] C:\WINDOWS\system32\lsass.exe (Microsoft Corporation, LSA Shell (Export Version))
- 0x866CE7D0 [1080] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x8646A660 [1148] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x86E3EDA0 [1184] C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation, NVIDIA Driver Helper Service, Version 81.98)
- 0x8609F020 [1200] C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard Co., HP CUE Alert Popup Window Objects)
- 0x86E3E460 [1216] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x86E74CD0 [1244] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x86493020 [1284] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x870959A0 [1292] C:\Program Files\Retrospect\Retrospect 7.5\retrorun.exe (EMC Corporation, Retrospect)
- 0x87020DA0 [1336] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x860B0770 [1360] C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Hewlett-Packard, GPCore COM object)
- 0x864C1D68 [1480] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x864C4C10 [1604] C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation, Spooler SubSystem App)
- 0x8626B8B0 [1708] C:\WINDOWS\system32\MsPMSPSv.exe (Microsoft Corporation, WMDM PMSP Service)
- 0x86FE0DA0 [1780] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x86468220 [1812] C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
- 0x86E46950 [1844] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc., Apple Mobile Device Service)
- 0x86E46DA0 [1860] C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc., Bonjour Service)
- 0x864A5228 [1948] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x86FE3228 [2028] C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation, Machine Debug Manager)
- 0x8624C648 [2096] C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation, Windows Update)
- 0x862731B0 [2496] C:\WINDOWS\system32\alg.exe (Microsoft Corporation, Application Layer Gateway Service)
- 0x8622C020 [2700] C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation, WMI)
- 0x86226020 [2768] C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation, Windows Security Center Notification App)
- 0x8621FDA0 [2780] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation, CTF Loader)
- 0x86441820 [2916] C:\WINDOWS\system32\WDBtnMgr.exe (Western Digital Technologies, Inc., WD Button Manager)
- 0x860AA020 [2976] C:\Documents and Settings\Marilyn\Desktop\RKunhooker\RKUnhookerLE.EXE (UG North, RKULE, SR2 Normandy)
- 0x861D7DA0 [3024] C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated, Adobe Photo Downloader 4.0 component)
- 0x8628C020 [3136] C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe (Roxio, Drag To Disc Application)
- 0x8628CDA0 [3192] C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe (Roxio, Inc., Roxio AudioCentral Media Manager Tray App)
- 0x86209A00 [3204] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x861D6020 [3288] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc., iTunesHelper Module)
- 0x86204020 [3336] C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard, hpwuSchd Application)
- 0x861D5638 [3348] C:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services)
- 0x8628EB48 [3368] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc., GoogleToolbarNotifier)
- 0x86256020 [3612] C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co., HP Digital Imaging Monitor)
- 0x86130DA0 [3644] C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe (Roxio, Inc., Roxio AudioCentral Media Manager Playlist)
- ==============================================
- >Drivers
- ==============================================
- 0xBF9D6000 C:\WINDOWS\System32\nv4_disp.dll 3956736 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 81.98 )
- 0xF65B3000 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 3538944 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 81.98 )
- 0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2150400 bytes (Microsoft Corporation, NT Kernel & System)
- 0x804D7000 PnpManager 2150400 bytes
- 0x804D7000 RAW 2150400 bytes
- 0x804D7000 WMIxWDM 2150400 bytes
- 0xBF800000 Win32k 1851392 bytes
- 0xBF800000 C:\WINDOWS\System32\win32k.sys 1851392 bytes (Microsoft Corporation, Multi-User Win32 Driver)
- 0xF40DF000 C:\WINDOWS\system32\drivers\ha10kx2k.sys 905216 bytes (Creative Technology Ltd, Creative EMU10KX HAL (WDM))
- 0xF73D6000 iaStor.sys 749568 bytes (Intel Corporation, Intel Matrix Storage Manager driver)
- 0xF3FFF000 C:\WINDOWS\system32\drivers\ctac32k.sys 647168 bytes (Creative Technology Ltd, Creative AC3 SW Decoder Device Driver (WDM))
- 0xF72A7000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)
- 0xF3C95000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
- 0xF63BA000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver)
- 0xF6500000 C:\WINDOWS\system32\drivers\ctaud2k.sys 368640 bytes (Creative Technology Ltd, Creative WDM Audio Device Driver)
- 0xF3DEA000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver)
- 0xB9810000 C:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver)
- 0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
- 0xB8F98000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)
- 0xF3F0D000 C:\WINDOWS\System32\Drivers\cdudf_xp.SYS 262144 bytes (Roxio, CD-UDF NT Filesystem Driver)
- 0xF3E68000 C:\WINDOWS\System32\Drivers\UdfReadr_xp.SYS 217088 bytes (Roxio, CD-UDF NT Filesystem Reader Driver)
- 0xF6418000 C:\WINDOWS\system32\DRIVERS\rdpdr.sys 196608 bytes (Microsoft Corporation, Microsoft RDP Device redirector)
- 0xF74E3000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)
- 0xB997F000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
- 0xF727A000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)
- 0xF648D000 C:\WINDOWS\system32\drivers\ctoss2k.sys 180224 bytes (Creative Technology Ltd., Creative OS Services Driver (WDM))
- 0xB78D7000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)
- 0xF3D05000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
- 0xF3D74000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)
- 0xF748D000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver)
- 0xF3D9C000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator)
- 0xF3ED7000 C:\WINDOWS\System32\Drivers\DVDVRRdr_xp.SYS 147456 bytes (Roxio, DVDVR XP Filesystem Reader Driver)
- 0xB91E1000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver)
- 0xF64DC000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
- 0xF655A000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
- 0xF64B9000 C:\WINDOWS\system32\drivers\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)
- 0xF3D52000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
- 0xF40BD000 C:\WINDOWS\system32\drivers\emupia2k.sys 139264 bytes (Creative Technology Ltd, E-mu Plug-in Architecture Driver (WDM))
- 0xF3D30000 C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 139264 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASKUTIL.SYS)
- 0xF657E000 C:\WINDOWS\system32\DRIVERS\b57xp32.sys 135168 bytes (Broadcom Corporation, Broadcom NetXtreme Gigabit Ethernet NDIS5.1 Driver.)
- 0x806E4000 ACPI_HAL 134400 bytes
- 0x806E4000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
- 0xF409D000 C:\WINDOWS\system32\drivers\ctsfm2k.sys 131072 bytes (Creative Technology Ltd, SoundFont(R) Manager (WDM))
- 0xF7386000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
- 0xF74B3000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)
- 0xF6470000 C:\WINDOWS\System32\Drivers\pwd_2k.SYS 118784 bytes (Roxio, Win2000 Framework for Packet Write Driver)
- 0xF7260000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver)
- 0xF73BE000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)
- 0xBAC92000 C:\WINDOWS\System32\DLA\DLAUDFAM.SYS 98304 bytes (Sonic Solutions, Drive Letter Access Component)
- 0xF3C7D000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes
- 0xF73A6000 C:\WINDOWS\System32\Drivers\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver)
- 0xF7347000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
- 0xF6459000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
- 0xBACD2000 C:\WINDOWS\System32\DLA\DLAIFS_M.SYS 90112 bytes (Sonic Solutions, Drive Letter Access Component)
- 0xBAC7C000 C:\WINDOWS\System32\DLA\DLAUDF_M.SYS 90112 bytes (Sonic Solutions, Drive Letter Access Component)
- 0xF735E000 DRVMCDB.SYS 90112 bytes (Sonic Solutions, Device Driver)
- 0xB96E3000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)
- 0xF3FEB000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver)
- 0xF659F000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)
- 0xF3E43000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)
- 0xF7334000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)
- 0xBF9C4000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)
- 0xF7374000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)
- 0xF74D2000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
- 0xF6448000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)
- 0xF76C2000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
- 0xF7882000 C:\WINDOWS\system32\DRIVERS\mf.sys 65536 bytes (Microsoft Corporation, Multifunction Enumerator)
- 0xF76A2000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager)
- 0xF7622000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)
- 0xF7782000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client)
- 0xF7872000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
- 0xB98B7000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)
- 0xF7742000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)
- 0xF7632000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)
- 0xF7672000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)
- 0xF76B2000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver)
- 0xF76D2000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
- 0xF7652000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
- 0xF76F2000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
- 0xF77B2000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver)
- 0xF7642000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)
- 0xF76E2000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
- 0xF633A000 C:\WINDOWS\System32\Drivers\DRVNDDM.SYS 40960 bytes (Sonic Solutions, Device Driver Manager)
- 0xF7612000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver)
- 0xF7722000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)
- 0xF7712000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)
- 0xF7662000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)
- 0xF77E2000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver)
- 0xF7702000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)
- 0xF7772000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)
- 0xB946D000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
- 0xF7682000 PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
- 0xF7762000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
- 0xF78A2000 cercsr6.sys 32768 bytes (Adaptec, Inc., DELL CERC SATA1.5/6ch Miniport Driver)
- 0xF7932000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)
- 0xF798A000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
- 0xF795A000 C:\WINDOWS\System32\DLA\DLABOIOM.SYS 28672 bytes (Sonic Solutions, Drive Letter Access Component)
- 0xF79AA000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver)
- 0xF791A000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
- 0xF7892000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
- 0xF78FA000 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 28672 bytes (Microsoft Corporation, USB Mass Storage Class Driver)
- 0xF7912000 C:\WINDOWS\System32\Drivers\DLARTL_N.SYS 24576 bytes (Sonic Solutions, Shared Driver Component)
- 0xF78E2000 C:\WINDOWS\System32\Drivers\dvd_2K.SYS 24576 bytes (Roxio, DVD-RAM AddOn Driver)
- 0xF79E2000 C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)
- 0xF79BA000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)
- 0xF79C2000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)
- 0xF793A000 C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 24576 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASDIFSV.SYS)
- 0xF7982000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
- 0xF7922000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
- 0xF78EA000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver)
- 0xF792A000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)
- 0xF789A000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)
- 0xF7A12000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)
- 0xF78B2000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel(R) mini-port/call-manager driver)
- 0xF7A02000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)
- 0xF794A000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)
- 0xBAD5C000 C:\WINDOWS\System32\DLA\DLAOPIOM.SYS 16384 bytes (Sonic Solutions, Drive Letter Access Component)
- 0xF6933000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)
- 0xBACEC000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)
- 0xF7A22000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)
- 0xF3F79000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)
- 0xF7227000 C:\WINDOWS\system32\DRIVERS\gameenum.sys 12288 bytes (Microsoft Corporation, Game Port Enumerator)
- 0xF721F000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
- 0xF6316000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
- 0xF7B56000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)
- 0xF7B3E000 C:\WINDOWS\system32\drivers\ctprxy2k.sys 8192 bytes (Creative Technology Ltd, Creative Proxy Device Driver (WDM))
- 0xF7B52000 C:\WINDOWS\System32\Drivers\DLACDBHM.SYS 8192 bytes (Sonic Solutions, Shared Driver Component)
- 0xF7B7A000 C:\WINDOWS\System32\DLA\DLAPoolM.SYS 8192 bytes (Sonic Solutions, Drive Letter Access Component)
- 0xF7B16000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver)
- 0xF7B62000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes
- 0xF7B54000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)
- 0xF7B12000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
- 0xF7B58000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)
- 0xF7B5A000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)
- 0xF7B44000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
- 0xF7B4A000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
- 0xF7B14000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
- 0xF7C11000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)
- 0xF7CE6000 C:\WINDOWS\System32\Drivers\Cdr4_xp.SYS 4096 bytes (Sonic Solutions, CDR4 CD and DVD Place Holder Driver (see PxHelp))
- 0xF7C93000 C:\WINDOWS\System32\DLA\DLADResN.SYS 4096 bytes (Sonic Solutions, Drive Letter Access Component)
- 0xF7BEC000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)
- 0xF7CE8000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)
- 0xF7BDA000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
- ==============================================
- >Stealth
- ==============================================
- WARNING: Virus alike driver modification [cpqdap01.sys]
- WARNING: Virus alike driver modification [nikedrv.sys]
- WARNING: Virus alike driver modification [rio8drv.sys]
- WARNING: Virus alike driver modification [riodrv.sys]
- WARNING: Virus alike driver modification [ws2ifsl.sys]
- WARNING: Virus alike driver modification [fsvga.sys]
- WARNING: Virus alike driver modification [IntelC51.sys]
- WARNING: Virus alike driver modification [smclib.sys]
- WARNING: Virus alike driver modification [tsbvcap.sys]
- WARNING: Virus alike driver modification [cinemst2.sys]
- WARNING: Virus alike driver modification [atmepvc.sys]
- WARNING: Virus alike driver modification [rawwan.sys]
- WARNING: Virus alike driver modification [atmuni.sys]
- WARNING: Virus alike driver modification [mohfilt.sys]
- WARNING: Virus alike driver modification [wpdusb.sys]
- WARNING: Virus alike driver modification [wmilib.sys]
- WARNING: Virus alike driver modification [IntelC53.sys]
- WARNING: Virus alike driver modification [tosdvd.sys]
- WARNING: Virus alike driver modification [nwlnkspx.sys]
- WARNING: Virus alike driver modification [vdmindvd.sys]
- WARNING: Virus alike driver modification [rootmdm.sys]
- WARNING: Virus alike driver modification [IntelC52.sys]
- WARNING: Virus alike driver modification [nwlnknb.sys]
- WARNING: Virus alike driver modification [enum1394.sys]
- WARNING: Virus alike driver modification [pfmodnt.sys]
- WARNING: Virus alike driver modification [mcd.sys]
- ==============================================
- >Files
- ==============================================
- !-->[Hidden] C:\Qoobox\BackEnv\AppData.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Cache.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Cookies.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Desktop.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Favorites.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\History.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\LocalAppData.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\LocalSettings.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Music.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\NetHood.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Personal.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Pictures.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\PrintHood.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Profiles.Folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Programs.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Recent.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\SendTo.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\SetPath.bat
- !-->[Hidden] C:\Qoobox\BackEnv\StartMenu.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\StartUp.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\SysPath.dat
- !-->[Hidden] C:\Qoobox\BackEnv\Templates.folder.dat
- !-->[Hidden] C:\Qoobox\BackEnv\VikPev00
- ==============================================
- >Hooks
- ==============================================
- ntkrnlpa.exe+0x0006ECAE, Type: Inline - RelativeJump 0x80545CAE-->80545CB5 [ntkrnlpa.exe]
- !!POSSIBLE ROOTKIT ACTIVITY DETECTED!! =)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement