Code:
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/05/24 16:06
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB0CDC000 Size: 98304 File Visible: No
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7A09000 Size: 8192 File Visible: No
Status: -
Name: PCI_PNP3612
Image Path: \Driver\PCI_PNP3612
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAFFA2000 Size: 45056 File Visible: No
Status: -
Name: spct.sys
Image Path: spct.sys
Address: 0xF74D6000 Size: 1048576 File Visible: No
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No
Status: -
Hidden/Locked Files
-------------------
Path: C:\DOOM2\INVULE~1.WAD:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
Status: Visible to the Windows API, but not on disk.
Path: C:\Dokumente und Einstellungen\Menschenfleischwolf\Anwendungsdaten\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρϴϱЄϱЃϵϳЅ
Status: Locked to the Windows API!
Path: C:\Dokumente und Einstellungen\Menschenfleischwolf\Anwendungsdaten\SecuROM\UserData\ЃϵϳЅЂϿϽϯІχϯπρЂϻϵЉЃϵϳЅ
Status: Locked to the Windows API!
Path: C:\Dokumente und Einstellungen\Menschenfleischwolf\Lokale Einstellungen\Apps\2.0\CTP9QBYY.2VR\8K8JCBBO.MJ5\manifests\Crysis-DX10 For WinXP.exe.cdf-ms
Status: Locked to the Windows API!
Path: C:\Dokumente und Einstellungen\Menschenfleischwolf\Lokale Einstellungen\Apps\2.0\CTP9QBYY.2VR\8K8JCBBO.MJ5\manifests\Crysis-DX10 For WinXP.exe.manifest
Status: Locked to the Windows API!
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0xf7aad53e
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xf7aad534
#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0xf7aad543
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0xf7aad54d
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spct.sys" at address 0xf74f5ca2
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spct.sys" at address 0xf74f6030
#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xf7aad552
#: 119 Function Name: NtOpenKey
Status: Hooked by "spct.sys" at address 0xf74d70c0
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xf7aad520
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xf7aad525
#: 160 Function Name: NtQueryKey
Status: Hooked by "spct.sys" at address 0xf74f6108
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spct.sys" at address 0xf74f5f88
#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xf7aad55c
#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xf7aad557
#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0xf7aad548
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0xf7aad52f
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x89b981f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x899081f8 Size: -
Object: Hidden Code [Driver: SscRdBus, IRP_MJ_CREATE]
Process: System Address: 0x89b991f8 Size: -
Object: Hidden Code [Driver: SscRdBus, IRP_MJ_CLOSE]
Process: System Address: 0x89b991f8 Size: -
Object: Hidden Code [Driver: SscRdBus, IRP_MJ_READ]
Process: System Address: 0x89b991f8 Size: -
Object: Hidden Code [Driver: SscRdBus, IRP_MJ_WRITE]
Process: System Address: 0x89b991f8 Size: -
Object: Hidden Code [Driver: SscRdBus, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89b991f8 Size: -
Object: Hidden Code [Driver: SscRdBus, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b991f8 Size: -
Object: Hidden Code [Driver: SscRdBus, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89b991f8 Size: -
Object: Hidden Code [Driver: SscRdBus, IRP_MJ_POWER]
Process: System Address: 0x89b991f8 Size: -
Object: Hidden Code [Driver: SscRdBus, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89b991f8 Size: -
Object: Hidden Code [Driver: SscRdBus, IRP_MJ_PNP]
Process: System Address: 0x89b991f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x89c101f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x89b9a1f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x898f41f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x898f41f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x898f41f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x898f41f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x898f41f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x898f41f8 Size: -
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x898f41f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x89c111f8 Size: -
Object: Hidden Code [Driver: ai4li3mnȅఇ牐牣,ꘘ覽물물, IRP_MJ_CREATE]
Process: System Address: 0x897531f8 Size: -
Object: Hidden Code [Driver: ai4li3mnȅఇ牐牣,ꘘ覽물물, IRP_MJ_CLOSE]
Process: System Address: 0x897531f8 Size: -
Object: Hidden Code [Driver: ai4li3mnȅఇ牐牣,ꘘ覽물물, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x897531f8 Size: -
Object: Hidden Code [Driver: ai4li3mnȅఇ牐牣,ꘘ覽물물, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x897531f8 Size: -
Object: Hidden Code [Driver: ai4li3mnȅఇ牐牣,ꘘ覽물물, IRP_MJ_POWER]
Process: System Address: 0x897531f8 Size: -
Object: Hidden Code [Driver: ai4li3mnȅఇ牐牣,ꘘ覽물물, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x897531f8 Size: -
Object: Hidden Code [Driver: ai4li3mnȅఇ牐牣,ꘘ覽물물, IRP_MJ_PNP]
Process: System Address: 0x897531f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x879101f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x879101f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x879101f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x879101f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x879101f8 Size: -
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x879101f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x8995c1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x8995c1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8995c1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8995c1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x8995c1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8995c1f8 Size: -
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x8995c1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x878df1f8 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_CREATE]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_CLOSE]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_READ]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_SHUTDOWN]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_CLEANUP]
Process: System Address: 0x878ad500 Size: -
Object: Hidden Code [Driver: Cry, IRP_MJ_PNP]
Process: System Address: 0x878ad500 Size: - |