Moriarty | 10.08.2010 17:38 | Hier die Logs von RootRepeal, zunächst vom Scan: Code:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/08/10 18:33
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
-------------------
Name: 1394BUS.SYS
Image Path: C:\Windows\system32\DRIVERS\1394BUS.SYS
Address: 0x9212C000 Size: 57344 File Visible: - Signed: -
Status: -
Name: acpi.sys
Image Path: C:\Windows\system32\drivers\acpi.sys
Address: 0x807B8000 Size: 286720 File Visible: - Signed: -
Status: -
Name: ACPI_HAL
Image Path: \Driver\ACPI_HAL
Address: 0x8361A000 Size: 3903488 File Visible: - Signed: -
Status: -
Name: afd.sys
Image Path: C:\Windows\system32\drivers\afd.sys
Address: 0x93357000 Size: 294912 File Visible: - Signed: -
Status: -
Name: atapi.sys
Image Path: C:\Windows\system32\drivers\atapi.sys
Address: 0x8BC82000 Size: 32768 File Visible: - Signed: -
Status: -
Name: ataport.SYS
Image Path: C:\Windows\system32\drivers\ataport.SYS
Address: 0x8BC8A000 Size: 122880 File Visible: - Signed: -
Status: -
Name: BATTC.SYS
Image Path: C:\Windows\system32\DRIVERS\BATTC.SYS
Address: 0x805F5000 Size: 40960 File Visible: - Signed: -
Status: -
Name: bcm4sbxp.sys
Image Path: C:\Windows\system32\DRIVERS\bcm4sbxp.sys
Address: 0x9210B000 Size: 69632 File Visible: - Signed: -
Status: -
Name: bcmwl6.sys
Image Path: C:\Windows\system32\DRIVERS\bcmwl6.sys
Address: 0x9200A000 Size: 1052672 File Visible: - Signed: -
Status: -
Name: Beep.SYS
Image Path: C:\Windows\System32\Drivers\Beep.SYS
Address: 0x92C9A000 Size: 28672 File Visible: - Signed: -
Status: -
Name: BOOTVID.dll
Image Path: C:\Windows\system32\BOOTVID.dll
Address: 0x8048B000 Size: 32768 File Visible: - Signed: -
Status: -
Name: bowser.sys
Image Path: C:\Windows\system32\DRIVERS\bowser.sys
Address: 0x93266000 Size: 102400 File Visible: - Signed: -
Status: -
Name: BthEnum.sys
Image Path: C:\Windows\system32\DRIVERS\BthEnum.sys
Address: 0xA33E0000 Size: 40960 File Visible: - Signed: -
Status: -
Name: bthmodem.sys
Image Path: C:\Windows\system32\DRIVERS\bthmodem.sys
Address: 0xA33EA000 Size: 61440 File Visible: - Signed: -
Status: -
Name: bthpan.sys
Image Path: C:\Windows\system32\DRIVERS\bthpan.sys
Address: 0x92F13000 Size: 106496 File Visible: - Signed: -
Status: -
Name: bthport.sys
Image Path: C:\Windows\System32\Drivers\bthport.sys
Address: 0xA3337000 Size: 524288 File Visible: - Signed: -
Status: -
Name: BTHUSB.sys
Image Path: C:\Windows\System32\Drivers\BTHUSB.sys
Address: 0xA332A000 Size: 53248 File Visible: - Signed: -
Status: -
Name: cdd.dll
Image Path: C:\Windows\System32\cdd.dll
Address: 0x81720000 Size: 57344 File Visible: - Signed: -
Status: -
Name: cdfs.sys
Image Path: C:\Windows\system32\DRIVERS\cdfs.sys
Address: 0xA32FD000 Size: 90112 File Visible: - Signed: -
Status: -
Name: cdrom.sys
Image Path: C:\Windows\system32\DRIVERS\cdrom.sys
Address: 0x8C3D8000 Size: 98304 File Visible: - Signed: -
Status: -
Name: CI.dll
Image Path: C:\Windows\system32\CI.dll
Address: 0x804D4000 Size: 917504 File Visible: - Signed: -
Status: -
Name: CLASSPNP.SYS
Image Path: C:\Windows\system32\drivers\CLASSPNP.SYS
Address: 0x8C965000 Size: 135168 File Visible: - Signed: -
Status: -
Name: CLFS.SYS
Image Path: C:\Windows\system32\CLFS.SYS
Address: 0x80493000 Size: 266240 File Visible: - Signed: -
Status: -
Name: CmBatt.sys
Image Path: C:\Windows\system32\DRIVERS\CmBatt.sys
Address: 0x921FB000 Size: 14208 File Visible: - Signed: -
Status: -
Name: compbatt.sys
Image Path: C:\Windows\system32\DRIVERS\compbatt.sys
Address: 0x805F2000 Size: 10496 File Visible: - Signed: -
Status: -
Name: crashdmp.sys
Image Path: C:\Windows\System32\Drivers\crashdmp.sys
Address: 0x93079000 Size: 53248 File Visible: - Signed: -
Status: -
Name: crcdisk.sys
Image Path: C:\Windows\system32\drivers\crcdisk.sys
Address: 0x8C986000 Size: 36864 File Visible: - Signed: -
Status: -
Name: csc.sys
Image Path: C:\Windows\system32\drivers\csc.sys
Address: 0x92EA1000 Size: 372736 File Visible: - Signed: -
Status: -
Name: dfsc.sys
Image Path: C:\Windows\System32\Drivers\dfsc.sys
Address: 0x92EFC000 Size: 94208 File Visible: - Signed: -
Status: -
Name: disk.sys
Image Path: C:\Windows\system32\drivers\disk.sys
Address: 0x8C954000 Size: 69632 File Visible: - Signed: -
Status: -
Name: drmk.sys
Image Path: C:\Windows\system32\drivers\drmk.sys
Address: 0x925D4000 Size: 151552 File Visible: - Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x93091000 Size: 32768 File Visible: No Signed: -
Status: -
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x93086000 Size: 45056 File Visible: No Signed: -
Status: -
Name: Dxapi.sys
Image Path: C:\Windows\System32\drivers\Dxapi.sys
Address: 0x93099000 Size: 40960 File Visible: - Signed: -
Status: -
Name: dxgkrnl.sys
Image Path: C:\Windows\System32\drivers\dxgkrnl.sys
Address: 0x91F5D000 Size: 659456 File Visible: - Signed: -
Status: -
Name: ecache.sys
Image Path: C:\Windows\System32\drivers\ecache.sys
Address: 0x8C92D000 Size: 159744 File Visible: - Signed: -
Status: -
Name: fileinfo.sys
Image Path: C:\Windows\system32\drivers\fileinfo.sys
Address: 0x8BCE4000 Size: 65536 File Visible: - Signed: -
Status: -
Name: fltmgr.sys
Image Path: C:\Windows\system32\drivers\fltmgr.sys
Address: 0x8BCB2000 Size: 204800 File Visible: - Signed: -
Status: -
Name: Fs_Rec.SYS
Image Path: C:\Windows\System32\Drivers\Fs_Rec.SYS
Address: 0x92C8A000 Size: 36864 File Visible: - Signed: -
Status: -
Name: fwpkclnt.sys
Image Path: C:\Windows\System32\drivers\fwpkclnt.sys
Address: 0x8C0F1000 Size: 110592 File Visible: - Signed: -
Status: -
Name: hal.dll
Image Path: C:\Windows\system32\hal.dll
Address: 0x839D3000 Size: 208896 File Visible: - Signed: -
Status: -
Name: HDAudBus.sys
Image Path: C:\Windows\system32\DRIVERS\HDAudBus.sys
Address: 0x8C10C000 Size: 577536 File Visible: - Signed: -
Status: -
Name: HIDCLASS.SYS
Image Path: C:\Windows\system32\DRIVERS\HIDCLASS.SYS
Address: 0x92F2D000 Size: 65536 File Visible: - Signed: -
Status: -
Name: HIDPARSE.SYS
Image Path: C:\Windows\system32\DRIVERS\HIDPARSE.SYS
Address: 0x92CAA000 Size: 28672 File Visible: - Signed: -
Status: -
Name: hidusb.sys
Image Path: C:\Windows\system32\DRIVERS\hidusb.sys
Address: 0xA3200000 Size: 36864 File Visible: - Signed: -
Status: -
Name: HTTP.sys
Image Path: C:\Windows\system32\drivers\HTTP.sys
Address: 0x931DC000 Size: 446464 File Visible: - Signed: -
Status: -
Name: i8042prt.sys
Image Path: C:\Windows\system32\DRIVERS\i8042prt.sys
Address: 0x921C7000 Size: 77824 File Visible: - Signed: -
Status: -
Name: intelide.sys
Image Path: C:\Windows\system32\drivers\intelide.sys
Address: 0x8BC5D000 Size: 28672 File Visible: - Signed: -
Status: -
Name: intelppm.sys
Image Path: C:\Windows\system32\DRIVERS\intelppm.sys
Address: 0x8C9D5000 Size: 61440 File Visible: - Signed: -
Status: -
Name: kbdclass.sys
Image Path: C:\Windows\system32\DRIVERS\kbdclass.sys
Address: 0x921F0000 Size: 45056 File Visible: - Signed: -
Status: -
Name: kbdhid.sys
Image Path: C:\Windows\system32\DRIVERS\kbdhid.sys
Address: 0x92F3D000 Size: 36864 File Visible: - Signed: -
Status: -
Name: kdcom.dll
Image Path: C:\Windows\system32\kdcom.dll
Address: 0x80403000 Size: 28672 File Visible: - Signed: -
Status: -
Name: kglyruod.sys
Image Path: C:\Users\***~1\AppData\Local\Temp\kglyruod.sys
Address: 0xA3313000 Size: 93056 File Visible: No Signed: -
Status: -
Name: kl1.sys
Image Path: C:\Windows\system32\DRIVERS\kl1.sys
Address: 0x8C40B000 Size: 5382144 File Visible: - Signed: -
Status: -
Name: klif.sys
Image Path: C:\Windows\system32\DRIVERS\klif.sys
Address: 0x92C0A000 Size: 524288 File Visible: - Signed: -
Status: -
Name: klim6.sys
Image Path: C:\Windows\system32\DRIVERS\klim6.sys
Address: 0x933E7000 Size: 32768 File Visible: - Signed: -
Status: -
Name: klmouflt.sys
Image Path: C:\Windows\system32\DRIVERS\klmouflt.sys
Address: 0x921DC000 Size: 36864 File Visible: - Signed: -
Status: -
Name: ks.sys
Image Path: C:\Windows\system32\DRIVERS\ks.sys
Address: 0x9249C000 Size: 172032 File Visible: - Signed: -
Status: -
Name: ksecdd.sys
Image Path: C:\Windows\System32\Drivers\ksecdd.sys
Address: 0x8BCFD000 Size: 462848 File Visible: - Signed: -
Status: -
Name: lltdio.sys
Image Path: C:\Windows\system32\DRIVERS\lltdio.sys
Address: 0x93185000 Size: 65536 File Visible: - Signed: -
Status: -
Name: luafv.sys
Image Path: C:\Windows\system32\drivers\luafv.sys
Address: 0x930B2000 Size: 110592 File Visible: - Signed: -
Status: -
Name: mcupdate_GenuineIntel.dll
Image Path: C:\Windows\system32\mcupdate_GenuineIntel.dll
Address: 0x8040A000 Size: 458752 File Visible: - Signed: -
Status: -
Name: modem.sys
Image Path: C:\Windows\system32\drivers\modem.sys
Address: 0x92BBB000 Size: 53248 File Visible: - Signed: -
Status: -
Name: monitor.sys
Image Path: C:\Windows\system32\DRIVERS\monitor.sys
Address: 0x930A3000 Size: 61440 File Visible: - Signed: -
Status: -
Name: mouclass.sys
Image Path: C:\Windows\system32\DRIVERS\mouclass.sys
Address: 0x921E5000 Size: 45056 File Visible: - Signed: -
Status: -
Name: mouhid.sys
Image Path: C:\Windows\system32\DRIVERS\mouhid.sys
Address: 0x92F46000 Size: 32768 File Visible: - Signed: -
Status: -
Name: mountmgr.sys
Image Path: C:\Windows\System32\drivers\mountmgr.sys
Address: 0x8BC72000 Size: 65536 File Visible: - Signed: -
Status: -
Name: mpsdrv.sys
Image Path: C:\Windows\System32\drivers\mpsdrv.sys
Address: 0x9327F000 Size: 86016 File Visible: - Signed: -
Status: -
Name: mrxdav.sys
Image Path: C:\Windows\system32\drivers\mrxdav.sys
Address: 0x93294000 Size: 135168 File Visible: - Signed: -
Status: -
Name: mrxsmb.sys
Image Path: C:\Windows\system32\DRIVERS\mrxsmb.sys
Address: 0x932B5000 Size: 126976 File Visible: - Signed: -
Status: -
Name: mrxsmb10.sys
Image Path: C:\Windows\system32\DRIVERS\mrxsmb10.sys
Address: 0x932D4000 Size: 233472 File Visible: - Signed: -
Status: -
Name: mrxsmb20.sys
Image Path: C:\Windows\system32\DRIVERS\mrxsmb20.sys
Address: 0x9330D000 Size: 98304 File Visible: - Signed: -
Status: -
Name: msahci.sys
Image Path: C:\Windows\system32\drivers\msahci.sys
Address: 0x8BCA8000 Size: 40960 File Visible: - Signed: -
Status: -
Name: Msfs.SYS
Image Path: C:\Windows\System32\Drivers\Msfs.SYS
Address: 0x92CEE000 Size: 45056 File Visible: - Signed: -
Status: -
Name: msisadrv.sys
Image Path: C:\Windows\system32\drivers\msisadrv.sys
Address: 0x805B4000 Size: 32768 File Visible: - Signed: -
Status: -
Name: msiscsi.sys
Image Path: C:\Windows\system32\DRIVERS\msiscsi.sys
Address: 0x8C1C4000 Size: 192512 File Visible: - Signed: -
Status: -
Name: msrpc.sys
Image Path: C:\Windows\system32\drivers\msrpc.sys
Address: 0x8BF0C000 Size: 176128 File Visible: - Signed: -
Status: -
Name: mssmbios.sys
Image Path: C:\Windows\system32\DRIVERS\mssmbios.sys
Address: 0x924C6000 Size: 40960 File Visible: - Signed: -
Status: -
Name: mup.sys
Image Path: C:\Windows\System32\Drivers\mup.sys
Address: 0x8C38B000 Size: 61440 File Visible: - Signed: -
Status: -
Name: ndis.sys
Image Path: C:\Windows\system32\drivers\ndis.sys
Address: 0x8BE01000 Size: 1093632 File Visible: - Signed: -
Status: -
Name: ndistapi.sys
Image Path: C:\Windows\system32\DRIVERS\ndistapi.sys
Address: 0x8C3F0000 Size: 45056 File Visible: - Signed: -
Status: -
Name: ndisuio.sys
Image Path: C:\Windows\system32\DRIVERS\ndisuio.sys
Address: 0x931BF000 Size: 40960 File Visible: - Signed: -
Status: -
Name: ndiswan.sys
Image Path: C:\Windows\system32\DRIVERS\ndiswan.sys
Address: 0x8BFCA000 Size: 143360 File Visible: - Signed: -
Status: -
Name: NDProxy.SYS
Image Path: C:\Windows\System32\Drivers\NDProxy.SYS
Address: 0x92543000 Size: 69632 File Visible: - Signed: -
Status: -
Name: netbios.sys
Image Path: C:\Windows\system32\DRIVERS\netbios.sys
Address: 0x933EF000 Size: 57344 File Visible: - Signed: -
Status: -
Name: netbt.sys
Image Path: C:\Windows\System32\DRIVERS\netbt.sys
Address: 0x9339F000 Size: 204800 File Visible: - Signed: -
Status: -
Name: NETIO.SYS
Image Path: C:\Windows\system32\drivers\NETIO.SYS
Address: 0x8BF37000 Size: 241664 File Visible: - Signed: -
Status: -
Name: Npfs.SYS
Image Path: C:\Windows\System32\Drivers\Npfs.SYS
Address: 0x92CF9000 Size: 57344 File Visible: - Signed: -
Status: -
Name: nsiproxy.sys
Image Path: C:\Windows\system32\drivers\nsiproxy.sys
Address: 0x92E97000 Size: 40960 File Visible: - Signed: -
Status: -
Name: Ntfs.sys
Image Path: C:\Windows\System32\Drivers\Ntfs.sys
Address: 0x8C207000 Size: 1114112 File Visible: - Signed: -
Status: -
Name: ntkrnlpa.exe
Image Path: C:\Windows\system32\ntkrnlpa.exe
Address: 0x8361A000 Size: 3903488 File Visible: - Signed: -
Status: -
Name: Null.SYS
Image Path: C:\Windows\System32\Drivers\Null.SYS
Address: 0x92C93000 Size: 28672 File Visible: - Signed: -
Status: -
Name: nvBridge.kmd
Image Path: C:\Windows\system32\DRIVERS\nvBridge.kmd
Address: 0x91F5B000 Size: 8192 File Visible: - Signed: -
Status: -
Name: nvlddmkm.sys
Image Path: C:\Windows\system32\DRIVERS\nvlddmkm.sys
Address: 0x9160A000 Size: 9768640 File Visible: - Signed: -
Status: -
Name: nwifi.sys
Image Path: C:\Windows\system32\DRIVERS\nwifi.sys
Address: 0x93195000 Size: 172032 File Visible: - Signed: -
Status: -
Name: OEM02Dev.sys
Image Path: C:\Windows\system32\DRIVERS\OEM02Dev.sys
Address: 0x93013000 Size: 235648 File Visible: - Signed: -
Status: -
Name: OEM02Vfx.sys
Image Path: C:\Windows\system32\DRIVERS\OEM02Vfx.sys
Address: 0x9304D000 Size: 7424 File Visible: - Signed: -
Status: -
Name: ohci1394.sys
Image Path: C:\Windows\system32\DRIVERS\ohci1394.sys
Address: 0x9211C000 Size: 62208 File Visible: - Signed: -
Status: -
Name: pacer.sys
Image Path: C:\Windows\system32\DRIVERS\pacer.sys
Address: 0x933D1000 Size: 90112 File Visible: - Signed: -
Status: -
Name: partmgr.sys
Image Path: C:\Windows\System32\drivers\partmgr.sys
Address: 0x805E3000 Size: 61440 File Visible: - Signed: -
Status: -
Name: pci.sys
Image Path: C:\Windows\system32\drivers\pci.sys
Address: 0x805BC000 Size: 159744 File Visible: - Signed: -
Status: -
Name: PCIIDEX.SYS
Image Path: C:\Windows\system32\drivers\PCIIDEX.SYS
Address: 0x8BC64000 Size: 57344 File Visible: - Signed: -
Status: -
Name: peauth.sys
Image Path: C:\Windows\system32\drivers\peauth.sys
Address: 0xA3209000 Size: 909312 File Visible: - Signed: -
Status: -
Name: PnpManager
Image Path: \Driver\PnpManager
Address: 0x8361A000 Size: 3903488 File Visible: - Signed: -
Status: -
Name: portcls.sys
Image Path: C:\Windows\system32\drivers\portcls.sys
Address: 0x925A7000 Size: 184320 File Visible: - Signed: -
Status: -
Name: PSHED.dll
Image Path: C:\Windows\system32\PSHED.dll
Address: 0x8047A000 Size: 69632 File Visible: - Signed: -
Status: -
Name: PxHelp20.sys
Image Path: C:\Windows\System32\Drivers\PxHelp20.sys
Address: 0x8BCF4000 Size: 36320 File Visible: - Signed: -
Status: -
Name: rasacd.sys
Image Path: C:\Windows\System32\DRIVERS\rasacd.sys
Address: 0x92D07000 Size: 36864 File Visible: - Signed: -
Status: -
Name: rasl2tp.sys
Image Path: C:\Windows\system32\DRIVERS\rasl2tp.sys
Address: 0x8BFB3000 Size: 94208 File Visible: - Signed: -
Status: -
Name: raspppoe.sys
Image Path: C:\Windows\system32\DRIVERS\raspppoe.sys
Address: 0x8BFED000 Size: 61440 File Visible: - Signed: -
Status: -
Name: raspptp.sys
Image Path: C:\Windows\system32\DRIVERS\raspptp.sys
Address: 0x8BD6E000 Size: 81920 File Visible: - Signed: -
Status: -
Name: rassstp.sys
Image Path: C:\Windows\system32\DRIVERS\rassstp.sys
Address: 0x8BD82000 Size: 86016 File Visible: - Signed: -
Status: -
Name: RAW
Image Path: \FileSystem\RAW
Address: 0x8361A000 Size: 3903488 File Visible: - Signed: -
Status: -
Name: rdbss.sys
Image Path: C:\Windows\system32\DRIVERS\rdbss.sys
Address: 0x92E5B000 Size: 245760 File Visible: - Signed: -
Status: -
Name: RDPCDD.sys
Image Path: C:\Windows\System32\DRIVERS\RDPCDD.sys
Address: 0x92CDE000 Size: 32768 File Visible: - Signed: -
Status: -
Name: rdpdr.sys
Image Path: C:\Windows\system32\DRIVERS\rdpdr.sys
Address: 0x92401000 Size: 561152 File Visible: - Signed: -
Status: -
Name: rdpencdd.sys
Image Path: C:\Windows\system32\drivers\rdpencdd.sys
Address: 0x92CE6000 Size: 32768 File Visible: - Signed: -
Status: -
Name: rfcomm.sys
Image Path: C:\Windows\system32\DRIVERS\rfcomm.sys
Address: 0xA33B7000 Size: 167936 File Visible: - Signed: -
Status: -
Name: rimmptsk.sys
Image Path: C:\Windows\system32\DRIVERS\rimmptsk.sys
Address: 0x92154000 Size: 57344 File Visible: - Signed: -
Status: -
Name: rimsptsk.sys
Image Path: C:\Windows\system32\DRIVERS\rimsptsk.sys
Address: 0x92162000 Size: 81920 File Visible: - Signed: -
Status: -
Name: rixdptsk.sys
Image Path: C:\Windows\system32\DRIVERS\rixdptsk.sys
Address: 0x92176000 Size: 331776 File Visible: - Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x92F4E000 Size: 49152 File Visible: No Signed: -
Status: -
Name: rspndr.sys
Image Path: C:\Windows\system32\DRIVERS\rspndr.sys
Address: 0x931C9000 Size: 77824 File Visible: - Signed: -
Status: -
Name: SCSIPORT.SYS
Image Path: C:\Windows\System32\Drivers\SCSIPORT.SYS
Address: 0x80792000 Size: 155648 File Visible: - Signed: -
Status: -
Name: sdbus.sys
Image Path: C:\Windows\system32\DRIVERS\sdbus.sys
Address: 0x9213A000 Size: 106496 File Visible: - Signed: -
Status: -
Name: secdrv.SYS
Image Path: C:\Windows\System32\Drivers\secdrv.SYS
Address: 0xA32E7000 Size: 40960 File Visible: - Signed: -
Status: -
Name: serscan.sys
Image Path: C:\Windows\system32\DRIVERS\serscan.sys
Address: 0x91600000 Size: 32768 File Visible: - Signed: -
Status: -
Name: sfdrv01.sys
Image Path: C:\Windows\System32\drivers\sfdrv01.sys
Address: 0x8C378000 Size: 77824 File Visible: - Signed: -
Status: -
Name: sfhlp02.sys
Image Path: C:\Windows\System32\drivers\sfhlp02.sys
Address: 0x8C370000 Size: 32768 File Visible: - Signed: -
Status: -
Name: sfvfs02.sys
Image Path: C:\Windows\System32\drivers\sfvfs02.sys
Address: 0x8C358000 Size: 98304 File Visible: - Signed: -
Status: -
Name: smb.sys
Image Path: C:\Windows\system32\DRIVERS\smb.sys
Address: 0x93343000 Size: 81920 File Visible: - Signed: -
Status: -
Name: spldr.sys
Image Path: C:\Windows\System32\Drivers\spldr.sys
Address: 0x8C350000 Size: 32768 File Visible: - Signed: -
Status: -
Name: sppj.sys
Image Path: C:\Windows\System32\Drivers\sppj.sys
Address: 0x80689000 Size: 1048576 File Visible: No Signed: -
Status: -
Name: spsys.sys
Image Path: C:\Windows\system32\drivers\spsys.sys
Address: 0x930D5000 Size: 720896 File Visible: - Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: srv.sys
Image Path: C:\Windows\System32\DRIVERS\srv.sys
Address: 0x92D4D000 Size: 319488 File Visible: - Signed: -
Status: -
Name: srv2.sys
Image Path: C:\Windows\System32\DRIVERS\srv2.sys
Address: 0x92D26000 Size: 159744 File Visible: - Signed: -
Status: -
Name: srvnet.sys
Image Path: C:\Windows\System32\DRIVERS\srvnet.sys
Address: 0x93249000 Size: 118784 File Visible: - Signed: -
Status: -
Name: storport.sys
Image Path: C:\Windows\system32\DRIVERS\storport.sys
Address: 0x8BF72000 Size: 266240 File Visible: - Signed: -
Status: -
Name: stwrt.sys
Image Path: C:\Windows\system32\drivers\stwrt.sys
Address: 0x92554000 Size: 339968 File Visible: - Signed: -
Status: -
Name: swenum.sys
Image Path: C:\Windows\system32\DRIVERS\swenum.sys
Address: 0x9249A000 Size: 4992 File Visible: - Signed: -
Status: -
Name: SynTP.sys
Image Path: C:\Windows\system32\DRIVERS\SynTP.sys
Address: 0x8C199000 Size: 175488 File Visible: - Signed: -
Status: -
Name: tap0901.sys
Image Path: C:\Windows\system32\DRIVERS\tap0901.sys
Address: 0x8C200000 Size: 25216 File Visible: - Signed: -
Status: -
Name: tcpip.sys
Image Path: C:\Windows\System32\drivers\tcpip.sys
Address: 0x8C007000 Size: 958464 File Visible: - Signed: -
Status: -
Name: tcpipreg.sys
Image Path: C:\Windows\System32\drivers\tcpipreg.sys
Address: 0xA32F1000 Size: 49152 File Visible: - Signed: -
Status: -
Name: TDI.SYS
Image Path: C:\Windows\system32\DRIVERS\TDI.SYS
Address: 0x8C400000 Size: 45056 File Visible: - Signed: -
Status: -
Name: tdx.sys
Image Path: C:\Windows\system32\DRIVERS\tdx.sys
Address: 0x92D10000 Size: 90112 File Visible: - Signed: -
Status: -
Name: termdd.sys
Image Path: C:\Windows\system32\DRIVERS\termdd.sys
Address: 0x9248A000 Size: 65536 File Visible: - Signed: -
Status: -
Name: TMPassthru.sys
Image Path: C:\Windows\system32\DRIVERS\TMPassthru.sys
Address: 0x924D0000 Size: 199936 File Visible: - Signed: -
Status: -
Name: TSDDD.dll
Image Path: C:\Windows\System32\TSDDD.dll
Address: 0x81700000 Size: 36864 File Visible: - Signed: -
Status: -
Name: tunmp.sys
Image Path: C:\Windows\system32\DRIVERS\tunmp.sys
Address: 0x8C9CC000 Size: 36864 File Visible: - Signed: -
Status: -
Name: tunnel.sys
Image Path: C:\Windows\system32\DRIVERS\tunnel.sys
Address: 0x8C9AF000 Size: 45056 File Visible: - Signed: -
Status: -
Name: uiwbrdr.sys
Image Path: C:\Windows\System32\DRIVERS\uiwbrdr.sys
Address: 0x92E13000 Size: 294912 File Visible: - Signed: -
Status: -
Name: umbus.sys
Image Path: C:\Windows\system32\DRIVERS\umbus.sys
Address: 0x92501000 Size: 53248 File Visible: - Signed: -
Status: -
Name: usbccgp.sys
Image Path: C:\Windows\system32\DRIVERS\usbccgp.sys
Address: 0x92FED000 Size: 94208 File Visible: - Signed: -
Status: -
Name: USBD.SYS
Image Path: C:\Windows\system32\DRIVERS\USBD.SYS
Address: 0x921DA000 Size: 8192 File Visible: - Signed: -
Status: -
Name: usbehci.sys
Image Path: C:\Windows\system32\DRIVERS\usbehci.sys
Address: 0x8C9BA000 Size: 61440 File Visible: - Signed: -
Status: -
Name: usbhub.sys
Image Path: C:\Windows\system32\DRIVERS\usbhub.sys
Address: 0x9250E000 Size: 217088 File Visible: - Signed: -
Status: -
Name: USBPORT.SYS
Image Path: C:\Windows\system32\DRIVERS\USBPORT.SYS
Address: 0x8C39A000 Size: 253952 File Visible: - Signed: -
Status: -
Name: USBSTOR.SYS
Image Path: C:\Windows\system32\DRIVERS\USBSTOR.SYS
Address: 0x9332E000 Size: 86016 File Visible: - Signed: -
Status: -
Name: usbuhci.sys
Image Path: C:\Windows\system32\DRIVERS\usbuhci.sys
Address: 0x8C9F0000 Size: 45056 File Visible: - Signed: -
Status: -
Name: vga.sys
Image Path: C:\Windows\System32\drivers\vga.sys
Address: 0x92CB1000 Size: 49152 File Visible: - Signed: -
Status: -
Name: VIDEOPRT.SYS
Image Path: C:\Windows\System32\drivers\VIDEOPRT.SYS
Address: 0x92CBD000 Size: 135168 File Visible: - Signed: -
Status: -
Name: volmgr.sys
Image Path: C:\Windows\system32\drivers\volmgr.sys
Address: 0x8BC04000 Size: 61440 File Visible: - Signed: -
Status: -
Name: volmgrx.sys
Image Path: C:\Windows\System32\drivers\volmgrx.sys
Address: 0x8BC13000 Size: 303104 File Visible: - Signed: -
Status: -
Name: volsnap.sys
Image Path: C:\Windows\system32\drivers\volsnap.sys
Address: 0x8C317000 Size: 233472 File Visible: - Signed: -
Status: -
Name: VSTAZL3.SYS
Image Path: C:\Windows\system32\DRIVERS\VSTAZL3.SYS
Address: 0x8BD97000 Size: 245760 File Visible: - Signed: -
Status: -
Name: VSTCNXT3.SYS
Image Path: C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
Address: 0x92B08000 Size: 733184 File Visible: - Signed: -
Status: -
Name: VSTDPV3.SYS
Image Path: C:\Windows\system32\DRIVERS\VSTDPV3.SYS
Address: 0x92A04000 Size: 1064960 File Visible: - Signed: -
Status: -
Name: wanarp.sys
Image Path: C:\Windows\system32\DRIVERS\wanarp.sys
Address: 0x92E00000 Size: 77824 File Visible: - Signed: -
Status: -
Name: watchdog.sys
Image Path: C:\Windows\System32\drivers\watchdog.sys
Address: 0x8C9E4000 Size: 49152 File Visible: - Signed: -
Status: -
Name: Wdf01000.sys
Image Path: C:\Windows\system32\drivers\Wdf01000.sys
Address: 0x80600000 Size: 507904 File Visible: - Signed: -
Status: -
Name: WDFLDR.SYS
Image Path: C:\Windows\system32\drivers\WDFLDR.SYS
Address: 0x8067C000 Size: 53248 File Visible: - Signed: -
Status: -
Name: Win32k
Image Path: \Driver\Win32k
Address: 0x814E0000 Size: 2109440 File Visible: - Signed: -
Status: -
Name: win32k.sys
Image Path: C:\Windows\System32\win32k.sys
Address: 0x814E0000 Size: 2109440 File Visible: - Signed: -
Status: -
Name: wmiacpi.sys
Image Path: C:\Windows\system32\DRIVERS\wmiacpi.sys
Address: 0x92000000 Size: 36864 File Visible: - Signed: -
Status: -
Name: WMILIB.SYS
Image Path: C:\Windows\System32\Drivers\WMILIB.SYS
Address: 0x80789000 Size: 36864 File Visible: - Signed: -
Status: -
Name: WMIxWDM
Image Path: \Driver\WMIxWDM
Address: 0x8361A000 Size: 3903488 File Visible: - Signed: -
Status: -
Hier vom Scan nach Stealth Objects Code:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/08/10 18:34
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x86f301f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x86f2e1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x86f2e1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86f2e1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86f2e1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x86f2e1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86f2e1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x86f2e1f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_CREATE]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_CLOSE]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_READ]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_WRITE]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_SHUTDOWN]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_POWER]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: cdroma, IRP_MJ_PNP]
Process: System Address: 0x87f801f8 Size: 121
Object: Hidden Code [Driver: USBSTORᮿ慖瞈駍腐蚙Ѕ捓䙌㙘蛐, IRP_MJ_CREATE]
Process: System Address: 0x8850d1f8 Size: 121
Object: Hidden Code [Driver: USBSTORᮿ慖瞈駍腐蚙Ѕ捓䙌㙘蛐, IRP_MJ_CLOSE]
Process: System Address: 0x8850d1f8 Size: 121
Object: Hidden Code [Driver: USBSTORᮿ慖瞈駍腐蚙Ѕ捓䙌㙘蛐, IRP_MJ_READ]
Process: System Address: 0x8850d1f8 Size: 121
Object: Hidden Code [Driver: USBSTORᮿ慖瞈駍腐蚙Ѕ捓䙌㙘蛐, IRP_MJ_WRITE]
Process: System Address: 0x8850d1f8 Size: 121
Object: Hidden Code [Driver: USBSTORᮿ慖瞈駍腐蚙Ѕ捓䙌㙘蛐, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8850d1f8 Size: 121
Object: Hidden Code [Driver: USBSTORᮿ慖瞈駍腐蚙Ѕ捓䙌㙘蛐, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8850d1f8 Size: 121
Object: Hidden Code [Driver: USBSTORᮿ慖瞈駍腐蚙Ѕ捓䙌㙘蛐, IRP_MJ_POWER]
Process: System Address: 0x8850d1f8 Size: 121
Object: Hidden Code [Driver: USBSTORᮿ慖瞈駍腐蚙Ѕ捓䙌㙘蛐, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8850d1f8 Size: 121
Object: Hidden Code [Driver: USBSTORᮿ慖瞈駍腐蚙Ѕ捓䙌㙘蛐, IRP_MJ_PNP]
Process: System Address: 0x8850d1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x87f4c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x87f4c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x87f4c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x87f4c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x87f4c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x87f4c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x87f4c1f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_CREATE]
Process: System Address: 0x884fb1f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_CLOSE]
Process: System Address: 0x884fb1f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x884fb1f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x884fb1f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_CLEANUP]
Process: System Address: 0x884fb1f8 Size: 121
Object: Hidden Code [Driver: Smb, IRP_MJ_PNP]
Process: System Address: 0x884fb1f8 Size: 121
Object: Hidden Code [Driver: netbt, IRP_MJ_CREATE]
Process: System Address: 0x88621500 Size: 121
Object: Hidden Code [Driver: netbt, IRP_MJ_CLOSE]
Process: System Address: 0x88621500 Size: 121
Object: Hidden Code [Driver: netbt, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x88621500 Size: 121
Object: Hidden Code [Driver: netbt, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x88621500 Size: 121
Object: Hidden Code [Driver: netbt, IRP_MJ_CLEANUP]
Process: System Address: 0x88621500 Size: 121
Object: Hidden Code [Driver: netbt, IRP_MJ_PNP]
Process: System Address: 0x88621500 Size: 121
Object: Hidden Code [Driver: iScsiPrt, IRP_MJ_CREATE]
Process: System Address: 0x880ce1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrt, IRP_MJ_CLOSE]
Process: System Address: 0x880ce1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrt, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x880ce1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrt, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x880ce1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrt, IRP_MJ_POWER]
Process: System Address: 0x880ce1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrt, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x880ce1f8 Size: 121
Object: Hidden Code [Driver: iScsiPrt, IRP_MJ_PNP]
Process: System Address: 0x880ce1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_CREATE]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_READ]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_WRITE]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_CLEANUP]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_POWER]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: volmgr, IRP_MJ_PNP]
Process: System Address: 0x8659c1f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x87f571f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x87f571f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x87f571f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x87f571f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x87f571f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x87f571f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x87f571f8 Size: 121
Object: Hidden Code [Driver: msahci, IRP_MJ_POWER]
Process: System Address: 0x86f2f1f8 Size: 121
Object: Hidden Code [Driver: msahci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86f2f1f8 Size: 121
Object: Hidden Code [Driver: msahci, IRP_MJ_PNP]
Process: System Address: 0x86f2f1f8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CLOSE]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_READ]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_WRITE]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_EA]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CLEANUP]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_POWER]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: mrxsmb, IRP_MJ_PNP]
Process: System Address: 0x8a4ff3e8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_CREATE]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_CLOSE]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_READ]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_WRITE]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_CLEANUP]
Process: System Address: 0x86b021f8 Size: 121
Object: Hidden Code [Driver: cdfsЅ慖卤캘請, IRP_MJ_PNP]
Process: System Address: 0x86b021f8 Size: 121
Bei Hidden Objects wurde von RootRepeal nix entdeckt: Code:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/08/10 18:35
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Hidden Services
-------------------
|