once again thanks for the help. combofix gave me an error at first that I still had mcafee virusscan enterprise on but I was sure I didnt. I exited out of two processes that started with mc... (I am not sure if that is dangerous or harmful to computer but yeah)
ComboFix ran and produced a report, it didn't restart my computer this time and I did update it when asked.
RootRepeal ran and opened a report when done both are posted in the following
Thanks for your help.
<<<<<<<<<<<<<<<<<<<<<<ComboFix Starts Here>>>>>>>>>>>>>>>>>>>>
ComboFix 09-10-06.03 - Baker 10/06/2009 20:56.2.2 - NTFSx86
Running from: c:\documents and settings\Baker\Desktop\combofix1.exe.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-09-07 to 2009-10-07 )))))))))))))))))))))))))))))))
.
2009-10-06 00:33 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-06 00:33 . 2009-10-06 00:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-06 00:33 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-04 23:33 . 2009-10-05 00:21 -------- d-----w- c:\documents and settings\Baker\DoctorWeb
2009-09-30 14:18 . 2009-09-30 14:18 -------- d-----w- c:\program files\Belarc
2009-09-30 14:18 . 2008-03-06 16:51 3840 ----a-w- c:\windows\system32\drivers\BANTExt.sys
2009-09-30 04:10 . 2009-09-30 04:10 -------- d-----w- c:\program files\ERUNT
2009-09-30 04:02 . 2009-09-30 04:02 -------- d-----w- c:\documents and settings\Baker\Application Data\Malwarebytes
2009-09-30 04:02 . 2009-09-30 04:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-30 01:21 . 2009-09-30 04:27 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-29 23:24 . 2009-09-29 23:24 -------- d-----w- c:\documents and settings\NetworkService\Application Data\WTablet
2009-09-29 19:21 . 2009-09-30 01:28 -------- d-----w- c:\program files\TweakNow RegCleaner
2009-09-29 19:21 . 2009-09-30 01:28 -------- d-----w- c:\documents and settings\Baker\Application Data\TweakNow RegCleaner
2009-09-29 03:23 . 2009-09-29 03:23 -------- d-----w- c:\program files\Trend Micro
2009-09-18 13:52 . 2009-09-18 14:04 -------- d-----w- c:\program files\RAR Password Cracker
2009-09-15 05:46 . 2009-09-15 05:47 -------- d-----w- c:\program files\iPhone Configuration Utility
2009-09-15 05:43 . 2009-09-15 05:43 -------- d-----w- c:\program files\iPod
2009-09-15 05:43 . 2009-09-15 05:45 -------- d-----w- c:\program files\iTunes
2009-09-15 05:43 . 2009-09-15 05:45 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-15 05:37 . 2009-09-15 05:39 -------- d-----w- c:\program files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-07 01:43 . 2008-06-09 22:57 -------- d-----w- c:\documents and settings\Baker\Application Data\uTorrent
2009-10-06 02:45 . 2008-07-25 19:36 -------- d-----w- c:\documents and settings\Baker\Application Data\WTablet
2009-09-30 04:27 . 2008-06-10 18:15 -------- d-----w- c:\program files\Spybot - Search & Destroy_old
2009-09-30 03:34 . 2008-06-10 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-29 05:21 . 2008-07-26 05:44 -------- d-----w- c:\documents and settings\LocalService\Application Data\WTablet
2009-09-29 04:11 . 2008-06-03 21:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-29 04:10 . 2009-02-07 01:35 -------- d-----w- c:\program files\BAS
2009-09-29 03:44 . 2008-06-10 18:28 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-22 08:26 . 2008-06-11 08:52 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-16 02:08 . 2008-06-09 23:26 -------- d-----w- c:\documents and settings\Baker\Application Data\Apple Computer
2009-09-15 05:43 . 2008-06-09 23:24 -------- d-----w- c:\program files\Common Files\Apple
2009-08-29 00:42 . 2009-03-27 02:09 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-29 00:42 . 2008-10-09 07:16 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-28 13:26 . 2008-06-11 08:52 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-28 13:26 . 2008-06-11 08:52 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 13:26 . 2008-06-11 08:52 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-09 06:35 . 2008-06-10 02:12 23864 -c--a-w- c:\documents and settings\Baker\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-09 02:47 . 2009-08-09 02:47 -------- d-----w- c:\program files\MSBuild
2009-08-06 03:09 . 2009-03-23 00:46 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2004-08-04 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-10-05_02.46.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-06 00:29 . 2009-10-06 00:29 208896 c:\windows\ERDNT\AutoBackup\10-5-2009\Users\00000002\UsrClass.dat
+ 2009-10-06 00:29 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\10-5-2009\ERDNT.EXE
+ 2009-10-06 00:29 . 2009-10-06 00:29 8716288 c:\windows\ERDNT\AutoBackup\10-5-2009\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"ATI Launchpad"="c:\program files\ATI Multimedia\main\LaunchPd.exe" [2001-10-02 98304]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
"ccleaner"="c:\documents and settings\Baker\My Documents\safety first\CCleaner.exe" [2009-01-20 1451248]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-27 1830128]
"Octoshape Streaming Services"="c:\documents and settings\Baker\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-12 70936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"WUSB54Gv2"="c:\program files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe" [2004-04-19 24576]
"Lachesis"="c:\program files\Razer\Lachesis\razerhid.exe" [2008-10-14 172032]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-29 88363]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-08-12 61952]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2004-10-21 2744832]
c:\documents and settings\Baker\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-6-9 3581680]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-18 4742184]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{A7091E1D-36A4-47F1-A739-173CC341414F}\Icon3E5562ED7.ico [2008-12-4 6144]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 13:26 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Baker\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"c:\\Program Files\\Raptr\\Raptr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"51321:TCP"= 51321:TCP:51321
"62515:UDP"= 62515:UDP:Cisco VPN Service
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-08-28 908056]
R3 atinysxx;ATI USB 2.0 TV Audio Crossbar;c:\windows\system32\DRIVERS\atinysxx.sys [2005-01-26 79360]
R3 atinyvxx;ATI TV WONDER USB2.0 Video & Audio;c:\windows\system32\DRIVERS\atinyvxx.sys [2005-01-26 174592]
R3 ATITUNEP2;ATI TV WONDER USB2.0 TV Tuner;c:\windows\system32\DRIVERS\atinyuxx.sys [2005-01-26 64512]
R3 ATIUTD;ATI TV WONDER USB2.0 Device Driver;c:\windows\system32\Drivers\ATIUTD.sys [2005-01-26 38912]
R3 PAC7302;PAC7302 VGA USB Camera;c:\windows\system32\DRIVERS\PAC7302.SYS [2007-06-14 457856]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-22 7408]
R3 TTDec;ATI TV WONDER USB2.0 Teletext Decoder;c:\windows\system32\DRIVERS\atinyttx.sys [2005-01-26 13824]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2008-04-23 15656]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-08-28 335240]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-05-05 108552]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-27 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-22 55024]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-06-10 108289]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-08-28 297752]
S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2008-06-06 3406120]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-08 12032]
.
Contents of the 'Scheduled Tasks' folder
2009-10-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = plimus.com,
www.plimus.com,regnow.com,www.regnow.com,
uInternet Settings,ProxyServer = socks=
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Baker\Application Data\Mozilla\Firefox\Profiles\fk8errpw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/ |
www.facebook.com
FF - component: c:\documents and settings\Baker\Application Data\Mozilla\Firefox\Profiles\fk8errpw.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Baker\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: XUL Cache: {1B1E558C-4DA4-4AA8-85F2-C8E2BAA23F20} - c:\documents and settings\Baker\Local Settings\Application Data\{1B1E558C-4DA4-4AA8-85F2-C8E2BAA23F20}
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-06 21:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1480)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\documents and settings\Baker\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(5640)
c:\windows\system32\WININET.dll
c:\program files\Stardock\ObjectDock\DockShellHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-10-07 21:02
ComboFix-quarantined-files.txt 2009-10-07 02:02
Pre-Run: 79,750,537,216 bytes free
Post-Run: 80,019,697,664 bytes free
195 --- E O F --- 2009-10-04 08:01
<<<<<<<<<<<<<<<<<<ComboFix Ends Here>>>>>>>>>>>>>>>>>>>>>
<<<<<<<<<<<<<<<<<<RootRepeal Starts Here>>>>>>>>>>>>>>>>>>>
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/10/06 21:05
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: catchme.sys
Image Path: C:\DOCUME~1\Baker\LOCALS~1\Temp\catchme.sys
Address: 0xF794B000 Size: 31744 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB644D000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AED000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PCI_PNP4616
Image Path: \Driver\PCI_PNP4616
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: PROCEXP90.SYS
Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Address: 0xF7AD5000 Size: 6464 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB2A87000 Size: 49152 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: spwb.sys
Image Path: spwb.sys
Address: 0xF7482000 Size: 1048576 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\RECYCLER
Status: Locked to the Windows API!
Path: \\?\C:\RECYCLER\*
Status: Could not enumerate files with the Windows API (0x00000005)!
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0xf7b6d956
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xf7b6d94c
#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0xf7b6d95b
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0xf7b6d965
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spwb.sys" at address 0xf74a1ca2
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spwb.sys" at address 0xf74a2030
#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xf7b6d96a
#: 119 Function Name: NtOpenKey
Status: Hooked by "spwb.sys" at address 0xf74830c0
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xf7b6d938
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xf7b6d93d
#: 160 Function Name: NtQueryKey
Status: Hooked by "spwb.sys" at address 0xf74a2108
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spwb.sys" at address 0xf74a1f88
#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xf7b6d974
#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xf7b6d96f
#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0xf7b6d960
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0xf7b6d947
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x86fd31f8 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_CREATE]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_CLOSE]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_READ]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_WRITE]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_CLEANUP]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Udfsࠅ扏煓ࠁఄ灐畳畘⠈뢸ÿ, IRP_MJ_PNP]
Process: System Address: 0x86bda500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x86ad11f8 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_CREATE]
Process: System Address: 0x86cae500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_CLOSE]
Process: System Address: 0x86cae500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_READ]
Process: System Address: 0x86cae500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_WRITE]
Process: System Address: 0x86cae500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86cae500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86cae500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_POWER]
Process: System Address: 0x86cae500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86cae500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_PNP]
Process: System Address: 0x86cae500 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x86f661f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x86cce1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x86cce1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86cce1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86cce1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x86cce1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86cce1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x86cce1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x86fd51f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x86bd7500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x86bd7500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86bd7500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86bd7500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x86bd7500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x86bd7500 Size: 121
Object: Hidden Code [Driver: ACPI#PNP, IRP_MJ_CREATE]
Process: System Address: 0x86ac91f8 Size: 121
Object: Hidden Code [Driver: ACPI#PNP, IRP_MJ_CLOSE]
Process: System Address: 0x86ac91f8 Size: 121
Object: Hidden Code [Driver: ACPI#PNP, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86ac91f8 Size: 121
Object: Hidden Code [Driver: ACPI#PNP, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86ac91f8 Size: 121
Object: Hidden Code [Driver: ACPI#PNP, IRP_MJ_POWER]
Process: System Address: 0x86ac91f8 Size: 121
Object: Hidden Code [Driver: ACPI#PNP, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86ac91f8 Size: 121
Object: Hidden Code [Driver: ACPI#PNP, IRP_MJ_PNP]
Process: System Address: 0x86ac91f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x86d5e500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x86d5e500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86d5e500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86d5e500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x86d5e500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86d5e500 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x86d5e500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x86bc5500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_CREATE]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_CLOSE]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_READ]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_CLEANUP]
Process: System Address: 0x86c01500 Size: 121
Object: Hidden Code [Driver: Cdfsః瑎て, IRP_MJ_PNP]
Process: System Address: 0x86c01500 Size: 121
==EOF==
<<<<<<<<<<<<<<<<<RootRepeal Ends Here>>>>>>>>>>>>>>>