coffeemetalcode
Topic Starter
XP SP3 netbook is infected. This is a neighbors computer and I suspect she's been on free music sites and the like. She may have fallen for one of the sham antivirus download sites. Here are her logs. dds "attach" is attached:
DDS (Ver_09-09-24.01) - NTFSx86
Run by [removed] at 13:03:59.23 on Sun 09/27/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.568 [GMT -4:00]
AV: Norton Internet Security *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Roxio\BackOnTrack\Instant Restore\BOTService.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\idt\wdm\stacsv.exe
C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
C:\WINDOWS\sYSteM32\SvchOst.eXE -k ddnsfilter
C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
C:\QUALCOMM\QDLService\QDLService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\webserver\webserver.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\windows\freddy66.exe
C:\windows\pp12.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\Internet Antivirus Pro\IAPro.exe
C:\Program Files\Wind Optimizer\WindOptimizer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\Program Files\MSN\Toolbar\3.0.0541.0\msntask.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\ishima ford\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=minipavilion&pf=cnnb
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=minipavilion&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=minipavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=minipavilion&pf=cnnb
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.7.2.11\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.7.2.11\IPSBHO.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.7.2.11\coIEPlg.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Microsoft Windows logon process] c:\documents and settings\ishima ford\application data\microsoft\windows\winlogon.exe
uRun: [Internet Antivirus Pro] "c:\program files\internet antivirus pro\IAPro.exe" /s
uRun: [Wind Optimizer] "c:\program files\wind optimizer\WindOptimizer.exe" /s
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IDTSysTrayApp] sttray.exe
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [sysldtray] c:\windows\ld14.exe
mRun: [SySmstray] c:\windows\mstre22.exe
mRun: [sysfbtray] c:\windows\freddy66.exe
mRun: [pp] c:\windows\pp12.exe
uExplorerRun: [ofofonin] "c:\documents and settings\ishima ford\local settings\application data\microsoft\works\portfolio\ofofonin.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton internet security\engine\16.7.2.11\CoIEPlg.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R?2 ddnsfilter;ddnsfilter;c:\windows\system32\SvchOst.eXE -k ddnsfilter [2008-4-15 14336]
R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [2009-3-9 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [2009-3-9 15856]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1007020.00b\SymEFA.sys [2009-9-8 310320]
R0 SysCow;SysCow;c:\windows\system32\drivers\syscow32x.sys [2008-9-25 103792]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nis\1007020.00b\BHDrvx86.sys [2009-9-8 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1007020.00b\cchpx86.sys [2009-9-8 482432]
R1 Filter;Filter;c:\windows\system32\drivers\FILTER.sys [2009-9-12 37504]
R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [2009-3-9 25584]
R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\roxio\backontrack\disaster recovery\SaibSVC.exe [2008-12-12 125424]
R2 BOTService;BOTService;c:\program files\roxio\backontrack\instant restore\BOTService.exe [2008-12-25 203248]
R2 ITGrdEngine;Guard Service;c:\documents and settings\ishima ford\local settings\application data\microsoft\windows\services.exe [2009-9-22 193536]
R2 Norton Internet Security;Norton Internet Security;c:\program files\norton internet security\engine\16.7.2.11\ccSvcHst.exe [2009-9-8 117640]
R2 QDLService;Qualcomm Gobi Download Service;c:\qualcomm\qdlservice\QDLService.exe [2009-1-14 345336]
R2 webserver;webserver;c:\program files\webserver\webserver.exe [2009-9-12 13824]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-3-9 112128]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-26 102448]
R3 QCFilterhp;HP USB Composite Device Filter Driver;c:\windows\system32\drivers\qcfilterhp.sys [2009-3-9 5248]
R3 qcusbnethp;HP USB-NDIS miniport;c:\windows\system32\drivers\qcusbnethp.sys [2009-3-9 115200]
R3 qcusbserhp;HP USB Device for Legacy Serial Communication;c:\windows\system32\drivers\qcusbserhp.sys [2009-3-9 104448]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090810.001\IDSXpx86.sys [2009-8-12 276344]
S3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090902.037\NAVENG.SYS [2009-9-3 84912]
S3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090902.037\NAVEX15.SYS [2009-9-3 1323568]
S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\verizo~1\vzacce~2\SMSIVZAM5.SYS [2009-3-20 32408]
=============== Created Last 30 ================
2009-09-27 10:54 0 a——- c:\windows\vkl_1254063258.exe
2009-09-27 10:54 0 a——- c:\windows\vkl_1254063257.exe
2009-09-27 02:01 –d—– C:\users
2009-09-26 23:17 147,456 a——- c:\windows\vkl_1254021450.exe
2009-09-26 22:05 147,456 a——- c:\windows\vkl_1254017115.exe
2009-09-24 19:00 2 a——- c:\windows\0101120101465454.xe
2009-09-24 19:00 77,824 ——– c:\windows\freddy66.exe
2009-09-23 08:38 –d—– c:\docume~1\ishima~1\applic~1\Wind Optimizer
2009-09-23 08:38 –d—– c:\program files\Wind Optimizer
2009-09-22 22:25 –d—– c:\docume~1\ishima~1\applic~1\Internet Antivirus Pro
2009-09-22 22:25 –d—– c:\program files\Internet Antivirus Pro
2009-09-21 05:42 2,145,380 a——- c:\program files\common files\InternetAntivirusPro.exe
2009-09-21 05:42 29,184 a——- c:\program files\common files\file.exe
2009-09-20 04:43 96,768 a——- c:\windows\vkl_1253436183.exe
2009-09-18 22:05 96,768 a——- c:\windows\vkl_1253325941.exe
2009-09-18 22:04 96,768 a——- c:\windows\vkl_1253325850.exe
2009-09-18 22:03 96,768 a——- c:\windows\vkl_1253325828.exe
2009-09-18 21:47 96,768 a——- c:\windows\vkl_1253324827.exe
2009-09-18 09:17 96,768 a——- c:\windows\vkl_1253279867.exe
2009-09-18 09:17 77,824 ——– c:\windows\freddy65.exe
2009-09-18 09:17 2 a——- c:\windows\0101120101465354.xe
2009-09-17 22:01 96,768 a——- c:\windows\vkl_1253239260.exe
2009-09-17 21:14 96,768 a——- c:\windows\vkl_1253236461.exe
2009-09-17 20:38 96,768 a——- c:\windows\vkl_1253234274.exe
2009-09-17 18:43 96,768 a——- c:\windows\vkl_1253227416.exe
2009-09-17 16:12 96,768 a——- c:\windows\vkl_1253218377.exe
2009-09-17 16:01 96,768 a——- c:\windows\vkl_1253217701.exe
2009-09-17 12:11 96,768 a——- c:\windows\vkl_1253203893.exe
2009-09-17 12:11 13,824 a——- c:\windows\vkl_1253203876.exe
2009-09-17 10:16 96,768 a——- c:\windows\vkl_1253196988.exe
2009-09-17 10:16 13,824 a——- c:\windows\vkl_1253196970.exe
2009-09-16 22:12 96,768 a——- c:\windows\vkl_1253153540.exe
2009-09-16 22:12 13,824 a——- c:\windows\vkl_1253153460.exe
2009-09-16 20:51 13,824 a——- c:\windows\vkl_1253148707.exe
2009-09-16 14:20 96,768 a——- c:\windows\vkl_1253125202.exe
2009-09-16 14:19 13,824 a——- c:\windows\vkl_1253125184.exe
2009-09-16 11:50 96,768 a——- c:\windows\vkl_1253116242.exe
2009-09-16 11:50 13,824 a——- c:\windows\vkl_1253116225.exe
2009-09-16 11:50 2 a——- c:\windows\010112010146116101.xe
2009-09-16 10:50 96,768 a——- c:\windows\vkl_1253112637.exe
2009-09-16 10:50 13,824 a——- c:\windows\vkl_1253112620.exe
2009-09-16 09:30 96,768 a——- c:\windows\vkl_1253107822.exe
2009-09-16 09:30 13,824 a——- c:\windows\vkl_1253107805.exe
2009-09-15 19:04 5 a——- c:\windows\system32\Band4
2009-09-15 19:04 7 a——- c:\windows\system32\Class11
2009-09-15 19:00 77,824 a——- c:\windows\vkl_1253055604.exe
2009-09-15 09:31 77,824 a——- c:\windows\vkl_1253021500.exe
2009-09-15 09:31 73,728 ——– c:\windows\freddy64.exe
2009-09-15 09:31 2 a——- c:\windows\0101120101465254.xe
2009-09-14 17:32 77,824 a——- c:\windows\vkl_1252963969.exe
2009-09-14 14:59 77,824 a——- c:\windows\vkl_1252954764.exe
2009-09-14 14:57 77,824 a——- c:\windows\vkl_1252954643.exe
2009-09-14 09:31 77,824 a——- c:\windows\vkl_1252935073.exe
2009-09-13 18:43 77,824 a——- c:\windows\vkl_1252881836.exe
2009-09-13 15:01 77,824 a——- c:\windows\vkl_1252868459.exe
2009-09-13 15:01 1 —-h— c:\windows\nlmark2.dat
2009-09-13 15:00 2 a——- c:\windows\0101120101465349.xe
2009-09-13 15:00 1 —-h— c:\windows\hpm2.dat
2009-09-13 15:00 2 a——- c:\windows\0101120101465249.xe
2009-09-13 15:00 1 —-h— c:\windows\bx4657.dat
2009-09-13 15:00 69,632 a——- c:\windows\sber17.exe
2009-09-13 15:00 2 a——- c:\windows\0101120101465549.xe
2009-09-13 09:55 77,824 a——- c:\windows\vkl_1252850118.exe
2009-09-13 09:55 13,824 a——- c:\windows\vkl_1252850101.exe
2009-09-12 21:43 77,824 a——- c:\windows\vkl_1252806185.exe
2009-09-12 21:43 77,824 a——- c:\windows\vkl_1252806183.exe
2009-09-12 21:42 13,824 a——- c:\windows\vkl_1252806166.exe
2009-09-12 21:42 77,824 a——- c:\windows\vkl_1252806127.exe
2009-09-12 21:41 13,824 a——- c:\windows\vkl_1252806111.exe
2009-09-12 21:41 77,824 a——- c:\windows\vkl_1252806098.exe
2009-09-12 21:41 13,824 a——- c:\windows\vkl_1252806081.exe
2009-09-12 21:40 77,824 a——- c:\windows\vkl_1252806053.exe
2009-09-12 21:40 13,824 a——- c:\windows\vkl_1252806036.exe
2009-09-12 21:39 1 a——- c:\windows\fdgg34353edfgdfdf
2009-09-12 21:39 49,152 —-h— c:\windows\pp12.exe
2009-09-12 21:39 37,504 a——- c:\windows\system32\drivers\FILTER.sys
2009-09-12 21:39 –d—– c:\program files\ddnsFilter
2009-09-12 21:39 77,824 a——- c:\windows\vkl_1252805949.exe
2009-09-12 21:39 1 —-h— c:\windows\bk23567.dat
2009-09-12 21:39 77,824 a——- c:\windows\vkl_1252805940.exe.exe
2009-09-12 21:39 77,824 a——- c:\windows\vkl_1252805940.exe
2009-09-12 21:39 1 —-h— c:\windows\mmsmark2.dat
2009-09-12 21:39 2 a——- c:\windows\0101120101465050.xe
2009-09-12 21:38 73,728 ——– c:\windows\freddy63.exe
2009-09-12 21:38 2 a——- c:\windows\0101120101465154.xe
2009-09-12 21:38 13,824 a——- c:\windows\vkl_1252805911.exe
2009-09-12 21:38 –d—– c:\program files\webserver
2009-09-12 21:38 13,824 a——- c:\windows\vkl_1252805889.exe
2009-09-12 21:38 18,432 a——- c:\windows\srpira1252805887.eXE
2009-09-12 21:38 2 a——- c:\windows\0535251103110107106.yux
2009-09-12 21:38 53,248 ——– c:\windows\ld14.exe
2009-09-11 21:53 –d—– c:\docume~1\alluse~1\applic~1\Symantec
2009-09-11 21:27 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys
==================== Find3M ====================
2009-09-10 18:41 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-09-10 18:41 60,808 a——- c:\windows\system32\S32EVNT1.DLL
2009-09-10 18:41 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-09-10 18:41 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-07-04 02:21 259,584 a–shr– C:\BCDEDIT.EXE
2009-07-04 02:21 102,400 a–shr– C:\bootsect.exe
2009-07-04 02:21 259,584 a——- c:\windows\system32\bcdedit.exe
2008-06-24 13:17 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat
============= FINISH: 13:04:59.23 ===============
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/27 13:08
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA982C000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AE2000 Size: 8192 File Visible: No Signed: -
Status: -
Name: hiber_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\hiber_WMILIB.SYS
Address: 0xF7AF8000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA8AFA000 Size: 49152 File Visible: No Signed: -
Status: -
Name: SYMEFA.SYS
Image Path: SYMEFA.SYS
Address: 0xF738A000 Size: 323584 File Visible: No Signed: -
Status: -
SSDT
——————-
#: 012 Function Name: NtAlertResumeThread
Status: Hooked by "" at address 0x85fe40a8
#: 013 Function Name: NtAlertThread
Status: Hooked by "" at address 0x86202508
#: 017 Function Name: NtAllocateVirtualMemory
Status: Hooked by "" at address 0x86009630
#: 019 Function Name: NtAssignProcessToJobObject
Status: Hooked by "" at address 0x85fe2120
#: 031 Function Name: NtConnectPort
Status: Hooked by "" at address 0x85d1e2b0
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xa9b87130
#: 043 Function Name: NtCreateMutant
Status: Hooked by "" at address 0x85bf81c0
#: 052 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "" at address 0x85c591d8
#: 053 Function Name: NtCreateThread
Status: Hooked by "" at address 0x862784a0
#: 057 Function Name: NtDebugActiveProcess
Status: Hooked by "" at address 0x85c691e8
#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xa9b873b0
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xa9b87910
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "" at address 0x85cb3e28
#: 083 Function Name: NtFreeVirtualMemory
Status: Hooked by "" at address 0x85c5e3c8
#: 089 Function Name: NtImpersonateAnonymousToken
Status: Hooked by "" at address 0x85c8c9d8
#: 091 Function Name: NtImpersonateThread
Status: Hooked by "" at address 0x85c830b0
#: 097 Function Name: NtLoadDriver
Status: Hooked by "" at address 0x85db5868
#: 108 Function Name: NtMapViewOfSection
Status: Hooked by "" at address 0x86281678
#: 114 Function Name: NtOpenEvent
Status: Hooked by "" at address 0x85fcf148
#: 122 Function Name: NtOpenProcess
Status: Hooked by "" at address 0x85c5e1c0
#: 123 Function Name: NtOpenProcessToken
Status: Hooked by "" at address 0x86020b98
#: 125 Function Name: NtOpenSection
Status: Hooked by "" at address 0x85cb21e8
#: 128 Function Name: NtOpenThread
Status: Hooked by "" at address 0x85c4c1c0
#: 137 Function Name: NtProtectVirtualMemory
Status: Hooked by "" at address 0x85fda110
#: 206 Function Name: NtResumeThread
Status: Hooked by "" at address 0x860278a8
#: 213 Function Name: NtSetContextThread
Status: Hooked by "" at address 0x85fe50a8
#: 228 Function Name: NtSetInformationProcess
Status: Hooked by "" at address 0x85d0bc20
#: 240 Function Name: NtSetSystemInformation
Status: Hooked by "" at address 0x85cb21b0
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xa9b87b60
#: 253 Function Name: NtSuspendProcess
Status: Hooked by "" at address 0x860071c0
#: 254 Function Name: NtSuspendThread
Status: Hooked by "" at address 0x860335b8
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "" at address 0x86101968
#: 258 Function Name: NtTerminateThread
Status: Hooked by "" at address 0x85d5f138
#: 267 Function Name: NtUnmapViewOfSection
Status: Hooked by "" at address 0x86311a38
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "" at address 0x85cb0c48
==EOF==