Here they are:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, October 29, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, October 28, 2009 16:52:54
Records in database: 3095707
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
A:\
C:\
E:\
F:\
I:\
J:\
K:\
L:\
Scan statistics:
Objects scanned: 104877
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 08:12:12
File name / Threat / Threats count
C:\System Volume Information\_restore{C97FC7EF-E0A9-49D2-872A-3588CD7C7DD6}\RP985\A0422241.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1
Selected area has been scanned.
~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2.47.41, on 29/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\slserv.exe
C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Programmi\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Java\jre6\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\QuickTime\qttask.exe
C:\Programmi\Navigator Mouse\moffice.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\DNA\btdna.exe
C:\Programmi\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Programmi\Orbitdownloader\orbitdm.exe
C:\Programmi\WinZip\WZQKPICK.EXE
C:\apps\ABoard\AOSD.exe
C:\Programmi\Navigator Mouse\MOUSE32A.DAT
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Java\jre6\bin\java.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Programmi\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmi\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programmi\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Collegamento alla pagina delle proprietą di High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Programmi\Navigator Mouse\moffice.exe
O4 - HKLM\..\Run: [AlcFDMonitor] C:\WINDOWS\ALCFDRTM.EXE
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FILECO~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [StartCCC] "C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Programmi\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BioniXWallpaper] "C:\games\Oh\Program Files\BioniX Wallpaper v4.60\BioniX Wallper.exe"
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Programmi\DNA\btdna.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programmi\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: CountDown.lnk = C:\Programmi\CountDown\CountDown.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Orbit.lnk = C:\Programmi\Orbitdownloader\orbitdm.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Download by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Programmi\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PokerStars.it - {C4046502-6524-4d87-896C-878F57D1FF07} - C:\Programmi\PokerStars.IT\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\it.htm
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmi\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Programmi\Virtual CD v4 SDK\system\vcssecs.exe
--
End of file - 8706 bytes
~~~~~~~~~~~~~~~~~~~~~~~~
Sec-Info2 scan
~~~~~~~~~~~~~~~~~~~~~~~~
Script run: 29/10/2009 2.46.39
~~~~~~~~~~~~~~~~~~~~~~~~
Company Name: AVG Technologies
AV Name: AVG Anti-Virus Free
Version Number: 8.5
On-Access Scanning Enabled: No
Product up-to-date: Yes
~~~~~~~~~~~~~~~~~~~~~~~~
Company Name: Softwin
Firewall Name: Bitdefender Firewall
Version Number: 8.0
Enabled: No
~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~
HJTUninstall Manager
~~~~~~~~~~~~~~~~~~~~~~~~
ACDSee 7.0
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0
Adobe Shockwave Player 11.5
AGEIA PhysX v7.09.13
Aggiornamento critico per Windows Media Player 11 (KB959772)
Aggiornamento della protezione per Step by Step Interactive Training (KB898458)
Aggiornamento della protezione per Step by Step Interactive Training (KB923723)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB938127-v2)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB956390)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB958215)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB960714)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB963027)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB969897)
Aggiornamento della protezione per Windows Internet Explorer 7 (KB974455)
Aggiornamento della protezione per Windows Internet Explorer 8 (KB974455)
Aggiornamento della protezione per Windows Media Player (KB952069)
Aggiornamento della protezione per Windows Media Player (KB954155)
Aggiornamento della protezione per Windows Media Player (KB968816)
Aggiornamento della protezione per Windows Media Player (KB973540)
Aggiornamento della protezione per Windows Media Player 10 (KB911565)
Aggiornamento della protezione per Windows Media Player 10 (KB936782)
Aggiornamento della protezione per Windows Media Player 11 (KB936782)
Aggiornamento della protezione per Windows Media Player 11 (KB954154)
Aggiornamento della protezione per Windows XP (KB923561)
Aggiornamento della protezione per Windows XP (KB938464)
Aggiornamento della protezione per Windows XP (KB938464-v2)
Aggiornamento della protezione per Windows XP (KB941569)
Aggiornamento della protezione per Windows XP (KB946648)
Aggiornamento della protezione per Windows XP (KB950762)
Aggiornamento della protezione per Windows XP (KB950974)
Aggiornamento della protezione per Windows XP (KB951066)
Aggiornamento della protezione per Windows XP (KB951376-v2)
Aggiornamento della protezione per Windows XP (KB951698)
Aggiornamento della protezione per Windows XP (KB951748)
Aggiornamento della protezione per Windows XP (KB952004)
Aggiornamento della protezione per Windows XP (KB952954)
Aggiornamento della protezione per Windows XP (KB954211)
Aggiornamento della protezione per Windows XP (KB954459)
Aggiornamento della protezione per Windows XP (KB954600)
Aggiornamento della protezione per Windows XP (KB955069)
Aggiornamento della protezione per Windows XP (KB956390)
Aggiornamento della protezione per Windows XP (KB956391)
Aggiornamento della protezione per Windows XP (KB956572)
Aggiornamento della protezione per Windows XP (KB956744)
Aggiornamento della protezione per Windows XP (KB956802)
Aggiornamento della protezione per Windows XP (KB956803)
Aggiornamento della protezione per Windows XP (KB956841)
Aggiornamento della protezione per Windows XP (KB956844)
Aggiornamento della protezione per Windows XP (KB957095)
Aggiornamento della protezione per Windows XP (KB957097)
Aggiornamento della protezione per Windows XP (KB958644)
Aggiornamento della protezione per Windows XP (KB958687)
Aggiornamento della protezione per Windows XP (KB958690)
Aggiornamento della protezione per Windows XP (KB958869)
Aggiornamento della protezione per Windows XP (KB959426)
Aggiornamento della protezione per Windows XP (KB960225)
Aggiornamento della protezione per Windows XP (KB960715)
Aggiornamento della protezione per Windows XP (KB960803)
Aggiornamento della protezione per Windows XP (KB960859)
Aggiornamento della protezione per Windows XP (KB961371)
Aggiornamento della protezione per Windows XP (KB961373)
Aggiornamento della protezione per Windows XP (KB961501)
Aggiornamento della protezione per Windows XP (KB968537)
Aggiornamento della protezione per Windows XP (KB969059)
Aggiornamento della protezione per Windows XP (KB969898)
Aggiornamento della protezione per Windows XP (KB970238)
Aggiornamento della protezione per Windows XP (KB971486)
Aggiornamento della protezione per Windows XP (KB971557)
Aggiornamento della protezione per Windows XP (KB971633)
Aggiornamento della protezione per Windows XP (KB971657)
Aggiornamento della protezione per Windows XP (KB971961)
Aggiornamento della protezione per Windows XP (KB973346)
Aggiornamento della protezione per Windows XP (KB973354)
Aggiornamento della protezione per Windows XP (KB973507)
Aggiornamento della protezione per Windows XP (KB973525)
Aggiornamento della protezione per Windows XP (KB973869)
Aggiornamento della protezione per Windows XP (KB974112)
Aggiornamento della protezione per Windows XP (KB974571)
Aggiornamento della protezione per Windows XP (KB975025)
Aggiornamento della protezione per Windows XP (KB975467)
Aggiornamento per Windows Internet Explorer 8 (KB973874)
Aggiornamento per Windows XP (KB951072-v2)
Aggiornamento per Windows XP (KB951978)
Aggiornamento per Windows XP (KB955839)
Aggiornamento per Windows XP (KB967715)
Aggiornamento per Windows XP (KB968389)
Aggiornamento per Windows XP (KB973815)
Aggiornamento rapido per Windows Media Player 11 (KB939683)
Aggiornamento rapido per Windows XP (KB952287)
Aggiornamento rapido per Windows XP (KB970653-v3)
Anki
ArcSoft Panorama Maker 3.0
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
ATI HydraVision
ATI Parental Control & Encoder
AVG Free 8.5
Avi Player
AVIVO Codecs
BattleForge
Blood Bowl 1.0.1.7
Catalyst Control Center - Branding
CodecInstaller 2.10.2
CountDown©
DAEMON Tools Toolbar
DivX
Driver Detective
EAX4 Unified Redist
Emote-Launcher (remove only)
FLV Player 2.0 (build 25)
Full Tilt Poker.Net
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB835221
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
IsoBuster 2.4
Java 2 Runtime Environment, SE v1.4.2_04
Java 6 Update 16
Kanji Gold 2.10
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Italian Language Pack
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Excel Viewer 2003
Microsoft Office PowerPoint - Visualizzatore 2003
Microsoft Office Standard Edition 2003
Microsoft Office Word Viewer 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 7.0
Mozilla Firefox (3.5.3)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB925673)
MSXML4 Parser
Navigator Mouse
Nero
OpenAL
OpenTTD 0.7.0
Orbit Downloader
Packard Bell Toolbar 1.0
PeerGuardian 2.0
Photo Story 3 for Windows
PokerStars.it
RealSpeak_Solo_Common_for_Panasonic
RealSpeak_Solo_English_for_Panasonic
RealSpeak_Solo_Italian_for_Panasonic
Realtek High Definition Audio Driver
SAPI5_Common
Smart Link 56K Modem
Sonic MyDVD
Sonic RecordNow!
Transport Tycoon Deluxe
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 1.0.1
Voice Editing
Windows Genuine Advantage v1.3.0254.0
Windows Imaging Component
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows XP Service Pack 3
WinRAR gestione archivi
WinZip
The Windows Firewall is disabled.
~~~~~~~~~~~~~~~~~~~~~~~~
The Security Center Anti-Virus Alerts are enabled.
The Security Center Firewall Alerts are enabled.
~~~~~~~~~~~~~~~~~~~~~~~~
Number of Restore Points found: 68
~~~~~~~~~~~~~~~~~~~~~~~~
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/29 13:04
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAC76C000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7B38000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PCI_PNP6936
Image Path: \Driver\PCI_PNP6936
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA9606000 Size: 49152 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: spxb.sys
Image Path: spxb.sys
Address: 0xF748C000 Size: 1052672 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: c:\windows\temp\perflib_perfdata_6fc.dat
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: C:\Documents and Settings\Paolo\Cookies\paolo@google[3].txt
Status: Invisible to the Windows API!
Path: c:\documents and settings\paolo\cookies\paolo@serving-sys[2].txt
Status: Size mismatch (API: 675, Raw: 699)
Path: C:\Documents and Settings\Paolo\Cookies\paolo@www.msn[3].txt
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Paolo\Cookies\paolo@bs.serving-sys[1].txt
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Paolo\Cookies\paolo@bs.serving-sys[2].txt
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Paolo\Cookies\paolo@google[6].txt
Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\Paolo\Cookies\paolo@www.msn[1].txt
Status: Visible to the Windows API, but not on disk.
Path: c:\documents and settings\paolo\impostazioni locali\temp\~df9bd5.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\paolo\impostazioni locali\temp\~df9c00.tmp
Status: Allocation size mismatch (API: 131072, Raw: 16384)
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "spxb.sys" at address 0xf748d0e0
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spxb.sys" at address 0xf74abca4
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spxb.sys" at address 0xf74ac032
#: 119 Function Name: NtOpenKey
Status: Hooked by "spxb.sys" at address 0xf748d0c0
#: 160 Function Name: NtQueryKey
Status: Hooked by "spxb.sys" at address 0xf74ac10a
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spxb.sys" at address 0xf74abf8a
#: 247 Function Name: NtSetValueKey
Status: Hooked by "spxb.sys" at address 0xf74ac19c
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x873531f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x867e4500 Size: 121
Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_CREATE]
Process: System Address: 0x873d21f8 Size: 121
Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_CLOSE]
Process: System Address: 0x873d21f8 Size: 121
Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873d21f8 Size: 121
Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873d21f8 Size: 121
Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_POWER]
Process: System Address: 0x873d21f8 Size: 121
Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873d21f8 Size: 121
Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_PNP]
Process: System Address: 0x873d21f8 Size: 121
Object: Hidden Code [Driver: perc2, IRP_MJ_CREATE]
Process: System Address: 0x873c61f8 Size: 121
Object: Hidden Code [Driver: perc2, IRP_MJ_CLOSE]
Process: System Address: 0x873c61f8 Size: 121
Object: Hidden Code [Driver: perc2, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873c61f8 Size: 121
Object: Hidden Code [Driver: perc2, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873c61f8 Size: 121
Object: Hidden Code [Driver: perc2, IRP_MJ_POWER]
Process: System Address: 0x873c61f8 Size: 121
Object: Hidden Code [Driver: perc2, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873c61f8 Size: 121
Object: Hidden Code [Driver: perc2, IRP_MJ_PNP]
Process: System Address: 0x873c61f8 Size: 121
Object: Hidden Code [Driver: cbidf, IRP_MJ_CREATE]
Process: System Address: 0x873561f8 Size: 121
Object: Hidden Code [Driver: cbidf, IRP_MJ_CLOSE]
Process: System Address: 0x873561f8 Size: 121
Object: Hidden Code [Driver: cbidf, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873561f8 Size: 121
Object: Hidden Code [Driver: cbidf, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873561f8 Size: 121
Object: Hidden Code [Driver: cbidf, IRP_MJ_POWER]
Process: System Address: 0x873561f8 Size: 121
Object: Hidden Code [Driver: cbidf, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873561f8 Size: 121
Object: Hidden Code [Driver: cbidf, IRP_MJ_PNP]
Process: System Address: 0x873561f8 Size: 121
Object: Hidden Code [Driver: ini910u, IRP_MJ_CREATE]
Process: System Address: 0x873cf1f8 Size: 121
Object: Hidden Code [Driver: ini910u, IRP_MJ_CLOSE]
Process: System Address: 0x873cf1f8 Size: 121
Object: Hidden Code [Driver: ini910u, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873cf1f8 Size: 121
Object: Hidden Code [Driver: ini910u, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873cf1f8 Size: 121
Object: Hidden Code [Driver: ini910u, IRP_MJ_POWER]
Process: System Address: 0x873cf1f8 Size: 121
Object: Hidden Code [Driver: ini910u, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873cf1f8 Size: 121
Object: Hidden Code [Driver: ini910u, IRP_MJ_PNP]
Process: System Address: 0x873cf1f8 Size: 121
Object: Hidden Code [Driver: asc, IRP_MJ_CREATE]
Process: System Address: 0x873d11f8 Size: 121
Object: Hidden Code [Driver: asc, IRP_MJ_CLOSE]
Process: System Address: 0x873d11f8 Size: 121
Object: Hidden Code [Driver: asc, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873d11f8 Size: 121
Object: Hidden Code [Driver: asc, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873d11f8 Size: 121
Object: Hidden Code [Driver: asc, IRP_MJ_POWER]
Process: System Address: 0x873d11f8 Size: 121
Object: Hidden Code [Driver: asc, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873d11f8 Size: 121
Object: Hidden Code [Driver: asc, IRP_MJ_PNP]
Process: System Address: 0x873d11f8 Size: 121
Object: Hidden Code [Driver: ql1280, IRP_MJ_CREATE]
Process: System Address: 0x873c81f8 Size: 121
Object: Hidden Code [Driver: ql1280, IRP_MJ_CLOSE]
Process: System Address: 0x873c81f8 Size: 121
Object: Hidden Code [Driver: ql1280, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873c81f8 Size: 121
Object: Hidden Code [Driver: ql1280, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873c81f8 Size: 121
Object: Hidden Code [Driver: ql1280, IRP_MJ_POWER]
Process: System Address: 0x873c81f8 Size: 121
Object: Hidden Code [Driver: ql1280, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873c81f8 Size: 121
Object: Hidden Code [Driver: ql1280, IRP_MJ_PNP]
Process: System Address: 0x873c81f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x86fea1f8 Size: 121
Object: Hidden Code [Driver: asc3350p, IRP_MJ_CREATE]
Process: System Address: 0x8735b1f8 Size: 121
Object: Hidden Code [Driver: asc3350p, IRP_MJ_CLOSE]
Process: System Address: 0x8735b1f8 Size: 121
Object: Hidden Code [Driver: asc3350p, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8735b1f8 Size: 121
Object: Hidden Code [Driver: asc3350p, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8735b1f8 Size: 121
Object: Hidden Code [Driver: asc3350p, IRP_MJ_POWER]
Process: System Address: 0x8735b1f8 Size: 121
Object: Hidden Code [Driver: asc3350p, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8735b1f8 Size: 121
Object: Hidden Code [Driver: asc3350p, IRP_MJ_PNP]
Process: System Address: 0x8735b1f8 Size: 121
Object: Hidden Code [Driver: mraid35x, IRP_MJ_CREATE]
Process: System Address: 0x873d01f8 Size: 121
Object: Hidden Code [Driver: mraid35x, IRP_MJ_CLOSE]
Process: System Address: 0x873d01f8 Size: 121
Object: Hidden Code [Driver: mraid35x, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873d01f8 Size: 121
Object: Hidden Code [Driver: mraid35x, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873d01f8 Size: 121
Object: Hidden Code [Driver: mraid35x, IRP_MJ_POWER]
Process: System Address: 0x873d01f8 Size: 121
Object: Hidden Code [Driver: mraid35x, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873d01f8 Size: 121
Object: Hidden Code [Driver: mraid35x, IRP_MJ_PNP]
Process: System Address: 0x873d01f8 Size: 121
Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_CREATE]
Process: System Address: 0x873cb1f8 Size: 121
Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_CLOSE]
Process: System Address: 0x873cb1f8 Size: 121
Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873cb1f8 Size: 121
Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873cb1f8 Size: 121
Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_POWER]
Process: System Address: 0x873cb1f8 Size: 121
Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873cb1f8 Size: 121
Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_PNP]
Process: System Address: 0x873cb1f8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CREATE]
Process: System Address: 0x8687e500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CLOSE]
Process: System Address: 0x8687e500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_READ]
Process: System Address: 0x8687e500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_WRITE]
Process: System Address: 0x8687e500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8687e500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_POWER]
Process: System Address: 0x8687e500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8687e500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_PNP]
Process: System Address: 0x8687e500 Size: 121
Object: Hidden Code [Driver: symc8xx, IRP_MJ_CREATE]
Process: System Address: 0x8735d1f8 Size: 121
Object: Hidden Code [Driver: symc8xx, IRP_MJ_CLOSE]
Process: System Address: 0x8735d1f8 Size: 121
Object: Hidden Code [Driver: symc8xx, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8735d1f8 Size: 121
Object: Hidden Code [Driver: symc8xx, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8735d1f8 Size: 121
Object: Hidden Code [Driver: symc8xx, IRP_MJ_POWER]
Process: System Address: 0x8735d1f8 Size: 121
Object: Hidden Code [Driver: symc8xx, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8735d1f8 Size: 121
Object: Hidden Code [Driver: symc8xx, IRP_MJ_PNP]
Process: System Address: 0x8735d1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x8707c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x8707c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8707c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8707c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x8707c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8707c1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x8707c1f8 Size: 121
Object: Hidden Code [Driver: ultra, IRP_MJ_CREATE]
Process: System Address: 0x8735a1f8 Size: 121
Object: Hidden Code [Driver: ultra, IRP_MJ_CLOSE]
Process: System Address: 0x8735a1f8 Size: 121
Object: Hidden Code [Driver: ultra, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8735a1f8 Size: 121
Object: Hidden Code [Driver: ultra, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8735a1f8 Size: 121
Object: Hidden Code [Driver: ultra, IRP_MJ_POWER]
Process: System Address: 0x8735a1f8 Size: 121
Object: Hidden Code [Driver: ultra, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8735a1f8 Size: 121
Object: Hidden Code [Driver: ultra, IRP_MJ_PNP]
Process: System Address: 0x8735a1f8 Size: 121
Object: Hidden Code [Driver: dac960nt, IRP_MJ_CREATE]
Process: System Address: 0x873621f8 Size: 121
Object: Hidden Code [Driver: dac960nt, IRP_MJ_CLOSE]
Process: System Address: 0x873621f8 Size: 121
Object: Hidden Code [Driver: dac960nt, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873621f8 Size: 121
Object: Hidden Code [Driver: dac960nt, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873621f8 Size: 121
Object: Hidden Code [Driver: dac960nt, IRP_MJ_POWER]
Process: System Address: 0x873621f8 Size: 121
Object: Hidden Code [Driver: dac960nt, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873621f8 Size: 121
Object: Hidden Code [Driver: dac960nt, IRP_MJ_PNP]
Process: System Address: 0x873621f8 Size: 121
Object: Hidden Code [Driver: aic78u2, IRP_MJ_CREATE]
Process: System Address: 0x873ce1f8 Size: 121
Object: Hidden Code [Driver: aic78u2, IRP_MJ_CLOSE]
Process: System Address: 0x873ce1f8 Size: 121
Object: Hidden Code [Driver: aic78u2, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873ce1f8 Size: 121
Object: Hidden Code [Driver: aic78u2, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873ce1f8 Size: 121
Object: Hidden Code [Driver: aic78u2, IRP_MJ_POWER]
Process: System Address: 0x873ce1f8 Size: 121
Object: Hidden Code [Driver: aic78u2, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873ce1f8 Size: 121
Object: Hidden Code [Driver: aic78u2, IRP_MJ_PNP]
Process: System Address: 0x873ce1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x873d61f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_CREATE]
Process: System Address: 0x873ca1f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_CLOSE]
Process: System Address: 0x873ca1f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873ca1f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873ca1f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_POWER]
Process: System Address: 0x873ca1f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873ca1f8 Size: 121
Object: Hidden Code [Driver: adpu160m, IRP_MJ_PNP]
Process: System Address: 0x873ca1f8 Size: 121
Object: Hidden Code [Driver: vcsmpdrvЅఅ坓慤ᡨ쑘纠⺰繰ᇐ횥섄, IRP_MJ_CREATE]
Process: System Address: 0x86eb8500 Size: 121
Object: Hidden Code [Driver: vcsmpdrvЅఅ坓慤ᡨ쑘纠⺰繰ᇐ횥섄, IRP_MJ_CLOSE]
Process: System Address: 0x86eb8500 Size: 121
Object: Hidden Code [Driver: vcsmpdrvЅఅ坓慤ᡨ쑘纠⺰繰ᇐ횥섄, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86eb8500 Size: 121
Object: Hidden Code [Driver: vcsmpdrvЅఅ坓慤ᡨ쑘纠⺰繰ᇐ횥섄, IRP_MJ_POWER]
Process: System Address: 0x86eb8500 Size: 121
Object: Hidden Code [Driver: vcsmpdrvЅఅ坓慤ᡨ쑘纠⺰繰ᇐ횥섄, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86eb8500 Size: 121
Object: Hidden Code [Driver: vcsmpdrvЅఅ坓慤ᡨ쑘纠⺰繰ᇐ횥섄, IRP_MJ_PNP]
Process: System Address: 0x86eb8500 Size: 121
Object: Hidden Code [Driver: sym_u3, IRP_MJ_CREATE]
Process: System Address: 0x8735c1f8 Size: 121
Object: Hidden Code [Driver: sym_u3, IRP_MJ_CLOSE]
Process: System Address: 0x8735c1f8 Size: 121
Object: Hidden Code [Driver: sym_u3, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8735c1f8 Size: 121
Object: Hidden Code [Driver: sym_u3, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8735c1f8 Size: 121
Object: Hidden Code [Driver: sym_u3, IRP_MJ_POWER]
Process: System Address: 0x8735c1f8 Size: 121
Object: Hidden Code [Driver: sym_u3, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8735c1f8 Size: 121
Object: Hidden Code [Driver: sym_u3, IRP_MJ_PNP]
Process: System Address: 0x8735c1f8 Size: 121
Object: Hidden Code [Driver: adhf7izrȅ扏煓䂈Ȃః瑎て, IRP_MJ_CREATE]
Process: System Address: 0x86ea31f8 Size: 121
Object: Hidden Code [Driver: adhf7izrȅ扏煓䂈Ȃః瑎て, IRP_MJ_CLOSE]
Process: System Address: 0x86ea31f8 Size: 121
Object: Hidden Code [Driver: adhf7izrȅ扏煓䂈Ȃః瑎て, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86ea31f8 Size: 121
Object: Hidden Code [Driver: adhf7izrȅ扏煓䂈Ȃః瑎て, IRP_MJ_POWER]
Process: System Address: 0x86ea31f8 Size: 121
Object: Hidden Code [Driver: adhf7izrȅ扏煓䂈Ȃః瑎て, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86ea31f8 Size: 121
Object: Hidden Code [Driver: adhf7izrȅ扏煓䂈Ȃః瑎て, IRP_MJ_PNP]
Process: System Address: 0x86ea31f8 Size: 121
Object: Hidden Code [Driver: a7sllx1gȅఇ浍浓고蛼@, IRP_MJ_CREATE]
Process: System Address: 0x86fb81f8 Size: 121
Object: Hidden Code [Driver: a7sllx1gȅఇ浍浓고蛼@, IRP_MJ_CLOSE]
Process: System Address: 0x86fb81f8 Size: 121
Object: Hidden Code [Driver: a7sllx1gȅఇ浍浓고蛼@, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x86fb81f8 Size: 121
Object: Hidden Code [Driver: a7sllx1gȅఇ浍浓고蛼@, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x86fb81f8 Size: 121
Object: Hidden Code [Driver: a7sllx1gȅఇ浍浓고蛼@, IRP_MJ_POWER]
Process: System Address: 0x86fb81f8 Size: 121
Object: Hidden Code [Driver: a7sllx1gȅఇ浍浓고蛼@, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x86fb81f8 Size: 121
Object: Hidden Code [Driver: a7sllx1gȅఇ浍浓고蛼@, IRP_MJ_PNP]
Process: System Address: 0x86fb81f8 Size: 121
Object: Hidden Code [Driver: abp480n5, IRP_MJ_CREATE]
Process: System Address: 0x873cc1f8 Size: 121
Object: Hidden Code [Driver: abp480n5, IRP_MJ_CLOSE]
Process: System Address: 0x873cc1f8 Size: 121
Object: Hidden Code [Driver: abp480n5, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873cc1f8 Size: 121
Object: Hidden Code [Driver: abp480n5, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873cc1f8 Size: 121
Object: Hidden Code [Driver: abp480n5, IRP_MJ_POWER]
Process: System Address: 0x873cc1f8 Size: 121
Object: Hidden Code [Driver: abp480n5, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873cc1f8 Size: 121
Object: Hidden Code [Driver: abp480n5, IRP_MJ_PNP]
Process: System Address: 0x873cc1f8 Size: 121
Object: Hidden Code [Driver: ql1080, IRP_MJ_CREATE]
Process: System Address: 0x873c91f8 Size: 121
Object: Hidden Code [Driver: ql1080, IRP_MJ_CLOSE]
Process: System Address: 0x873c91f8 Size: 121
Object: Hidden Code [Driver: ql1080, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873c91f8 Size: 121
Object: Hidden Code [Driver: ql1080, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873c91f8 Size: 121
Object: Hidden Code [Driver: ql1080, IRP_MJ_POWER]
Process: System Address: 0x873c91f8 Size: 121
Object: Hidden Code [Driver: ql1080, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873c91f8 Size: 121
Object: Hidden Code [Driver: ql1080, IRP_MJ_PNP]
Process: System Address: 0x873c91f8 Size: 121
Object: Hidden Code [Driver: symc810, IRP_MJ_CREATE]
Process: System Address: 0x873631f8 Size: 121
Object: Hidden Code [Driver: symc810, IRP_MJ_CLOSE]
Process: System Address: 0x873631f8 Size: 121
Object: Hidden Code [Driver: symc810, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873631f8 Size: 121
Object: Hidden Code [Driver: symc810, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873631f8 Size: 121
Object: Hidden Code [Driver: symc810, IRP_MJ_POWER]
Process: System Address: 0x873631f8 Size: 121
Object: Hidden Code [Driver: symc810, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873631f8 Size: 121
Object: Hidden Code [Driver: symc810, IRP_MJ_PNP]
Process: System Address: 0x873631f8 Size: 121
Object: Hidden Code [Driver: hpn, IRP_MJ_CREATE]
Process: System Address: 0x873571f8 Size: 121
Object: Hidden Code [Driver: hpn, IRP_MJ_CLOSE]
Process: System Address: 0x873571f8 Size: 121
Object: Hidden Code [Driver: hpn, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873571f8 Size: 121
Object: Hidden Code [Driver: hpn, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873571f8 Size: 121
Object: Hidden Code [Driver: hpn, IRP_MJ_POWER]
Process: System Address: 0x873571f8 Size: 121
Object: Hidden Code [Driver: hpn, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873571f8 Size: 121
Object: Hidden Code [Driver: hpn, IRP_MJ_PNP]
Process: System Address: 0x873571f8 Size: 121
Object: Hidden Code [Driver: ql12160, IRP_MJ_CREATE]
Process: System Address: 0x873c71f8 Size: 121
Object: Hidden Code [Driver: ql12160, IRP_MJ_CLOSE]
Process: System Address: 0x873c71f8 Size: 121
Object: Hidden Code [Driver: ql12160, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873c71f8 Size: 121
Object: Hidden Code [Driver: ql12160, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873c71f8 Size: 121
Object: Hidden Code [Driver: ql12160, IRP_MJ_POWER]
Process: System Address: 0x873c71f8 Size: 121
Object: Hidden Code [Driver: ql12160, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873c71f8 Size: 121
Object: Hidden Code [Driver: ql12160, IRP_MJ_PNP]
Process: System Address: 0x873c71f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x8691d500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x8691d500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8691d500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8691d500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x8691d500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x8691d500 Size: 121
Object: Hidden Code [Driver: aic78xx, IRP_MJ_CREATE]
Process: System Address: 0x873d31f8 Size: 121
Object: Hidden Code [Driver: aic78xx, IRP_MJ_CLOSE]
Process: System Address: 0x873d31f8 Size: 121
Object: Hidden Code [Driver: aic78xx, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x873d31f8 Size: 121
Object: Hidden Code [Driver: aic78xx, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x873d31f8 Size: 121
Object: Hidden Code [Driver: aic78xx, IRP_MJ_POWER]
Process: System Address: 0x873d31f8 Size: 121
Object: Hidden Code [Driver: aic78xx, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x873d31f8 Size: 121
Object: Hidden Code [Driver: aic78xx, IRP_MJ_PNP]
Process: System Address: 0x873d31f8 Size: 121
Object: Hidden Code [Driver: amsint, IRP_MJ_CREATE]
Process: System Address: 0x873611f8 Size: 121
Object: Hidden Code [Driver: amsint, IRP_MJ_CLOSE]
Process: System Address: 0x873611f8 Size: 121
Object: Hidden Code [Driver: amsint, IRP_MJ_DEVICE==EOF==
Edited by TheBigKahuna, 29 October 2009 - 07:28 AM.