Děkuju moc za snahu a zájem :) Tady jsou všechny tři logy:
ComboFixComboFix 09-09-25.01 - Jakubisko 27.09.2009 19:49.1.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1658 [GMT 2:00]
Spuštěný z: c:\documents and settings\Jakubisko\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090926-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Sygate Personal Firewall *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\ieuinit.inf
c:\windows\system32\logs
c:\windows\UA000080.DLL
c:\windows\system32\drivers\null.sys chyběl.
Obnovena kopie z - c:\windows\system32\dllcache\null.sys
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-08-27 do 2009-09-27 )))))))))))))))))))))))))))))))
.
2009-09-27 17:52 . 2001-10-25 12:00 2944 -c--a-w- c:\windows\system32\dllcache\null.sys
2009-09-27 17:52 . 2001-10-25 12:00 2944 ----a-w- c:\windows\system32\drivers\null.sys
2009-09-27 09:26 . 2009-09-27 09:27 -------- d-----w- C:\rsit
2009-09-24 14:44 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-24 14:44 . 2009-09-24 14:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-24 14:44 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-22 16:53 . 2009-09-22 16:53 -------- d-----w- c:\program files\Trend Micro
2009-09-20 20:06 . 2009-09-20 20:06 -------- d-----w- c:\program files\SDP Downloader
2009-09-15 22:47 . 2009-09-15 22:50 -------- d-----w- C:\PIRATES
2009-09-02 13:32 . 2009-09-02 13:32 -------- d-----w- c:\program files\Easy Video Splitter
2009-09-01 22:29 . 2007-10-12 13:14 3734536 ----a-w- c:\windows\system32\d3dx9_36.dll
2009-09-01 22:28 . 2009-09-01 22:28 -------- d-----w- c:\windows\Logs
2009-09-01 22:10 . 2009-09-27 09:21 -------- d-----w- c:\program files\Steam
2009-09-01 21:32 . 2009-09-01 21:32 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-09-01 21:32 . 2009-04-27 12:21 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2009-09-01 21:32 . 2009-09-01 21:32 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-27 17:41 . 2007-10-25 21:35 -------- d-----w- c:\program files\Trillian
2009-09-15 20:45 . 2007-12-15 21:59 -------- d-----w- c:\program files\Google
2009-09-01 22:10 . 2007-10-25 23:20 -------- d-----w- c:\program files\Sports Interactive
2009-09-01 22:07 . 2009-01-17 20:29 -------- d-----w- c:\program files\Microsoft Games
2009-09-01 22:06 . 2008-11-09 16:02 -------- d-----w- c:\program files\Gabest
2009-09-01 22:06 . 2009-04-08 13:13 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-09-01 22:06 . 2008-03-01 20:32 -------- d-----w- c:\program files\Total Video Converter
2009-09-01 22:06 . 2008-01-01 17:11 -------- d-----w- c:\program files\Scorpions WinCheater
2009-09-01 21:58 . 2007-10-25 20:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-01 21:53 . 2009-01-24 19:39 -------- d-----w- c:\program files\Common Files\AOL
2009-09-01 21:32 . 2009-01-20 21:15 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-08-17 16:10 . 2007-10-25 21:00 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2007-10-25 21:00 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2007-10-25 21:00 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2008-04-05 13:15 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-04-05 13:15 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2007-10-25 21:00 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2007-10-25 21:00 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2007-10-25 21:00 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2007-10-25 21:00 97480 ----a-w- c:\windows\system32\AVASTSS.scr
2009-07-30 06:58 . 2008-11-09 16:02 -------- d-----w- c:\program files\Xvid
2009-07-30 06:58 . 2007-10-26 09:55 -------- d-----w- c:\program files\Codec Pack - All In 1
2009-07-30 06:58 . 2008-01-28 06:26 -------- d-----w- c:\program files\DivX
2009-07-30 06:58 . 2008-06-17 20:14 -------- d-----w- c:\program files\mIRC
2009-07-30 06:58 . 2008-09-06 17:59 -------- d-----w- c:\program files\TVUPlayer
2009-07-30 06:58 . 2009-03-21 18:44 -------- d-----w- c:\program files\TmNationsForever
2009-07-30 06:58 . 2008-03-08 11:11 -------- d-----w- c:\program files\ABC
2009-07-29 09:32 . 2009-07-29 09:32 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-07-29 09:32 . 2009-07-29 09:32 110592 ----a-w- c:\windows\system32\OpenAL32.dll
.
------- Sigcheck -------
[7] 2001-10-25 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\beep.sys ... chybí !!
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Centrum.cz Notifikátor"="c:\program files\NetCentrum\Notifikator\Notifikator.exe" [2007-10-25 606720]
"Steam"="c:\program files\steam\steam.exe" [2009-09-01 1217784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2005-05-25 6746112]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"EPSON Stylus DX4400 Series"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "c:\windows\TEMP\E_SAA.tmp" /EF "HKCU"
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"UVS11 Preload"=c:\program files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
"Ad-Watch"=c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" /s
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe"
"SoundMAX"="c:\program files\Analog Devices\SoundMAX\Smax4.exe" /tray
"nwiz"=nwiz.exe /install
"NvMediaCenter"=RUNDLL32.EXE c:\windows\System32\NvMcTray.dll,NvTaskbarInit
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\ABC\\abc.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\football manager 2009\\fm.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [20.1.2009 20:20 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5.4.2008 15:15 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.4.2008 15:15 20560]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [1.9.2009 23:32 604416]
R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [18.5.2008 11:25 6016]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18.1.2009 23:34 1028432]
S3 ASNDIS5;ASNDIS5 Protocol Driver;c:\windows\system32\ASNDIS5.sys [10.10.2008 16:06 16269]
S3 CamdDriverV32;CamdDriverV32;c:\windows\system32\drivers\CamdDriverV32.sys [4.12.2007 17:53 515200]
S3 CamdVideo32;CamdVideo32;c:\windows\system32\drivers\CamdVideo32.sys [4.12.2007 17:53 3768]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\docume~1\JAKUBI~1\LOCALS~1\Temp\Rar$EX00.796\kerneld.wnt --> c:\docume~1\JAKUBI~1\LOCALS~1\Temp\Rar$EX00.796\kerneld.wnt [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
2009-09-27 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37]
2009-09-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 17:20]
2009-09-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Jakubisko\Data aplikací\Mozilla\Firefox\Profiles\v3r5h2l0.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-27 19:54
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\docume~1\JAKUBI~1\LOCALS~1\Temp\Rar$EX00.796\kerneld.wnt"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Celkový čas: 2009-09-27 19:56
ComboFix-quarantined-files.txt 2009-09-27 17:55
Před spuštěním: Volných bajtů: 11 263 668 224
Po spuštění: Volných bajtů: 11 983 536 128
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
190 --- E O F --- 2008-05-14 22:23
GooredFixGooredFix by jpshortstuff (24.09.09.1)
Log created at 20:07 on 27/09/2009 (Jakubisko)
Firefox version 3.5.3 (cs)
========== GooredScan ==========
========== GooredLog ==========
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [18:23 21/09/2009]
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [07:29 20/04/2008]
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
(none)
-=E.O.F=-
RootRepealROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/09/27 20:08
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: 00000050
Image Path: \Driver\00000050
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB7BB9000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79DD000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB5C34000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 017 Function Name: NtAllocateVirtualMemory
Status: Hooked by "C:\WINDOWS\System32\drivers\wpsdrvnt.sys" at address 0xf749eb30
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb7c356b8
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb7c35574
#: 053 Function Name: NtCreateThread
Status: Hooked by "C:\WINDOWS\System32\drivers\wpsdrvnt.sys" at address 0xf749e6f0
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb7c35a52
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb7c3514c
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf7508c22
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf7508f9a
#: 108 Function Name: NtMapViewOfSection
Status: Hooked by "C:\WINDOWS\System32\drivers\wpsdrvnt.sys" at address 0xf749e470
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb7c3564e
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb7c3508c
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb7c350f0
#: 137 Function Name: NtProtectVirtualMemory
Status: Hooked by "C:\WINDOWS\System32\drivers\wpsdrvnt.sys" at address 0xf749ec50
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf7509064
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb7c3576e
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb7c3572e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xb7c358ae
#: 249 Function Name: NtShutdownSystem
Status: Hooked by "C:\WINDOWS\System32\drivers\wpsdrvnt.sys" at address 0xf749e990
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\WINDOWS\System32\drivers\wpsdrvnt.sys" at address 0xf749e8d0
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\WINDOWS\System32\drivers\wpsdrvnt.sys" at address 0xf749ed60
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x89c015d0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x89707dd0 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_CREATE]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_CLOSE]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_READ]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_WRITE]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_CLEANUP]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: sys, IRP_MJ_PNP]
Process: System Address: 0x894a10e8 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CREATE]
Process: System Address: 0x898660e8 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CLOSE]
Process: System Address: 0x898660e8 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x898660e8 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x898660e8 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_POWER]
Process: System Address: 0x898660e8 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x898660e8 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_PNP]
Process: System Address: 0x898660e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x898a90e8 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_CREATE]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_CLOSE]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_READ]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_WRITE]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_POWER]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_PNP]
Process: System Address: 0x89c01808 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x89c01c78 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x89c01eb0 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x8976c0e8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x8976c0e8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8976c0e8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8976c0e8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x8976c0e8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x8976c0e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLOSE]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_WRITE]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_EA]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_EA]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SHUTDOWN]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLEANUP]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_SECURITY]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_POWER]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_QUOTA]
Process: System Address: 0x895808d0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x895242a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_CREATE]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_CLOSE]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_READ]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_WRITE]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_CLEANUP]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Npfsȅఐ偶瑲, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8952d508 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_CREATE]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_CLOSE]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_READ]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_WRITE]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_CLEANUP]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x896af0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅః瑎て, IRP_MJ_SET_SECURITY]
Process: System Address: 0x896af0e8 Size: 15
==EOF==