RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows Vista Version 6.0.6002 (Service Pack 2) Number of processors #2 ============================================== >SSDT State ============================================== ============================================== >Shadow ============================================== ============================================== >Processes ============================================== 0x93144220 [364] C:\Windows\System32\agrsmsvc.exe (Agere Systems, Agere Soft Modem Call Progress Service) 0x93145020 [384] C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION, Service of ConfigFree.) 0x93149D90 [472] C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation, PresentationFontCache.exe) 0x913A7AE8 [528] C:\Windows\System32\smss.exe (Microsoft Corporation, Windows Session Manager) 0x887DE4A0 [596] C:\Windows\System32\csrss.exe (Microsoft Corporation, Proces wykonawczy klienta/serwera) 0x91F20650 [648] C:\Windows\System32\wininit.exe (Microsoft Corporation, Aplikacja uruchamiania systemu Windows) 0x887DE8D0 [660] C:\Windows\System32\csrss.exe (Microsoft Corporation, Proces wykonawczy klienta/serwera) 0x912BDAD8 [696] C:\Windows\System32\winlogon.exe (Microsoft Corporation, Aplikacja logowania systemu Windows) 0x91F2AB58 [736] C:\Windows\System32\services.exe (Microsoft Corporation, Usługi i aplikacja Kontroler) 0x91F55D90 [748] C:\Windows\System32\lsass.exe (Microsoft Corporation, Proces urzędu zabezpieczeń lokalnych) 0x9313AA28 [752] C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation, RAID Monitor) 0x88A73208 [756] C:\Windows\System32\lsm.exe (Microsoft Corporation, Usługa Menedżer sesji lokalnej) 0x91FB9B98 [916] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0x922A1C40 [976] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0x91FD4D90 [1012] C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation, Antimalware Service Executable) 0x92296820 [1144] C:\Windows\System32\Ati2evxx.exe (ATI Technologies Inc., ATI External Event Utility EXE Module) 0x9270AA00 [1160] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0x922C3B20 [1196] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0x931AA2D0 [1208] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0x922BF2E8 [1212] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0x9279CD90 [1352] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0xA8068988 [1368] C:\Windows\ehome\ehmsas.exe (Microsoft Corporation, Media Center Media Status Aggregator Service) 0x92743C68 [1380] C:\Windows\System32\SLsvc.exe (Microsoft Corporation, Usługa licencjonowania oprogramowania firmy Microsoft) 0x92727598 [1448] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0x931A33B0 [1528] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0x927C5248 [1584] C:\Windows\System32\Ati2evxx.exe (ATI Technologies Inc., ATI External Event Utility EXE Module) 0x92730CA0 [1596] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0xC3121248 [1608] C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation, Internet Explorer) 0x931B3D90 [1648] C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH, Toshiba TEMPRO) 0x927A8D90 [1868] C:\Windows\System32\spoolsv.exe (Microsoft Corporation, Spooler SubSystem App) 0x927CA020 [1892] C:\Windows\System32\svchost.exe (Microsoft Corporation, Proces hosta dla usług systemu Windows) 0xA7A28390 [1912] C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG, Nero Home) 0x931B0D90 [2136] C:\Program Files\TOSHIBA\TOSHIBA HD DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation, TOSHIBA Navi Support Service) 0x931E8020 [2156] C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation, TDCSrv Application) 0x931CB020 [2176] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION, TOSHIBA Bluetooth Service) 0x922FBAD8 [2204] C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc., ULCDRSvr) 0x931E9AC0 [2244] C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation, Microsoft® Windows Live ID Service) 0x8E5D7CE8 [2336] C:\Windows\System32\SearchIndexer.exe (Microsoft Corporation, Indeksator programu Microsoft Windows Search) 0xA7A7F300 [2580] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION., TosA2dp) 0x8509AD90 [2592] C:\Windows\System32\wuauclt.exe (Microsoft Corporation, Windows Update) 0x9239E020 [2596] C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation, Microsoft® Windows Live ID Service Monitor) 0x923AC500 [2808] C:\Windows\System32\taskeng.exe (Microsoft Corporation, Aparat Harmonogramu zadań) 0x931556A0 [2840] C:\Windows\System32\dwm.exe (Microsoft Corporation, Menedżer okien pulpitu) 0x91341D90 [2872] C:\Windows\System32\taskeng.exe (Microsoft Corporation, Aparat Harmonogramu zadań) 0x91FB1BF0 [2944] C:\Windows\explorer.exe (Microsoft Corporation, Eksplorator Windows) 0xC33EFCE8 [3124] C:\Windows\System32\wbem\WmiPrvSE.exe (Microsoft Corporation, WMI Provider Host) 0xC323D0F0 [3188] C:\Users\Mario\Desktop\RKUnhookerLE.EXE (UG North, RKULE, SR2 Normandy) 0x9276B928 [3332] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION., TosBtHSP) 0xA8A35C40 [3376] C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG, Nero Home) 0xA81EB168 [3420] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor, HD Audio Control Panel) 0xA0840218 [3468] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc., Synaptics TouchPad Enhancements) 0xA7BFB618 [3488] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation, Event Monitor User Notification Tool) 0xA7E4D8D8 [3544] C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH, Toshiba TEMPRO) 0x922BBD90 [3568] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc., Java(TM) Update Scheduler) 0xA85F97A8 [3580] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation, Microsoft Security Client User Interface) 0xA7E3B318 [3596] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA, CD/DVD Drive Acoustic Silencer) 0xA08B7A70 [3604] C:\Windows\ehome\ehtray.exe (Microsoft Corporation, Media Center Tray Applet) 0x9238F798 [3620] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG, Nero Home) 0x927029C0 [3628] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc., GoogleToolbarNotifier) 0xA97B55A8 [3644] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION., TosBtMng) 0xA09DD9C0 [3672] C:\Program Files\Synaptics\SynTP\SynToshiba.exe (Synaptics, Inc., Toshiba Custom PlugIn Application) 0xC315C508 [3756] C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation, Internet Explorer) 0x926F82E0 [3784] C:\Windows\System32\alg.exe (Microsoft Corporation, Usługa bramy warstwy aplikacji) 0x9276B698 [4024] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION., -) 0x8503DD90 [4] System 0x9279C648 [1320] C:\Windows\System32\audiodg.exe (Microsoft Corporation, Izolacja wykresu urządzenia audio systemu Windows ) ============================================== >Drivers ============================================== 0x8D403000 C:\Windows\system32\DRIVERS\atikmdag.sys 7176192 bytes (ATI Technologies Inc., ATI Radeon Kernel Mode Driver) 0x82C10000 C:\Windows\system32\ntkrnlpa.exe 3903488 bytes (Microsoft Corporation, NT Kernel & System) 0x82C10000 PnpManager 3903488 bytes 0x82C10000 RAW 3903488 bytes 0x82C10000 WMIxWDM 3903488 bytes 0x8DC04000 C:\Windows\system32\DRIVERS\NETw4v32.sys 2256896 bytes (Intel Corporation, Intel® Wireless WiFi Link Driver) 0x9D490000 Win32k 2109440 bytes 0x9D490000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Współużytkowany sterownik Win32) 0x91604000 C:\Windows\system32\drivers\RTKVHDA.sys 1781760 bytes (Realtek Semiconductor Corp., Realtek(r) High Definition Audio Function Driver) 0x9180C000 C:\Windows\system32\DRIVERS\AGRSM.sys 1163264 bytes (Agere Systems, SoftModem Device Driver) 0x88E04000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, Sterownik systemu plików NT) 0x83A03000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver) 0x88C0E000 C:\Windows\System32\drivers\tcpip.sys 970752 bytes (Microsoft Corporation, TCP/IP Driver) 0x806DD000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module) 0xA0C01000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver) 0x8CA00000 C:\Windows\System32\Drivers\dump_iaStor.sys 778240 bytes 0x8380F000 C:\Windows\system32\DRIVERS\iaStor.sys 778240 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32) 0xA0CF5000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor) 0x8DADB000 C:\Windows\System32\drivers\dxgkrnl.sys 659456 bytes (Microsoft Corporation, DirectX Graphics Kernel) 0x8CAE6000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver) 0x8320C000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, Dynamiczna struktura WDF) 0x8397A000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0x80613000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library) 0x9F60B000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, Stos protokołu HTTP) 0x9F77C000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver) 0x8DE49000 C:\Windows\system32\drivers\tifm21.sys 311296 bytes (Texas Instruments, tifm21.sys) 0x88F52000 C:\Windows\system32\DRIVERS\tos_sps32.sys 307200 bytes (TOSHIBA Corporation, tos_sps2) 0x83348000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver) 0x91406000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x83295000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, Sterownik ACPI dla systemu NT) 0x8069C000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver) 0x8DF69000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver) 0x88DA2000 C:\Windows\system32\drivers\HdAudio.sys 258048 bytes (Microsoft Corporation, High Definition Audio Function Driver) 0x8DB93000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0x838CD000 C:\Windows\system32\DRIVERS\iaNvStor.sys 245760 bytes (Intel Corporation, Intel(R) Turbo Memory Driver) 0x914B7000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0x83B39000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem) 0x9F703000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr) 0x88F14000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Sterownik kopiowania woluminów w tle) 0x88D51000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB) 0x82FC9000 ACPI_HAL 208896 bytes 0x82FC9000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0x83938000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Menedżer filtrów systemu plików firmy Microsoft) 0x9144E000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver) 0x8DF3A000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver) 0x833A7000 C:\Windows\system32\DRIVERS\pcmcia.sys 184320 bytes (Microsoft Corporation, Sterownik magistrali PCMCIA) 0x83B74000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0x8DED4000 C:\Windows\system32\DRIVERS\SynTP.sys 184320 bytes (Synaptics, Inc., Synaptics Touchpad Driver) 0x83B0E000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider) 0x8CBBB000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library) 0x915B6000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver) 0x91535000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver) 0x9F754000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver) 0x88FB4000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache) 0x91935000 C:\Windows\system32\DRIVERS\MpFilter.sys 159744 bytes (Microsoft Corporation, Microsoft antimalware file system filter driver) 0x832F6000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, Licznik NT Plug and Play PCI) 0xA0DA5000 C:\Windows\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0x83BA1000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0x8DFD7000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x88D16000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll) 0x9F6C3000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0x83BC6000 C:\Windows\System32\Drivers\usbvideo.sys 135168 bytes (Microsoft Corporation, USB Video Class Driver) 0x9198F000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver) 0x9F6E4000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0x83911000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension) 0x9F678000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver) 0x88CFB000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API) 0x91583000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, Sterownik filtru wirtualizacji plików LUA) 0x8DE95000 C:\Windows\system32\DRIVERS\sdbus.sys 106496 bytes (Microsoft Corporation, SecureDigital Bus Driver) 0x9F695000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver) 0x8DF12000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0x9F7E2000 C:\Users\Mario\AppData\Local\Temp\fwlcypod.sys 98304 bytes 0x9F73C000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector) 0x8DBE0000 C:\Windows\system32\DRIVERS\Rtlh86.sys 98304 bytes (Realtek Corporation , Realtek 8101E/8168/8169 NDIS6 32-bit Driver ) 0x914FD000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver) 0x8DFB5000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0x919CB000 C:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0xA0DE1000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver) 0x91480000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, Harmonogram pakietów QoS) 0x917B7000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver) 0x9F6AE000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver) 0x8CB96000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager) 0x8CB82000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0x917CD000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver) 0x8DEB6000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, Sterownik portu i8042) 0x915EA000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6) 0x914A4000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0x88FDB000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver) 0x88D91000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy) 0x80683000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Sterownik błędów sprzętowych charakterystycznych dla platformy) 0x8396A000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver) 0x9151D000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library) 0x915A6000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver) 0x833D4000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager) 0x8DE2B000 C:\Windows\system32\DRIVERS\ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0x8CBAB000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver) 0x8DF2A000 C:\Windows\System32\Drivers\tosrfcom.sys 65536 bytes (TOSHIBA Corporation, Bluetooth RFCOMM Driver) 0x8CAD7000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver) 0x91574000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver) 0x88FA5000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0x8331D000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver) 0x8CB73000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0x8DBD1000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0x83339000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver) 0x8DE3B000 C:\Windows\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0x9D6D0000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver) 0x8CBE5000 C:\Windows\system32\DRIVERS\circlass.sys 57344 bytes (Microsoft Corporation, Consumer IR Class Driver for eHome) 0x91496000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver) 0x919E2000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver) 0x83399000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0x9155D000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver) 0x91928000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Sterownik modemu) 0x88D44000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator) 0x83288000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR) 0xA0CE9000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver) 0x91983000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0x8DB7C000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver) 0x8DEC9000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Sterownik klasy klawiatury) 0x8DF03000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Sterownik klasy myszy) 0x919C0000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver) 0x8DFCC000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0x8DFAA000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper) 0x88D86000 C:\Windows\system32\DRIVERS\tosporte.sys 45056 bytes (TOSHIBA Corporation, TOSHIBA Bluetooth Port Emulation Driver) 0x8CAC3000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x8DB88000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0x8332F000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver) 0x9156A000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver) 0x832EC000 C:\Windows\system32\DRIVERS\LPCFilter.sys 40960 bytes (COMPAL ELECTRONIC INC., LPCFilter) 0xA0DCB000 C:\Windows\system32\DRIVERS\MpNWMon.sys 40960 bytes (Microsoft Corporation, Network monitor driver) 0x8CBF3000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver) 0x915E0000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver) 0x914F3000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy) 0xA0CDF000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0x88FF5000 C:\Windows\system32\DRIVERS\CplIR.SYS 36864 bytes (COMPAL ELECTRONIC INC., CPLIR) 0x88FEC000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver) 0x9195C000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver) 0x91514000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0x8392F000 C:\Windows\system32\drivers\msahci.sys 36864 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver) 0xA0DD5000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0x919F0000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0x9D6B0000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver) 0x8CACE000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x91800000 C:\Windows\System32\Drivers\UVCFTR_S.SYS 36864 bytes (Chicony Electronics Co., Ltd., UVCFTR_S.sys) 0x832DB000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0x83909000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver) 0x80694000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver) 0x9152D000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, Sterownik filtru myszy HID) 0x832E4000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver) 0x919B0000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x919B8000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x88F9D000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor) 0x9196C000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver) 0x9197C000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0x83392000 C:\Windows\system32\drivers\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0x8060C000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0x91965000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver) 0x88F4D000 C:\Windows\system32\DRIVERS\TVALZ_O.SYS 20480 bytes (TOSHIBA Corporation, TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver) 0x8DEAF000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver) 0x8DF0E000 C:\Windows\system32\DRIVERS\tdcmdpst.sys 16384 bytes (TOSHIBA Corporation., Toshiba ODD Writing Driver For x86.) 0x8332C000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver) 0x8DEB3000 C:\Windows\system32\DRIVERS\tosrfec.sys 12288 bytes (TOSHIBA Corporation, TOSHIBA Bluetooth EC Driver) 0x8DFFA000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0x8DF01000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) ============================================== >Stealth ============================================== ============================================== >Files ============================================== ============================================== >Hooks ============================================== ntkrnlpa.exe+0x000A87AA, Type: Inline - RelativeJump 0x82CB87AA-->82CB87B1 [ntkrnlpa.exe] [1608]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x773C8E3B-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x773D1305-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7740847D-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x773F2EF5-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x77408152-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x773F10B0-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x7741D639-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x7741D65D-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x7741D4D9-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x7741D5D3-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x773C87AD-->00000000 [ieframe.dll] [1608]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x773C98DB-->00000000 [ieframe.dll] [3756]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x773D1305-->00000000 [ieframe.dll] [3756]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7740847D-->00000000 [ieframe.dll] [3756]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x773F2EF5-->00000000 [ieframe.dll] [3756]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x77408152-->00000000 [ieframe.dll] [3756]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x773F10B0-->00000000 [ieframe.dll] [3756]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x7741D639-->00000000 [ieframe.dll] [3756]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x7741D65D-->00000000 [ieframe.dll] [3756]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x7741D4D9-->00000000 [ieframe.dll] [3756]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x7741D5D3-->00000000 [ieframe.dll]