Edit C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll
MZ? ?? ? @ ? ? ?!?L?!This program cannot be run in DOS mode. $ ???z???z???z?f?'???z?????z???????z???{??z?????z?????z??????z?????z?????z?????z?Rich??z? PE L ???e ? ! \ ? 8C p ` WP @ ?Y x ?N ? 0 ? ?? P, @ ? 8% @ .text h[ \ `.data ?? p ` @ ?.rsrc ? 0 f @ @.reloc x @ l @ B ?W ?V ?V ?V ?V W W .W @W RW TX DX 2X X X ?W ?V ?W ?W ?W ?W ?W xW dW (T 4T JT `T nT ~T ?T ?T ?T ?S rV VV BV (V V ?U ?U ?U ?U ?U ?U ?U ?U dU NU <U .U U U ?T ?T ?T BR NR ZR pR ?R ?R ?R ?R ?R ?R ?R ?R S S (S 6S LS \S lS |S ?S ?S ?S ?S ?S ?S T T ?T ?X ?X Y Y "Y 8Y ?Y ?Y jY XY ?Y ?X rX s ? ?o ??X ?X ?X R R R ?Q ?Q ?Q (R ?Q ?Q ?Q ?Q ?Q ?Q ?Q ?Q ?Q |Q !? ???e } ?% ? \ R e g i s t r y \ U s e r \ F i l e C a c h e \ k e r n e l 3 2 . d l l IsWow64Process2 IsWow64Process S e A s s i g n P r i m a r y T o k e n P r i v i l e g e \ S a f e 3 6 0 P o r t FilterGetDosName FilterVolumeFindClose FilterVolumeFindNext FilterVolumeFindFirst FilterConnectCommunicationPort FilterGetMessage FilterReplyMessage FilterSendMessage f l t l i b . d l l InterlockedPushEntrySList InterlockedPopEntrySList InitializeSListHead \ I N I T S T A R T F A I L E D S y s t e m \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ 3 6 0 F s F l t \ E n u m F l a g s A l t i t u d e 3 8 2 3 0 0 I n s t a n c e s \ 3 6 0 T o p I n s t a n c e D e f a u l t I n s t a n c e 3 6 0 T o p I n s t a n c e I n s t a n c e s I m a g e P a t h G r o u p D e p e n d O n S e r v i c e S t a r t W o r k C o n f i g W O W 6 4 s y s t e m 3 2 \ D R I V E R S \ 3 6 0 F s F l t . s y s D e l e t e F l a g F S F i l t e r A c t i v i t y M o n i t o r F l t M g r S y s t e m \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ 3 6 0 F s F l t RtlGetVersion n t d l l . d l l : NtDeleteKey NtCreateKey ntdll.dll S y m b o l i c L i n k V a l u e \ R e g i s t r y \ U s e r \ F i l e C a c h e \ ? ? \ D C o m F i l t e r \ R e g i s t r y \ M a c h i n e \ S Y S T E M \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ 3 6 0 F s F l t \ R e g i s t r y \ M a c h i n e \ S Y S T E M \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ q u t m d s e r v n t d l l DbgPrint RtlUpcaseUnicodeChar Wow64RevertWow64FsRedirection Wow64DisableWow64FsRedirection K e r n e l 3 2 . d l l * 3 6 0 F s F l t m i n i - f i l t e r d r i v e r 3 6 0 F s F l t 3 6 0 F s F l t . s y s 3 6 0 F s F l t _ W i n 1 0 . s y s 3 6 0 F s F l t _ a r m 6 4 . s y s \ d r i v e r s \ 3 6 0 F s F l t . s y s % s . % 0 3 d S y s t e m \ C u r r e n t C o n t r o l S e t \ S e r v i c e s % 0 8 X % 0 8 X % 0 8 X % 0 8 X I n f o r m a t i o n \ D e v i c e \ M u p \ \ D e v i c e \ L a n m a n R e d i r e c t o r \ S Y S T E M \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ q u t m d s e r v \\.\qutmdrv \\.\360HookPort s y s t e m 3 2 \ D R I V E R S \ h o o k p o r t . s y s S y s t e m \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ h o o k p o r t D i s p l a y N a m e E r r o r C o n t r o l T y p e Q u a n t u m D e e p S c a n n e r S e r v e r s s y s t e m 3 2 \ D R I V E R S \ q u t m d r v . s y s S y s t e m \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ q u t m d s e r v \ \ . \ q u t m d r v CreateProcessInternalW CreateProcessW kernel32.dll RtlNtStatusToDosError NtSetValueKey NtQueryValueKey NtOpenKey RtlUpcaseUnicodeString RtlUnicodeStringToAnsiString RtlAnsiStringToUnicodeString RtlFreeUnicodeString RtlInitAnsiString RtlInitUnicodeString CancelIPChangeNotify I p h l p a p i . d l l GetNameInfoW w s 2 _ 3 2 . d l l ?u?u? Start DeleteFlag System\CurrentControlSet\Services\hookport B o o t B u s E x t e n d e r h o o k p o r t . s y s . d a t EfiLoadBitmap e f i p r o c . d l l \ d r i v e r s \ e f i m o n . s y s e f i m o n . s y s H o o k P o r t h o o k p o r t s a f e m o n \ h o o k p o r t . s y s \ d r i v e r s \ h o o k p o r t . s y s q u t m d r v . s y s . d a t System\CurrentControlSet\Services\qutmdserv q u t m d s e r v \ d r i v e r s \ q u t m d r v . s y s . t m p q u t m d r v . s y s q u t m d r v _ w i n 1 0 . s y s \ d r i v e r s \ q u t m d r v . s y s %s.%03d \drivers\qutmdrv.sys System\CurrentControlSet\Services qutmdserv \ R e g i s t r y \ F i l e C a c h e ?8?eI?{B[???????K?g???4????o??z?_??]M+???O? ^X???i??-?7k?+Uo?G???t?r>.,d???dAZ???u?q?d?$H????(?{??V?a?p . s y s NtQuerySystemInformation Wow64GetThreadContext GetModuleInformation64 ReadProcessMemory64 GetModuleFileNameExW64 GetModuleFileNameExW \ S y s t e m 3 2 \ P s A p i . d l l SymGetModuleInfoW64 SymGetSymFromAddr64 SymCleanup SymLoadModuleExW SymSetOptions SymRegisterCallback64 SymInitialize SymGetModuleBase64 SymFunctionTableAccess64 StackWalk64 \ d b g h e l p . d l l \ i p c \ x 6 4 f o r 3 2 l i b . d l l \ % S % S \SystemRoot\ % s + 0 x % I 6 4 X % s ! % S + 0 x % I 6 4 X Invalid parameter passed to C runtime function. X&?&?????? ?????EEE??? 00?P?? ('8PW? 700PP? (???? ```hhhxppwpp H ?q &