ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2011/03/25 21:23
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
Address: 0x9DA97000 Size: 892928 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x9CC9A000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: c:\documents and settings\melissa\local settings\temp\~dfb082.tmp
Status: Allocation size mismatch (API: 65536, Raw: 16384)
Path: c:\documents and settings\melissa\local settings\temp\~dfb2d6.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\melissa\local settings\temp\~dfbed2.tmp
Status: Allocation size mismatch (API: 131072, Raw: 16384)
Path: C:\System Rollback Data\Restore\Archive\00000045\00000044\0\Target\Documents and Settings\All Users\Application Data\AVG10\Chjw\300648~1.DAT:d10ba13b-56b1-4a0f-9116-b417a99cbd3d
Status: Visible to the Windows API, but not on disk.
Processes
-------------------
Path: C:\WINDOWS\system32\MPK\MPK.exe
PID: 1788 Status: Hidden from the Windows API!
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0xa3c985c6
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xa3c985bc
#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0xa3c985cb
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0xa3c985d5
#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xa3c985da
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xa3c985a8
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xa3c985ad
#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xa3c985e4
#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xa3c985df
#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0xa3c985d0
==EOF==