ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2009/08/04 19:56 Program Version: Version 1.3.3.0 Windows Version: Windows XP SP3 ================================================== Drivers ------------------- Name: aujasnkj.sys Image Path: C:\DOCUME~1\Ginga\LOCALS~1\Temp\aujasnkj.sys Address: 0xA58DD000 Size: 82432 File Visible: No Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xA80C1000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xBA61C000 Size: 8192 File Visible: No Signed: - Status: - Name: hiber_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\hiber_WMILIB.SYS Address: 0xBA63A000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA593D000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ------------------- Path: C:\hiberfil.sys Status: Locked to the Windows API! Path: c:\windows\temp\perflib_perfdata_df4.dat Status: Allocation size mismatch (API: 16384, Raw: 0) Path: C:\Documents and Settings\Ginga\My Documents\My Pictures\-Family\PictureScans\b41920\Price\1900 JH Grandfather John Albert Price Nov. 20 1837 - Feb. 10.jpg Status: Locked to the Windows API! SSDT ------------------- #: 012 Function Name: NtAlertResumeThread Status: Hooked by "" at address 0x89e670f0 #: 013 Function Name: NtAlertThread Status: Hooked by "" at address 0x8a3e6108 #: 017 Function Name: NtAllocateVirtualMemory Status: Hooked by "" at address 0x89e94750 #: 031 Function Name: NtConnectPort Status: Hooked by "" at address 0x89e3f320 #: 043 Function Name: NtCreateMutant Status: Hooked by "" at address 0x8a4a7b68 #: 053 Function Name: NtCreateThread Status: Hooked by "" at address 0x89e4b088 #: 083 Function Name: NtFreeVirtualMemory Status: Hooked by "" at address 0x89e4dfc0 #: 089 Function Name: NtImpersonateAnonymousToken Status: Hooked by "" at address 0x89e91b80 #: 091 Function Name: NtImpersonateThread Status: Hooked by "" at address 0x89e92660 #: 108 Function Name: NtMapViewOfSection Status: Hooked by "" at address 0x89e4b180 #: 114 Function Name: NtOpenEvent Status: Hooked by "" at address 0x89e64820 #: 123 Function Name: NtOpenProcessToken Status: Hooked by "" at address 0x89e193a8 #: 129 Function Name: NtOpenThreadToken Status: Hooked by "" at address 0x89e3dd58 #: 137 Function Name: NtProtectVirtualMemory Status: Hooked by "C:\WINDOWS\system32\drivers\wpsdrvnt.sys" at address 0xba1cd2f0 #: 143 Function Name: NtQueryDefaultLocale Status: Hooked by "SysPlant.sys" at address 0xb9d57830 #: 206 Function Name: NtResumeThread Status: Hooked by "" at address 0x89e8b108 #: 213 Function Name: NtSetContextThread Status: Hooked by "" at address 0x8a3fa848 #: 228 Function Name: NtSetInformationProcess Status: Hooked by "" at address 0x89e40eb8 #: 229 Function Name: NtSetInformationThread Status: Hooked by "" at address 0x89cb8680 #: 253 Function Name: NtSuspendProcess Status: Hooked by "" at address 0x89e64748 #: 254 Function Name: NtSuspendThread Status: Hooked by "" at address 0x8a57e0d8 #: 257 Function Name: NtTerminateProcess Status: Hooked by "" at address 0x89e19558 #: 258 Function Name: NtTerminateThread Status: Hooked by "" at address 0x8a54f308 #: 267 Function Name: NtUnmapViewOfSection Status: Hooked by "" at address 0x89e2fae8 #: 277 Function Name: NtWriteVirtualMemory Status: Hooked by "" at address 0x89e8d6e8 Shadow SSDT ------------------- #: 383 Function Name: NtUserGetAsyncKeyState Status: Hooked by "" at address 0x87b9cce8 ==EOF==