ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2009/10/03 13:10 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ------------------- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xEB894000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF8C8D000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xEC8D4000 Size: 49152 File Visible: No Signed: - Status: - SSDT ------------------- #: 041 Function Name: NtCreateKey Status: Hooked by "" at address 0xf8e41a2e #: 053 Function Name: NtCreateThread Status: Hooked by "" at address 0xf8e41a24 #: 063 Function Name: NtDeleteKey Status: Hooked by "" at address 0xf8e41a33 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "" at address 0xf8e41a3d #: 098 Function Name: NtLoadKey Status: Hooked by "" at address 0xf8e41a42 #: 122 Function Name: NtOpenProcess Status: Hooked by "" at address 0xf8e41a10 #: 128 Function Name: NtOpenThread Status: Hooked by "" at address 0xf8e41a15 #: 193 Function Name: NtReplaceKey Status: Hooked by "" at address 0xf8e41a4c #: 204 Function Name: NtRestoreKey Status: Hooked by "" at address 0xf8e41a47 #: 247 Function Name: NtSetValueKey Status: Hooked by "" at address 0xf8e41a38 #: 257 Function Name: NtTerminateProcess Status: Hooked by "" at address 0xf8e41a1f #: 277 Function Name: NtWriteVirtualMemory Status: Hooked by "" at address 0xf8e41a1a ==EOF==