ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2009/10/13 20:57 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ------------------- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF1E32000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7AFE000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xEE949000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ------------------- Path: C:\hiberfil.sys Status: Locked to the Windows API! Path: C:\pagefile.sys Status: Locked to the Windows API! Path: c:\documents and settings\jess\local settings\temp\etilqs_niqy9fgabjhxpr2z1bvg Status: Allocation size mismatch (API: 32768, Raw: 0) Path: c:\documents and settings\jess\local settings\application data\google\chrome\user data\default\current session Status: Size mismatch (API: 80095, Raw: 79618) Path: c:\documents and settings\jess\local settings\application data\google\chrome\user data\default\history index 2009-10-journal Status: Size mismatch (API: 267272, Raw: 259064) ==EOF==