Thanks in advance,
TwinDiddy
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/07/19 11:41
Program Version: Version 1.3.2.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB87FD000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79BB000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB6C24000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0xf7a9d236
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xf7a9d22c
#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0xf7a9d23b
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0xf7a9d245
#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xf7a9d24a
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xf7a9d218
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xf7a9d21d
#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xf7a9d254
#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xf7a9d24f
#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0xf7a9d240
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0xf7a9d227
==EOF==
Edited by TwinDiddy, 19 July 2009 - 11:01 AM.