Thanks for your reply.
Here is the RootRepeal log and attachment for the OTS file.
While RootRepeal was scanning, when it reached the SSDT tab, a message came up saying it couldn't scan the boot sector and told me to adjust the Disk Access Level in the Options dialog but I tried that and it didn't work.
And I couldn't find the 64 bit checkbox you spoke for the OTS.
If you need me to do the scans again, let me know.
Thanks!
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/03 10:52
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF42E5000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF89D1000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PCI_NTPNP3076
Image Path: \Driver\PCI_NTPNP3076
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEFA44000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\HIBERFIL.SYS
Status: Locked to the Windows API!
Path: c:\documents and settings\john\local settings\temporary internet files\content.ie5\hrqlyppy\white-x-red-circle-critical-warning-virus-help-t257317[2].htm
Status: Allocation size mismatch (API: 1081344, Raw: 131072)
Path: c:\documents and settings\john\local settings\temporary internet files\content.ie5\hrqlyppy\search[2].htm
Status: Allocation size mismatch (API: 1081344, Raw: 65536)
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "sptd.sys" at address 0xf82bb0d0
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf82c0fb2
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf82c1340
#: 119 Function Name: NtOpenKey
Status: Hooked by "sptd.sys" at address 0xf82bb0b0
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf82c1418
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "sptd.sys" at address 0xf82c1298
#: 247 Function Name: NtSetValueKey
Status: Hooked by "sptd.sys" at address 0xf82c14aa
Stealth Objects
-------------------
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x82d671e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x828661e8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x829471e8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x829471e8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x829471e8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x829471e8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x829471e8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x829471e8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x829471e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x82dd61e8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x82960270 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x82960270 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82960270 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82960270 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x82960270 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x82960270 Size: 121
Object: Hidden Code [Driver: aixlgmv9Ѕ敓Ёఈ䵃慖, IRP_MJ_CREATE]
Process: System Address: 0x8290d1e8 Size: 121
Object: Hidden Code [Driver: aixlgmv9Ѕ敓Ёఈ䵃慖, IRP_MJ_CLOSE]
Process: System Address: 0x8290d1e8 Size: 121
Object: Hidden Code [Driver: aixlgmv9Ѕ敓Ёఈ䵃慖, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8290d1e8 Size: 121
Object: Hidden Code [Driver: aixlgmv9Ѕ敓Ёఈ䵃慖, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8290d1e8 Size: 121
Object: Hidden Code [Driver: aixlgmv9Ѕ敓Ёఈ䵃慖, IRP_MJ_POWER]
Process: System Address: 0x8290d1e8 Size: 121
Object: Hidden Code [Driver: aixlgmv9Ѕ敓Ёఈ䵃慖, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8290d1e8 Size: 121
Object: Hidden Code [Driver: aixlgmv9Ѕ敓Ёఈ䵃慖, IRP_MJ_PNP]
Process: System Address: 0x8290d1e8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x828821e8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x828821e8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x828821e8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x828821e8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x828821e8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x828821e8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x828821e8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x82a16790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_CREATE]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_CLOSE]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_READ]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_SHUTDOWN]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_CLEANUP]
Process: System Address: 0x829af790 Size: 121
Object: Hidden Code [Driver: Cdfsȅఅ瑁䅭뺰쀇ँFileNa, IRP_MJ_PNP]
Process: System Address: 0x829af790 Size: 121
==EOF==
Edited by MrParadox, 03 November 2009 - 01:22 PM.