ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2009/12/02 21:33 Program Version: Version 1.3.5.0 Windows Version: Windows XP Media Center Edition SP2 ================================================== Processes ------------------- Path: System PID: 4 Status: - Path: C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe PID: 240 Status: - Path: C:\Program Files\Java\jre6\bin\jqs.exe PID: 360 Status: - Path: C:\Program Files\McAfee\SiteAdvisor\McSACore.exe PID: 476 Status: - Path: C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe PID: 584 Status: - Path: C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe PID: 668 Status: - Path: C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe PID: 776 Status: - Path: C:\WINDOWS\system32\smss.exe PID: 800 Status: - Path: C:\WINDOWS\system32\csrss.exe PID: 852 Status: - Path: C:\WINDOWS\system32\winlogon.exe PID: 880 Status: - Path: C:\WINDOWS\system32\services.exe PID: 932 Status: - Path: C:\WINDOWS\system32\lsass.exe PID: 944 Status: - Path: C:\Documents and Settings\Owner.SPARKLE\Desktop\RootRepeal.exe PID: 1100 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 1108 Status: - Path: C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe PID: 1132 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 1216 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 1260 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 1300 Status: - Path: C:\Program Files\McAfee\MPF\MpfSrv.exe PID: 1368 Status: - Path: C:\Program Files\Intel\Wireless\Bin\EvtEng.exe PID: 1384 Status: - Path: C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe PID: 1436 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 1468 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 1588 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 1616 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 1652 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 1700 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 1796 Status: - Path: C:\WINDOWS\system32\spoolsv.exe PID: 1852 Status: - Path: C:\WINDOWS\ehome\ehrecvr.exe PID: 1956 Status: - Path: C:\WINDOWS\ehome\ehSched.exe PID: 1988 Status: - Path: C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS PID: 2000 Status: - Path: C:\WINDOWS\system32\svchost.exe PID: 2040 Status: - Path: C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe PID: 2088 Status: - Path: C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe PID: 2100 Status: - Path: C:\WINDOWS\system32\wuauclt.exe PID: 2124 Status: - Path: C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe PID: 2204 Status: - Path: C:\WINDOWS\ehome\ehmsas.exe PID: 2256 Status: - Path: C:\WINDOWS\system32\alg.exe PID: 2260 Status: - Path: C:\Program Files\Viewpoint\Common\ViewpointService.exe PID: 2264 Status: - Path: C:\WINDOWS\system32\igfxsrvc.exe PID: 2436 Status: - Path: C:\WINDOWS\ehome\mcrdsvc.exe PID: 2636 Status: - Path: C:\WINDOWS\explorer.exe PID: 2820 Status: - Path: C:\PROGRA~1\McAfee.com\Agent\mcagent.exe PID: 3216 Status: - Path: C:\WINDOWS\ehome\ehtray.exe PID: 3552 Status: - Path: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe PID: 3580 Status: - Path: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe PID: 3604 Status: - Path: C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe PID: 3656 Status: - Path: C:\WINDOWS\stsystra.exe PID: 3664 Status: - Path: C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe PID: 3680 Status: - Path: C:\WINDOWS\system32\igfxtray.exe PID: 3688 Status: - Path: C:\WINDOWS\system32\hkcmd.exe PID: 3704 Status: - Path: C:\WINDOWS\system32\igfxpers.exe PID: 3720 Status: - Path: C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe PID: 3728 Status: - Path: C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe PID: 3736 Status: - Path: C:\Program Files\HP\HP Software Update\hpwuSchd2.exe PID: 3768 Status: - Path: C:\Program Files\Common Files\Real\Update_OB\realsched.exe PID: 3828 Status: - Path: C:\WINDOWS\system32\dllhost.exe PID: 3844 Status: - Path: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe PID: 3876 Status: - Path: C:\WINDOWS\system32\ctfmon.exe PID: 3904 Status: - Path: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe PID: 3960 Status: - Path: C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe PID: 5096 Status: -