ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2010/11/05 19:54 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ------------------- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xB2A5D000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xB860A000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB0EE4000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ------------------- Path: c:\documents and settings\caba\ustawienia lokalne\temp\bcg23.tmp Status: Allocation size mismatch (API: 16384, Raw: 0) Path: c:\documents and settings\caba\ustawienia lokalne\temp\bcg24.tmp Status: Allocation size mismatch (API: 16384, Raw: 0) Path: c:\documents and settings\caba\ustawienia lokalne\dane aplikacji\google\chrome\user data\default\current session Status: Size mismatch (API: 12106, Raw: 40231) SSDT ------------------- #: 025 Function Name: NtClose Status: Hooked by "C:\WINDOWS\system32\drivers\HookCentre.sys" at address 0xb8439376 #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\system32\drivers\HookCentre.sys" at address 0xb843a420 #: 063 Function Name: NtDeleteKey Status: Hooked by "C:\WINDOWS\system32\drivers\HookCentre.sys" at address 0xb843a55c #: 065 Function Name: NtDeleteValueKey Status: Hooked by "C:\WINDOWS\system32\drivers\HookCentre.sys" at address 0xb843a57e #: 119 Function Name: NtOpenKey Status: Hooked by "C:\WINDOWS\system32\drivers\HookCentre.sys" at address 0xb843a4b4 #: 122 Function Name: NtOpenProcess Status: Hooked by "C:\WINDOWS\system32\drivers\HookCentre.sys" at address 0xb843a2fe #: 247 Function Name: NtSetValueKey Status: Hooked by "C:\WINDOWS\system32\drivers\HookCentre.sys" at address 0xb843a52e ==EOF==