ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Time: 2009/07/03 19:36 Program Version: Version 1.3.0.0 Windows Version: Windows XP SP2 ================================================== Drivers ------------------- Name: 206f56b4.sys Image Path: C:\WINDOWS\System32\drivers\206f56b4.sys Address: 0xB4045000 Size: 100736 File Visible: No Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xB3F75000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xB8624000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB2F3F000 Size: 49152 File Visible: No Signed: - Status: - Stealth Objects ------------------- Object: Hidden Code [ETHREAD: 0x89b00330] Process: System Address: 0x88f8e790 Size: 1000 Hidden Services ------------------- Service Name: 206f56b4 Image Path: C:\WINDOWS\System32\drivers\206f56b4.sys ==EOF==