Code:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/01/21 22:01
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: a6kcga24.SYS
Image Path: H:\WINDOWS\System32\Drivers\a6kcga24.SYS
Address: 0xB7354000 Size: 229376 File Visible: - Signed: -
Status: -
Name: ACPI.sys
Image Path: ACPI.sys
Address: 0xB9E5F000 Size: 188800 File Visible: - Signed: -
Status: -
Name: ACPI_HAL
Image Path: \Driver\ACPI_HAL
Address: 0x804D7000 Size: 2154496 File Visible: - Signed: -
Status: -
Name: afd.sys
Image Path: H:\WINDOWS\System32\drivers\afd.sys
Address: 0xA9AF0000 Size: 138496 File Visible: - Signed: -
Status: -
Name: AFS2K.SYS
Image Path: H:\WINDOWS\System32\Drivers\AFS2K.SYS
Address: 0xBA138000 Size: 54336 File Visible: - Signed: -
Status: -
Name: atapi.sys
Image Path: atapi.sys
Address: 0xB9E17000 Size: 98304 File Visible: - Signed: -
Status: -
Name: atapi.sys
Image Path: atapi.sys
Address: 0x00000000 Size: 0 File Visible: - Signed: -
Status: -
Name: ati2cqag.dll
Image Path: H:\WINDOWS\System32\ati2cqag.dll
Address: 0xBF063000 Size: 577536 File Visible: - Signed: -
Status: -
Name: ati2dvag.dll
Image Path: H:\WINDOWS\System32\ati2dvag.dll
Address: 0xBF012000 Size: 331776 File Visible: - Signed: -
Status: -
Name: ati2mtag.sys
Image Path: H:\WINDOWS\system32\DRIVERS\ati2mtag.sys
Address: 0xB742F000 Size: 5455872 File Visible: - Signed: -
Status: -
Name: ati3duag.dll
Image Path: H:\WINDOWS\System32\ati3duag.dll
Address: 0xBF1AD000 Size: 4120576 File Visible: - Signed: -
Status: -
Name: atikvmag.dll
Image Path: H:\WINDOWS\System32\atikvmag.dll
Address: 0xBF0F0000 Size: 471040 File Visible: - Signed: -
Status: -
Name: atiok3x2.dll
Image Path: H:\WINDOWS\System32\atiok3x2.dll
Address: 0xBF163000 Size: 303104 File Visible: - Signed: -
Status: -
Name: ativvaxx.dll
Image Path: H:\WINDOWS\System32\ativvaxx.dll
Address: 0xBF59B000 Size: 2498560 File Visible: - Signed: -
Status: -
Name: atksgt.sys
Image Path: H:\WINDOWS\system32\DRIVERS\atksgt.sys
Address: 0xA72E1000 Size: 271360 File Visible: - Signed: -
Status: -
Name: ATMFD.DLL
Image Path: H:\WINDOWS\System32\ATMFD.DLL
Address: 0xBFFA0000 Size: 286720 File Visible: - Signed: -
Status: -
Name: audstub.sys
Image Path: H:\WINDOWS\system32\DRIVERS\audstub.sys
Address: 0xBA6EE000 Size: 3072 File Visible: - Signed: -
Status: -
Name: avgio.sys
Image Path: H:\Programme\Avira\AntiVir Desktop\avgio.sys
Address: 0xBA606000 Size: 6144 File Visible: - Signed: -
Status: -
Name: avgntflt.sys
Image Path: H:\WINDOWS\system32\DRIVERS\avgntflt.sys
Address: 0xA75F4000 Size: 81920 File Visible: - Signed: -
Status: -
Name: avipbb.sys
Image Path: H:\WINDOWS\system32\DRIVERS\avipbb.sys
Address: 0xA9A39000 Size: 114688 File Visible: - Signed: -
Status: -
Name: Beep.SYS
Image Path: H:\WINDOWS\System32\Drivers\Beep.SYS
Address: 0xBA5FC000 Size: 4224 File Visible: - Signed: -
Status: -
Name: BOOTVID.dll
Image Path: H:\WINDOWS\system32\BOOTVID.dll
Address: 0xBA4B8000 Size: 12288 File Visible: - Signed: -
Status: -
Name: Cdfs.SYS
Image Path: H:\WINDOWS\System32\Drivers\Cdfs.SYS
Address: 0xBA288000 Size: 63744 File Visible: - Signed: -
Status: -
Name: cdrom.sys
Image Path: H:\WINDOWS\system32\DRIVERS\cdrom.sys
Address: 0xBA148000 Size: 62976 File Visible: - Signed: -
Status: -
Name: CLASSPNP.SYS
Image Path: H:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Address: 0xBA0E8000 Size: 53248 File Visible: - Signed: -
Status: -
Name: disk.sys
Image Path: disk.sys
Address: 0xBA0D8000 Size: 36352 File Visible: - Signed: -
Status: -
Name: drmk.sys
Image Path: H:\WINDOWS\system32\drivers\drmk.sys
Address: 0xBA208000 Size: 61440 File Visible: - Signed: -
Status: -
Name: dump_atapi.sys
Image Path: H:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA9959000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: H:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA608000 Size: 8192 File Visible: No Signed: -
Status: -
Name: Dxapi.sys
Image Path: H:\WINDOWS\System32\drivers\Dxapi.sys
Address: 0xA9C4C000 Size: 12288 File Visible: - Signed: -
Status: -
Name: dxg.sys
Image Path: H:\WINDOWS\System32\drivers\dxg.sys
Address: 0xBF000000 Size: 73728 File Visible: - Signed: -
Status: -
Name: dxgthk.sys
Image Path: H:\WINDOWS\System32\drivers\dxgthk.sys
Address: 0xBA7F2000 Size: 4096 File Visible: - Signed: -
Status: -
Name: fdc.sys
Image Path: H:\WINDOWS\system32\DRIVERS\fdc.sys
Address: 0xBA4A0000 Size: 27392 File Visible: - Signed: -
Status: -
Name: Fips.SYS
Image Path: H:\WINDOWS\System32\Drivers\Fips.SYS
Address: 0xBA258000 Size: 44672 File Visible: - Signed: -
Status: -
Name: flpydisk.sys
Image Path: H:\WINDOWS\system32\DRIVERS\flpydisk.sys
Address: 0xBA390000 Size: 20480 File Visible: - Signed: -
Status: -
Name: fltMgr.sys
Image Path: fltMgr.sys
Address: 0xB9DF7000 Size: 129792 File Visible: - Signed: -
Status: -
Name: Fs_Rec.SYS
Image Path: H:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Address: 0xBA5FA000 Size: 7936 File Visible: - Signed: -
Status: -
Name: ftdisk.sys
Image Path: ftdisk.sys
Address: 0xB9E2F000 Size: 126336 File Visible: - Signed: -
Status: -
Name: GEARAspiWDM.sys
Image Path: H:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
Address: 0xBA428000 Size: 21120 File Visible: - Signed: -
Status: -
Name: H8SRTtmkftololt.sys
Image Path: H:\WINDOWS\system32\drivers\H8SRTtmkftololt.sys
Address: 0xA9BCC000 Size: 114688 File Visible: - Signed: -
Status: Hidden from the Windows API!
Name: hal.dll
Image Path: H:\WINDOWS\system32\hal.dll
Address: 0x806E5000 Size: 134400 File Visible: - Signed: -
Status: -
Name: HDAudBus.sys
Image Path: H:\WINDOWS\system32\DRIVERS\HDAudBus.sys
Address: 0xB73F3000 Size: 163840 File Visible: - Signed: -
Status: -
Name: HIDCLASS.SYS
Image Path: H:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Address: 0xBA298000 Size: 36864 File Visible: - Signed: -
Status: -
Name: HIDPARSE.SYS
Image Path: H:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Address: 0xBA3A0000 Size: 28672 File Visible: - Signed: -
Status: -
Name: hidusb.sys
Image Path: H:\WINDOWS\system32\DRIVERS\hidusb.sys
Address: 0xAA159000 Size: 10368 File Visible: - Signed: -
Status: -
Name: HTTP.sys
Image Path: H:\WINDOWS\System32\Drivers\HTTP.sys
Address: 0xA6BA9000 Size: 264832 File Visible: - Signed: -
Status: -
Name: i8042prt.sys
Image Path: H:\WINDOWS\system32\DRIVERS\i8042prt.sys
Address: 0xBA178000 Size: 52992 File Visible: - Signed: -
Status: -
Name: imapi.sys
Image Path: H:\WINDOWS\system32\DRIVERS\imapi.sys
Address: 0xBA128000 Size: 42112 File Visible: - Signed: -
Status: -
Name: ipnat.sys
Image Path: H:\WINDOWS\system32\DRIVERS\ipnat.sys
Address: 0xA9B12000 Size: 152832 File Visible: - Signed: -
Status: -
Name: ipsec.sys
Image Path: H:\WINDOWS\system32\DRIVERS\ipsec.sys
Address: 0xA9BB9000 Size: 75264 File Visible: - Signed: -
Status: -
Name: isapnp.sys
Image Path: isapnp.sys
Address: 0xBA0A8000 Size: 37632 File Visible: - Signed: -
Status: -
Name: kbdclass.sys
Image Path: H:\WINDOWS\system32\DRIVERS\kbdclass.sys
Address: 0xBA4A8000 Size: 25216 File Visible: - Signed: -
Status: -
Name: KDCOM.DLL
Image Path: H:\WINDOWS\system32\KDCOM.DLL
Address: 0xBA5A8000 Size: 8192 File Visible: - Signed: -
Status: -
Name: kmixer.sys
Image Path: H:\WINDOWS\system32\drivers\kmixer.sys
Address: 0xA6B2E000 Size: 172416 File Visible: - Signed: -
Status: -
Name: ks.sys
Image Path: H:\WINDOWS\system32\DRIVERS\ks.sys
Address: 0xB73B0000 Size: 143360 File Visible: - Signed: -
Status: -
Name: KSecDD.sys
Image Path: KSecDD.sys
Address: 0xB9DCE000 Size: 92928 File Visible: - Signed: -
Status: -
Name: lirsgt.sys
Image Path: H:\WINDOWS\system32\DRIVERS\lirsgt.sys
Address: 0xBA460000 Size: 18048 File Visible: - Signed: -
Status: -
Name: mnmdd.SYS
Image Path: H:\WINDOWS\System32\Drivers\mnmdd.SYS
Address: 0xBA5FE000 Size: 4224 File Visible: - Signed: -
Status: -
Name: mouclass.sys
Image Path: H:\WINDOWS\system32\DRIVERS\mouclass.sys
Address: 0xBA378000 Size: 23552 File Visible: - Signed: -
Status: -
Name: mouhid.sys
Image Path: H:\WINDOWS\system32\DRIVERS\mouhid.sys
Address: 0xAA155000 Size: 12288 File Visible: - Signed: -
Status: -
Name: MountMgr.sys
Image Path: MountMgr.sys
Address: 0xBA0B8000 Size: 42368 File Visible: - Signed: -
Status: -
Name: mrxsmb.sys
Image Path: H:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Address: 0xA9A55000 Size: 455296 File Visible: - Signed: -
Status: -
Name: Msfs.SYS
Image Path: H:\WINDOWS\System32\Drivers\Msfs.SYS
Address: 0xBA3B0000 Size: 19072 File Visible: - Signed: -
Status: -
Name: msgpc.sys
Image Path: H:\WINDOWS\system32\DRIVERS\msgpc.sys
Address: 0xBA1B8000 Size: 35072 File Visible: - Signed: -
Status: -
Name: mssmbios.sys
Image Path: H:\WINDOWS\system32\DRIVERS\mssmbios.sys
Address: 0xB9CAF000 Size: 15488 File Visible: - Signed: -
Status: -
Name: Mup.sys
Image Path: Mup.sys
Address: 0xB9CE7000 Size: 105344 File Visible: - Signed: -
Status: -
Name: NDIS.sys
Image Path: NDIS.sys
Address: 0xB9D01000 Size: 182656 File Visible: - Signed: -
Status: -
Name: ndistapi.sys
Image Path: H:\WINDOWS\system32\DRIVERS\ndistapi.sys
Address: 0xB9CBB000 Size: 10112 File Visible: - Signed: -
Status: -
Name: ndisuio.sys
Image Path: H:\WINDOWS\system32\DRIVERS\ndisuio.sys
Address: 0xA75D4000 Size: 14592 File Visible: - Signed: -
Status: -
Name: ndiswan.sys
Image Path: H:\WINDOWS\system32\DRIVERS\ndiswan.sys
Address: 0xB7329000 Size: 91520 File Visible: - Signed: -
Status: -
Name: NDProxy.SYS
Image Path: H:\WINDOWS\System32\Drivers\NDProxy.SYS
Address: 0xBA1D8000 Size: 40576 File Visible: - Signed: -
Status: -
Name: netbios.sys
Image Path: H:\WINDOWS\system32\DRIVERS\netbios.sys
Address: 0xBA248000 Size: 34688 File Visible: - Signed: -
Status: -
Name: netbt.sys
Image Path: H:\WINDOWS\system32\DRIVERS\netbt.sys
Address: 0xA9B38000 Size: 162816 File Visible: - Signed: -
Status: -
Name: Npfs.SYS
Image Path: H:\WINDOWS\System32\Drivers\Npfs.SYS
Address: 0xBA3B8000 Size: 30848 File Visible: - Signed: -
Status: -
Name: Ntfs.sys
Image Path: Ntfs.sys
Address: 0xB9D2E000 Size: 574976 File Visible: - Signed: -
Status: -
Name: ntkrnlpa.exe
Image Path: H:\WINDOWS\system32\ntkrnlpa.exe
Address: 0x804D7000 Size: 2154496 File Visible: - Signed: -
Status: -
Name: Null.SYS
Image Path: H:\WINDOWS\System32\Drivers\Null.SYS
Address: 0xBA731000 Size: 2944 File Visible: - Signed: -
Status: -
Name: parport.sys
Image Path: H:\WINDOWS\system32\DRIVERS\parport.sys
Address: 0xB7340000 Size: 80384 File Visible: - Signed: -
Status: -
Name: PartMgr.sys
Image Path: PartMgr.sys
Address: 0xBA330000 Size: 19712 File Visible: - Signed: -
Status: -
Name: ParVdm.SYS
Image Path: H:\WINDOWS\System32\Drivers\ParVdm.SYS
Address: 0xBA644000 Size: 7040 File Visible: - Signed: -
Status: -
Name: pci.sys
Image Path: pci.sys
Address: 0xB9E4E000 Size: 68224 File Visible: - Signed: -
Status: -
Name: PCI_PNP2974
Image Path: \Driver\PCI_PNP2974
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: pciide.sys
Image Path: pciide.sys
Address: 0xBA670000 Size: 3328 File Visible: - Signed: -
Status: -
Name: PCIIDEX.SYS
Image Path: H:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Address: 0xBA328000 Size: 28672 File Visible: - Signed: -
Status: -
Name: PnpManager
Image Path: \Driver\PnpManager
Address: 0x804D7000 Size: 2154496 File Visible: - Signed: -
Status: -
Name: portcls.sys
Image Path: H:\WINDOWS\system32\drivers\portcls.sys
Address: 0xAA175000 Size: 147456 File Visible: - Signed: -
Status: -
Name: processr.sys
Image Path: H:\WINDOWS\system32\DRIVERS\processr.sys
Address: 0xBA318000 Size: 39936 File Visible: - Signed: -
Status: -
Name: psched.sys
Image Path: H:\WINDOWS\system32\DRIVERS\psched.sys
Address: 0xB72D6000 Size: 69120 File Visible: - Signed: -
Status: -
Name: ptilink.sys
Image Path: H:\WINDOWS\system32\DRIVERS\ptilink.sys
Address: 0xBA340000 Size: 17792 File Visible: - Signed: -
Status: -
Name: PxHelp20.sys
Image Path: PxHelp20.sys
Address: 0xBA0F8000 Size: 35712 File Visible: - Signed: -
Status: -
Name: rasacd.sys
Image Path: H:\WINDOWS\system32\DRIVERS\rasacd.sys
Address: 0xBA594000 Size: 8832 File Visible: - Signed: -
Status: -
Name: rasl2tp.sys
Image Path: H:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Address: 0xBA188000 Size: 51328 File Visible: - Signed: -
Status: -
Name: raspppoe.sys
Image Path: H:\WINDOWS\system32\DRIVERS\raspppoe.sys
Address: 0xBA198000 Size: 41472 File Visible: - Signed: -
Status: -
Name: raspptp.sys
Image Path: H:\WINDOWS\system32\DRIVERS\raspptp.sys
Address: 0xBA1A8000 Size: 48384 File Visible: - Signed: -
Status: -
Name: raspti.sys
Image Path: H:\WINDOWS\system32\DRIVERS\raspti.sys
Address: 0xBA348000 Size: 16512 File Visible: - Signed: -
Status: -
Name: RAW
Image Path: \FileSystem\RAW
Address: 0x804D7000 Size: 2154496 File Visible: - Signed: -
Status: -
Name: rdbss.sys
Image Path: H:\WINDOWS\system32\DRIVERS\rdbss.sys
Address: 0xA9AC5000 Size: 175744 File Visible: - Signed: -
Status: -
Name: RDPCDD.sys
Image Path: H:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Address: 0xBA600000 Size: 4224 File Visible: - Signed: -
Status: -
Name: redbook.sys
Image Path: H:\WINDOWS\system32\DRIVERS\redbook.sys
Address: 0xBA158000 Size: 57728 File Visible: - Signed: -
Status: -
Name: rootrepeal.sys
Image Path: H:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA6CF2000 Size: 49152 File Visible: No Signed: -
Status: -
Name: Rtenicxp.sys
Image Path: H:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
Address: 0xB73D3000 Size: 130816 File Visible: - Signed: -
Status: -
Name: RtkHDAud.sys
Image Path: H:\WINDOWS\system32\drivers\RtkHDAud.sys
Address: 0xA9C58000 Size: 5197824 File Visible: - Signed: -
Status: -
Name: RtKHDMI.sys
Image Path: H:\WINDOWS\system32\drivers\RtKHDMI.sys
Address: 0xAA199000 Size: 3721664 File Visible: - Signed: -
Status: -
Name: SCSIPORT.SYS
Image Path: H:\WINDOWS\System32\Drivers\SCSIPORT.SYS
Address: 0xB9E8E000 Size: 98304 File Visible: - Signed: -
Status: -
Name: serenum.sys
Image Path: H:\WINDOWS\system32\DRIVERS\serenum.sys
Address: 0xB9CBF000 Size: 15744 File Visible: - Signed: -
Status: -
Name: serial.sys
Image Path: H:\WINDOWS\system32\DRIVERS\serial.sys
Address: 0xBA168000 Size: 65536 File Visible: - Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: spxi.sys
Image Path: spxi.sys
Address: 0xB9EA6000 Size: 1052672 File Visible: No Signed: -
Status: -
Name: sr.sys
Image Path: sr.sys
Address: 0xB9DE5000 Size: 73472 File Visible: - Signed: -
Status: -
Name: srv.sys
Image Path: H:\WINDOWS\system32\DRIVERS\srv.sys
Address: 0xA71C7000 Size: 333952 File Visible: - Signed: -
Status: -
Name: ssmdrv.sys
Image Path: H:\WINDOWS\system32\DRIVERS\ssmdrv.sys
Address: 0xBA3C0000 Size: 23040 File Visible: - Signed: -
Status: -
Name: swenum.sys
Image Path: H:\WINDOWS\system32\DRIVERS\swenum.sys
Address: 0xBA5F2000 Size: 4352 File Visible: - Signed: -
Status: -
Name: sysaudio.sys
Image Path: H:\WINDOWS\system32\drivers\sysaudio.sys
Address: 0xB65A8000 Size: 60800 File Visible: - Signed: -
Status: -
Name: tcpip.sys
Image Path: H:\WINDOWS\system32\DRIVERS\tcpip.sys
Address: 0xA9B60000 Size: 361600 File Visible: - Signed: -
Status: -
Name: TDI.SYS
Image Path: H:\WINDOWS\system32\DRIVERS\TDI.SYS
Address: 0xBA4B0000 Size: 20480 File Visible: - Signed: -
Status: -
Name: termdd.sys
Image Path: H:\WINDOWS\system32\DRIVERS\termdd.sys
Address: 0xBA1C8000 Size: 40704 File Visible: - Signed: -
Status: -
Name: update.sys
Image Path: H:\WINDOWS\system32\DRIVERS\update.sys
Address: 0xB65E8000 Size: 384768 File Visible: - Signed: -
Status: -
Name: USBD.SYS
Image Path: H:\WINDOWS\system32\DRIVERS\USBD.SYS
Address: 0xBA5F6000 Size: 8192 File Visible: - Signed: -
Status: -
Name: usbehci.sys
Image Path: H:\WINDOWS\system32\DRIVERS\usbehci.sys
Address: 0xBA438000 Size: 30208 File Visible: - Signed: -
Status: -
Name: usbhub.sys
Image Path: H:\WINDOWS\system32\DRIVERS\usbhub.sys
Address: 0xBA218000 Size: 59520 File Visible: - Signed: -
Status: -
Name: usbohci.sys
Image Path: H:\WINDOWS\system32\DRIVERS\usbohci.sys
Address: 0xBA430000 Size: 17152 File Visible: - Signed: -
Status: -
Name: USBPORT.SYS
Image Path: H:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Address: 0xB738C000 Size: 147456 File Visible: - Signed: -
Status: -
Name: USBSTOR.SYS
Image Path: H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Address: 0xBA3C8000 Size: 26368 File Visible: - Signed: -
Status: -
Name: vga.sys
Image Path: H:\WINDOWS\System32\drivers\vga.sys
Address: 0xBA3A8000 Size: 20992 File Visible: - Signed: -
Status: -
Name: VIDEOPRT.SYS
Image Path: H:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Address: 0xB741B000 Size: 81920 File Visible: - Signed: -
Status: -
Name: VolSnap.sys
Image Path: VolSnap.sys
Address: 0xBA0C8000 Size: 53760 File Visible: - Signed: -
Status: -
Name: wanarp.sys
Image Path: H:\WINDOWS\system32\DRIVERS\wanarp.sys
Address: 0xBA238000 Size: 34560 File Visible: - Signed: -
Status: -
Name: watchdog.sys
Image Path: H:\WINDOWS\System32\watchdog.sys
Address: 0xBA3D0000 Size: 20480 File Visible: - Signed: -
Status: -
Name: wdmaud.sys
Image Path: H:\WINDOWS\system32\drivers\wdmaud.sys
Address: 0xA704A000 Size: 83072 File Visible: - Signed: -
Status: -
Name: Win32k
Image Path: \Driver\Win32k
Address: 0xBF800000 Size: 1851392 File Visible: - Signed: -
Status: -
Name: win32k.sys
Image Path: H:\WINDOWS\System32\win32k.sys
Address: 0xBF800000 Size: 1851392 File Visible: - Signed: -
Status: -
Name: WMILIB.SYS
Image Path: H:\WINDOWS\System32\Drivers\WMILIB.SYS
Address: 0xBA5AA000 Size: 8192 File Visible: - Signed: -
Status: -
Name: WMIxWDM
Image Path: \Driver\WMIxWDM
Address: 0x804D7000 Size: 2154496 File Visible: - Signed: -
Status: -
Name: WudfPf.sys
Image Path: WudfPf.sys
Address: 0xB9DBB000 Size: 77568 File Visible: - Signed: -
Status: -
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/01/21 22:02
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Stealth Objects
-------------------
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: services.exe (PID: 912) Address: 0x10000000 Size: 36864
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: lsass.exe (PID: 924) Address: 0x10000000 Size: 36864
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: Ati2evxx.exe (PID: 1136) Address: 0x10000000 Size: 36864
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: svchost.exe (PID: 1156) Address: 0x10000000 Size: 86016
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: svchost.exe (PID: 1156) Address: 0x008b0000 Size: 36864
Object: Hidden Module [Name: H8SRTikatwjubqo.dll]
Process: svchost.exe (PID: 1156) Address: 0x00950000 Size: 65536
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: svchost.exe (PID: 1156) Address: 0x00d10000 Size: 86016
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: svchost.exe (PID: 1256) Address: 0x10000000 Size: 86016
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: svchost.exe (PID: 1380) Address: 0x10000000 Size: 86016
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: svchost.exe (PID: 1424) Address: 0x10000000 Size: 86016
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: svchost.exe (PID: 1500) Address: 0x10000000 Size: 86016
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: svchost.exe (PID: 1588) Address: 0x10000000 Size: 86016
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: Ati2evxx.exe (PID: 1672) Address: 0x10000000 Size: 36864
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: spoolsv.exe (PID: 1792) Address: 0x10000000 Size: 36864
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: jqs.exe (PID: 1908) Address: 0x10000000 Size: 36864
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: svchost.exe (PID: 1952) Address: 0x10000000 Size: 86016
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: alg.exe (PID: 844) Address: 0x10000000 Size: 36864
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: Explorer.EXE (PID: 636) Address: 0x00c00000 Size: 36864
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: Explorer.EXE (PID: 636) Address: 0x10000000 Size: 86016
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: RTHDCPL.EXE (PID: 1284) Address: 0x10000000 Size: 36864
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: ctfmon.exe (PID: 1332) Address: 0x10000000 Size: 36864
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: firefox.exe (PID: 4072) Address: 0x01080000 Size: 86016
Object: Hidden Module [Name: H8SRTmwxidvrnre.dll]
Process: firefox.exe (PID: 4072) Address: 0x01420000 Size: 151552
Object: Hidden Module [Name: H8SRTvfprqlotqw.dll]
Process: RootRepeal.exe (PID: 1560) Address: 0x10000000 Size: 36864
Object: Hidden Module [Name: H8SRTvhpdncbfpv.dll]
Process: iexplore.exe (PID: 3440) Address: 0x10000000 Size: 86016
Object: Hidden Module [Name: H8SRTmwxidvrnre.dll]
Process: iexplore.exe (PID: 3440) Address: 0x00e50000 Size: 151552
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x89dcf1f8 Size: 121
Object: Hidden Code [Driver: a6kcga24ȅఠ浍瑓耈覽, IRP_MJ_CREATE]
Process: System Address: 0x89afa500 Size: 121
Object: Hidden Code [Driver: a6kcga24ȅఠ浍瑓耈覽, IRP_MJ_CLOSE]
Process: System Address: 0x89afa500 Size: 121
Object: Hidden Code [Driver: a6kcga24ȅఠ浍瑓耈覽, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89afa500 Size: 121
Object: Hidden Code [Driver: a6kcga24ȅఠ浍瑓耈覽, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89afa500 Size: 121
Object: Hidden Code [Driver: a6kcga24ȅఠ浍瑓耈覽, IRP_MJ_POWER]
Process: System Address: 0x89afa500 Size: 121
Object: Hidden Code [Driver: a6kcga24ȅఠ浍瑓耈覽, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89afa500 Size: 121
Object: Hidden Code [Driver: a6kcga24ȅఠ浍瑓耈覽, IRP_MJ_PNP]
Process: System Address: 0x89afa500 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x89bb41f8 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_CREATE]
Process: System Address: 0x88dfa500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_CLOSE]
Process: System Address: 0x88dfa500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_READ]
Process: System Address: 0x88dfa500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_WRITE]
Process: System Address: 0x88dfa500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x88dfa500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x88dfa500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_POWER]
Process: System Address: 0x88dfa500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x88dfa500 Size: 121
Object: Hidden Code [Driver: usbstor, IRP_MJ_PNP]
Process: System Address: 0x88dfa500 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE]
Process: System Address: 0x89b891f8 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE]
Process: System Address: 0x89b891f8 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b891f8 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89b891f8 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER]
Process: System Address: 0x89b891f8 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89b891f8 Size: 121
Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP]
Process: System Address: 0x89b891f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x89e411f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x89a9e1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x89a9e1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89a9e1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89a9e1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x89a9e1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x89a9e1f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x89b721f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x89b721f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89b721f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89b721f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x89b721f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89b721f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x89b721f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x89a8f1f8 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_CREATE]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_CLOSE]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_READ]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_SHUTDOWN]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_CLEANUP]
Process: System Address: 0x89c47500 Size: 121
Object: Hidden Code [Driver: Cdfsఐ卆浩Ȗ, IRP_MJ_PNP]
Process: System Address: 0x89c47500 Size: 121
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/01/21 22:02
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Hidden Services
-------------------
Service Name: H8SRTd.sys
Image PathH:\WINDOWS\system32\drivers\H8SRTtmkftololt.sys
4. scanlist