ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2011/07/27 12:12 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP2 ================================================== Drivers ------------------- Name: dump_atapi.sys Image Path: E:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xEFA65000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: E:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF8ABA000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: E:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xED28F000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ------------------- Path: E:\hiberfil.sys Status: Locked to the Windows API! ==EOF==