Saw a similar topic earlier but never saw where person did what was suggested. I ran the rootrepeal program/scan as suggested. here is copy of report:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/30 13:15
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB2EC8000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0xb60d70c6
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xb60d70bc
#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0xb60d70cb
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0xb60d70d5
#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xb60d70da
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xb60d70a8
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xb60d70ad
#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xb60d70e4
#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xb60d70df
#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0xb60d70d0
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0xb60d70b7
==EOF==
Hope that helps.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/30 13:15
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB2EC8000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0xb60d70c6
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xb60d70bc
#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0xb60d70cb
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0xb60d70d5
#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xb60d70da
#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xb60d70a8
#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xb60d70ad
#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xb60d70e4
#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xb60d70df
#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0xb60d70d0
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0xb60d70b7
==EOF==
Hope that helps.

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top









