DDS wouldnt run - This program cannot be run in DOS mode!!
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/02 16:16
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dimaint.sys
Image Path: dimaint.sys
Address: 0xF837E000 Size: 91136 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF43C6000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8AAE000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF0A39000 Size: 49152 File Visible: No Signed: -
Status: -
Name: SYMEVENT.SYS
Image Path: C:\Program Files\Symantec\SYMEVENT.SYS
Address: 0xF45B9000 Size: 118208 File Visible: No Signed: -
Status: -
Name: SYMTDI.SYS
Image Path: C:\WINDOWS\System32\Drivers\SYMTDI.SYS
Address: 0xF45D6000 Size: 261344 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: c:\i386\symndis.sys
Status: Size mismatch (API: 182656, Raw: 34424)
Path: c:\windows\$ntservicepackuninstall$\ndis.sys
Status: Size mismatch (API: 182656, Raw: 182912)
Path: C:\Documents and Settings\JARROD HOLDSWORTH\Cookies\index[2].htm
Status: Locked to the Windows API!
Path: c:\windows\system32\drivers\ndis.sys
Status: Size mismatch (API: 182656, Raw: 212224)
Path: c:\windows\system32\drivers\symndis.sys
Status: Size mismatch (API: 182656, Raw: 47192)
Path: c:\windows\system32\dllcache\ndis.sys
Status: Size mismatch (API: 182656, Raw: 212224)
Path: c:\documents and settings\jarrod holdsworth\local settings\temp\~dfd46.tmp
Status: Allocation size mismatch (API: 131072, Raw: 16384)
Path: c:\documents and settings\jarrod holdsworth\local settings\temp\~dfeb4d.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\jarrod holdsworth\local settings\temp\~dffb39.tmp
Status: Allocation size mismatch (API: 24576, Raw: 0)
Path: C:\Documents and Settings\JARROD HOLDSWORTH\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys
Status: Size mismatch (API: 182656, Raw: 0)
Path: C:\Documents and Settings\LocalService\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys
Status: Size mismatch (API: 182656, Raw: 0)
SSDT
-------------------
#: 031 Function Name: NtConnectPort
Status: Hooked by "<unknown>" at address 0x828ddde0
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf8917470
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf8917520
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf89175c0
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf8917660
Stealth Objects
-------------------
Object: Hidden Module [Name: svchost.exe]
Process: svchost.exe (PID: 2284) Address: 0x01000000 Size: 20480
Object: Hidden Module [Name: svchost.exe]
Process: svchost.exe (PID: 2296) Address: 0x01000000 Size: 20480
==EOF==