ROOTREPEAL (c) AD, 2007-2010
==================================================
Report Save Time: 2010/06/09 19:30
Program Version: Version 2.0.0.0
Windows Version: Windows XP SP3
==================================================
DRIVERS
-------------------
File Invisible dump_atapi.sys 0xf6aa1000 C:\WINDOWS\System32\Drivers\dump_atapi.sys, 98304 bytes
File Invisible dump_WMILIB.SYS 0xf912a000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS, 8192 bytes
File Invisible rootrepeal.sys 0xf6a11000 C:\WINDOWS\system32\drivers\rootrepeal.sys, 49152 bytes
PROCESSES
-------------------
4 - System
160 - C:\Program Files\AVG\AVG9\avgemc.exe
252 - C:\Program Files\AVG\AVG9\avgnsx.exe
328 - C:\WINDOWS\system32\svchost.exe
372 - C:\WINDOWS\Nhksrv.exe
388 - C:\Program Files\AVG\AVG9\avgwdsvc.exe
404 - C:\WINDOWS\system32\CTsvcCDA.EXE
468 - C:\Program Files\AVG\AVG9\avgcsrvx.exe
556 - C:\WINDOWS\system32\smss.exe
620 - C:\WINDOWS\system32\csrss.exe
644 - C:\WINDOWS\system32\winlogon.exe
688 - C:\WINDOWS\system32\services.exe
700 - C:\WINDOWS\system32\lsass.exe
856 - C:\WINDOWS\system32\svchost.exe
936 - C:\WINDOWS\system32\svchost.exe
976 - C:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe
1032 - C:\WINDOWS\system32\svchost.exe
1064 - C:\WINDOWS\system32\svchost.exe
1112 - C:\Program Files\AVG\AVG9\avgchsvx.exe
1120 - C:\Program Files\AVG\AVG9\avgrsx.exe
1220 - C:\WINDOWS\system32\MsPMSPSv.exe
1232 - C:\WINDOWS\system32\svchost.exe
1256 - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
1272 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
1308 - C:\WINDOWS\system32\ZuneBusEnum.exe
1324 - C:\WINDOWS\system32\svchost.exe
1404 - C:\Program Files\AVG\AVG9\avgcsrvx.exe
1732 - C:\WINDOWS\system32\spoolsv.exe
1924 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
2008 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
2016 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
2024 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
2032 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
2132 - C:\WINDOWS\system32\alg.exe
2376 - C:\Program Files\Mozilla Firefox\firefox.exe
2428 - C:\Program Files\PokerShortcuts\PokerShortcuts.exe
2892 - C:\WINDOWS\explorer.exe
2996 - C:\WINDOWS\MMKeybd.exe
3012 - C:\PROGRA~1\AVG\AVG9\avgtray.exe
3028 - C:\WINDOWS\BCMSMMSG.exe
3068 - C:\Program Files\Microsoft IntelliType Pro\itype.exe
3076 - C:\Program Files\Microsoft IntelliPoint\ipoint.exe
3168 - C:\WINDOWS\system32\ctfmon.exe
3312 - C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
3404 - C:\WINDOWS\system32\WudfHost.exe
3708 - C:\PROGRA~1\Yahoo!\Messenger\Ymsgr_tray.exe
4016 - C:\Documents and Settings\Ravish Prajapati\Desktop\RootRepeal.exe
FILES
-------------------
Mismatch C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl, Allocation size mismatch (API: 99625786543304832, Raw: 8192)
HIDDEN SERVICES
-------------------
SSDT
-------------------
SYSCALL OK, INT 0x2E OK, ServiceTable OK, Driver IAT OK
SHADOW SSDT
-------------------
CALLBACKS
-------------------
==================================================
Report Save Time: 2010/06/09 19:30
Program Version: Version 2.0.0.0
Windows Version: Windows XP SP3
==================================================
DRIVERS
-------------------
File Invisible dump_atapi.sys 0xf6aa1000 C:\WINDOWS\System32\Drivers\dump_atapi.sys, 98304 bytes
File Invisible dump_WMILIB.SYS 0xf912a000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS, 8192 bytes
File Invisible rootrepeal.sys 0xf6a11000 C:\WINDOWS\system32\drivers\rootrepeal.sys, 49152 bytes
PROCESSES
-------------------
4 - System
160 - C:\Program Files\AVG\AVG9\avgemc.exe
252 - C:\Program Files\AVG\AVG9\avgnsx.exe
328 - C:\WINDOWS\system32\svchost.exe
372 - C:\WINDOWS\Nhksrv.exe
388 - C:\Program Files\AVG\AVG9\avgwdsvc.exe
404 - C:\WINDOWS\system32\CTsvcCDA.EXE
468 - C:\Program Files\AVG\AVG9\avgcsrvx.exe
556 - C:\WINDOWS\system32\smss.exe
620 - C:\WINDOWS\system32\csrss.exe
644 - C:\WINDOWS\system32\winlogon.exe
688 - C:\WINDOWS\system32\services.exe
700 - C:\WINDOWS\system32\lsass.exe
856 - C:\WINDOWS\system32\svchost.exe
936 - C:\WINDOWS\system32\svchost.exe
976 - C:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe
1032 - C:\WINDOWS\system32\svchost.exe
1064 - C:\WINDOWS\system32\svchost.exe
1112 - C:\Program Files\AVG\AVG9\avgchsvx.exe
1120 - C:\Program Files\AVG\AVG9\avgrsx.exe
1220 - C:\WINDOWS\system32\MsPMSPSv.exe
1232 - C:\WINDOWS\system32\svchost.exe
1256 - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
1272 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
1308 - C:\WINDOWS\system32\ZuneBusEnum.exe
1324 - C:\WINDOWS\system32\svchost.exe
1404 - C:\Program Files\AVG\AVG9\avgcsrvx.exe
1732 - C:\WINDOWS\system32\spoolsv.exe
1924 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
2008 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
2016 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
2024 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
2032 - C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
2132 - C:\WINDOWS\system32\alg.exe
2376 - C:\Program Files\Mozilla Firefox\firefox.exe
2428 - C:\Program Files\PokerShortcuts\PokerShortcuts.exe
2892 - C:\WINDOWS\explorer.exe
2996 - C:\WINDOWS\MMKeybd.exe
3012 - C:\PROGRA~1\AVG\AVG9\avgtray.exe
3028 - C:\WINDOWS\BCMSMMSG.exe
3068 - C:\Program Files\Microsoft IntelliType Pro\itype.exe
3076 - C:\Program Files\Microsoft IntelliPoint\ipoint.exe
3168 - C:\WINDOWS\system32\ctfmon.exe
3312 - C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
3404 - C:\WINDOWS\system32\WudfHost.exe
3708 - C:\PROGRA~1\Yahoo!\Messenger\Ymsgr_tray.exe
4016 - C:\Documents and Settings\Ravish Prajapati\Desktop\RootRepeal.exe
FILES
-------------------
Mismatch C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl, Allocation size mismatch (API: 99625786543304832, Raw: 8192)
HIDDEN SERVICES
-------------------
SSDT
-------------------
SYSCALL OK, INT 0x2E OK, ServiceTable OK, Driver IAT OK
SHADOW SSDT
-------------------
CALLBACKS
-------------------