I was reading your previous posts, so here is copy of my system look and rootrepeal reports.
also I get axwin frame window:svchost.exe application Error
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 06:16 on 02/02/2010 by HP_Owner (Administrator - Elevation successful)
========== filefind ==========
Searching for "scecli.dll"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll --a--- 181248 bytes [04:04 14/07/2009] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll --a--- 181248 bytes [01:00 27/09/2008] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\system32\dllcache\scecli.dll --a--c 180224 bytes [12:00 28/02/2006] [12:00 28/02/2006] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\system32\scecli.dll --a--- 180224 bytes [12:00 28/02/2006] [12:00 28/02/2006] 0F78E27F563F2AAF74B91A49E2ABF19A
Searching for "netlogon.dll"
C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll --a--- 408064 bytes [18:46 06/02/2009] [18:46 06/02/2009] 6C476D33D82F1054849790181E8F7772
C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll --a--- 408064 bytes [18:46 06/02/2009] [18:46 06/02/2009] 6C476D33D82F1054849790181E8F7772
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll --a--- 407040 bytes [04:04 14/07/2009] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll --a--- 407040 bytes [00:59 27/09/2008] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\system32\dllcache\netlogon.dll --a--c 407040 bytes [12:00 28/02/2006] [12:00 28/02/2006] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\system32\netlogon.dll --a--- 407040 bytes [12:00 28/02/2006] [12:00 28/02/2006] 96353FCECBA774BB8DA74A1C6507015A
Searching for "eventlog.dll"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll --a--- 56320 bytes [04:02 14/07/2009] [00:11 14/04/2008] 6D4FEB43EE538FC5428CC7F0565AA656
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll --a--- 56320 bytes [00:57 27/09/2008] [00:11 14/04/2008] 6D4FEB43EE538FC5428CC7F0565AA656
C:\WINDOWS\system32\dllcache\eventlog.dll --a--c 55808 bytes [12:00 28/02/2006] [12:00 28/02/2006] 82B24CB70E5944E6E34662205A2A5B78
C:\WINDOWS\system32\eventlog.dll --a--- 55808 bytes [12:00 28/02/2006] [12:00 28/02/2006] 82B24CB70E5944E6E34662205A2A5B78
Searching for "winlogon.exe"
C:\Documents and Settings\HP_Owner\Local Settings\Temp\wz8694\Malwarebytes Anti-Malware 1.44\winlogon.exe ------ 5115824 bytes [23:09 08/01/2010] [23:09 08/01/2010] E6111E6D0B99286F99C35B09835DB9BA
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe --a--- 507904 bytes [04:05 14/07/2009] [00:12 14/04/2008] ED0EF0A136DEC83DF69F04118870003E
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe --a--- 507904 bytes [01:01 27/09/2008] [00:12 14/04/2008] ED0EF0A136DEC83DF69F04118870003E
C:\WINDOWS\system32\dllcache\winlogon.exe --a--c 502272 bytes [12:00 28/02/2006] [12:00 28/02/2006] 01C3346C241652F43AED8E2149881BFE
C:\WINDOWS\system32\winlogon.exe --a--- 502272 bytes [12:00 28/02/2006] [12:00 28/02/2006] 01C3346C241652F43AED8E2149881BFE
Searching for "comres.dll"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\comres.dll --a--- 792064 bytes [04:02 14/07/2009] [00:11 14/04/2008] 1280A158C722FA95A80FB7AEBE78FA7D
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\comres.dll --a--- 792064 bytes [00:57 27/09/2008] [00:11 14/04/2008] 1280A158C722FA95A80FB7AEBE78FA7D
C:\WINDOWS\system32\comres.dll --a--- 792064 bytes [12:00 28/02/2006] [12:00 28/02/2006] 6728270CB7DBB776ED086F5AC4C82310
C:\WINDOWS\system32\dllcache\comres.dll --a--c 792064 bytes [12:00 28/02/2006] [12:00 28/02/2006] 6728270CB7DBB776ED086F5AC4C82310
Searching for "crypt32.dll"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\crypt32.dll --a--- 599040 bytes [04:02 14/07/2009] [00:11 14/04/2008] BDAAF79DD63F194434D31A74B9BB8B77
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\crypt32.dll --a--- 599040 bytes [00:57 27/09/2008] [00:11 14/04/2008] BDAAF79DD63F194434D31A74B9BB8B77
C:\WINDOWS\system32\crypt32.dll --a--- 597504 bytes [12:00 28/02/2006] [12:00 28/02/2006] EFC958396A7A7EF7E6D4A52B97512E18
C:\WINDOWS\system32\dllcache\crypt32.dll --a--c 597504 bytes [12:00 28/02/2006] [12:00 28/02/2006] EFC958396A7A7EF7E6D4A52B97512E18
Searching for "gpedit.dll"
No files found.
Searching for "rundll32.exe"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\rundll32.exe --a--- 33280 bytes [04:04 14/07/2009] [00:12 14/04/2008] 037B1E7798960E0420003D05BB577EE6
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\rundll32.exe --a--- 33280 bytes [01:00 27/09/2008] [00:12 14/04/2008] 037B1E7798960E0420003D05BB577EE6
C:\WINDOWS\system32\dllcache\rundll32.exe --a--c 33280 bytes [12:00 28/02/2006] [12:00 28/02/2006] DA285490BBD8A1D0CE6623577D5BA1FF
C:\WINDOWS\system32\rundll32.exe --a--- 33280 bytes [12:00 28/02/2006] [12:00 28/02/2006] DA285490BBD8A1D0CE6623577D5BA1FF
Searching for "sfc.dll"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sfc.dll --a--- 5120 bytes [04:04 14/07/2009] [00:12 14/04/2008] 96E1C926F22EE1BFBAE82901A35F6BF3
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\sfc.dll --a--- 5120 bytes [01:00 27/09/2008] [00:12 14/04/2008] 96E1C926F22EE1BFBAE82901A35F6BF3
C:\WINDOWS\system32\dllcache\sfc.dll --a--c 5120 bytes [12:00 28/02/2006] [12:00 28/02/2006] E8A12A12EA9088B4327D49EDCA3ADD3E
C:\WINDOWS\system32\sfc.dll --a--- 5120 bytes [12:00 28/02/2006] [12:00 28/02/2006] E8A12A12EA9088B4327D49EDCA3ADD3E
Searching for "svchost.exe"
C:\Program Files\svchost.exe --a--- 37376 bytes [18:10 01/02/2010] [18:10 01/02/2010] 1EDC2204B5DC0A1C0B5793A1FCD98EE8
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\svchost.exe --a--- 14336 bytes [04:05 14/07/2009] [00:12 14/04/2008] 27C6D03BCDB8CFEB96B716F3D8BE3E18
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe --a--- 14336 bytes [01:00 27/09/2008] [00:12 14/04/2008] 27C6D03BCDB8CFEB96B716F3D8BE3E18
C:\WINDOWS\system32\dllcache\svchost.exe --a--c 14336 bytes [12:00 28/02/2006] [12:00 28/02/2006] 8F078AE4ED187AAABC0A305146DE6716
C:\WINDOWS\system32\svchost.exe --a--- 14336 bytes [12:00 28/02/2006] [12:00 28/02/2006] 8F078AE4ED187AAABC0A305146DE6716
Searching for "cngaudit.dll"
No files found.
Searching for "beep.sys"
C:\WINDOWS\system32\dllcache\beep.sys --a--c 4224 bytes [12:00 28/02/2006] [12:00 28/02/2006] DA1F27D85E0D1525F6621372E7B685E9
C:\WINDOWS\system32\drivers\beep.sys --a--- 4224 bytes [12:00 28/02/2006] [12:00 28/02/2006] DA1F27D85E0D1525F6621372E7B685E9
Searching for "wscntfy.exe"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\wscntfy.exe --a--- 13824 bytes [04:05 14/07/2009] [00:12 14/04/2008] F92E1076C42FCD6DB3D72D8CFE9816D5
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wscntfy.exe --a--- 13824 bytes [01:01 27/09/2008] [00:12 14/04/2008] F92E1076C42FCD6DB3D72D8CFE9816D5
C:\WINDOWS\system32\dllcache\wscntfy.exe --a--c 13824 bytes [12:00 28/02/2006] [12:00 28/02/2006] 49911DD39E023BB6C45E4E436CFBD297
C:\WINDOWS\system32\wscntfy.exe --a--- 13824 bytes [12:00 28/02/2006] [12:00 28/02/2006] 49911DD39E023BB6C45E4E436CFBD297
Searching for "atapi.sys"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys --a--- 96512 bytes [04:02 14/07/2009] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys --a--- 96512 bytes [00:57 27/09/2008] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\atapi.sys --a--- 95360 bytes [12:00 28/02/2006] [12:00 28/02/2006] CDFE4411A69C224BD1D11B2DA92DAC51
-=End Of File=-
_______________________________________________________________________
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/02/02 06:45
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: rootre~1.sys
Image Path: C:\WINDOWS\system32\drivers\rootre~1.sys
Address: 0xF79C0000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: c:\windows\temp\cf7bfe8b-92a4-4dc6-8df2-04bdb597ff4f.tmp
Status: Allocation size mismatch (API: 262144, Raw: 0)
Path: c:\windows\temp\470d584f-d531-41d7-b472-2c4ee654db7f.tmp
Status: Allocation size mismatch (API: 0, Raw: 65536)
==EOF==
also I get axwin frame window:svchost.exe application Error
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 06:16 on 02/02/2010 by HP_Owner (Administrator - Elevation successful)
========== filefind ==========
Searching for "scecli.dll"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll --a--- 181248 bytes [04:04 14/07/2009] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll --a--- 181248 bytes [01:00 27/09/2008] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\system32\dllcache\scecli.dll --a--c 180224 bytes [12:00 28/02/2006] [12:00 28/02/2006] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\system32\scecli.dll --a--- 180224 bytes [12:00 28/02/2006] [12:00 28/02/2006] 0F78E27F563F2AAF74B91A49E2ABF19A
Searching for "netlogon.dll"
C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll --a--- 408064 bytes [18:46 06/02/2009] [18:46 06/02/2009] 6C476D33D82F1054849790181E8F7772
C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll --a--- 408064 bytes [18:46 06/02/2009] [18:46 06/02/2009] 6C476D33D82F1054849790181E8F7772
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll --a--- 407040 bytes [04:04 14/07/2009] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll --a--- 407040 bytes [00:59 27/09/2008] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\system32\dllcache\netlogon.dll --a--c 407040 bytes [12:00 28/02/2006] [12:00 28/02/2006] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\system32\netlogon.dll --a--- 407040 bytes [12:00 28/02/2006] [12:00 28/02/2006] 96353FCECBA774BB8DA74A1C6507015A
Searching for "eventlog.dll"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll --a--- 56320 bytes [04:02 14/07/2009] [00:11 14/04/2008] 6D4FEB43EE538FC5428CC7F0565AA656
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll --a--- 56320 bytes [00:57 27/09/2008] [00:11 14/04/2008] 6D4FEB43EE538FC5428CC7F0565AA656
C:\WINDOWS\system32\dllcache\eventlog.dll --a--c 55808 bytes [12:00 28/02/2006] [12:00 28/02/2006] 82B24CB70E5944E6E34662205A2A5B78
C:\WINDOWS\system32\eventlog.dll --a--- 55808 bytes [12:00 28/02/2006] [12:00 28/02/2006] 82B24CB70E5944E6E34662205A2A5B78
Searching for "winlogon.exe"
C:\Documents and Settings\HP_Owner\Local Settings\Temp\wz8694\Malwarebytes Anti-Malware 1.44\winlogon.exe ------ 5115824 bytes [23:09 08/01/2010] [23:09 08/01/2010] E6111E6D0B99286F99C35B09835DB9BA
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe --a--- 507904 bytes [04:05 14/07/2009] [00:12 14/04/2008] ED0EF0A136DEC83DF69F04118870003E
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe --a--- 507904 bytes [01:01 27/09/2008] [00:12 14/04/2008] ED0EF0A136DEC83DF69F04118870003E
C:\WINDOWS\system32\dllcache\winlogon.exe --a--c 502272 bytes [12:00 28/02/2006] [12:00 28/02/2006] 01C3346C241652F43AED8E2149881BFE
C:\WINDOWS\system32\winlogon.exe --a--- 502272 bytes [12:00 28/02/2006] [12:00 28/02/2006] 01C3346C241652F43AED8E2149881BFE
Searching for "comres.dll"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\comres.dll --a--- 792064 bytes [04:02 14/07/2009] [00:11 14/04/2008] 1280A158C722FA95A80FB7AEBE78FA7D
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\comres.dll --a--- 792064 bytes [00:57 27/09/2008] [00:11 14/04/2008] 1280A158C722FA95A80FB7AEBE78FA7D
C:\WINDOWS\system32\comres.dll --a--- 792064 bytes [12:00 28/02/2006] [12:00 28/02/2006] 6728270CB7DBB776ED086F5AC4C82310
C:\WINDOWS\system32\dllcache\comres.dll --a--c 792064 bytes [12:00 28/02/2006] [12:00 28/02/2006] 6728270CB7DBB776ED086F5AC4C82310
Searching for "crypt32.dll"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\crypt32.dll --a--- 599040 bytes [04:02 14/07/2009] [00:11 14/04/2008] BDAAF79DD63F194434D31A74B9BB8B77
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\crypt32.dll --a--- 599040 bytes [00:57 27/09/2008] [00:11 14/04/2008] BDAAF79DD63F194434D31A74B9BB8B77
C:\WINDOWS\system32\crypt32.dll --a--- 597504 bytes [12:00 28/02/2006] [12:00 28/02/2006] EFC958396A7A7EF7E6D4A52B97512E18
C:\WINDOWS\system32\dllcache\crypt32.dll --a--c 597504 bytes [12:00 28/02/2006] [12:00 28/02/2006] EFC958396A7A7EF7E6D4A52B97512E18
Searching for "gpedit.dll"
No files found.
Searching for "rundll32.exe"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\rundll32.exe --a--- 33280 bytes [04:04 14/07/2009] [00:12 14/04/2008] 037B1E7798960E0420003D05BB577EE6
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\rundll32.exe --a--- 33280 bytes [01:00 27/09/2008] [00:12 14/04/2008] 037B1E7798960E0420003D05BB577EE6
C:\WINDOWS\system32\dllcache\rundll32.exe --a--c 33280 bytes [12:00 28/02/2006] [12:00 28/02/2006] DA285490BBD8A1D0CE6623577D5BA1FF
C:\WINDOWS\system32\rundll32.exe --a--- 33280 bytes [12:00 28/02/2006] [12:00 28/02/2006] DA285490BBD8A1D0CE6623577D5BA1FF
Searching for "sfc.dll"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sfc.dll --a--- 5120 bytes [04:04 14/07/2009] [00:12 14/04/2008] 96E1C926F22EE1BFBAE82901A35F6BF3
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\sfc.dll --a--- 5120 bytes [01:00 27/09/2008] [00:12 14/04/2008] 96E1C926F22EE1BFBAE82901A35F6BF3
C:\WINDOWS\system32\dllcache\sfc.dll --a--c 5120 bytes [12:00 28/02/2006] [12:00 28/02/2006] E8A12A12EA9088B4327D49EDCA3ADD3E
C:\WINDOWS\system32\sfc.dll --a--- 5120 bytes [12:00 28/02/2006] [12:00 28/02/2006] E8A12A12EA9088B4327D49EDCA3ADD3E
Searching for "svchost.exe"
C:\Program Files\svchost.exe --a--- 37376 bytes [18:10 01/02/2010] [18:10 01/02/2010] 1EDC2204B5DC0A1C0B5793A1FCD98EE8
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\svchost.exe --a--- 14336 bytes [04:05 14/07/2009] [00:12 14/04/2008] 27C6D03BCDB8CFEB96B716F3D8BE3E18
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe --a--- 14336 bytes [01:00 27/09/2008] [00:12 14/04/2008] 27C6D03BCDB8CFEB96B716F3D8BE3E18
C:\WINDOWS\system32\dllcache\svchost.exe --a--c 14336 bytes [12:00 28/02/2006] [12:00 28/02/2006] 8F078AE4ED187AAABC0A305146DE6716
C:\WINDOWS\system32\svchost.exe --a--- 14336 bytes [12:00 28/02/2006] [12:00 28/02/2006] 8F078AE4ED187AAABC0A305146DE6716
Searching for "cngaudit.dll"
No files found.
Searching for "beep.sys"
C:\WINDOWS\system32\dllcache\beep.sys --a--c 4224 bytes [12:00 28/02/2006] [12:00 28/02/2006] DA1F27D85E0D1525F6621372E7B685E9
C:\WINDOWS\system32\drivers\beep.sys --a--- 4224 bytes [12:00 28/02/2006] [12:00 28/02/2006] DA1F27D85E0D1525F6621372E7B685E9
Searching for "wscntfy.exe"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\wscntfy.exe --a--- 13824 bytes [04:05 14/07/2009] [00:12 14/04/2008] F92E1076C42FCD6DB3D72D8CFE9816D5
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wscntfy.exe --a--- 13824 bytes [01:01 27/09/2008] [00:12 14/04/2008] F92E1076C42FCD6DB3D72D8CFE9816D5
C:\WINDOWS\system32\dllcache\wscntfy.exe --a--c 13824 bytes [12:00 28/02/2006] [12:00 28/02/2006] 49911DD39E023BB6C45E4E436CFBD297
C:\WINDOWS\system32\wscntfy.exe --a--- 13824 bytes [12:00 28/02/2006] [12:00 28/02/2006] 49911DD39E023BB6C45E4E436CFBD297
Searching for "atapi.sys"
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys --a--- 96512 bytes [04:02 14/07/2009] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys --a--- 96512 bytes [00:57 27/09/2008] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\atapi.sys --a--- 95360 bytes [12:00 28/02/2006] [12:00 28/02/2006] CDFE4411A69C224BD1D11B2DA92DAC51
-=End Of File=-
_______________________________________________________________________
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/02/02 06:45
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: rootre~1.sys
Image Path: C:\WINDOWS\system32\drivers\rootre~1.sys
Address: 0xF79C0000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: c:\windows\temp\cf7bfe8b-92a4-4dc6-8df2-04bdb597ff4f.tmp
Status: Allocation size mismatch (API: 262144, Raw: 0)
Path: c:\windows\temp\470d584f-d531-41d7-b472-2c4ee654db7f.tmp
Status: Allocation size mismatch (API: 0, Raw: 65536)
==EOF==